luni, 20 octombrie 2008

troian dangerous

Vineri seara m-am prricopsit cu un vierme care iti intra prin portul 80 ,aparut acum aprox 1 luna si are ca efect daca va aduceti aminte blasterul(iti da mesaj - Restartare de pc),dupa care dupa restartare nu mai ai acces la partitii si iti mai strege si din date. Avand KAV 2007 instalat,acesta la detectat dar nu poate sa faca nimic. Asa ca am cautat mijloace de curatare al pc-ului, si dupa vreo 2 zile de cautari am gasit ceva vandabil,care te scuteste de pierderea timpului si de nervi. Asa ca m-am gandit sa postez metoda de dezinfectie care merge 100% cu rezultate sigure. Dezinfectia se va face numai in safe mode-ATENTIE,nu incercati in mod normal cu win ca munciti degeaba.
"Here’s the REAL way to clean this off your system. You should do these steps after a fresh reboot or in safe mode.

1) Navigate to the problem drive(s) via the Explore option.

2) Click on TOOLS -> FOLDER OPTIONS

3) Click the button which says ‘Show hidden files and folders.

4) UNCHECK the following boxes:

Hide extensions for known file types
Hide protected operrating system files

5) Find and delete the autorun.ini file and the resycled folder on the root directory of all affected drives.

6) Check “c:windowssystem32dllcache” for boot.com file and delete it if present.

7) Check “c:windowsprefetch” for boot.com file and delete if present.

8) Delete all files from c:windowstemp

(Some files may not delete, that’s ok, they’re in use by the system and not virus files.)

9) Delete all files from c:Documents and Settings[USER PROFILE]Local SettingsTemp

(Again, a couple files may not delete, don’t worry.)

10) Run Regedit

11) Make sure you are at the very first entry of the registry hive. (y Computer should be hilighted) then click EDIT -> FIND

12) Search for “boot.com”. If it finds an entry, delete it. Keep hitting F3 until you’ve deleted all instances of boot.com in the entire registry.

13) Scroll the left comumn back up to the top and hilight the My Computer again at the top of the registry hive.

14) Click Edit -> Find again and search for ‘resycled’ and repeat as in step 13, deleting the entries as it finds them. (I found 2 of each)

15) Close registry editor and try opening the infected drives. They should work now.

Worked for me at least. I ran NAV2008 2 times on it and it was able to find the files but unable to remove them for some reason. Doing this, seems to have completely resolved the issue for me.

Good luck!

Niciun comentariu: