If your computer is already infected with the Conficker virus , which now scourge of computer users around the world, not to worry. You are not alone because there are estimated to have 12 million infected computers around the world today. If the antivirus is still failing to overcome, there is a way membasminya even need a bit of hard work.
Consider the 7 steps eradicate the Conficker virus from Vaksincom following:
1. Decide who will clean your computer from the network / Internet. Turn off WiFi access when there and pull the ethernet cable from the LAN network.
2. Turn off system restore (Windows XP / Vista).
How select Start>> All Programs>> Accesories>> System Tools>> System Restore and then select the settings menu off for all partitions. (See Figure 1)
3. Turn off the active virus process in services. Use the removal tool from Norman to clean the virus is active. This program is available free of charge and can be downloaded below (See Figure 2):
http://download.norman.no/public/Norman_Malware_Cleaner.exe
4. Delete service svchost.exe implanted fake virus in the registry. You can search the registry manually. (See Figure 3)
5. Delete Task Schedule made by the virus. (C:-WINDOWS-Tasks)
6. Remove string registry created by the virus. To make it easier to use the registry script below. Copy this script and then install.
[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del
[UnhookRegKey]
HKCU, Software-Microsoft-Windows-CurrentVersion-Explorer-Advanced, Hidden, 0x00000001, 1
HKCU, Software-Microsoft-Windows-CurrentVersion-Explorer-Advanced, SuperHidden, 0x00000001, 1
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Explorer-Advanced-Folders-Hidden-SHOWALL, CheckedValue, 0x00000001, 1
HKLM, SYSTEM, CurrentControlSet-Services-BITS, Start, 0x00000002, 2
HKLM, SYSTEM-CurrentControlSet-Services-ERSvc, Start, 0x00000002, 2
HKLM, SYSTEM-CurrentControlSet-Services-wscsvc, Start, 0x00000002, 2
HKLM, SYSTEM-CurrentControlSet-Services-wuauserv, Start, 0x00000002, 2
[del]
HKCU, Software-Microsoft-Windows-CurrentVersion-Applets, dl
HKCU, Software-Microsoft-Windows-CurrentVersion-Applets, ds
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Applets, dl
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Applets, ds
HKLM, SYSTEM-CurrentControlSet-Services-tcpip-Parameters, TcpNumConnections
Use notepad to copy, then save with the name "repair.inf" (use the Save As Type option to All Files to avoid mistakes). Run repair.inf with right click, then select install.
Note: For the active file on startup, you can disable the "msconfig" or be able to manually delete the string:
"HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Run"
7. For cleaning the virus W32/Conficker.DV optimally and prevent re-infection, antiviral agents should use an updated and can detect this virus very well and patch your computer with http://www.microsoft.com/technet/security/Bulletin/ MS08-067.mspx to prevent reinfection
source:tekno.kompas.com
Consider the 7 steps eradicate the Conficker virus from Vaksincom following:
1. Decide who will clean your computer from the network / Internet. Turn off WiFi access when there and pull the ethernet cable from the LAN network.
2. Turn off system restore (Windows XP / Vista).
How select Start>> All Programs>> Accesories>> System Tools>> System Restore and then select the settings menu off for all partitions. (See Figure 1)
3. Turn off the active virus process in services. Use the removal tool from Norman to clean the virus is active. This program is available free of charge and can be downloaded below (See Figure 2):
http://download.norman.no/public/Norman_Malware_Cleaner.exe
4. Delete service svchost.exe implanted fake virus in the registry. You can search the registry manually. (See Figure 3)
5. Delete Task Schedule made by the virus. (C:-WINDOWS-Tasks)
6. Remove string registry created by the virus. To make it easier to use the registry script below. Copy this script and then install.
[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del
[UnhookRegKey]
HKCU, Software-Microsoft-Windows-CurrentVersion-Explorer-Advanced, Hidden, 0x00000001, 1
HKCU, Software-Microsoft-Windows-CurrentVersion-Explorer-Advanced, SuperHidden, 0x00000001, 1
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Explorer-Advanced-Folders-Hidden-SHOWALL, CheckedValue, 0x00000001, 1
HKLM, SYSTEM, CurrentControlSet-Services-BITS, Start, 0x00000002, 2
HKLM, SYSTEM-CurrentControlSet-Services-ERSvc, Start, 0x00000002, 2
HKLM, SYSTEM-CurrentControlSet-Services-wscsvc, Start, 0x00000002, 2
HKLM, SYSTEM-CurrentControlSet-Services-wuauserv, Start, 0x00000002, 2
[del]
HKCU, Software-Microsoft-Windows-CurrentVersion-Applets, dl
HKCU, Software-Microsoft-Windows-CurrentVersion-Applets, ds
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Applets, dl
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Applets, ds
HKLM, SYSTEM-CurrentControlSet-Services-tcpip-Parameters, TcpNumConnections
Use notepad to copy, then save with the name "repair.inf" (use the Save As Type option to All Files to avoid mistakes). Run repair.inf with right click, then select install.
Note: For the active file on startup, you can disable the "msconfig" or be able to manually delete the string:
"HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Run"
7. For cleaning the virus W32/Conficker.DV optimally and prevent re-infection, antiviral agents should use an updated and can detect this virus very well and patch your computer with http://www.microsoft.com/technet/security/Bulletin/ MS08-067.mspx to prevent reinfection
source:tekno.kompas.com
0 comments:
Post a Comment
Disclaimer :
I can not guarantee that the information on my blog is 100% correct..
Don't Forget!Leave Comment Here NO SPAM PLEASE!!