Skip to content


Malware Prevalence – 3 Malware to Beware of

Posted in Tutorials.
Malware Prevalence – 3 Malware to Beware of

Virus Bulletin independently tests anti-virus products. This is a malware prevalence report submitted by VB100. The Virus Bulletin prevalence table is compiled monthly from virus reports received by Virus Bulletin; both directly, and from other companies who pass on their statistics.

antimalware01

Remove Conficker Manually
1. Conficker Worm attaches itself to these processes.
svchost.exe
explorer.exe
services.exe
2. Remove Conficker Worm registry keys
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices{random}Parameters”ServiceDll” = “Path to worm”
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices{random}”ImagePath” = %SystemRoot%system32svchost.exe -k netsvcs
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParameters
“TcpNumConnections” = dword:0×00FFFFFE
3. Delete Conficker Worm DLLs
%System%[Random].dll
%Program Files%Internet Explorer[Random].dll
%Program Files%Movie Maker[Random].dll
%All Users Application Data%[Random].dll
%Temp%[Random].dll
4. Delete Conficker Worm files
%System%[Random].tmp
%Temp%[Random].tmp

Remove Autorun
1. Kill the autorun process through Task Manager.
2. Restart the system in safe mode and open the command prompt.
3. List all system and .exe files on the C drive.
4. Disable hidden, system, and read only attributes for autorun.inf and ntdelect.com.
5. Repeat these steps for all the drives on your computer.
6. Search for kavo.exe in C:\windows\system32\ and delete it.
7. Clear the following registry,
HKEY_LOCAL_MACHINE\SOFTWARE
HKEY_CURRENT_USER\SOFTWARE

Remove Virtumonde Manually
1. Kill the following process in task manager
windowsupd2.exe
winhost.exe
quicken.exe
editpad.exe
%System%\winhost32.exe
2. Remove the following VirtuMonde Registry Values
KEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}scan
HKEY_LOCAL_MACHINE\SOFTWARE\TargetSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEpl.IEpl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEpl.IEPl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tdev
HKEY_USERS\S-1-5-21-1887652994-1477516851-2064603551-500\Software\Microsoft
HKEY_CLASSES_ROOT\CLSID\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
\Windows\CurrentVersion\Ext\Stats\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder.1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
2. Delete the following VirtuMonde DLLs
virtumonde.dll
lspak.dll
%System%\wincore.dll
%System%\cidrules.dll
%UserProfile%\Local Settings\Temp\wincore.dll
%System%\winupd.dll
%UserProfile%\Local Settings\Temp\cidrules.dll

Tagged with , , .


2 Responses

Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.

  1. lace wigs says

    Winter day, my father,Lace Wigs mother and grandmother.Lace Front WigsAlong the way,Full Lace Wigs I saw was stuck in traffic.Custom Lace Wigs Mother said: “there are a lot of automotive exhaust,Beyonce Lace Wigs carbon dioxide inhalation body bad to the body,Indian Lace Wigs still can increase the body’s lead,Remy Lace Wigs affect our growth.”Human Hair Wigs If more than one out of the car and car exhaust,Human Wigs therefore,Straight Wigs we should protect the environment and driving less as far as possible,Wavy Wigs had better not drive,Curly Wigs to take a bus.Celebrity WigsThrough a park!Spring is near,every girl wants to be the bride in the special season.links of london mother of the bride dresses prom dresses brides dresses plus size wedding dresses bridesmaid dresses

  2. columbia sportwear says

    Make tracks to the nearest lodge in this Columbia Sportswear alpine-inspired zip up Columbia Shoesfeatures the cozy look of a sweater outside and the comfort of soft fleece inside Columbia FEATURES No need to dodge raindropsOmni-ShieldColumbia Mens Shoes water-repellent finishColumbia Sportswear Clothing offers great protection from the elements Columbia Sportswear OutletFlattering seaming at the waist and front slant pockets Shaped fit Made of 100 polyester Heritage sweater fleece Omni-Shield advanced repellency Front slant pocketsColumbia Sportswear Parka Columbia Jackets ALPINE TRAX FULL ZIP Columbia Hiking Shoes Columbia Clothingsweaters Columbia Sportswear Jackets full zip jackets women s sweater Columbia Sportswear Titanium Columbia Sportswear Sale
    Fix It
    Pandora



Some HTML is OK

or, reply to this post via trackback.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word