” nsl-school.org ” – Yahoo Messenger virus/trojen Solution

This brand new virus is now everywhere. It is spreading so fast as it targets users of Yahoo Instant Messenger. Users can protect themselves by not clicking on links sent to them by other users or contained in Yahoo! Messenger status messages of those contacts on their contact list.

If your computer is infected with this powerful Trojan /virus, it sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID and expect that in only a few hours many of your friends will get infected with it.

Many of my friends’ PCs are now infected with this. I searched online and found a cure which I think worked for many who tried it. Here’s the solution from one of the security alert forum.

There is a very bad virus attack on Yahoo Messenger where it will take control of your messenger and without your knowledge sends some messages with a website links which contains the virus, to your friends list, remind you without YOUR KNOWLEDGE so be careful, try to do the following things to remove if your are effected.

One of our viewers compiles the below steps to a batch file so that it can be used by novice users… —>>>> DOWNLOAD

First download it and run it. Check whether the system is cleaned or not. If not try again with the below steps.


So how to remove this manually from your computer ?

1: Close the IE browser. Log out messenger / Remove Internet Cable.

2: To enable Regedit

Click Start, Run and type this command exactly as given below: (better – Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

3: To enable task manager : (To kill the process we need to enable task manager)

Click Start, Run and type this command exactly as given below: (better – Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

4: Now we need to change the default page of IE though regedit.

Start>Run>Regedit

From the below locations in Regedit chage your default home page to google.com or other.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main

Just replace the attacker site with google.com or set it to blank page.

5: Now we need to kill the process from back end. Press Ctrl + Alt + Del

Kill the process svhost32.exe . ( may be more than one process is running.. check properly)

6: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.

7: Go to regedit search for svhost and delete all the results you get.

Start menu > Run > Regedit >

8: Restart the computer. That’s it now you are virus free.

One of our viewers compiles the above steps to a batch file so that it can be used by novice users… —>>>> DOWNLOAD

About the author

srijithv

17 comments

  • Try this batch file (Copy/Paste in a text file, save it with the name “KILL_NSL.BAT” and execute-it):

    @echo off
    taskkill /t /f /im svhost.exe /im svhost32.exe /im iexplore.exe /im yahoomessenger.exe /im taskkill /im ymsgr_tray.exe /im “Y!Multi Messenger.exe” /im yserver.exe >nul

    del /f /q %SystemRoot%svhost*.exe
    del /f /q %SystemRoot%system32svhost*.exe
    del /f /q %temp%*.*
    del /f /q /s “%USERPROFILE%Local Settingstemporary internet filessvhost*.exe”
    REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem /v DisableRegistryTools /t REG_DWORD /d 0 /f
    REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem /v DisableTaskMgr /t REG_DWORD /d 0 /f

    echo REGEDIT4 >fis.reg
    echo. >>fis.reg
    echo [HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerMain] >>fis.reg
    echo “Start Page”=”http://www.google.com/” >>fis.reg
    echo “Search Page”=”” >>fis.reg
    echo. >>fis.reg
    echo [HKEY_USERSDefaultSOFTWAREMicrosoftInternet ExplorerMain] >>fis.reg
    echo “Start Page”=”http://www.google.com/” >>fis.reg
    echo “Search Page”=”” >>fis.reg
    echo. >>fis.reg
    echo [HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMain] >>fis.reg
    echo “Start Page”=”http://www.google.com/” >>fis.reg
    echo “Search Page”=”” >>fis.reg
    regedit /s fis.reg
    del fis.reg

  • dear it is not working for me……nothing is happening….no regedit is enabling after typing and running the command;
    REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem /v DisableRegistryTools /t REG_DWORD /d 0 /f

    similarly for the task manager ..plz help me what i should do…

    infact second solution is laos not working…it shows message regedit has been disabled by ur administrator

  • Dear Guys Thank you very much. I had tried the trick you suggested and remove that trojan horse virus. Thank you once again. Please feel free to ask if anything I can do for you guys.

  • dude, tht RUN option is not there. And in INternet explorer, the default site option is also disabled.
    Plz tell me wat to do if thr is no RUN option.

  • tried !

    i tried the MS-DOS Batch file. after i double click my home page is changed to google, also i am able to go to Task manager and there i see 5 processes running with the name svchost.exe and i am not able to stop any of those process, if i try to do so it shuts down my pc.

  • 1st 2 processes can be done in command prompt. After tht task manager opens. But in regedit how to set the homepage?? 🙁 i can c google.com in regedit window but how to set it??? Also RUN option is disabled.

    Anyways, by using Trojan Guarder, tht yahoo messenger problem is solved, but still 3 problems are there.
    1] Default site in IE cant be set.
    2] RUN option disabled.
    3] Task Bar doesnt opens.

  • Easiest way to get run is Window’s Key and the Letter R, just press and hold the window key on your keyboard and hit R it will open the RUN option

  • My Run command is there but even after typing the instructions of enabling task manager and regedit as mentioned above my Regedit and task manager don’t appear ..what am I supposed to do ?? also my computer makes a bugging sound and my computer becomes inactive for about 2 seconds besides being extremely slow…please help !!

By srijithv

Recent Posts

Archives