Tuesday, 7 February 2012

How to Fix/Remove “XeAyAl.eXE” Virus Worm Malware

Couple days ago, one of my friend just borrowed my USB drive. When he returned it, I plugged my USB drive as usual to my laptop, and to my surprise, my Avast Anti Virus warned me that my USB drive was just infected by “XeAyAl.eXE” worm. I immediately remove the worm file through my antivirus, and performed full scan to my USB drive. I’m actually not sure what’s going to happen if my antivirus didn’t detect the worm and executed it.

According to prvex.com, here’s what’s gonna happen if you executed it.

XEAYAL.EXE has been seen to perform the following behavior:
Executes a Process
This process creates other processes on disk
Registers a Dynamic Link Library File
Uses DNS to retrieve the IP address for web sites
Visits web sites on your PC without you knowing
Adds a Registry Key (RUN) to auto start Programs on system start up
Writes to another Process’s Virtual Memory (Process Hijacking)
Can communicate with other computer systems using HTTP protocols
Injects code into other processes
This Process Deletes Other Processes From Disk

XEAYAL.EXE has been the subject of the following behavior:
Created as a process on disk
Executed as a Process
Registered as a Dynamic Link Library File
Added as a Registry auto start to load Program on Boot up
Has code inserted into its Virtual Memory space by other programs
Terminated as a Process

I personally didn’t really trust that website to fix my computer. I am afraid that website will give me more trouble than ”XeAyAl.eXE” if I used the website only scanner to remove the worm. So, I did more research on ways to fix my USB drive. What happened now after I deleted the “XeAyAl.eXE” using Avast Anti Virus, is that I can’t open my USB drive. Every time I am trying to open it, my computer gives me this message:
Windows cannot find ‘XeAyAl.eXE’. Make sure you typed the
name correctly, and then try again. To search for a file, click
the Start buttonm and then click search.

Windows cannot find ‘XeAyAl.eXE’. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button and then click search.

After I found a post from forospyware.com, I was kinda guessing that the problem was in my USB drive autorun.inf. Lo and behold, here’s the content of my autorun.inf from my USB drive:

[AutoRUn]
acTioN=Open folder to view files
sHElLexECuTE=XeAyAl.eXE
ICOn=%SYsteMROOt%\SYSTEm32\shELL32.dlL,4
USEAUTopLay=1

Apparently, the actual worm itself, “XeAyAl.eXE”, has been deleted. However, it modified my autorun.inf before it got deleted by Avast antivirus. This modified autorun.inf was causing the USB drive to give me the ‘XeAyAl.eXE’ not-found warning, because the ‘XeAyAl.eXE’ file has been deleted, therefore the OS can’t find the file. To fix this, I deleted the autorun.inf itself. You can also just delete the content of autorun.inf while still keeping the file, if you still want to use autorun.inf for your autorun behaviour of this USB drive. This will fix the problem, guys.

If you want to follow what’s being said in forospyware.com in the section of how to clean USB drive using flashdesinfector, you can try that too. Let me know if it gives better result for you or not.

I hope my post will help you to handle ‘XeAyAl.eXE’ worm. If you have any questions or encounter something different, please drop me a comment.

No comments:

Post a Comment

Updates Via E-Mail

Labels

007 Legends (1) 007 Legends repack (1) 007 Legends-Black Box (1) 007 Legends-Black Box repack (1) 2K Games (1) 2K Marin (1) Action (8) Action RPG (5) Activision Blizzard (3) Alan Wake American Nightmare (1) Alan Wake American Nightmare-Black Box (1) ANARCHY (5) Antara AES dan pemandu kereta perasan bijak (1) antivirus (6) ARTIKEL (90) Bethesda Softworks (2) Binary Domain (2) BioShock 2 (1) BioWare Corporation (1) bitComposer Games (1) Bugbear Entertainment (1) Call of Duty: Modern Warfare 3 (1) Call of Duty: Modern Warfare 3-Black Box (1) CARDING (3) CD Projekt Red Studio (1) CERITA (7) CRACKER (18) Crysis 2 (1) Crytek Studios (1) Dark Souls: Prepare to Die Edition (1) Dark Souls: Prepare to Die Edition-Black Box (1) Darksiders (1) Darksiders II (1) Deface (1) Devil's Details (2) Digital Extremes (1) Doom 3:BFG Edition (1) Doom 3:BFG Edition-Black Box (1) EA Sports (1) Electronic Arts Inc. (4) ENGLISH MOVIE (29) Eurocom Entertainment Software (1) event (1) Exploit (76) FABLE III (1) Facebook Game Hack (1) FIFA 13 (1) FIFA 13-Black Box (1) Flashing (1) Flying Wild Hog (1) From Dust (1) From Dust-Black Box (1) From Software (1) gba games (1) Global Ops: Commando Libya (1) Global Ops: Commando Libya-Black Box (1) GORE (1) Hard Reset (1) Hard Reset-Black Box (1) HIJACK (2) History (3) id Software (1) iklan. (4) Infinity Ward (1) INFO (35) iPhone Jailbreak (9) ISU SEMASA (33) JOB (1) JOOMLA (1) KILLUMINATI (7) Konami (1) Lain-Lain Trick (1) LionHead Studios (1) MAKE MONEY (1) MALAY MOVIE (15) Mass Effect 2 (1) Max Payne 3 (1) Max Payne 3-Black Box (1) Maxis (1) Microsoft Game Studios (1) misteri (4) MOBILE (1) MUJAHID (27) music album mp3 (20) n-gage (1) Namco Bandai Games (3) NDS (1) Notepad Trick (1) OS (5) OTHER MOVIE LANGUES (8) PC GAME (141) photo (5) political (2) Pro Evolution Soccer 2013 (1) Pro Evolution Soccer 2013-Black Box (1) Prototype 2 (1) Prototype 2-Black Box (1) PS VITA (4) PS3 GAME (32) PSN GAME (6) PSP (7) PSPGAMES (4) puisi (1) putlocker games (5) Racing (1) Radical Entertainment (1) religion (12) Remedy Entertainment (1) repack game (1) REVEAL (32) Ridge Racer Unbounded-Black Box (1) Rockstar Games (1) S60v2 (1) Samsung U1000 (1) SEGA (2) SEO (2) Shooter (2) Shooting (2) Soalan bocor SPM 2012 ada di sini (1) Soft Skills Guide (1) software (31) Spectral Games (1) Sport (2) Strategy (1) SYSTEME (3) The Darkness II (1) The Darkness II-Black Box (1) The Elder Scrolls V: Skyrim (1) The Elder Scrolls V: Skyrim-Black Box (1) The Sims 3 (1) The Sims 3 Complete (1) The Sims 3 Complete-Black Box (1) The Witcher 2: Assassins of Kings (1) THQ Inc (2) tips (1) TOKOH (1) tool (2) Tutorial (30) TWEAK (6) Ubisoft Studios (1) UNDERGROUND (4) video movie (1) video music (1) Vigil Games (2) Website Hack (1) wii (2) XBOX360 (7) xboxone (1)

Total Pageviews

Blog Archive

LIST