Remove W32.Rontokbro.B@mm

A few steps to Remove W32.Rontokbro.B@mm

1. Disable System Restore (Windows Me/XP).

2. Restarted your computer in Safe mode

3. In safe mode run xp_secconsole.exe and in Windows explorer > uncheck
Disable Folder Options then in System Security > uncheck Disable
Regedit after that exit that application.

xp_secconsole.exe can be download from
http://www.dougknox.com/xp/utils/xp_secconsole.zip

4. Delete the following files:

%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\winlogon.exe
%UserProfile%\Start Menu\Programs\Startup\Empty.pif
%UserProfile%\Templates\A.kotnorB.com
%Windir%\inf\norBtok.exe
%System%\3D Animation.scr

Note:
%System% is a variable that refers to the System folder. By default
this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32
(Windows NT/2000), or C:\Windows\System32 (Windows XP).
%Windir% is a variable that refers to the Windows installation folder.
By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt
(Windows NT/2000).
%UserProfile% is a variable that refers to the current user’s profile
folder. By default, this is C:\Documents and Settings\[CURRENT USER]
(Windows NT/2000/XP).

Delete the directory:

%UserProfile%\Local Settings\Application Data\Bron.tok-3-3

5. delete the scheduled tasks added by the worm

Click Start, and then click Control Panel. (In Windows XP, switch to
Classic View.)
In the Control Panel window, double click Scheduled Tasks.
Right click the task icon and select Properties from pop-up menu.
The properties of the task is displayed.
Delete the task if the contents of the Run text box in the task pane,
matches the following:

%UserProfile%\Templates\A.kotnorB.com

Note that if you use removable storage media, it’s sure that device
will be with that virus. So what you can do is here. Folder Options >
click View All file and folder and Click System file and folder. And
view your device there will be some virus files in your device. Just
give them SHIFT + DELETE. There you go, happy, your system is clean
now. Thanks for reading this.


Sursa
2009-01-31 16:31:26



Comenteaza





Ultimele 25 posturi adăugate

16:23:26Fără Titlu —» Путепроводные Заметки
05:21:37Fără Titlu —» Путепроводные Заметки
20:37:35Fără Titlu —» Путепроводные Заметки
17:11:16Fără Titlu —» Путепроводные Заметки
16:09:26Fără Titlu —» Путепроводные Заметки
14:38:58Fără Titlu —» Путепроводные Заметки
14:12:21Nou: Radacini Long Charmat Brut —» Fine Wine
06:13:00FĂRĂ... —» Leo Butnaru
04:51:53Fără Titlu —» Путепроводные Заметки
21:36:17Din cauza, din cauză că, pentru că – cum este corect? —» Moldova Creștină
20:55:3924 de ani, istoria se repetă (live) —» Curaj.TV | Media alternativă
20:02:10Fără Titlu —» Путепроводные Заметки
14:22:15Fără Titlu —» Путепроводные Заметки
09:33:16Un punct de vedere dincolo de timp —» Biblioteca de Arte 'Tudor Arghezi'
06:34:00PARTEA A DOUA —» Leo Butnaru
03:36:57Fără Titlu —» Путепроводные Заметки
19:47:47Fără Titlu —» Путепроводные Заметки
18:39:00SĂ NU NE GRĂBIM CU CONCLUZIILE —» Leo Butnaru
15:10:35Fără Titlu —» Путепроводные Заметки
14:34:48Un OZN numit Iubire —» Argentina Gribincea's Blog
08:13:35Noutăți bune de la Crama Mircești —» Fine Wine
00:14:24Fără Titlu —» Путепроводные Заметки
19:22:13Marș de protest la București cu pichetare de ambasade —» Curaj.TV | Media alternativă
19:18:41Se plînge de discriminare și neglijare —» Curaj.TV | Media alternativă
18:39:56Fără Titlu —» Путепроводные Заметки