Hello ye all,
Here is the description of the virus and the register alterations that should be checked. The only description I could find is in Polish, but accurate:
http://wirusy.antivirenkit.pl/en/opis/Virus.Win32.Nsag.b.htmlLook for 6 register modification
11 register key modification
14 added to the register are
15 added values to register
19 added values to register
At the end it says to desinfect:
+ Open the register editor by:
- click START -> Run, and entering REGEDIT in the box. (Click OK).
The Registry Editor window will appear.
+ Open under key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and scan for the trojan files
+ Scan under: HKEY_CLASSES_ROOT\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3}
+ Open under key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Policies\Explorer
amd scan for:
"NoActiveDesktopChanges"
+ Open under key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Policies\System
and scan for:
"NoDispBackgroundPage"
"NoDispAppearancePage"
That's it,
polonus