Having downloaded from the Internet and running the seemingly necessary file, I started a curious little animal in my Windows. According to unconfirmed information, the animal is completely harmless, and even performs a useful function - it carries the art to the masses, changing the wallpaper on the desktop to:



A free translation that speaks for itself:
TrojanhorseGALLERY is a virtual gallery, an alternative space for representing young artists, in an environment that is becoming more and more common. Its main goal is to bring art closer to people, right on the wallpaper of their desktops. ThG spreads in the form of a Trojan horse virus, but it is completely safe, leaving the system intact, eliminating one system setting that is responsible for the desktop property. Then, with each reboot, the virus changes the desktop wallpaper to random operation from our database. You can delete ThG at any time.
')
The author of this interesting idea is a certain Slovak (judging by the Slovak phone number
+421 902 352 308
and e-mail
simonfy@azet.sk )
Michal Šimonfy is a freelance
web artist . I really liked his work.
I am not a specialist virologist, however, made some conclusions:
- The virus spreads through the Internet
- Thanks to the included autorun feature, it can infect other computers from external media.
- The virus does download wallpapers from the gallery of th.GALLERY
- Most likely, he is really harmless
So, if you are a fan of modern art, you can easily help the spread of a good starting Slovak freelancer - just install yourself this Trojan and not hinder its spread :)
Install tH.G
If you are not infected, installing a simple virus is simple - download the file
from here (
direct link ) and launch it.
Please check how antiviruses and anti-spyware react to it . Kaspersky Internet Security 7 with the latest updates it like a fish.
Virus removal
Michal
promises to post a virus uninstaller on May 20, 2008. Of course, antivirus vendors will be ahead of him. For now, you can use the following methodology:
Attention, developed by the method of scientific spear!Delete:
- From the
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
registry key Gallery - From % WINDIR% hidden files thG.exe , wallpaper.jpg.tmp and autorun.inf , file sys.wglog
- From % WINDIR% \ System32 files wthG.vbs , dontexecute.dll , thgcounted.dll , wget.exe , orx.hiv , sys.result , sys.wglog , hidden autorun.inf file
Thank you for your attention, do not judge strictly - this is my first habratopik.