<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Virus from Surigao	</title>
	<atom:link href="https://nelson.ph/2008/10/virus-from-surigao/feed/" rel="self" type="application/rss+xml" />
	<link>https://nelson.ph/2008/10/virus-from-surigao/</link>
	<description>Life is not all beer and skittles</description>
	<lastBuildDate>Mon, 14 Sep 2009 07:09:22 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.2</generator>
	<item>
		<title>
		By: kang		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1303</link>

		<dc:creator><![CDATA[kang]]></dc:creator>
		<pubDate>Mon, 14 Sep 2009 07:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1303</guid>

					<description><![CDATA[check this link, instead. :) 
http://pointblank.i.ph/blogs/pointblank/2008/01/26/getting-rid-of-autruninf/]]></description>
			<content:encoded><![CDATA[<p>check this link, instead. 🙂<br />
<a href="http://pointblank.i.ph/blogs/pointblank/2008/01/26/getting-rid-of-autruninf/" rel="nofollow ugc">http://pointblank.i.ph/blogs/pointblank/2008/01/26/getting-rid-of-autruninf/</a></p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Fefe		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1296</link>

		<dc:creator><![CDATA[Fefe]]></dc:creator>
		<pubDate>Tue, 11 Aug 2009 21:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1296</guid>

					<description><![CDATA[Man, my girlfriend has the same virus, you are not the only one. We search for the solution but we don&#039;t find.]]></description>
			<content:encoded><![CDATA[<p>Man, my girlfriend has the same virus, you are not the only one. We search for the solution but we don&#8217;t find.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: HELP		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1243</link>

		<dc:creator><![CDATA[HELP]]></dc:creator>
		<pubDate>Thu, 20 Nov 2008 11:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1243</guid>

					<description><![CDATA[Aw help.
Meron na rin to sakin ba...
DI MO RIN MAOPEN ANG MGA HARD DRIVE DAHIL DITO!!!
 TULLONNNGG!!!!!
PANO TO ALISIN!????]]></description>
			<content:encoded><![CDATA[<p>Aw help.<br />
Meron na rin to sakin ba&#8230;<br />
DI MO RIN MAOPEN ANG MGA HARD DRIVE DAHIL DITO!!!<br />
 TULLONNNGG!!!!!<br />
PANO TO ALISIN!????</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Hiro		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1242</link>

		<dc:creator><![CDATA[Hiro]]></dc:creator>
		<pubDate>Sat, 15 Nov 2008 21:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1242</guid>

					<description><![CDATA[Ah dear. @_@

That English, I do not care to deduce... but that&#039;s insane. &#062;&#060;]]></description>
			<content:encoded><![CDATA[<p>Ah dear. @_@</p>
<p>That English, I do not care to deduce&#8230; but that&#8217;s insane. &gt;&lt;</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: iam a victim!		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1241</link>

		<dc:creator><![CDATA[iam a victim!]]></dc:creator>
		<pubDate>Thu, 13 Nov 2008 07:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1241</guid>

					<description><![CDATA[deim!! na infect din ang system ko nitoh. and until now. la akong mahanap na solution!! sheeet. tagal na un sa comp ko bah. baka magka loko2 na yun. deim!! =(]]></description>
			<content:encoded><![CDATA[<p>deim!! na infect din ang system ko nitoh. and until now. la akong mahanap na solution!! sheeet. tagal na un sa comp ko bah. baka magka loko2 na yun. deim!! =(</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: rina		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1249</link>

		<dc:creator><![CDATA[rina]]></dc:creator>
		<pubDate>Mon, 10 Nov 2008 19:57:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1249</guid>

					<description><![CDATA[okay this is the secret way i get rid of newly created virus..

run windows from safe mode, or better yet use a boot disc that can boot to command prompt

1. boot windows in &quot;safe mode with command prompt&quot; to see this option press &quot;F8&quot; right before the windows loading screen.

2. it might tell you to log in as administrator or your account. select administrator for now if it asked you.

3. in command prompt go to the root directory of your drive.
&quot;type cd&quot; and you wpuld be in the root directory or &quot;c:&quot;

4. at c: type &quot;dir /a:h&quot;
this will display all the hidden files that you cannot see in windows even though you have enabled the &quot;show hidden files option&quot;

the files that you are looking for are

autorun.inf
*.com
*.vbs
*.exe
*.dll

these files are important do not ever erase them since it&#039;s windows boot files. These files are the only ones that should be in the root directory of c: except  the folders.
boot.ini
IO.sys
nrdlr
MSDOS.sys
NTDETECT.COM

if there is an autorun.inf and other suspicious files then good we could proceed further.

5. autorun.inf is not evil it&#039;s job is to auto execute a program when browse or inserted (usb or dics). it&#039;s just being exploited by virus makers. Since it&#039;s job is to execute a certain file we would now what files is the virus.

at c: type &quot;type autorun.inf&quot;

ex. C:type autorun.inf, you&#039;ll see bunch of text like these

;qa5dDjAa222Ljosw0aoKqa14LsrAikkrAfs3jL3p5Aawo140fL73sLfD3akq3
[AutoRun]
;2L3HkloslJaikioJUek2ijA83S35kpJpaAr08sZl8aJ2walk4d4ddKwKeKsA4wad042639arCi27s0k3LKO3aKsawDik5sowD4rkKkdaw2Df
open=obehha.com
;kOlokdajw3K17il8l1saKKsKe4a92dsLqskK0LkLiH4Kwsd
shellopenCommand=obehha.com
;aDKS2a4o0j4d5s3lDL33LikoofdswKqlf4c
shellopenDefault=1
;D
shellexploreCommand=obehha.com
;4fjK2eAw3jf3Dfsk6sZKeLA9qS44L152llasDdi24sp7Dwwwds0kHsdak38K5fsaomkwoJkilr0okka23Z

but the ones that matter are these
open=obehha.com
shellopenCommand=obehha.com
shellexploreCommand=obehha.com

as you can see at these example that &quot;obehha.com&quot; is the virus or tha culprit that spreads the virus

take note of that file since we will be deleting that.

6. at c: &quot;type del (virus name) /f/q/s/a&quot;
ex.
c:del obehha.com /f/q/s/a

if the virus has a unique name, you can use wildcards commands incase the virus has dl files included

ex. C:del obehha.* /f/q/s/a or c:del obehha*.* /f/q/s/a

7. do that command to all drives including your usb devices.
to change drives type the drive letter plus collon sign &quot;:&quot;

 at c: and going to d: type d:
ex c:d:
and you would be at D: and type dir /a:h to check if that same file exixt there and you the del &quot;virus&quot; /f/q/s/a to delete it

becarefull using that command since it searches all files within the drive, hidden or not, in a folder or not, system files or not and deletes it permanently. normal del (delete) won&#039;t remove the file since it&#039;s a hidden system files.

8. after deleting the file go back to c: and delete all suspicious files just remember to write down the suspicious files your deleting we need that later.

9. you should also check the windows directory and system32 directory to navigate to them

at c: type &quot;cd windows&quot;
ex. c:cd windows and youll be inside the windows directory
c:windows
check for suspicious files by typing dir /a:h
then navigate to system32
at c:windows type cd system32
c:windowscd system32 you&#039;ll be inside the system32 directory
check for suspicious files by typing dir /a:h and delete it.

don&#039;t forget to also delete the autorun.inf. just ignore te other autorun.inf it deletes it doen&#039;t matter anyway

10. now your half done reboot again in safemode with command prompt and this time select you account. if no selection appears proceed to step 11.

11. again check the root directory of your c:  if the files return obviously you left the main virus undeleted.  if the suspicious deleted files are gone then good were making progress.

type explorer and the recognisable windows will apear and ask you about safemode and stuffs just click yes.

12. hope you have UnHookExec.inf or taskmanagerfix.exe in advance since we need to run it now. UnHookExec.inf is much powerfull since it reverts all change that the virus has made in your registry.

13. click &quot;run&quot; and type &quot;msconfig&quot; and a windoow will apear and select the &quot;startup&quot; tab and check for the files that you have deleted on the command column if it&#039;s there un tick the box and apply the setting.

14. click &quot;run&quot; and type &quot;regedit&quot; search all the suspicous files you wote down and delete all the strings that contain those command.

you can also find other files theat the virus execute other files related to it.

do not delete rundll just the files you wrote down
and if you see the virus is hooked with explorer just delete the virus name leving the explorer behind

it&#039;s very dangerous deleting stuffs on your registry.. tis is not neccessary though since the virus is gone. but the massage it displays or other changes the virus has made is still there. this is just for cleaning up the virus tracks. do not attemp to mess with the registry if your unsure what you are doing.

you can use ccleaner to do the cleaning for you. since you deleted the files and the registry cannot point, locate and execute that files. ccleaner will dellete it for you in a safe way.

all cleaning you need to do is the mountpoints2
in the registry click the computer then search for mountpoints2
you should see a bunch of folders with kind of resembles this names

{009ff59d-5cce-11dd-841e-001966656651}
{074add66-5a6e-11dd-9858-c3b868304521}
{0cf191a9-5a6d-11dd-ab2a-806e6f6e6963}
{0cf191aa-5a6d-11dd-ab2a-806e6f6e6963}
{0cf191ad-5a6d-11dd-ab2a-806e6f6e6963}

and at the bottom you&#039;ll see

C
CPC
D
E
F

depending how many drive letters you have.
if you browese those folders with weird names you&#039;ll find out how the virus speads or where it was executed and the virus names you wrote can be found there.

so delete all those folders leaving only

C
CPC
D
E
F

and also delete all &quot;folders&quot; that is inside

C
D
E
F

only CPC should have folders inside

and don&#039;t delete the keys inside
C
CPC
D
E
F
these key are namely &quot;default&quot; and &quot;baseclass&quot;

15. if everything goes right. you&#039;ll free youself from that virus and having to reformat again and again when faced with a new viirus.

if you can&#039;t remove the virus you can send it to me to be analyzed.

at safemode command prompt assuming you checked inside the autorun.inf and found out the file name of the virus

at c: type attrib -s -h -r &quot;Virus name&quot;
ex. c:attrib -s -h -r obehha.com

now that file should be visible in plain dir or windows

copy that file to a different folder or usb device zip or rar it with password and send it to me

tunay na email ko yan

pa delete na lang ng comment ko pag na save mo na sa notepad

di ko alam kung baket nawawala ang mga  (slash sign) sa dulo ng mga c: o d: sana sanay ka sa DOS/CMD]]></description>
			<content:encoded><![CDATA[<p>okay this is the secret way i get rid of newly created virus..</p>
<p>run windows from safe mode, or better yet use a boot disc that can boot to command prompt</p>
<p>1. boot windows in &#8220;safe mode with command prompt&#8221; to see this option press &#8220;F8&#8221; right before the windows loading screen.</p>
<p>2. it might tell you to log in as administrator or your account. select administrator for now if it asked you.</p>
<p>3. in command prompt go to the root directory of your drive.<br />
&#8220;type cd&#8221; and you wpuld be in the root directory or &#8220;c:&#8221;</p>
<p>4. at c: type &#8220;dir /a:h&#8221;<br />
this will display all the hidden files that you cannot see in windows even though you have enabled the &#8220;show hidden files option&#8221;</p>
<p>the files that you are looking for are</p>
<p>autorun.inf<br />
*.com<br />
*.vbs<br />
*.exe<br />
*.dll</p>
<p>these files are important do not ever erase them since it&#8217;s windows boot files. These files are the only ones that should be in the root directory of c: except  the folders.<br />
boot.ini<br />
IO.sys<br />
nrdlr<br />
MSDOS.sys<br />
NTDETECT.COM</p>
<p>if there is an autorun.inf and other suspicious files then good we could proceed further.</p>
<p>5. autorun.inf is not evil it&#8217;s job is to auto execute a program when browse or inserted (usb or dics). it&#8217;s just being exploited by virus makers. Since it&#8217;s job is to execute a certain file we would now what files is the virus.</p>
<p>at c: type &#8220;type autorun.inf&#8221;</p>
<p>ex. C:type autorun.inf, you&#8217;ll see bunch of text like these</p>
<p>;qa5dDjAa222Ljosw0aoKqa14LsrAikkrAfs3jL3p5Aawo140fL73sLfD3akq3<br />
[AutoRun]<br />
;2L3HkloslJaikioJUek2ijA83S35kpJpaAr08sZl8aJ2walk4d4ddKwKeKsA4wad042639arCi27s0k3LKO3aKsawDik5sowD4rkKkdaw2Df<br />
open=obehha.com<br />
;kOlokdajw3K17il8l1saKKsKe4a92dsLqskK0LkLiH4Kwsd<br />
shellopenCommand=obehha.com<br />
;aDKS2a4o0j4d5s3lDL33LikoofdswKqlf4c<br />
shellopenDefault=1<br />
;D<br />
shellexploreCommand=obehha.com<br />
;4fjK2eAw3jf3Dfsk6sZKeLA9qS44L152llasDdi24sp7Dwwwds0kHsdak38K5fsaomkwoJkilr0okka23Z</p>
<p>but the ones that matter are these<br />
open=obehha.com<br />
shellopenCommand=obehha.com<br />
shellexploreCommand=obehha.com</p>
<p>as you can see at these example that &#8220;obehha.com&#8221; is the virus or tha culprit that spreads the virus</p>
<p>take note of that file since we will be deleting that.</p>
<p>6. at c: &#8220;type del (virus name) /f/q/s/a&#8221;<br />
ex.<br />
c:del obehha.com /f/q/s/a</p>
<p>if the virus has a unique name, you can use wildcards commands incase the virus has dl files included</p>
<p>ex. C:del obehha.* /f/q/s/a or c:del obehha*.* /f/q/s/a</p>
<p>7. do that command to all drives including your usb devices.<br />
to change drives type the drive letter plus collon sign &#8220;:&#8221;</p>
<p> at c: and going to d: type d:<br />
ex c:d:<br />
and you would be at D: and type dir /a:h to check if that same file exixt there and you the del &#8220;virus&#8221; /f/q/s/a to delete it</p>
<p>becarefull using that command since it searches all files within the drive, hidden or not, in a folder or not, system files or not and deletes it permanently. normal del (delete) won&#8217;t remove the file since it&#8217;s a hidden system files.</p>
<p>8. after deleting the file go back to c: and delete all suspicious files just remember to write down the suspicious files your deleting we need that later.</p>
<p>9. you should also check the windows directory and system32 directory to navigate to them</p>
<p>at c: type &#8220;cd windows&#8221;<br />
ex. c:cd windows and youll be inside the windows directory<br />
c:windows<br />
check for suspicious files by typing dir /a:h<br />
then navigate to system32<br />
at c:windows type cd system32<br />
c:windowscd system32 you&#8217;ll be inside the system32 directory<br />
check for suspicious files by typing dir /a:h and delete it.</p>
<p>don&#8217;t forget to also delete the autorun.inf. just ignore te other autorun.inf it deletes it doen&#8217;t matter anyway</p>
<p>10. now your half done reboot again in safemode with command prompt and this time select you account. if no selection appears proceed to step 11.</p>
<p>11. again check the root directory of your c:  if the files return obviously you left the main virus undeleted.  if the suspicious deleted files are gone then good were making progress.</p>
<p>type explorer and the recognisable windows will apear and ask you about safemode and stuffs just click yes.</p>
<p>12. hope you have UnHookExec.inf or taskmanagerfix.exe in advance since we need to run it now. UnHookExec.inf is much powerfull since it reverts all change that the virus has made in your registry.</p>
<p>13. click &#8220;run&#8221; and type &#8220;msconfig&#8221; and a windoow will apear and select the &#8220;startup&#8221; tab and check for the files that you have deleted on the command column if it&#8217;s there un tick the box and apply the setting.</p>
<p>14. click &#8220;run&#8221; and type &#8220;regedit&#8221; search all the suspicous files you wote down and delete all the strings that contain those command.</p>
<p>you can also find other files theat the virus execute other files related to it.</p>
<p>do not delete rundll just the files you wrote down<br />
and if you see the virus is hooked with explorer just delete the virus name leving the explorer behind</p>
<p>it&#8217;s very dangerous deleting stuffs on your registry.. tis is not neccessary though since the virus is gone. but the massage it displays or other changes the virus has made is still there. this is just for cleaning up the virus tracks. do not attemp to mess with the registry if your unsure what you are doing.</p>
<p>you can use ccleaner to do the cleaning for you. since you deleted the files and the registry cannot point, locate and execute that files. ccleaner will dellete it for you in a safe way.</p>
<p>all cleaning you need to do is the mountpoints2<br />
in the registry click the computer then search for mountpoints2<br />
you should see a bunch of folders with kind of resembles this names</p>
<p>{009ff59d-5cce-11dd-841e-001966656651}<br />
{074add66-5a6e-11dd-9858-c3b868304521}<br />
{0cf191a9-5a6d-11dd-ab2a-806e6f6e6963}<br />
{0cf191aa-5a6d-11dd-ab2a-806e6f6e6963}<br />
{0cf191ad-5a6d-11dd-ab2a-806e6f6e6963}</p>
<p>and at the bottom you&#8217;ll see</p>
<p>C<br />
CPC<br />
D<br />
E<br />
F</p>
<p>depending how many drive letters you have.<br />
if you browese those folders with weird names you&#8217;ll find out how the virus speads or where it was executed and the virus names you wrote can be found there.</p>
<p>so delete all those folders leaving only</p>
<p>C<br />
CPC<br />
D<br />
E<br />
F</p>
<p>and also delete all &#8220;folders&#8221; that is inside</p>
<p>C<br />
D<br />
E<br />
F</p>
<p>only CPC should have folders inside</p>
<p>and don&#8217;t delete the keys inside<br />
C<br />
CPC<br />
D<br />
E<br />
F<br />
these key are namely &#8220;default&#8221; and &#8220;baseclass&#8221;</p>
<p>15. if everything goes right. you&#8217;ll free youself from that virus and having to reformat again and again when faced with a new viirus.</p>
<p>if you can&#8217;t remove the virus you can send it to me to be analyzed.</p>
<p>at safemode command prompt assuming you checked inside the autorun.inf and found out the file name of the virus</p>
<p>at c: type attrib -s -h -r &#8220;Virus name&#8221;<br />
ex. c:attrib -s -h -r obehha.com</p>
<p>now that file should be visible in plain dir or windows</p>
<p>copy that file to a different folder or usb device zip or rar it with password and send it to me</p>
<p>tunay na email ko yan</p>
<p>pa delete na lang ng comment ko pag na save mo na sa notepad</p>
<p>di ko alam kung baket nawawala ang mga  (slash sign) sa dulo ng mga c: o d: sana sanay ka sa DOS/CMD</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: linapuhan		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1248</link>

		<dc:creator><![CDATA[linapuhan]]></dc:creator>
		<pubDate>Thu, 30 Oct 2008 16:18:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1248</guid>

					<description><![CDATA[sagad na gid ko ya sa math.  :shock:  :laugh:  :faint:]]></description>
			<content:encoded><![CDATA[<p>sagad na gid ko ya sa math.  😯  :laugh:  :faint:</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: linapuhan		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1247</link>

		<dc:creator><![CDATA[linapuhan]]></dc:creator>
		<pubDate>Thu, 30 Oct 2008 16:13:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1247</guid>

					<description><![CDATA[uy nagsulod na comment ko nels. hehe, nagtest pa ko kay basi makapuyan lang ko sang type kun indi pa gid magsulod. ....
hmmm.... ano gani to sulat ko man? nalipat ko ah...
ah, ang mga virus nga ni bala, daw may suspetsa ako nga ang mga nagabaligya man lang sang mga antivirus ang gapang obra sini, dayon mahimo sila &quot;bulong&quot; kano abi sa amo na nga mga virus. o di vah? business gid. haisst. waay man ko choice, gamit man ko antivirus. hehe. free edition lang man.

your anti-spam asked 7+8 =?  ang sabat ko ay 15... kun makasulod ni comment ko, sagad na ko sa math. wahaha  :laugh:]]></description>
			<content:encoded><![CDATA[<p>uy nagsulod na comment ko nels. hehe, nagtest pa ko kay basi makapuyan lang ko sang type kun indi pa gid magsulod. &#8230;.<br />
hmmm&#8230;. ano gani to sulat ko man? nalipat ko ah&#8230;<br />
ah, ang mga virus nga ni bala, daw may suspetsa ako nga ang mga nagabaligya man lang sang mga antivirus ang gapang obra sini, dayon mahimo sila &#8220;bulong&#8221; kano abi sa amo na nga mga virus. o di vah? business gid. haisst. waay man ko choice, gamit man ko antivirus. hehe. free edition lang man.</p>
<p>your anti-spam asked 7+8 =?  ang sabat ko ay 15&#8230; kun makasulod ni comment ko, sagad na ko sa math. wahaha  :laugh:</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: linapuhan		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1246</link>

		<dc:creator><![CDATA[linapuhan]]></dc:creator>
		<pubDate>Thu, 30 Oct 2008 16:07:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1246</guid>

					<description><![CDATA[test]]></description>
			<content:encoded><![CDATA[<p>test</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Justin		</title>
		<link>https://nelson.ph/2008/10/virus-from-surigao/#comment-1245</link>

		<dc:creator><![CDATA[Justin]]></dc:creator>
		<pubDate>Thu, 30 Oct 2008 06:36:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.flirt-wind.net/?p=374#comment-1245</guid>

					<description><![CDATA[hmm that must be soo annoying. Maybe the only fix left is to reformat your PC.]]></description>
			<content:encoded><![CDATA[<p>hmm that must be soo annoying. Maybe the only fix left is to reformat your PC.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
