Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Premium Land with House for Sale
anil1961
Updated:
Yesterday at 10:15 AM
AWS Certified Solutions Architect-Associate + AWS Certified Cloud Practitioner
Sanjeewani95
Updated:
Wednesday at 8:16 PM
🚀 එක පැකේජ් එකයි - මාසෙටම Unlimited Internet! 🌐
sayuru bandara
Updated:
Tuesday at 10:57 AM
🎬 CapCut Pro 1 Month Access! LKR 600
sayuru bandara
Updated:
Tuesday at 10:55 AM
🚀 Google One AI PRO Plan (Gemini Pro Activation) – 18 Months Access! LKR 2200
sayuru bandara
Updated:
Tuesday at 10:53 AM
Electronics
Vehicles
Property
Search
Reply to thread
Forums
Computers & Internet
Problems and Troubleshooting
මේක ransomware එකක්ද, නැත්තන් worm එකක්ද?
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="charitha2011" data-source="post: 25530829" data-attributes="member: 331367"><p><strong><span style="font-size: 18px"><span style="color: rgb(184, 49, 47)">Infection Channel:</span></span></strong></p><p>Dropped by other malware, Downloaded from the Internet, Via physical/removable drives</p><p>This worm arrives via removable drives. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.</p><p></p><p>It drops an AUTORUN.INF file to automatically execute the copies it drops when a user accesses the drives of an affected system.</p><p></p><p>It steals system information.</p><p></p><p></p><p><strong><span style="font-size: 18px"><span style="color: rgb(184, 49, 47)">Arrival Details</span></span></strong></p><p></p><p><u>This worm arrives via removable drives.</u></p><p></p><p>It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.</p><p></p><p><span style="color: rgb(251, 160, 38)"><u><strong><span style="font-size: 18px">SOLUTION</span></strong></u></span></p><p></p><p></p><p><strong>Step 1</strong></p><p></p><p>Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must <a href="http://about-threats.trendmicro.com/SystemRestore.aspx?language=us" target="_blank">disable <em>System Restore</em></a> to allow full scanning of their computers.</p><p></p><p></p><p><strong>Step 2</strong></p><p></p><p>Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.</p><p></p><p></p><p><strong>Step 3</strong></p><p></p><p>Restart in Safe Mode</p><p></p><p></p><p><strong>Step 4</strong></p><p></p><p>Search and delete <em>AUTORUN.INF</em> files created by WORM_RASITH.A that contain these strings</p><p></p><p><strong>[AutoRun]</strong></p><p><strong>action=Open</strong></p><p><strong>shell\execute=kabe.bat</strong></p><p><strong>shell\explore\command=kabe.bat</strong></p><p><strong>USEAUTOPLAY=1</strong></p><p><strong>shell\Open\command=kabe.bat</strong></p><p><strong>shell\Autorun\command=kabe.bat</strong></p><p><strong>shell\Search\command=kabe.bat</strong></p><p><strong></strong></p><p><strong></strong></p><p><strong>Step 5</strong></p><p></p><p>Search and delete this file</p><p></p><p>[ Learn More ]</p><p>There may be some files that are hidden. Please make sure you check the <em>Search Hidden Files and Folders</em> checkbox in the "More advanced options" option to include all hidden files and folders in the search result.</p><ul> <li data-xf-list-type="ul">%User Startup%\msfold.exe</li> <li data-xf-list-type="ul">%User Temp%\sajith_and_rasini.db</li> <li data-xf-list-type="ul">%User Temp%\i_love_you_rasini.db</li> </ul><p></p><p><strong>Step 6</strong></p><p></p><p>Restart in normal mode and scan your computer with Your Antivirus Guard</p><p></p><p></p><p><a href="https://www.trendmicro.com/vinfo/dk/threat-encyclopedia/malware/worm_rasith.a" target="_blank">More Infomation</a></p></blockquote><p></p>
[QUOTE="charitha2011, post: 25530829, member: 331367"] [B][SIZE=5][COLOR=rgb(184, 49, 47)]Infection Channel:[/COLOR][/SIZE][/B] Dropped by other malware, Downloaded from the Internet, Via physical/removable drives This worm arrives via removable drives. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It drops an AUTORUN.INF file to automatically execute the copies it drops when a user accesses the drives of an affected system. It steals system information. [B][SIZE=5][COLOR=rgb(184, 49, 47)]Arrival Details[/COLOR][/SIZE][/B] [U]This worm arrives via removable drives.[/U] It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. [COLOR=rgb(251, 160, 38)][U][B][SIZE=5]SOLUTION[/SIZE][/B][/U][/COLOR] [B]Step 1[/B] Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must [URL='http://about-threats.trendmicro.com/SystemRestore.aspx?language=us']disable [I]System Restore[/I][/URL] to allow full scanning of their computers. [B]Step 2[/B] Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step. [B]Step 3[/B] Restart in Safe Mode [B]Step 4[/B] Search and delete [I]AUTORUN.INF[/I] files created by WORM_RASITH.A that contain these strings [B][AutoRun] action=Open shell\execute=kabe.bat shell\explore\command=kabe.bat USEAUTOPLAY=1 shell\Open\command=kabe.bat shell\Autorun\command=kabe.bat shell\Search\command=kabe.bat Step 5[/B] Search and delete this file [ Learn More ] There may be some files that are hidden. Please make sure you check the [I]Search Hidden Files and Folders[/I] checkbox in the "More advanced options" option to include all hidden files and folders in the search result. [LIST] [*]%User Startup%\msfold.exe [*]%User Temp%\sajith_and_rasini.db [*]%User Temp%\i_love_you_rasini.db [/LIST] [B]Step 6[/B] Restart in normal mode and scan your computer with Your Antivirus Guard [URL='https://www.trendmicro.com/vinfo/dk/threat-encyclopedia/malware/worm_rasith.a']More Infomation[/URL] [/QUOTE]
Insert quotes…
Verification
Hata thunen beduwama keeyada? (60 bedeema thuna)
Post reply
Top
Bottom