This virus has its own characteristics is its ability to convert all files ending in. EXE. Alman virus spreads through network targeting dnegan be shared directory and infects files - EXE files that exist in the folder.
Virus Alman is made by using the programming language Visual C + +6.0 Micrososft and be active in memory as a service and will infect the library in the file explorer.exe as well as monitoring the internet connection. This makes the malware downloaded and executed.
When the virus is active, the virus Alman will create several master file that will run the first time each computer is active. File - the file parent such as:
* C: \ Windows \ linkinfo.dll
* C: \ Windows \ System32 \ drivers \ LsDrv118.sys
* C: \ Windows \ System32 \ drivers \ nvmini.sys
* C: \ Windows \ System32 \ drivers \ cdralw.sys
* C: \ Windows \ System32 \ drivers \ riodrvs.sys
* C: \ Windows \ System32 \ drivers \ DKIs6.sys
In addition to creating a master file, the virus can also interfere with the workings of the registry and turn off and remove programs / applications / malware like c0nime.exe, ctmontv.exe, explorer.exe, internet.exe, and others - others.
Like a virus - the virus that other viruses also have an antivirus Alman. But in writing this time Alman can be cleaned without using antivirus like we used to do. Here I will explain how or steps - steps that can do to clean the virus Alman.
1. If your Internet-connected computer, unplug before cleaning.
2. Turn off System Restore during the cleaning process takes place.
3. Do the cleaning in safe mode.
4. Deadly virus active service dimemori by:
a. Click Start + Run
b. Click service.msc on the Run dialog box and click OK
5. Find a service virus by the name of NVIDIA Compatible Windows Miniport Driver or RioDrvs Usb Driver
6. Click the Action menu> Properties
7. Click the stop button
8. In the Startup Type select Manual
9. Click OK
10. Deleting Windows registry that already created by the virus that is by writing the following programs at
notepad and then saved with the name repair.inf.
[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del
[UnhookRegKey]
HKLM, Software \ CLASSES \ batfile \ shell \ open \ command ,,,,"""% 1 ""%*"
HKLM, Software \ CLASSES \ comfile \ shell \ open \ command ,,,,"""% 1 ""%*"
HKLM, Software \ CLASSES \ exefile \ shell \ open \ command ,,,,"""% 1 ""%*"
HKLM, Software \ CLASSES \ piffile \ shell \ open \ command ,,,,"""% 1 ""%*"
HKLM, Software \ CLASSES \ regfile \ shell \ open \ command ,,,," regedit.exe "% 1" "
HKLM, Software \ CLASSES \ scrfile \ shell \ open \ command ,,,,"""% 1 ""%*"
HKLM, SOFTWARE \ Micrososft \ Windows NT \ CurrentVersion \ Winlogon, Shell, 0, "Explorer.exe"
HKLM, SYSTEM \ ControlSet001 \ Control \ SafeBoot, AlternateShell, 0, "cmd.exe"
HKLM, SYSTEM \ ControlSet002 \ Control \ SafeBoot, AlternateShell, 0, "cmd.exe"
HKLM, SYSTEM \ CurrentControlSet \ Control \ SafeBoot, AlternateShell, 0, "cmd.exe"
HKLM, SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Adcanced \ Folder \ SuperHidden, UncheckedValue, 0 × 00010001.1
[Del]
HKLM, Software \ Microsoft \ Internet Explorer \ Main, Window Title
HKLM, SYSTEM \ ControlSet001 \ Services \ RioDrvs
HKLM, SYSTEM \ ControlSet001 \ Services \ cdralw
HKLM, SYSTEM \ ControlSet001 \ Services \ nvmini
HKLM, SYSTEM \ CurrentControlSet \ Services \ RioDrvs
HKLM, SYSTEM \ CurrentControlSet \ Services \ nvmini
HKLM, SYSTEM \ CurrentControlSet \ Services \ cdralw
HKLM, SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_RIODRVS
HKLM, SYSTEM \ CurrentControlSet001 \ Enum \ Root \ LEGACY_RIODRVS
HKLM, SYSTEM \ CurrentControlSet001 \ Enum \ Root \ LEGACY_nvmini
HKLM, SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_cdralw
HKLM, SYSTEM \ CurrentControlSet001 \ Enum \ Root \ LEGACY_cdralw
HKLM, SYSTEM \ CurrentControlSet001 \ Enum \ Root \ LEGACY_nvmini
11. Run the file by right click then click install repair.inf.
12. Delete files damaged by viruses in the directory
a. C: \ Windows \ linkinfo.dll
b. C: \ Windows \ System32 \ drivers \ lsDrv118.sys
c. C: \ Windows \ System32 \ drivers \ nvmini.sys
d. C: \ Windows \ System32 \ drivers \ cdralw.sys
e. C: \ Windows \ System32 \ drivers \ rodrvs.sys
f. C: \ Windows \ System32 \ drivers \ DKIs6.sys
13. Delete the file autorun.inf boot.exe and was made in flash
14. Now, before deleting the file, you should first display the hidden files by:
a. Open Windows Explorer
b. Click the "Tools" menu and select Folder Options
c. Click the tab "View"
d. Select the option to "Show Hidden Files and Folders"
e. Uncheck the option "Hide protected operating system files"
f. Click "Apply"
u. Click "OK"
Well, It's so easy how to clean virus without using antivirus?
Good try,,,, Hopefully helpful
Selasa, 21 Desember 2010
How to remove virus worm win32 without anti virus
Langganan:
Posting Komentar (Atom)
0 komentar:
Posting Komentar