Hacked by Yahaa, Your Firewall is F**k (Pt. 2)

Hi hi sorry. Previous post is for quick remedy for the infection on the spot. But if your PC infected by 'Yahaa' the removal steps is different.
After this infection, your drives cannot be open with double clicks but need to open using right click then open. Here are the steps:
  1. once you open your drive, open Tools>Folder Option>View then tick the Show hidden files and folders option.
  2. then untick 'Hidden protected operating systems files'
  3. now you'll be able to see the 'autorun.inf' and 'autoupdate.dll.vbs' files. right click on 'autoupdate.dll.vbs' and click Properties, untick the Read-Only option.
  4. right click again on 'autoupdate.dll.vbs', click Edit. you can see a script will be open in notepad.
  5. if you scroll down you can see something like HKEY...there will be 'Free for Yahaa' and etc.
  6. delete or change those sentences like put your name.
  7. after that, save the changes and double-click on that file. now you can see the changes you made.
  8. after that, type 'msconfig' in Run, a window will appear click on Startup option. Find 'autoupdate.dll' and untick it.
  9. now delete the 'autorun.inf' and 'autoupdate.dll.vbs'
  10. if you cant delete the file press 'Ctrl+Alt+Del' to open Task Manager and click on Process option. End process that related to autoupdate.dll. Now u can delete.
  11. restart, and check if you successfully get rid of it.
p/s: These steps are ideas of mine and my friend to recover the system and delete the script. If you guys got better solution please free to inform me. You can mail to me so that I can post here. Thank you.

3 comments:

Anonymous said...

where do i locate the vbs file? i dont know where to find it or how. please please help2

Anonymous said...

hello..my pc had been hacked by this stupid script oso..but my antivirus software (AVG) detected it and i already removed all the script files. but problem now is when i right click on My Computer -> properties,like what u said the properties is changed already. so without the autoupdate.dll.vbs script file now how can i change back the properties? and also the title on my IE window still remains T.T

k3sh said...

well try use anti-yahaa first..
if still cant means..
send ur reply in shoutbox..
i'l give another way (quite long )