You clicked on an email, and now your computer is talking to you. You have the Amus worm. The following Tech-Recipes tutorial explains how to clear it from your system.
You clicked on an email, and your computer says the following:
- How are you. I am back. My name is mister hamsi. I am seeing you. Haaaaaaaa. You must come to turkiye. I am cleaning your computer. 5. 4. 3. 2. 1. 0. Gule. Gule.
Here is the evil it can do:
- – On the 1, 6, 20 and 25 of each month, it will replace the home page URL in Internet Explorer with the following text:
[list]Konneting du pepil and dizkoneting you. Anlami: Baglansan ne olacak, baglanmasan ne olacak. Zaten hatlar burada rezalet.
– On the 2, 15 and 17 of each month it will try to delete all .ini files in the Windows folder.
– On the 10 and 23 of each month, it will try to delete all .dll files in the Windows folder.
The email address of the infected person who sent it to you is not forged.
The attachment name is Masum.exe.
The subject name of the email is Listen and Smile
It uses Microsoft Outlook to send itself to all your contacts.
The body of the email will read as follows:
Hey. I beg your pardon. You must listen.
You can confirm that you have this malware by looking in the root directory of your c: drive. It should contain a file named masum.exe.
It frequently also copies itself into as the following files in your /windows folder:
It places the two following registry keys:
To correct this infection, use CTRL-ALT-DEL and kill any of the files listed above that are actively running. Then delete all the files involved. Remove the registry keys as well.
Most antivirus programs are now finding this creature. Update your antivirus, and let it clear your system. You will probably need to remove the leftovers manually from the registry.