Recently a new virus is determined and found easy to remove. It is named as W32.Yimfoca
It is considered as itself less risky but more dangerous because it can download more malware.
| Discovered | May 2,2010 |
| Updated | May 3,2010 |
| Type | Worm |
| Infection length | Varies |
| System Affected | Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000 |
Main target of the virus is the users using Yahoo! Messenger
To remove this virus completely we have to follow following steps:
- Disable System Restore (Windows Me/XP).
- Update the virus definitions.
- Run a full system scan.
- Delete any values added to the registry.
Disable System Restore
This virus mainly makes a restore point where virus includes itself within it. So temporary disable them.
To disable them in windows XP:-
- On the Desktop, Right Click on My Computer
- Select the System Restore Tab
- Mark the “Turn Off System Restore” to disable and UnMark to Enable
- Click Apply on the Bottom of the Dialog Box to save the settings.
- A message “This deletes all existing restore points” will appear, click Yes to disable.
- Click OK.
Update the virus Definitions
Many of the antivirus have been updated with this new virus definition and it is not hard to delete the virus. So use good antivirus and update it.
Some of the antivirus softwares that may help you are:-
Symantec, Kaspersky, Eset antivirus.
Run a full system scan
For the full system scan it will be more fruitful if you do it in Safe mode. So open the computer in Safe mode and run the antivirus software. Be sure that you checked full system scan. Run the scan.
After the completion of full system scan restart the computer in normal mode.
Delete values in the registry
- Click Start > Run.
- Type regedit.
- Click OK.
- Navigate to and delete the following registry entry:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”Firewall Administrating” = “%Windir%\infocard.exe”
- Exit the Registry Editor.
If registry editor is disabled then follow this <download and run this tool>
You are now free from the Yahoo! Messenger virus.
Note:- Every steps are only for XP because it is the most popular OS. And for Mac users there is effect of this virus.
Reference:
Pingback: 'Is this your pic' on Yahoo messenger contains link to virus