Remove W32.Rontokbro.B@mm

A few steps to Remove W32.Rontokbro.B@mm

1. Disable System Restore (Windows Me/XP).

2. Restarted your computer in Safe mode

3. In safe mode run xp_secconsole.exe and in Windows explorer > uncheck
Disable Folder Options then in System Security > uncheck Disable
Regedit after that exit that application.

xp_secconsole.exe can be download from
http://www.dougknox.com/xp/utils/xp_secconsole.zip

4. Delete the following files:

%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\winlogon.exe
%UserProfile%\Start Menu\Programs\Startup\Empty.pif
%UserProfile%\Templates\A.kotnorB.com
%Windir%\inf\norBtok.exe
%System%\3D Animation.scr

Note:
%System% is a variable that refers to the System folder. By default
this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32
(Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder.
By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt
(Windows NT/2000).
%UserProfile% is a variable that refers to the current user’s profile
folder. By default, this is C:\Documents and Settings\[CURRENT USER]
(Windows NT/2000/XP).

Delete the directory:

%UserProfile%\Local Settings\Application Data\Bron.tok-3-3

5. delete the scheduled tasks added by the worm

Click Start, and then click Control Panel. (In Windows XP, switch to
Classic View.)
In the Control Panel window, double click Scheduled Tasks.
Right click the task icon and select Properties from pop-up menu.
The properties of the task is displayed.
Delete the task if the contents of the Run text box in the task pane,
matches the following:

%UserProfile%\Templates\A.kotnorB.com

Note that if you use removable storage media, it’s sure that device
will be with that virus. So what you can do is here. Folder Options >
click View All file and folder and Click System file and folder. And
view your device there will be some virus files in your device. Just
give them SHIFT + DELETE. There you go, happy, your system is clean
now. Thanks for reading this.


Sursa
2009-01-31 16:31:26



Comenteaza





Ultimele 25 posturi adăugate

21:35:35Carlo Masala – If Russia wins —» APort | "Pentru un român care știe citi, cel mai greu lucru e să nu scrie." I.L. Carag
19:41:52Ilie Todorov, actor de teatru și film, regizor și pedagog —» Biblioteca de Arte 'Tudor Arghezi'
06:35:00PENTRU SĂNĂTATEA DUMNEAVOASTRĂ —» Leo Butnaru
10:49:08Nou: Mileștii Mici Riesling Brut Natur —» Fine Wine
08:09:00DINSPRE HOMER SPRE NOI —» Leo Butnaru
10:59:00UN YES-EU —» Leo Butnaru
07:00:00DIN POEZIA FRANCEZĂ MODERNĂ —» Leo Butnaru
14:57:18Agresat la adunare aur în Suedia (priviți integral) —» Curaj.TV | Media alternativă
17:44:00Mafiot pus la punct cu dosar penal —» Curaj.TV | Media alternativă
09:39:26#ISCOADA Talks // Masculinitate și discriminare de gen în epoca digitală —» Curaj.TV | Media alternativă
06:08:00DIN REVISTA TINERILOR —» Leo Butnaru
13:06:39Tradiții muzicale ale orașului Chișinău —» CHIŞINĂU MUZICAL | Blogul Bibliotecii de Arte "Tudor Arghezi"
08:51:00UN DIALOG DESPRE JURNALUL UNEI EPOCI —» Leo Butnaru
06:51:00REPARAȚIE, EVACUARE, JAZZ —» Leo Butnaru
19:32:00Incredibil ce gafă poate face ANAD. Cazul de dopaj care poate intra în istorie! —» Sandu GRECU
17:07:00Predicția lui Andre Barbault pentru 2026 —» codul omega
13:00:31Elfrida Koroliova. Prin labirintul pasiunilor —» Biblioteca de Arte 'Tudor Arghezi'
12:28:16Drama primului fotbalist din Moldova prins dopat. Adevărul ascuns —» Sandu GRECU
07:35:00BIBLIOTECA —» Leo Butnaru
06:47:43Criza de încredere: sport global. Moldova joacă în deplasare, fără rezerve. —» Efrosnatalita’s Blog
06:32:00PĂUNUL ȘI LIBERTATEA —» Leo Butnaru
14:22:00Calatorie/Viaje —» Andrei LANGA. Blogul personal
13:42:00Constantin Romașcanu, compositor, dirijor și profesor universitar —» CHIŞINĂU MUZICAL | Blogul Bibliotecii de Arte "Tudor Arghezi"
14:43:002026 – Revelarea Adevărului —» codul omega
13:24:00Siguranța cetățenilor, asigurată zi de zi de structurile Ministerului Afacerilor Interne —» Sandu GRECU