<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: THB and Jammer Virus Removal</title>
	<atom:link href="http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/</link>
	<description>Inspired by Technology</description>
	<pubDate>Sun, 01 Aug 2010 06:36:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Abhijith BR</title>
		<link>http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/comment-page-1/#comment-805</link>
		<dc:creator>Abhijith BR</dc:creator>
		<pubDate>Thu, 29 Apr 2010 07:43:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.techlemon.com/?p=479#comment-805</guid>
		<description>Hi,
Here's some info about that THB malware.

C:\WINDOWS\system32\win.dll\avgs.exe
C:\WINDOWS\system32\win.dll\Desktop.ini
C:\WINDOWS\system32\win.dll\DLL.ico
C:\WINDOWS\system32\win.dll\drivelist.txt
C:\WINDOWS\system32\win.dll\Icon.ico
C:\WINDOWS\system32\win.dll\reproduce.txt
C:\WINDOWS\system32\win.dll\script1.txt
C:\WINDOWS\system32\win.dll\std.txt
C:\WINDOWS\system32\win.dll\thb.ico
C:\WINDOWS\system32\win.dll\win.exe
C:\WINDOWS\system32\win.dll\win.mp3
C:\WINDOWS\system32\win.dll\reg.bkp\autorun.inf
c:\thb.ico

These are the files which distributed by %$thb$% malware.
This malware also includes its source code in that directory.
The source code file are,
C:\WINDOWS\system32\win.dll\reproduce.txt
C:\WINDOWS\system32\win.dll\script1.txt
C:\WINDOWS\system32\win.dll\std.txt

the executable avgs.exe and win.exe are the compilers for the scripts.
Its purely written in A********y language.
Its a gud language, but everyone is using this for writing malwares.

The registry entries made by the malware,

HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
It checks for that value, then if it is not 0, sets to 0

HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run,winlogon,C:\WINDOWS\system32\win.dll\win.exe C:\WINDOWS\system32\win.dll\std.txt
look at this regentry, it sets the winlogon value to Win.exe + the source code.

Easy Cure:
1,Close the malware processes(win.exe, avgs.exe)
2,repair the registry keys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
go to this location and set "CheckedValue" to 1
3, delete the folder named C:\WINDOWS\system32\win.dll, including its contents.
4, delete C:\autorun.inf and c:\winthb.exe
5, finally rename the c:\ drive and give it a null name. The feaky icon'll change.

Enjoy the Computing!</description>
		<content:encoded><![CDATA[<p>Hi,<br />
Here&#8217;s some info about that THB malware.</p>
<p>C:\WINDOWS\system32\win.dll\avgs.exe<br />
C:\WINDOWS\system32\win.dll\Desktop.ini<br />
C:\WINDOWS\system32\win.dll\DLL.ico<br />
C:\WINDOWS\system32\win.dll\drivelist.txt<br />
C:\WINDOWS\system32\win.dll\Icon.ico<br />
C:\WINDOWS\system32\win.dll\reproduce.txt<br />
C:\WINDOWS\system32\win.dll\script1.txt<br />
C:\WINDOWS\system32\win.dll\std.txt<br />
C:\WINDOWS\system32\win.dll\thb.ico<br />
C:\WINDOWS\system32\win.dll\win.exe<br />
C:\WINDOWS\system32\win.dll\win.mp3<br />
C:\WINDOWS\system32\win.dll\reg.bkp\autorun.inf<br />
c:\thb.ico</p>
<p>These are the files which distributed by %$thb$% malware.<br />
This malware also includes its source code in that directory.<br />
The source code file are,<br />
C:\WINDOWS\system32\win.dll\reproduce.txt<br />
C:\WINDOWS\system32\win.dll\script1.txt<br />
C:\WINDOWS\system32\win.dll\std.txt</p>
<p>the executable avgs.exe and win.exe are the compilers for the scripts.<br />
Its purely written in A********y language.<br />
Its a gud language, but everyone is using this for writing malwares.</p>
<p>The registry entries made by the malware,</p>
<p>HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL<br />
It checks for that value, then if it is not 0, sets to 0</p>
<p>HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run,winlogon,C:\WINDOWS\system32\win.dll\win.exe C:\WINDOWS\system32\win.dll\std.txt<br />
look at this regentry, it sets the winlogon value to Win.exe + the source code.</p>
<p>Easy Cure:<br />
1,Close the malware processes(win.exe, avgs.exe)<br />
2,repair the registry keys<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL<br />
go to this location and set &#8220;CheckedValue&#8221; to 1<br />
3, delete the folder named C:\WINDOWS\system32\win.dll, including its contents.<br />
4, delete C:\autorun.inf and c:\winthb.exe<br />
5, finally rename the c:\ drive and give it a null name. The feaky icon&#8217;ll change.</p>
<p>Enjoy the Computing!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: narayan</title>
		<link>http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/comment-page-1/#comment-773</link>
		<dc:creator>narayan</dc:creator>
		<pubDate>Thu, 28 May 2009 17:26:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.techlemon.com/?p=479#comment-773</guid>
		<description>this is the e mail address


narayankg@aim.com


the above guys who tried it i believe it worked for them.. u guys are also encouraged for posting me.... lets BE FRIENDS !!!

waiting for the response very eagerly</description>
		<content:encoded><![CDATA[<p>this is the e mail address</p>
<p><a href="mailto:narayankg@aim.com">narayankg@aim.com</a></p>
<p>the above guys who tried it i believe it worked for them.. u guys are also encouraged for posting me&#8230;. lets BE FRIENDS !!!</p>
<p>waiting for the response very eagerly</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: narayan</title>
		<link>http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/comment-page-1/#comment-772</link>
		<dc:creator>narayan</dc:creator>
		<pubDate>Thu, 28 May 2009 17:24:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.techlemon.com/?p=479#comment-772</guid>
		<description>i tried with this, but i was not able to find a file named  "win.exe".... actually 1st i tried for a 1st aid, which dint work, so dint try for a complete cure.... my question is if i reinstall my windows will it go &#38; how does the computer got affected by JAMMER VIRUS.... does make the comp performance slow or something related to that.... will be very happy if i get the troubleshooting steps in my e mail address mentioned above.... will be happy if i get is soon


thanks in advance

narayan (can call me as rocky)</description>
		<content:encoded><![CDATA[<p>i tried with this, but i was not able to find a file named  &#8220;win.exe&#8221;&#8230;. actually 1st i tried for a 1st aid, which dint work, so dint try for a complete cure&#8230;. my question is if i reinstall my windows will it go &amp; how does the computer got affected by JAMMER VIRUS&#8230;. does make the comp performance slow or something related to that&#8230;. will be very happy if i get the troubleshooting steps in my e mail address mentioned above&#8230;. will be happy if i get is soon</p>
<p>thanks in advance</p>
<p>narayan (can call me as rocky)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maya</title>
		<link>http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/comment-page-1/#comment-771</link>
		<dc:creator>maya</dc:creator>
		<pubDate>Wed, 06 May 2009 09:10:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.techlemon.com/?p=479#comment-771</guid>
		<description>This article helps me a lot.thank you very much..</description>
		<content:encoded><![CDATA[<p>This article helps me a lot.thank you very much..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arunjith</title>
		<link>http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/comment-page-1/#comment-752</link>
		<dc:creator>Arunjith</dc:creator>
		<pubDate>Thu, 29 Jan 2009 04:40:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.techlemon.com/?p=479#comment-752</guid>
		<description>@Arun, you can just follow the steps mentioned. It will work. Techlemon does not have a ready executable file to do this.</description>
		<content:encoded><![CDATA[<p>@Arun, you can just follow the steps mentioned. It will work. Techlemon does not have a ready executable file to do this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arun</title>
		<link>http://www.techlemon.com/2008/12/30/thb-jammervirus-removal/comment-page-1/#comment-748</link>
		<dc:creator>arun</dc:creator>
		<pubDate>Fri, 23 Jan 2009 06:11:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.techlemon.com/?p=479#comment-748</guid>
		<description>sir i have same problem, but not able to follow. so plz give me a executable file to delete the virus</description>
		<content:encoded><![CDATA[<p>sir i have same problem, but not able to follow. so plz give me a executable file to delete the virus</p>
]]></content:encoded>
	</item>
</channel>
</rss>
