| Find/Invite Friends | Register | Calendar | Search | Today's Posts | Mark Forums Read |
| FAQ | Members List | Bongo Flava | Zilipendwa | Taarab | Injili |
|
|
#1 | |||||||||||
|
||||||||||||
|
Views: 8293
|
||||||||||||
|
#2
|
|||||||||||
|
|||||||||||
|
Habari Kwanza Sio Kweli Kwamba Komputer Yako Inapokuwa Na Odinga Unashidwa Kuandika Tovuti Kama Ni Hivyo Pc Yako Itakuwa Ina Madhara Mengine Tofauti
Hiyo Software Iliyoandikwa Hapo Ina Utata Mkubwa Mimi Siamini Hata Kidogo Njia Rahisi Ya Kuondoa Ondika Ni Kutumia Programu Ya Dup Killer Hiyo Ita Tafuta File Zote Za Odinga Za Kuzifuta Manually Au Unaweza Kutumia Windows Search Ukifanya Search Ukipata Odinga Delele Kisha Bonyeza Control Alt Delete , Utaona Odinga Katika Process , Pale Click End Task Inabidi Uende Haraka Sana |
|
#3
|
||||||||||||
|
||||||||||||
|
Well Shy,
I might be mistaken but I do believe if someone follows my instructions can get rid of it. Technical details This Trojan has a malicious payload. It is a Windows PE EXE file. The Trojan components may vary in size from 17KB to 286KB. Installation Once launched, the Trojan extracts a file with the following name from its body to the current user's desktop: Raila Odinga.gif and launches it. The user will see the following image: ![]() The Trojan also copies its executable file to the following directory: %System%\drivers\RailaOdinga.exe It also extracts the following file from its body: %Temp%\nswC.tmp\System.dll In order to ensure that the Trojan is launched automatically each time the system is booted, the Trojan adds a link to its executable file in the system registry: [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] @ = "%System%\drivers\RailaOdinga" The Trojan also creates the following shortcut: %Documents and Settings%\Start Menu \Programs\Autorun\RailaOdinga.lnk When this shortcut is run, the Trojan executable file will be launched. Payload The Trojan copies its executable file to all removable media under the following name: :\smss.exe It also copies the extracted image: :\Raila Odinga.gif stands for the letter of the removable disk. The Trojan creates an autorun.inf file in the root of the removable disk. This file will automatically launch the Trojan executable file when the user attempts to open the infected disk using Explorer. The Trojan also recursively copies its executable file to all folders on the removable disk. These copies use the names of files which are located in these folders together with an .exe extension. Removal instructions If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program: * Use Task Manager to terminate the Trojan process. * Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). * Delete the following system registry key parameter: [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] @ = "%System%\drivers\RailaOdinga" * Delete the following files: %Temp%\nswC.tmp\System.dll %System%\drivers\RailaOdinga.exe %Documents and Settings%\ Start Menu \Programs\Autorun\RailaOdinga.lnk * Delete the following file from the desktop: Raila Odinga.gif * Delete all copies of the Trojan from removable disks. * Delete the autorun.inf file from the root directory of all removable disks.
__________________
Ficha Upumbavu wako; Usiifiche Hekima yako! ![]() Thank you for supporting JF! <---(click to support us) Waliochangia 2010: <--- (click to read) JINSI YA KUCHANGIA JF<---(click to read) ![]() 24/7 Email SUPPORT: support@jamiiforums.com ![]() |
|
#4
|
||||||||||||
|
||||||||||||
|
And as per McAfee:
__________________
Ficha Upumbavu wako; Usiifiche Hekima yako! ![]() Thank you for supporting JF! <---(click to support us) Waliochangia 2010: <--- (click to read) JINSI YA KUCHANGIA JF<---(click to read) ![]() 24/7 Email SUPPORT: support@jamiiforums.com ![]() |
||||||||||||
|
#5
|
||||||||||||
|
||||||||||||
|
invisible I followed the steps from your first post while attending a neighbours computer, it worked perfectly. Thanks.
__________________
some people dream of success, while others wake up and work hard at it. |
|
#6
|
|||||||||||||||
|
|||||||||||||||
Once two other comments will come with same outcome we'll close the topic and keep it as RESOLVED.
__________________
Ficha Upumbavu wako; Usiifiche Hekima yako! ![]() Thank you for supporting JF! <---(click to support us) Waliochangia 2010: <--- (click to read) JINSI YA KUCHANGIA JF<---(click to read) ![]() 24/7 Email SUPPORT: support@jamiiforums.com ![]() |
|||||||||||||||
|
#7
|
|||||||||||
|
|||||||||||
|
I had that kind of virus (Raila Odinga) in my PC.
I cleaned it using Avira Antivirus and I no longer have such a nuisance. May be other antivirus remove, but I have not tried them. Regards Idimi |
|
#8
|
||||||||||||
|
||||||||||||
|
Mkuu Invisible,
Umenielimisha kitu kimoja muhimu sana. Nafikiri kumekuja mtindo wa hackers kujaribu kutumia websites ambazo zimezubaa katika masuala yote muhimu ya security. Ni vulnerability hii ndio inasababisha websites hizi zitumiwe kuweka Trojans na harmful executable worms na kuharibu computer za watu. Sasa naona ni vizuri kwamba tunaelimishana. Weekend njema.
__________________
"Nothing in all the world is more dangerous than sincere ignorance and conscientious stupidity"- Martin Luther King Jr |
|
#9
|
||||||||||||
|
||||||||||||
|
__________________
Ficha Upumbavu wako; Usiifiche Hekima yako! ![]() Thank you for supporting JF! <---(click to support us) Waliochangia 2010: <--- (click to read) JINSI YA KUCHANGIA JF<---(click to read) ![]() 24/7 Email SUPPORT: support@jamiiforums.com ![]() |
|
#10
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
I see no more questions pertaining to Raila Odinga virus, hope the remedies that we suggested here have solved the problem.
Long live JF
«
Previous Thread
|
Next Thread
»
Tuma Ukurasa huu kwa rafiki yako! All times are GMT +3. The time now is 10:50 PM.
Powered by JamiiForums.com
Copyrights reserved to JamiiForums.com | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||