Академический Документы
Профессиональный Документы
Культура Документы
P/S : You dun have to think you could google Antivirus or similar keyword on your
browser, bcoz it will auto close your browser.
1st We need to get alternative 3rd party Task manager, i recommend Starter
http://www.snapfiles.com/opinions/Starter/Starter.html
2nd Replace your Task Manager with Process Explorer, which have more details
compare with taskmgr.exe
http://www.microsoft.com/technet/sysintern...ssExplorer.mspx
3rd Enable to view SUPER HIDDEN FOLDER, Please download this regtick
http://www.snapfiles.com/get/regtick.html
Lets Start....
Run Starter, kill these processes currently running, KILL THESE PROCESSES IF RUNS
UNDER "YOUR USERNAME" NOT THE "SYSTEM". If you accidently kill any process
under System, no worry.. Either your pc auto restart or just u need to reboot your pc.
j<random>.exe
o<random>.exe
b<random>.exe
csrss.exe
lsass.exe
services.exe
smss.exe
sv<random>.exe
winlogon.exe
Done, now you should able to run your task manager. Please user Process Explorer.
Double check any of these process listed above still running. If yes, please kill it.
Completed then now we'll remove the physical files used by this virus. Please access
to these locationd and remove all the files
Use regtick to enable your regedit.exe, done proceed to remove the registry entry
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run
<random characters>
<User>\Local Settings\Application Data\dv<random>\yesbron.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
<random characters>
<Windows>\_default<random>.pif
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
<random characters>
<System>\n<random>\sv<random>.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random characters>
<Windows>\j<random>.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<Windows>\o<random>.exe"
(the default value for this registry entry is "Explorer.exe" which causes the Microsoft
file <Windows>\Explorer.exe to be run on startup).
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Windows>\j<random>.exe
The following registry entry is set, disabling the registry editor (regedit):
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
Registry entries are set as follows:
HKCU\Software\Brontok
Message
Look @ "C:\Baca Bro !!!.txt"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
0
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0