Latest News Latest News

Critical RCE Flaws Affect VMware ESXi and vSphere Client — Patch Now

VMware has addressed multiple critical remote code execution (RCE) vulnerabilities in VMware ESXi and vSphere Client virtual infrastructure management platform that may allow attackers to execute arbitrary commands and take control of affected systems.

Read More...

Masslogger Trojan Upgraded to Steal All Your Outlook, Chrome Credentials

A credential stealer infamous for targeting Windows systems has resurfaced in a new phishing campaign that aims to steal credentials from Microsoft Outlook, Google Chrome, and instant messenger apps.

Read More...

Privacy Bug in Brave Browser Exposes Dark-Web Browsing History of Its Users

Brave has fixed a privacy issue in its browser that sent queries for .onion domains to public internet DNS resolvers rather than routing them through Tor nodes, thus exposing users' visits to dark web websites. The bug was addressed in a hotfix release (V1.20.108).

Read More...

New Chrome Browser 0-day Under Active Attack—Update Immediately!

Google has patched a zero-day vulnerability in Chrome web browser for desktop that it says is being actively exploited in the wild.

Read More...

Emotet Malware

Emotet—a sophisticated Trojan commonly functioning as a downloader or dropper of other malware—resurged in July 2020, after a dormant period that began in February. Since August, emotet increase in malicious cyber actors targeting state and local governments with it's phishing emails. This increase has rendered Emotet one of the most prevalent ongoing threats.

Read More...

New Cryptojacking Malware Targeting Apache, Oracle, Redis Servers

A financially-motivated threat actor notorious for its cryptojacking attacks has leveraged a revised version of their malware to target cloud infrastructures using vulnerabilities in web server technologies.

Read More...

Italy CERT Warns of a New Credential Stealing Android Malware

Researchers have disclosed a new family of Android malware that abuses accessibility services in the device to hijack user credentials and record audio and video.

Read More...

New Attack Could Let Remote Hackers Target Devices On Internal Networks

A newly devised variant of the NAT Slipstreaming attack can be leveraged to compromise and expose any device in an internal network.

Read More...

Microsoft Issues Patches for Defender Zero-Day and 82 Other Windows Flaws

For the first patch Tuesday of 2021, Microsoft released security updates addressing a total of 83 flaws spanning as many as 11 products and services, including an actively exploited zero-day vulnerability.

Read More...

Ransomware Attackers Using SystemBC Malware With RAT and Tor Proxy

Cybercriminals are increasingly outsourcing the task of deploying ransomware to affiliates using commodity malware and attack tools.

Read More...

Contact Us Contact Us

Free Call[OH]: 933

Phone Number: +251-993939270,

                            +251-936825343,

                            +251-944-33-68-02

E-mail: ethiocert@insa.gov.et

P.O.Box: 124498

Download PGP Keys


Report an Incident

Tool Tool

Back

IDM.vbs Virus Removal

IDM.vbs Virus Removal Solutions

The following antivirus products can detect and remove IDM virus. If you have one of these products, update it in order to remove the virus.

·         Avast

·         Comodo

·         ESET-NOD32

·         GData

·         Ikarus

·         Microsoft

·         NANO-Antivirus

·         Panda

·         Rising

·         Symantec

·         TrendMicro-HouseCall

Periodically scan your computer and also scan removable devices (such as Flash disk, memory card, CD-RW...) whenever you insert them to your computer. This will prevent the virus from propagating to other computers.

If your anti-virus product couldn't remove the virus or if you don't have any anti-virus installed on your computer, you have two options

1.     Manually (It is recommended for advanced users)

2.     Automatically using INSA IDM Virus Fixer

Manually

It is possible to remove the virus manually with the following steps.

1. First open task manager on your system. (ctrl+Shift+Esc)

2. On processes tab, find "wscript.exe" and kill the process

For Windows XP

3. Go to Tools->Folder options->View

·         Click the show hidden files and folders option

4. Go to Application data folder

·         \Documents and Settings\<Username>\Application Data, then remove IDM.vbs
Replace Username with the current logged in account name

5. Go to Temp folder

·         \Documents and Settings\Username\Local Settings\Temp, then remove "temp" folder

·         You have to find temp folder in "Temp" directory. Otherwise do not remove the Temp directory

6. Go to startup folder

·         \Documents and Settings\Username\StartMenu\Programs\Startup, then remove IDM.vbs shortcut link

For Windows 7

3. Go to Organize->Folder options->View

·         Click the show hidden files, folders and drives option

4. Go to Application data folder

·         \Users\Username\AppData\Roaming, then remove IDM.vbs

5. Go to Temp folder

·         \Users\Username\AppData\Local\Temp. then remove "temp" folder

·         You have to find temp folder in "Temp" directory. Otherwise do not remove the Temp directory

6. Go to startup folder

·         \Users\Username\AppData\Roaming\Microsoft\Windows\StartMenu\Programs\Startup, then remove IDM.vbs shortcut link

To Unhide the Hidden Files

To unhide your hidden files on removable drives you can run the following command on cmd.exe

·         Run cmd.exe from start menu->run

o    Type cmd in it

·         On the cmd navigate to your removable drive

o    Cd <your removable drive name>:\

·         attrib –s –h /s /d *.*

Example – if your removable drive name is the letter "G"

·         cd G:\

·         attrib –s –h /s /d *.*

If the above solutions couldn't remove the virus you can use the IDM virus fixer tool.

IDM Virus Fixer

The tool has three functionalities

·         Stops IDM.vbs script virus from running

·         Removes IDM.vbs from the copied locations on the system

              - Application data folder

              - Temp folder

              - Startup folder

·         Unhide files which were marked hidden by the idm virus and remove shortcuts created by the virus on removable Medias. It's performed with two options

·         Automatically when users click on the fix button if any removable media is connected

·         When user clicks the unhide button by providing the removable media on demand

Note: IDM Virus Fixer only works for removing IDM Virus

Minimum requirements

·         XP service pack 2 and above

For service pack 1 users upgrade to service pack2 or above


Tool usage

·         First download IDM virus fixer zip file from the link below

o    Download Here:

http://ethiocert.insa.gov.et/

·         Unzip the file

·         Disable any running anti-virus

·         Run "IDM virus fixer.exe"

·         Enable your anti-virus after fixing the problem.

If you need any help contact us with the following address

Call us: +251-930100296.

Email: ethiocert@insa.gov.et.


Values Values

  • Trustworthiness
  • Innovation
  • Scientific
  • Democracy
  • Synergy
  • Saving