Der er endnu et dum virus i omløb på kazaa (sikkert flere), denne her kommer
ind med exe filer som mange andre virus, måden den viser sig på er at der
ikke sker en skid når man dobbelklikker på den, dernæst stjæler den
totalmeget CPU kraft og smitter alle exe filer i din shared folder samt
deler dit C-Drev med andre kazaa brugere, også selvom du ikke deler
filer.......Den har nu været fremme i noget tid uden at være blevet godkendt
som virus......og dog
http://housecall.trendmicro.com/housecall/start_corp.asp kan genkende den,
men ikke gøre noget ved den, FEDT !!!
På min computer fandt jeg den her:
C:\WINDOWS\Temp\Dust.exe
C:\WINDOWS\System32\dust.exe
Har du samme problem vil jeg henvise til denne side her:
http://makeashorterlink.com/?P29D227E6
******************************************************
.....og er siden væk kan du læse hvordan du får løst problemet her:
I just wanted to start a thread about this. I downloaded something off of
KazAa that was infected with this trojan. Though it's not an officially
recognized virus at this point. The file name will always be 'Dust.exe' This
virus corrupted every .exe file in my "My Shared Folder" on my computer for
KazAa. File sizes will range depending on what that .exe was originally.
This thing kills your system resources and loads along side with
explorer.exe. I did a regedit search for "Dust.exe" and found it had
implanted itself along side with explorer in these registry keys.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run
probably also in here
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run
Also you can instantly tell if you have it if you find Dust.exe on "C:\"
root. At this point when I realized I had the dust.exe trojan... I looked in
My Shared Folder and tried executing one of my exe's... well when I double
clicked on one, nothing happened and the exe's were missing their program
icons, immediately after double clicking on it, it created a .bat file with
this in the body of the file "Dust.exe". I was pissed off so this is what I
did to remove it.. seeing Symantec has NOTHING about it. and only
Computing.net has forum threads about this trojan with people all confused
about what to do. Here are MY steps to removing this virus under Windows XP.
Step 1: Analyze your computer for other viruses by going into Safe mode and
performing a Full Scan on all of your harddrives.
*To get into safe mode for Windows XP, boot up your computer. Then before
the "Windows XP loader" begins, tap on the F8 key repeatedly until you get
to a Selection menu screen. Once there select "Safe Mode with Networking".
(You can also select "Safe Mode" alone if you wish, though with "Safe Mode
with Networking" you can have internet access while under Safe Mode so you
can do some research on how to FULLY remove any viruses if you find any.
I.E. Such as locating and removing registry key entries or obtaining "Fix
Tools for certain viruses")
Step 2: If you locate OTHER viruses, remove them fully and make sure they
are FULLY gone, we don't want any OTHER viruses screwing aroung with us in
this process. (Dust.exe is not recognized as an official virus/trojan so you
wont find it here. None of the virus scanners that I know of, have
officially recognized it at this point)
Step 3: Once the Full Virus scan is complete and if you locate any viruses,
remove them accordingly.
Now Do a "Find" search on XP for the filename "Dust.exe" and delete ALL of
the files that come up. You will/should see Dust.exe files in these
locations if you have the virus:
C:\
c:\windows
c:\windows\temp
c:\windows\system32
*windows can be replaced with whatever "Windows Folder name" variable your
Windows installation was installed into.
You will also need to delete ALL of the .exe files in your "My Shared
Folder" for KazAa... or the Definately infected shared p2p folder. I say
this because I'm not sure if anyone else has gotten this virus under any
other p2p program other than KazAa..
Note: Delete on the exe files if they match my notice in the above notes..
if you notice all of the program .exe files in your "My Shared Folder" are
missing their program icons and they were supposed to have them.. also if
when you double click on the majority of them and they dont obviously
execute.. and if you notice the presence of .bat files in your shared folder
with the "Dust.exe" line. It should be the only line in those .bat files.
Step 4: REG ASSASSIN TIME - Now you will need to venture into the registry..
I only advise you proceed if you are comfortable with the registry and know
for certain that I am not bull****ing you about this. If you wish do this.
• Run regedit
• Navigate to this registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Shell
it will look like this: refer to picture 1 below. I have attached to.
Afterwards it should look like this: refer to picture 2 below.
now the keys may be in these keys too. In my case they were. These are the
keys that can be found in the msconfig "Startup" tab.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run
probably also in here
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run
Once thats edited exit out of regedit and reboot your computer. You should
be clean of this damn Dust.exe file. I noticed the only serious things it
does is:
• Corrupts all .exe file in My Shared Folder for KazAa
• Kills system resources.. I didnt really notice this one, because I have a
gig of ram.. but on desktop alone my XP PRO system usually uses like 170mb
steady... but with this Dust.exe infection it jumped to a shakey ~520mb and
my cpu flucuated from 50% to 30% to 90%.. ~Very Annoying~
I imagine on lower spec computers, that this virus would have obvious
effects.
I hope I helped.. I also hope my fellow EOCF members and other visitors dont
think I'm pulling your chain with this. I am a professional computer expert
at a few computer stores in Massachusetts along with being a Professional
Web Designer.. and I hate when people run these hoaxes.. though I'm not one
of those people and I just needed to vent so I could help someone out. I'm
just mad that Symantec or any other company has not recognized this virus. I
just keep getting this Dust.exe trojan over and over again, so my KazAa use
is to a bare minimum for now. GOOD LUCK
-Rico aka(Midnight)