Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the HijackThis Log Help forum, or the "First Steps" link at the top right of each page.

Reply
 
Thread Tools
Old 06-27-2008, 12:05 PM   #1 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 2
OS: Win Xp Professional


Sohanad variants removal

Hi Everyone

I work in a medium sized company consisting of a network of 15 computers which is not protected by an av. We have been constantly at war with Sohanad worm/virus and each time we run kaspersky for removal. Now I believe that Kaspersky av is one of the best av nowadays but i can't understand that while the removal is accomplished but the registry fixes have to be achieved manually. Why is that?

Plus could anyone list the removal instructions for this infection i.e the registry fixes. This particular variant was identified by kaspersky as Win32.AutoIt.aa

Thanks
Forak is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 06-28-2008, 08:32 AM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 25,395
OS: 2000 Pro; XP Pro; XP Home


Re: Sohanad variants removal

Seems to me that you need to get protection on each of those workstations. An Enterprise edition of Kaspersky (or other) would help your situation immensely.

Sohanad is an autoruns infection, which tries to install itself to all removable drives. If your users are inserting flash drives from machine to machine, they may just be reinfecting. You can run Flash_Disinfector to help prevent that, but with 15 workstations and no protection installed on them individually, you have your work cut out for you.

There are several variants, so it's not so cut and dried as to what registry items to look for.

Here is some info on the variant you've described:

http://www.threatexpert.com/report.a...7-0bf0f8e04c94

http://www.threatexpert.com/report.a...0-b73047656c07
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006
Our help is voluntary, but this site needs donations to operate.
Please consider Donating to the Forum.


Please do not ask for help via Private Message. Ask in the forums, so all may gain from the experience.
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 02:21 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82