Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 6

adaware you can download a free 'multi spyware removal' at

http://www.lavasoft.de/software/adaware/
avdisk for information and a program on {how to create an
antivirus boot disk} go to http://www.avdisk.org/pages/about.html
avg for a {free anti-virus program} go to
http://free.grisoft.com/freeweb.php/doc/2/
avp you can get 'anti viral toolkit pro' avp from www.avp.com
aplore the removal instructions for the 'w32.aplore' can be found
at http://www.nohack.net/aplore.htm or
http://securityresponse.symantec.com/avcenter/venc/data/w32.aplore@mm.html
aploreremoval to remove 'aplore' goto
http://www.dokfleed.net/files/viruses/aplore.exe ,download it, close all programs
and run it.
badtrans for information on badtrans go to
http://securityresponse.symantec.com/avcenter/venc/data/w32.badtrans.b@mm.html

badtrans.b download and run


http://securityresponse.symantec.com/avcenter/fixbadtr.exe (close all open apps
while running)
bhong.vbs
blaster
blasterworm for the removal of the blasterworm exploit you find a fix at:
http://www.microsoft.com/downloads/details.aspx?familyid=2354406c-c5b6-44ac-9532-
3de40f69c074&displaylang=en
blebla
blink removal instruction and information about 'blink' virus can be
found at http://securityresponse.symantec.com/avcenter/venc/data/js.blink.a@m.html
bugbear information about the w32.bugbear worm at
http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear@mm.html and
the tool is found at
http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear@mm.removal.too
l.html {shortcuts --> http://securityresponse.symantec.com/avcenter/fxbgbear.exe }
chernobyl.vbs
cih the removal instructions and the fix kill_cih to clean 'cih' can
be found at http://www.symantec.com/avcenter/kill_cih.html
cleaner you may get a copy of the cleaner at
http://www.moosoft.com/products/cleaner/download/ *remember* to update it by
selecting moolive from the cleaner menu, after it's done updating, run 'the
cleaner'. the 'cleaner' will remove any known trojans it finds. *note* you {must
close mirc} if you have an mirc related trojan
combofix you may get the file on and save it to your desktop and don't use
your mouse start on hit use the arrow up and down to locate the file and hit enter
--- http://download.bleepingcomputer.com/subs/combofix.exe'
copypaste
decodeclean
dmsetup
dokmirc
doly the url for 'doly' trojan {removal instructions and procedures}
{[v} (1.1) and v (1.2) \] can be found at
http://www.fruitloop.net/virushelp/doly.html and for {[v} (2.0) \] at
http://www.dark-e.com/archive/trojans/doly/20/index.shtml
dumaru the removal instructions and the fix for 'dumaru' can be
wound at:
http://securityresponse.symantec.com/avcenter/venc/data/w32.dumaru@mm.removal.tool
.html
exbuz
excursion excursion is a script that tends to often mislead people, where
it at times can send out fake 'you have a {$decode} worm' messages. this however
does not mean that you don't have a {$decode} worm, only that it is able to
generate fake ones. delete the script, and download a new one from
www.mircscripts.org or ask in #helpdesk for more information.
falseaplore if after a full system scan you do not detect the 'w32.aplore@mm'
trojan, check your ident and nick. if they are both set to the same thing, you may
be mistakenly detected as having aplore
findfile our helper will make you type a command {($findfile)} and your
mirc will seem to crash/freeze, but it is just performing the command, so don't
worry if you can't type anything or mirc 'freezes' temporarily (~30 seconds) ok ?
firewall download the 'conseal firewall' {trial version for win9x} from
http://www.consealfirewall.com/scripts/cfdownload.cfm , fill out the form to be
directed to download or download the free 'zonealarm firewall' to block attacks
onto your computer from http://downloads-zdnet.com.com/3000-2092-
9616657.html?tag=lst-0-3
firewalls for a review on what #nohack ops think about some of the common
windows firewalls goto http://www.fruitloop.net/virushelp/firewalls.html , those
links leads to firewalls homepages as well from where yew can download'em
fprotdos you can get the latest zipped dos version of f-secure anti virus
from ftp://ftp.f-secure.com/anti-virus/free/ download fp-312.zip unzip it to your
{c: drive} and run it under dos-mode
freelove.vbs
freepics.jpg.vbs
funlove funlove: to remove the funlove worm goto
http://securityresponse.symantec.com/avcenter/venc/data/pf/dos.funlove.4099.fix.to
ol.html
golcorlist for a list of common irc exploits see
http://golcor.tripod.com/viruses
goner the removal tool for 'goner' is
http://securityresponse.symantec.com/avcenter/fixgoner.exe , and for further
information about 'goner' go to
http://securityresponse.symantec.com/avcenter/venc/data/w32.goner.a@mm.removal.too
l.html
gtbot for information about the 'gtbots' and variants go to
http://www.nohack.net/gtbots.htm
hackereliminator to scan for know trojans and bots on your windows system,
download http://hacker-eliminator.com/
haptime the fix for removing the 'haptime' virus can be found at
http://www.symantec.com/avcenter/fixhaptime.exe , download the fix {close all
programs and disable all anti-viruses} then run the fix and for {instructions on
manual removal} go to
http://www.symantec.com/avcenter/venc/data/vbs.haptime.fix.html
help usage: the following vscan info system commands are are
available: 1. .add itemname description text - will let you add the itemname with
the corresponding text. 2. .del itemname - will remove the requested item (if
exsist) from the database. 3. .ls itemname - will let you search through available
topics (you can used wildcards in itemname). note: .add and .del are only
available to registered ops of vscan.
helped1 your problem was solved. but this doesn't mean that you're
system is 100% clean and protected. to be sure that your system is clean, do an
online scan at http://housecall.trendmicro.com .here are some advices to stay
clean: 1. keep your irc cliend updated by installing the latest version. 2. never
visit any sites you receive on irc and never receive files sent to you by people
you don't know or if you didn't asked him/her to send you anything.
helped2 3. don't ever type any unknown irc commands. 4. keep all
programs that you use updated, especially your browser (internet explorer,
firefox, etc.) and your pop3 mail client. 5. get a good anti-virus program,
install it and configure it properly and update it regulary. if you can't afford
such program, do a periodical scan at http://housecall.trendmicro.com.
hijackthis you can get a copy of hijackthis (scan the registry and hard
drive for spyware) from http://216.180.233.162/~merijn/files/hijackthis.exe
hybris in order to remove the 'hybris' infection go to
http://www.pandasoftware.es/library/gusano/w32hybris_en_2.htm , read the {how to
repair} part before downloading the zipped icon and follow the instructions. note
that it has to be run in dos mode.
ident for information on how to setup ident on a windows computer goto
http://kline.dal.net/exploits/winident.htm to set it up on a mac goto
http://kline.dal.net/exploits/macident.htm for more information on ident read
http://kline.dal.net/exploits/ident.htm
ignore warning your v!rus has placed our nohack helpers on ignore.
they cannot help you until you type /!ignore -r please type this now and then say
ready in the channel to get more help
ily download the fix for the 'i.love.you.txt.vbs' {and variants} at
http://www.symantec.com/avcenter/fixlove.exe , make sure you {mirc is closed}
while running it and you can read about 'loveletter' and {manual removal} at
http://www.nohack.net/iloveyou.html
jdbgmgr information on the 'jdbgmgr.exe' hoax can be found at
http://securityresponse.symantec.com/avcenter/venc/data/jdbgmgr.exe.file.hoax.html
jpg.bat
js.exception information about 'js.exception.exploit' can be found at
http://securityresponse.symantec.com/avcenter/venc/data/js.exception.exploit.html
karma
kaspersky you may download kaspersky antivirus or firewall trial versions
at http://www.kaspersky.com/trials, download, update and scan in safe mode.
klez the 'klez' removal fix tool is
http://www.bitdefender.com/download/download.php?file=antiklez.exe or you can get
it from http://securityresponse.symantec.com/avcenter/fixklez.com
klezreview to read about 'klez' go to
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html
or http://www.europe.f-secure.com/v-descs/klez.shtml
lifescan for a free, online anti-virus scanning and removal goto
http://housecall.antivirus.com/housecall/start_corp.asp chose your country and
click on go, let the applets download then check all your hard drive letters and
don't forget the check the {auto clean} before you click on scan
lifestage the fix for lifestages can be found at http://hey.to/remedy you
need to download the file, save it, then close your mirc entirely, before double
clicking on the 'fixlife.exe' that you saved.
links
lop.com the fix for removing the 'spyware: lop.com' is
http://www.lop.com/uninstall.exe
mcafee you can download 'mcafee virusscan' {30 - days evaluation}
from http://download.mcafee.com/eval/user-
registration2.asp?l=14&o=10&pkgc=229&prdc=27&s=home&x=n&img=vscan_6x.jpg&zz=viruss
can&nz=0&comp=391&zfs=4477%2e93+kb
me_sysrest to turn off your system restore: click 'startsettingscontrol
panel', double-click the system icon (if the system icon is not visible, click
'view all control panel options' to display it.) on 'performance' tab click file
system & click the 'troubleshooting' tab, check disable system restore and click
ok. turn it on again after finishing by doind the same steps but uncheck the
disable system restore.
mircinihelp the mirc.ini unleashed help file unfolds all secrets of the
mirc.ini file. get the latest version from
http://www.mishscript.de/help/mircini/index.htm
movie.avi.pif
mscriptbox get the mscriptbox helpfile which contains hundreds of tutorials
and references for mirc/irc. get the latest version from
http://www.mishscript.de/msbindex.htm
mtx the removal tool for 'mtx' can be found at
http://www.symantec.com/avcenter/fixmtx.exe , start the computer in 'safe mode'
and run the 'fixmtx.exe' tool from an 'ms-dos' window. to read more about 'mtx' go
to http://www.symantec.com/avcenter/venc/data/w95.mtx.html
nai you can download 'mcafee virusscan' {30 - days evaluation} from
http://download.mcafee.com/eval/user-
registration2.asp?l=14&o=10&pkgc=229&prdc=27&s=home&x=n&img=vscan_6x.jpg&zz=viruss
can&nz=0&comp=391&zfs=4477%2e93+kb
netbus
nimda to protect yourself from 'win32.nimda' download the remover at
http://download.com.com/3000-2239-7249328.html?legacy=cnet , download the fix, run
it and then download necessary {critical updates} at
http://windowsupdate.microsoft.com. if you are on lan make sure you disable all
your shares or set {full passwords} or easier to make the infected pc a {stand
alone} pc ,unplugged from the hub or disconnected from the network
nimdaprotect
nkie for information on the {nkie($decode)} worm go to
http://www.nohack.net/nkie.htm
nohack the url for dalnet's virus and trojans help channel #nohack
is http://www.nohack.net
noidle please leave this channel if you do not require
vi�us/tr0jan removal assistance. this is not a regular chat-channel, and we do not
allow idle users in here, to prevent exploiting legitimate users of this channel.
noob information and removal instructions about vbs.trojan.noob can be
found at
http://securityresponse.symantec.com/avcenter/venc/data/vbs.trojan.noob.html
nudesex
oblivion
onlinescan
ports to display and get a network probe of your computer and which
service ports are accepting connections, please go to
https://grc.com/x/ne.dll?bh0bkyd2
portscan
ppark the fix for 'pretty park' worm can be found at
http://securityresponse.symantec.com/avcenter/venc/data/fix.prettypark.html {note
that this tool works only for win9x and winnt}
reg-backup
reg-restore
restore to disable your restore option for winme go to
http://service1.symantec.com/support/tsgeninfo.nsf/docid/2001012513122239 , as for
winxp go to
http://service1.symantec.com/support/tsgeninfo.nsf/docid/2001111912274039

router_dlink dlink router & mirc setup help can be found at:
http://support.dlink.com/faq/view.asp?prod_id=1337&question=port+fowarding+mirc
and at
http://www.dslreports.com/forum/remark,5996519~reverse=0:days=10:root=dlink:mode=f
ull
router_lancom lancom router & mirc setup can be found at:
http://www2.lancom.de/kb.nsf/0/e5543365becbb5a9c1256ed10054d3a8?opendocument
router_linksys linksys router & mirc setup help can be found at:
http://www.mishscript.de/help/linksys.htm
router_smc
safemode to boot your pc in safe mode for win9x,me go to
http://service1.symantec.com/support/tsgeninfo.nsf/docid/1999101916343139
scripts you can find one of these {war,virus,backdoor - free}
http://www.mircscripts.org or http://www.pairc.com or http://www.team-clanx.net/
or http://www.mishscript.de/ or http://www.mirc-egg.net/
security
sircam
sober_g
sobig for information on the w32/sobig.f worm go to
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?vname=worm_sobig.f
spamblock to protect yourself from 'spam' on irc go to
http://kline.dal.net/exploits/spamblock.htm to learn how to set modes against
'spam'
spamremover to get rid of most spam download this zip file
http://www.dejhantulip.net/nohack/files/spamrem.zip and *please* read the readme
file before using it!
spysweeper get spysweeper to fight against spywares, note it's a trial
version only get it from http://www.webroot.com/consumer/downloads/. download,
update and scan in 'safe mode'.
spyware a non-malicious piece of software used by companies to
report how you use your computer. may often use a great amount of your computer's
resources. for a spyware-remover, please check out spybot. more information
available at: www.spybot.info
startup for information about {common startup programs} goto:
http://www.sysinfo.org/startupinfo.html
stinger you may get mcafee avert stinger removal tool for specific
v!rus removals at http://vil.nai.com/vil/stinger/ *note* please read the
instructions provided and follow the procedure describe in the website.
story.vbs
submittrojan to submit a trojan to the nohack resource team you can
email it to golcor@youdontknowwhoiam.org or join #gtbot and dcc send it to any
@operator there
swatit get swat it! the free trojan scanning utility from
http://swatit.org/ , download, install, update, and make sure your mirc is closed
before you run the scan.
symantec the url for symantec security response {['latest} virus threat',
'security advisories', 'definitions', 'updates' and 'removal tools'\] is
http://www.symantec.com/avcenter/
tunes.vbs the fix for 'tunes.vbs' removal can be found at
http://www.fruitloop.net/virushelp/fix/vbstunerem.exe ,download it then {close
your mirc} before running the fix
updates to get the 'critical updates and service pack' go to
http://windowsupdate.microsoft.com or simply type /run wupdmgr , then click on
'product updates', upgrade your internet explorer and get the security patches as
well
usage usage: the following vscan info system commands are are
available: 1. .add itemname description text - will let you add the itemname with
the corresponding text. 2. .del itemname - will remove the requested item (if
exsist) from the database. 3. .ls itemname - will let you search through available
topics (you can used wildcards in itemname). note: .add and .del are only
available to registered ops of vscan.
vbs.lava information on the removal of the virus vbs.lava can be found at
http://securityresponse.symantec.com/avcenter/venc/data/vbs.lava.html
vbs the fixes page for *.vbs {[links,} nudesex, mypicture, story,
tune\]' can be found at http://www.fruitloop.net/virushelp/vbs.html
virusscan to scan you pc online, go to
http://security2.norton.com/ssc/lunavbrk.asp?scantype=2&langid=us&venid=sym&plfid=
20&pkj=kkmkyhgbyncjeimxqkc - note: your activex and/or scripting must be supported
or enabled
vscan vscan is the #nohack virus database eggdrop bot - designed to
support helpers with additional information displayed in the channel.
xp_sysrest to turn off system restore in windows xp: right click on my
computer and choose properties then system restore. finally check 'turn off system
restore' then apply. you can turn it on again when you finish by doing the same
steps and uncheck 'turn off system restore'.
xpfirewall windows xp/firewall & mirc setup help can be found at this
locations: for xp - sp1 goto: http://www.mishscript.de/ircguide/appb1.htm and for
xp sp2 goto: http://www.mishscript.de/ircguide/appb2.htm
yaha to remove all versions of 'yaha' virus use this tools:
http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.removal.tool.html
or ftp://ftp.europe.f-secure.com/anti-virus/tools/yahatool.zip info about the
lasted version of yaha.k
http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.k@mm.html
zonealarm zonealarm' to block attacks onto your computer from
http://www.download.com/zonealarm/3000-2092-10306241.html?tag=lst-0-1

*!*@203.160.175.184 quit msg clean

You might also like