The Bottom Line
-----------------------------------------------
Antivirus software won't help you. This is a security
and privacy issue, not a virus per se.
"Yo Mama, Osama" is a popular internet shooting game.
The game promises a free cell phone booster to players that
are successful in "taking out" Osama Bin Ladin. The
players, however, are the ones being taken...
"taken in" that is.
Play the game and you'll end up with a spyware/adware trojan
created by Twistedhumor.com that monitors your Internet
usage, sends your private information without your knowledge
and feeds popup ads to you long after the game is over.
Uninstalling the game does NOT uninstall the spyware!
If You Are A Victim... Automatic Removal Instructions
--------------------------------------------------------
The easiest way to get rid of this, and all other spyware/adware
from your system is to get a free copy of "AdAware" from LavaSoft.
This tool never ceases to amaze us. Feeling safe and secure,
and there's no "junk" on your system? Run AdAware and find out
how many software spies your system is home to.
Download AdAware here:
Be sure to click on the "Getting Started" link for instructions
and info.
Manual Removal Instructions
--------------------------------------------------------
If you prefer to remove Osama manually, you will need to be
more than a novice user. You will need to be familiar with
changing the Startup Folder, safe use of Windows Explorer
and REGEDIT.
When you install Yo Mama Osama for game play, the trojan's
software files are also downloaded and installed on your PC and
a shortcut is placed in your startup folder so that the trojan
will start itself every time you boot your system.
On Windows 95/98, press CTRL-ALT-DEL and you will get a window
containing a list of all programs that are running.
On Windows 2000 and XP, press CTRL+ALT+DEL and click on "Task
Manager" and go to the "Processes" list.
Once you have the list of running processes, look for
the WNAD.EXE process and "End Task" it.
Next, start Windows Explorer and make sure that your options
are set to display all files (including system and hidden files).
Navigate to your Windows folder and delete these files:
WNAD.EXE
WNAD.DAT
WNAD-UPDATE.EXE
WNAD.LGC
Next, edit the registry and remove the "C:\Windows\Wnad.exe"
value from the following Registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Finally, open up the startup folder and delete the shortcut
to WNAD.EXE.
How Did This Happen?
----------------------------------
In Twistedhumor.com's press release, they described
the game as a means to raise charitable contributions
for the American Red Cross. What they didn't tell us
is how the money is being raised. Since the game
play is free, and your info is used in order to force
popup ads on you, the funds are most certainly being
acquired from the advertisers. BTW, officials at
Twistedhumor.com did not respond to requests for
further information.
Best Regards,
Marc Deschenes, VACM Editor
The VACM Project at
Automated PC Solutions
|
*** Be sure to check out the appendix at the end of this alert
******** APPENDIX - Handy How-To Tips ********** * How To Boot into Safe Mode Shut the computer down so that the power is off.
|