Omg! On the 4th day of Chinese New Year, I kena virus!
PWS-LegMir.gen.k.dll. This is a trojan horse, it will steal ur passwords and is spread thru USB Flash Drive (commnly known as thumb drive). Mcafee Virus Scan will only detect and stops this virus, it will not remove it for u. Because this virus is less than a month old, there isn't a official way or tool to remove it. But today mong will teach u step by step, how to remove this dam thing!
(Source: Adapted from
suggestafix)
Step 1: Download
HijackThis &
SDFix. & Extract SDFix
Step 2: Restart your PC and press F8 when you heard a "beep". Choose the option of safe mode.
Step 3: Start HijackThis then check the box against:
"O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe"
then click on "Fix Checked" and when finished exit HijackThis
Step 5: Locate C:\WINDOWS\system32\amvo.exe and delete it
Step 6: Do a full search for files named "amv*.*" and delete if found.
Step 7: Open the SDFix folder and double click on
RunThis.Bat, Type
Y and
Enter. Follow the instruction on SDFix. And the pc will restart to normal mode.
Step 8: Your PC should now be in normal mode. Press any key to end the SDFix. From here the virus is now removed! But because the above 7 steps only remove the virus and does not roll back the destruction caused by the virus, u need to proceed to step 9.
Step 9: Click
start >
run >
regedit and press
enter. Navigate to the following:
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL"
Change the value of
CheckValue and
DefaultValue to
1.

There u go! You are now a Trojan Buster! This is a smart virus, it will disable you from showing hidden files, and all the files that are being created by the virus are all hidden (Smart?). Meaning when you want to view your hidden files ("Show hidden files") and delete them, it will auto reverse back to "Do not show hidden file". Causing you to be unable to delete the .inf and .cmd files. If u have being reading my blog u will realize that autorun.inf files are executed when the the
flash drive is plug in.
It will make a copy of these 2 files on every drives!
This is why it also infects your thumb drive and spread thru it.
From here please do a anti-virus full system scan and anti-spyware full system scan to confirm ur pc is free from shyts.
Thx u for viewing & below is a very nice song from Sam Lee Sheng Jie, enjoy~
Feeling great as Trojan Buster? Click Here!