SEARCH

Tuesday, August 31, 2010

3 How to Clean the Virus 'eaters Notebook'

Stuxnet Virus, or also known as Winsta, devouring all the vacant land on the hard drive until it is full. According to Alfons Tanujaya, antivirus analysts from Vaksincom, to ITGazine, Friday (07/30/2010), Indonesia is a country with the second largest number of victims Stuxnet in the world after Iran.

The virus initially spread from various porn sites, pirated programs and content 'gray' other was quite disturbing. Here are the steps eradicate the virus, such as antivirus Vaksincom spoken by the analyst Adi Saputra:


1. Using Dr. Web CureIt

Adi suggested the victim Winsta aka Stuxnet it to download the virus removal software.Removal Tools called Dr.Web CureIt it can be downloaded from the site FreeDrWeb.com


2. Registry Fix

Later, Adi suggested improvements to the modified Windows regitri by the virus. How, first of all, copy the script below into Wordpad files.

[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del

[UnhookRegKey]
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced, ShowSuperHidden, 0x00010001, 1
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced, SuperHidden, 0x00010001, 1
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced, HideFileExt, 0x00010001, 0
HKLM, SOFTWARE \ CLASSES \ batfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, SOFTWARE \ CLASSES \ comfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, SOFTWARE \ CLASSES \ exefile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, SOFTWARE \ CLASSES \ piffile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, SOFTWARE \ CLASSES \ regfile \ shell \ open \ command,,, "regedit.exe"% 1 ""
HKLM, SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon, Shell, 0, "Explorer.exe"

[Del]
HKLM, SYSTEM \ CurrentControlSet \ Services \ MRxCls
HKLM, SYSTEM \ CurrentControlSet \ Services \ MRxNet
HKLM, SYSTEM \ ControlSet001 \ Services \ MRxCls
HKLM, SYSTEM \ ControlSet002 \ Services \ MRxNet
HKLM, SYSTEM \ CurrentControlSet \ Services \ Enum \ Root \ LEGACY_MRXClS
HKLM, SYSTEM \ CurrentControlSet \ Services \ Enum \ Root \ LEGACY_MRXNET
HKLM, SYSTEM \ ControlSet001 \ Services \ Enum \ Root \ LEGACY_MRXClS
HKLM, SYSTEM \ ControlSet002 \ Services \ Enum \ Root \ LEGACY_MRXNET

Then, save the file with the name 'repair.inf'. Use the option to Save as type Text Document to avoid mistakes. Then, right-click the file 'repair.inf', select 'Install' and restart the computer.

"Clean up temporary files, this is for to prevent the rest of the trojan that tries to be active again. Use tools such as the ATF Cleaner or use the Windows feature of the Disk Clean-Up," wrote Adi.


3. Emergency Solutions

In addition, here is the script that can be used in emergencies to prevent Winsta not re-infect. Save the following script with the name Winsta.bat (file type: Text)

@ Echo off
del / f c: \ windows \ system32 \ winsta.exe
brake rd c: \ windows \ system32 \ winsta.exe
md c: \ windows \ system32 \ winsta.exe
del / f c: \ windows \ system32 \ drivers \ mrxnet.sys
brake rd c: \ windows \ system32 \ drivers \ mrxnet.sys
md c: \ windows \ system32 \ drivers \ mrxnet.sys
del / f c: \ windows \ system32 \ drivers \ mrxcls.sys
brake rd c: \ windows \ system32 \ drivers \ mrxcls.sys
md c: \ windows \ system32 \ drivers \ mrxcls.sys
attrib + r + h + s c: \ windows \ system32 \ winsta.exe
attrib + r + h + sc: \ windows \ system32 \ drivers \ mrxnet.sys
attrib + r + h + sc: \ windows \ system32 \ drivers \ mrxnet.sys

When finished, double click the file Winsta.bat generated. For optimal cleaning and prevent re-infection, re-scan using updated antivirus and recognize this virus very well.

Renungkanlah

Meditate in your heart and give emphasis, each reading a lettered word BIG. WE arehuman beings created perfectly, but when we can be perfect, even the word "WHOME??" just never had in mind at all, with PATIENCE and sincere, ranging from I learned to crawl, STAND, WALK, EAT, DRINK, SPEAK, and many other things, I forget if that'sall the result of your labor in order to see thy son to be PERFECT. But what happens,when I started growing up, I slowly forgot that your services, I'm sorry for hurting heartsMOTHER, when MOTHER command, I refuse, when the speech a little louder toneMOTHER was silent, or think with tears.

"YES YOU ARE THE GOD Forgiving, OWNER OF ALL THE POWER YOU thy servant,Forgive my child who has dared MOTHER who has been conceived against me, whohad educated him, let me take away the sin my son, because I'm his mother, who had been educated up to DARE against me. ...." Let us ponder for a moment what we have done to our Mother, when we are having - fun with our friends, we do not even think about the state of our mothers, but we are never the slightest MOTHER rescue us fromhis mind, Have we THANK YOU and SORRY mngucapkan said sincerely on us that have been mature MOTHER us until we can be here. GOOD OPPORTUNITY IS NOTLOST, because nothing is certain in this world besides DEATH ....

Tahukah Anda

Not PSYCHOLOGIST friend or boyfriend who can solve our problems, only we ourselvescan solve our problems, they just as a place for us to express a sense that there is in theheart.

Everything is not a big problem and will not be great if we believe that we can through it,speck of doubt can make us fail in solving a problem, although it was only a small problem. But if we BELIEVE that we are capable of then we must ABLE

Did you know that people who spend their time protecting others actually are people who really need someone to protect them?

Did you know that three of the hardest things to say are ... 'I love you' 'Sorry' and 'Helpme'??!

Did you know if you help someone, help will be returned two-fold?

Did you know that it's easier to say your feelings in writing than saying

Did you know that people who looked so strong his heart was very weak and needshelp?

Not everything we think it is as easy as what we imagine. stay how we are addressing aproblem that arises. we also need to go through it all no one else. So Keep Your Smile

Best Article

Visitor Information