Question about Operating Systems

1 Answer

Virus hi i have to clear w32..wat i want to do????

Posted by on

  • PureFire May 11, 2010

    if you can "boot-up" open "regedit" and follow this:
    current_user\software\Microsoft\windows\current version\run
    In there is the list of start up tasks find which one doesn't look legit and find the path of the file and trace it back to its root folder and delete it.

  • Lee Hodgson
    Lee Hodgson May 11, 2010

    Hi there.
    The win32 virus is very serious, can you tell me how bad the PC is acting and when you think you got the virus, then i will be able to give you a concise answer on that to do.

    Regards


×

1 Answer

  • Level 1:

    An expert who has achieved level 1.

    Hot-Shot:

    An expert who has answered 20 questions.

    Corporal:

    An expert that hasĀ over 10 points.

    Mayor:

    An expert whose answer gotĀ voted for 2 times.

  • Contributor
  • 21 Answers

Try kaspersky internet security....

Posted on Mar 11, 2009


Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

Remove w32/sality


Infected files can be healed by using of Win32/Sality removal tool. Download the following three files ( rmsality.exe, rmsality.nt, rmsality.dos) and run the rmsality.exe file. 1)rmsality.exe 2)rmsality.nt 3)rmsality.dos
Note:
Successful running of the remover requires administrator rights. After the healing process please run the antivirus to make sure your computer is virus-free.
good luck!

Jun 23, 2010 | Microsoft Windows XP Professional SP2

2 Answers

Can't delete viruses: i'm using antivir guard and there are a lot of viruses that can't be deleted namely worm/mabezat,w32/mabezat, tr/dropper.gen


boot the system into safe mode by hitting the f8 key after the bios flashes onscreen but before the windows load screen comes up try cleaning the system in safe mode...also try using windows help support and the system restore utility and take the system back to before u had the virus.
if this wont work for you you need to seek a local professional

Oct 02, 2009 | HP Operating Systems

1 Answer

Removing csrcs.exe virus


What you are referring to is probably the W32.Harakit virus. You can find removal instructions here:
http://www.symantec.com/security_response/writeup.jsp?docid=2008-102011-5014-99&tabid=3

Apr 06, 2009 | Microsoft Windows XP Professional

4 Answers

Cannot access anti-virus websites


Download STINGER antivirus and scan with this tool.

Variants Can Detect:
BackDoor-ALI,BackDoor-AQJ,BackDoor-AQJ.b,BackDoor-CEB,BackDoor-CEB!bat,BackDoor-CEB!hosts,BackDoor-CEB.b,BackDoor-CEB.c,BackDoor-CEB.d,BackDoor-CEB.dll,BackDoor-CEB.dr,BackDoor-CEB.e,BackDoor-CEB.f,BackDoor-CEB.sys,BackDoor-CFB,BackDoor-JZ,BackDoor-JZ.dam,BackDoor-JZ.dr,BackDoor-JZ.gen,BackDoor-JZ.gen.b,Bat/Mumu.worm,Cleanup,CoreFlood,Coreflood!psexec,Coreflood.dldr,CoreFlood.dll,CoreFlood.dr,Danmec,Downloader-DN.a,Downloader-DN.b,Downloader-UA,Exploit-DcomRpc,Exploit-DcomRpc.b,Exploit-DcomRpc.dll,Exploit-Lsass,Exploit-Lsass.dll,Exploit-MS04-011,Exploit-MS04-011.gen,Exploit-MSExcel.k,Exploit-MSExcel.l,Exploit-MSExcel.m,Exploit-MSExcel.n,Exploit-MSExcel.o,Exploit-MSExcel.p,Exploit-MSExcel.q,Exploit-MSExcel.r,Exploit-PDF.b,Exploit-PDF.c,Exploit-PDF.d,Exploit-PDF.e,Exploit-PDF.f,Exploit-PDF.g,Exploit-PDF.h,Exploit-XMLhttp.d,Exploit-XMLhttp.d.gen,Exploit-XMLhttp.d.gen.b,Exploit-XMLhttpd.d,FakeAlert,FakeAlert-AA,FakeAlert-AB,FakeAlert-AB!htm,FakeAlert-AB.dldr,FakeAlert-AB.dr,FakeAlert-AC,FakeAlert-AD,FakeAlert-AE,FakeAlert-AF,FakeAlert-AG,FakeAlert-AG.gen.b,FakeAlert-AG.gen.c,FakeAlert-AH,FakeAlert-AI,FakeAlert-AJ,FakeAlert-AK,FakeAlert-AL,FakeAlert-AM,FakeAlert-AN,FakeAlert-AntiVirusPro,FakeAlert-AntiVirusXP,FakeAlert-AO,FakeAlert-AP,FakeAlert-AQ,FakeAlert-AR,FakeAlert-AS,FakeAlert-AT,FakeAlert-AU,FakeAlert-av360,FakeAlert-AW,FakeAlert-AZ,FakeAlert-AZ!htm,FakeAlert-B,FakeAlert-B.dldr,FakeAlert-B.dr,FakeAlert-BA,FakeAlert-BB,FakeAlert-BC,FakeAlert-BD,FakeAlert-BE,FakeAlert-BE.gen,FakeAlert-BF,FakeAlert-BG.dldr,FakeAlert-BH.dldr,FakeAlert-BI,FakeAlert-BJ,FakeAlert-BK,FakeAlert-BL,FakeAlert-BM,FakeAlert-BN,FakeAlert-BO,FakeAlert-BO.dldr,FakeAlert-BP,FakeAlert-BQ,FakeAlert-BR,FakeAlert-BS,FakeAlert-C,FakeAlert-C.dr,FakeAlert-C.gen,FakeAlert-D,FakeAlert-E,FakeAlert-F,FakeAlert-G,FakeAlert-H,FakeAlert-I,FakeAlert-J,FakeAlert-K,FakeAlert-L,FakeAlert-LastDefender,FakeAlert-M,FakeAlert-N,FakeAlert-N.dldr,FakeAlert-O,FakeAlert-P,FakeAlert-Q,FakeAlert-R,FakeAlert-S,FakeAlert-S.dll,FakeAlert-SpyKiller,FakeAlert-SpywareGuard,FakeAlert-T,FakeAlert-U,FakeAlert-V,FakeAlert-W,FakeAlert-WinwebSecurity,FakeAlert-X,FakeAlert-XPAntivirus,FakeAlert-XPSecCenter,FakeAlert-Y,FakeAlert-Y.dr,FakeAlert-Z,Fribet,Generic FakeAlert,Generic FakeAlert.d,Generic FakeAlert.e,Generic!atr,HideWindow,HideWindow.dll,HTool-T2W,IPCScan,IRC/Flood.ap,IRC/Flood.ap.bat,IRC/Flood.ap.dr,IRC/Flood.bi,IRC/Flood.bi.dr,IRC/Flood.cd,JS/Autorun.worm.ci,JS/Downloader-AUE,JS/FakeAlert,JS/FakeAlert-AB.dldr,NTServiceLoader,ProcKill,Proxy-Agent.af,Proxy-Agent.af.dr,PWS-Banker.dldr,PWS-FireMing,PWS-FireMing.dll,PWS-FireMing.dr,PWS-Gamania.gen.a,PWS-Narod,PWS-Narod.dll,PWS-Narod.gen,PWS-Sincom,PWS-Sincom.dll,PWS-Sincom.dr,rootkit,VBS/Autorun.bj,VBS/Autorun.worm.au,VBS/Autorun.worm.ay,VBS/Autorun.worm.bi,VBS/Autorun.worm.bj,VBS/Autorun.worm.bs,VBS/Autorun.worm.by,VBS/Autorun.worm.ca,VBS/Autorun.worm.cy,VBS/Autorun.worm.dm,VBS/Autorun.worm.dn,VBS/Autorun.worm.dn!atr,VBS/Autorun.worm.dn!txt,VBS/Autorun.worm.dv,VBS/Autorun.worm.dz,VBS/Autorun.worm.en,VBS/Autorun.worm.k,VBS/Autorun.worm.k!bat,VBS/Autorun.worm.zd,VBS/Autorun.worm.ze,VBS/Autorun.worm.zl,VBS/Autorun.worm.zn,VBS/FakeAlert-AB,VBS/IE-Title,Vundo,Vundo.dldr,Vundo.dr,Vundo.gen.h,Vundo.gen.i,Vundo.gen.j,Vundo.gen.k,Vundo.gen.l,Vundo.gen.m,Vundo.gen.n,Vundo.gen.o,Vundo.gen.p,Vundo.gen.r,Vundo.gen.s,Vundo.gen.t,Vundo.gen.u,W32/Anig.worm,W32/Anig.worm.dll,W32/Autorun.worm,W32/Autorun.worm!inf,W32/Autorun.worm!ini,W32/Autorun.worm.a,W32/Autorun.worm.aa,W32/Autorun.worm.ab,w32/autorun.worm.ac,W32/Autorun.worm.ad,W32/Autorun.worm.ae,W32/Autorun.worm.af,W32/Autorun.worm.ag,W32/Autorun.worm.ai,W32/Autorun.worm.aj,W32/Autorun.worm.ak,W32/Autorun.worm.al,W32/Autorun.worm.am,W32/Autorun.worm.an,W32/Autorun.worm.ao,W32/Autorun.worm.ap,W32/Autorun.worm.aq,W32/Autorun.worm.ar,W32/Autorun.worm.as,W32/Autorun.worm.at,W32/Autorun.worm.av,W32/Autorun.worm.aw,W32/Autorun.worm.ax,W32/Autorun.worm.az,W32/Autorun.worm.b,W32/Autorun.worm.b.cfg,W32/Autorun.worm.ba,W32/Autorun.worm.bb,W32/Autorun.worm.bc,W32/Autorun.worm.bd,W32/Autorun.worm.be,W32/Autorun.worm.bf,W32/Autorun.worm.bg,W32/Autorun.worm.bh,W32/Autorun.worm.bk,W32/Autorun.worm.bl,W32/Autorun.worm.bm,W32/Autorun.worm.bn,W32/Autorun.worm.bo,W32/Autorun.worm.bp,W32/Autorun.worm.bp!reg,W32/Autorun.worm.bq,W32/Autorun.worm.br,W32/Autorun.worm.bt,W32/Autorun.worm.bw,W32/Autorun.worm.bx,W32/Autorun.worm.bx!inf,W32/Autorun.worm.bx.gen,W32/Autorun.worm.bz,W32/Autorun.worm.c,W32/Autorun.worm.cb,W32/Autorun.worm.cb.dr,W32/Autorun.worm.cc,W32/Autorun.worm.cd,W32/Autorun.worm.ce,W32/Autorun.worm.cf,W32/Autorun.worm.cg,W32/Autorun.worm.ch,W32/Autorun.worm.cj,W32/Autorun.worm.ck,W32/Autorun.worm.cm,W32/Autorun.worm.cn,W32/Autorun.worm.co,W32/Autorun.worm.cp,W32/Autorun.worm.cp!bat,W32/Autorun.worm.cq,W32/Autorun.worm.cr,W32/Autorun.worm.cs,W32/Autorun.worm.ct,W32/Autorun.worm.cu,W32/Autorun.worm.cv,W32/Autorun.worm.cw,W32/Autorun.worm.cx,W32/Autorun.worm.cz,W32/Autorun.worm.d,W32/Autorun.worm.da,W32/Autorun.worm.db,W32/Autorun.worm.dc,W32/Autorun.worm.dd,W32/Autorun.worm.dd!inf,W32/Autorun.worm.de,W32/Autorun.worm.df,W32/Autorun.worm.dg,W32/Autorun.worm.dh,W32/Autorun.worm.di,W32/Autorun.worm.dj,W32/Autorun.worm.dk,W32/Autorun.worm.dl,W32/Autorun.worm.dn,W32/Autorun.worm.do,W32/Autorun.worm.dp,W32/Autorun.worm.dq,W32/Autorun.worm.ds,W32/Autorun.worm.dt,W32/Autorun.worm.du,W32/Autorun.worm.dw,W32/Autorun.worm.dx,W32/Autorun.worm.dy,W32/Autorun.worm.e,W32/Autorun.worm.ea,W32/Autorun.worm.eb,W32/Autorun.worm.ec,W32/Autorun.worm.ed,W32/Autorun.worm.ef,W32/Autorun.worm.eg,W32/Autorun.worm.ei,W32/Autorun.worm.ej,W32/Autorun.worm.ek,W32/Autorun.worm.el,W32/Autorun.worm.em,W32/Autorun.worm.eo,W32/Autorun.worm.ep,W32/Autorun.worm.eq,W32/Autorun.worm.f,W32/Autorun.worm.g,W32/Autorun.worm.gen!job,W32/Autorun.worm.gen.cl,W32/Autorun.worm.gen.za,W32/Autorun.worm.gen.zb,W32/Autorun.worm.h,W32/Autorun.worm.h!lnk,W32/Autorun.worm.i,W32/Autorun.worm.j,W32/Autorun.worm.l,W32/Autorun.worm.m,W32/Autorun.worm.n,W32/Autorun.worm.o,W32/Autorun.worm.p,W32/Autorun.worm.q,W32/Autorun.worm.r,W32/Autorun.worm.remmants,W32/Autorun.worm.s,W32/Autorun.worm.t,W32/Autorun.worm.u,W32/Autorun.worm.v,W32/Autorun.worm.v!bat,W32/Autorun.worm.w,W32/Autorun.worm.x,W32/Autorun.worm.y,W32/Autorun.worm.z,W32/Autorun.worm.zc,W32/Autorun.worm.zf,W32/Autorun.worm.zg,W32/Autorun.worm.zh,W32/Autorun.worm.zi,W32/Autorun.worm.zj,W32/Autorun.worm.zk,W32/Autorun.worm.zm,W32/Bagle,W32/Bagle!eml.gen,W32/Bagle!pwdzip,W32/Bagle.ad!src,W32/Bagle.dldr,W32/Bagle.dll.dr,W32/Bagle.eml,W32/Bagle.fb!pwdzip,W32/Bagle.fc!pwdzip,W32/Bagle.fd!pwdzip,W32/Bagle.fe!pwdzip,W32/Bagle.fm.dldr,W32/Bagle.gen,W32/Bagle@MM!cpl,W32/Blaster.worm,W32/Blaster.worm.k,W32/Bropia.worm,W32/Bugbear,W32/Bugbear.a.dam,W32/Bugbear.b!data,W32/Bugbear.b.dam,W32/Bugbear.gen@MM,W32/Bugbear.h@MM,W32/Bugbear@MM,W32/Conficker,W32/Conficker.sys,W32/Conficker.worm,W32/Conficker.worm!inf,W32/Conficker.worm!job,W32/Conficker.worm.gen.a,W32/Conficker.worm.gen.b,W32/Deborm.worm.ah,W32/Deborm.worm.gen,W32/Doomjuice.worm,W32/Dumaru,W32/Dumaru.ad@MM,W32/Dumaru.al.dll,W32/Dumaru.dll,W32/Dumaru.eml,W32/Dumaru.gen,W32/Dumaru.gen@MM,W32/Dumaru.w.gen,W32/Elkern.cav,W32/Elkern.cav.c,W32/Elkern.cav.c.dam,W32/Fizzer,W32/Fizzer.dll,W32/Fujacks!htm,W32/FunLove,W32/FunLove.apd,W32/Gaobot.worm,W32/Harwig.worm,W32/IRCbot,W32/IRCbot.worm,W32/IRCbot.worm.dll,W32/Klez,W32/Klez.dam,W32/Klez.eml,W32/Klez.gen.b@MM,W32/Klez.rar,W32/Koobface.worm,W32/Korgo.worm,W32/Lirva,W32/Lirva.c.htm,W32/Lirva.eml,W32/Lirva.gen@MM,W32/Lirva.htm,W32/Lirva.txt,W32/Lovgate,W32/Mimail,W32/Mimail.c@MM,W32/Mimail.i!data,W32/Mimail.q@MM,W32/MoFei.worm,W32/MoFei.worm.dr,W32/Mumu.b.worm,W32/Mydoom,W32/Mydoom!bat,W32/Mydoom!ftp,W32/Mydoom.b!hosts,W32/Mydoom.dam,W32/Mydoom.t.dll,W32/Mytob,W32/Mytob.gen@MM,W32/Mytob.worm,W32/MyWife,W32/MyWife.dll,W32/MyWife@MM,W32/Nachi!tftpd,W32/Nachi.worm,W32/Netsky,W32/Netsky.af@MM,W32/Nimda,W32/Nimda.dam,W32/Nimda.eml,W32/Nimda.gen@MM,W32/Nimda.htm,W32/Nuwar,W32/Nuwar.dam,W32/Nuwar.sys,W32/Nuwar@MM,W32/Nuwar@MM!rar,W32/Pate,W32/Pate!dam,W32/Pate.dam,W32/Pate.dr,W32/Polip,W32/Polip!mem,W32/Polybot,W32/Polybot.bat,W32/Sasser.worm,W32/Sasser.worm!ftp,W32/Sdbot,W32/Sdbot!irc,W32/Sdbot.bat,W32/Sdbot.cli,W32/Sdbot.dll,W32/Sdbot.dr,W32/Sdbot.worm,W32/Sdbot.worm!ftp,W32/Sdbot.worm.bat.b,W32/Sdbot.worm.dr,W32/Sdbot.worm.gen,W32/Sdbot.worm.gen.a,W32/Sdbot.worm.gen.b,W32/Sdbot.worm.gen.c,W32/Sdbot.worm.gen.d,W32/Sdbot.worm.gen.e,W32/Sdbot.worm.gen.q,W32/Sober,W32/Sober!data,W32/Sober.dam,W32/Sober.eml,W32/Sober.f.dam,W32/Sober.g.dam,W32/Sober.q!spam,W32/Sober.r.dr,W32/Sober.r@MM,W32/Sobig,W32/Sobig.dam,W32/Sobig.eml,W32/Sobig.f.dam,W32/Sobig.gen@MM,W32/Spybot.worm,W32/SQLSlammer.worm,W32/Swen,W32/Swen@MM,W32/Virut,W32/Virut!mem,W32/Yaha.eml,W32/Yaha.gen@MM,W32/Yaha.y@MM,W32/Yaha@MM,W32/Zafi,W32/Zafi.b.dam,W32/Zindos.worm,W32/Zotob.worm,W32/Zotob.worm!hosts


Download v10.0.0.482 [2,641,920 bytes] (01/10/2009).


Hope this will be helpfull

Thanks & Regards

Nanda Kishore :)

Mar 25, 2009 | Microsoft Windows XP Professional

1 Answer

I couldn't view the hidden files when i apply show hidden files in my folder options in tools menu in menu bar.


Folder Options is removed from Tools in Windows by a virus. The virus is called W32.Rontokbro@mm OR W32/Rontokbro.gen@MM

The removal of this virus is slightly difficult. Antivirus can't remove it automatically. However detailed procedure to remove it is available at

http://coolexp.blogspot.com/2008/01/fold...

About this Virus/Worm:
What it does is creating new files which looked like a folder but its actually a .exe file. Unless you’ve enabled the view extensions in the folder options or else you won’t see the .exe extension of the file. The file is approximately 43.7Kb and normally people will click to open it because it looked like a folder. So after you’ve open it, the virus will run each time during startup and keep on spreading and spreading… into the harddrives.

More troubles coming up. Normally when you click “Tools” in explorer, there’s a “folder options” underneath it. Once the pc is infected with the virus, the Folder Options will be missing, which disabled you to change the options to view the extension of the files. So when you see a new folder appeared from nowhere and you clicked to open it out of curiousity, the virus spread more again. Moreover, the virus disabled the registry edit where you will see this message “Registry edit is disabled by the administrator” everytime you try to edit the registry.

So how to clean the virus then? I found some solution from the following link and have successfully cleaned it from my system.

http://coolexp.blogspot.com/2008/01/fold...

It will help you to get rid of this virus named W32.Rontokbro@mm aka brontok.a and to get back your hidden files. Source(s): http://coolexp.blogspot.com/2008/01/fold...

P.S.: If this information was helpful, please rate this solution.

Mar 14, 2009 | Microsoft Windows XP Professional

1 Answer

W32 Virus


Kaspersky AntiVirus is Best ....

Download Kaspersky Antivirus and your problem will be solved...

Dec 20, 2008 | Microsoft Windows XP Professional

5 Answers

Windows xp


First thought: Not a legal copy or not activated?
Second thought: A virus or spyware? Have you run a full virus scan and a separate antispyware scan?

I don't know if either of these will work, but give them a try (especially the full anti virus and anti spyware scans). I use AVG Antivirus Free and AVG Antispyware Free. I also use ZoneAlarm Free as my firewall to prevent hackers getting access.

I have had a somewhat similar problem (years ago) which turned out to be some malicious spyware controlling access to some Administrator functions.

Good luck

Apr 06, 2008 | Microsoft Windows XP Professional

2 Answers

Funny UST Scandal


hi my friend got that last week to... ehat you need to do is download kaspersky. after running kaspersky. that will be gone. you can download kaspersky @ majorgeeks.com Here are some examples of autorun viruses which rely on the autorun function of Windows to infect PC’s and flash drives. Funny UST Scandal.avi.exe Autorun.vbs win32.autorun.k copy.exe imgkulot taga lipa are autorun.vbs recycler FS6519.dll.vbs strawberry from baguio W32/Perlovga (copy.exe | host.exe) VBS_RESULOWS.A Bha.dll.vbs w32automa worm (Autorun.vbs) Trojan.Win32.VB.atg | Win32/Dzan | Worm_vb.bnr (tel.xls.exe | mmc.exe) W32/RJump.worm (RavMonE) Worm.Win32.Delf.bf | W32.Fujacks (spoclsv.exe) W32.Fujacks.BH (****.vbs) WORM_AGENT.PGV (soundmix.exe) W32/Hakaglan.worm (RVHost.exe) Trojan.Win32.VB.ayo [AVP] (Macromedia_Setup.exe) Trojan.VBS.DeltreeY.b#1 (Destrukto!!! | destrukto.vbs) if you want to manually delete it... Solution is here: 1. Start Notepad [Start Menu-All Programs-Accessories-Notepad] or right-click any empty space in your desktop then select New-Text Document 2. Copy the following text. (note: Everything in between the square brackets should be in one line) REGEDIT4 [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIniFileMappingAutorun.inf] @="@SYS:DoesNotExist" 3. Save the file with a name (anything) like DisableAutoRun.reg (The extension .reg is the important part) 4. Double Click your newly created registry file. Choose yes or continue to the warning that will appear. hope this helps

Jan 24, 2008 | Operating Systems

1 Answer

Rontokbro


You can run the w32.Rontokbro.mm through google, you know do a search.  Here is just one link I found to remove the virus: http://srnmicro.com/virusinfo/brontok.htm

Oct 30, 2007 | Microsoft Windows 2000 for PC

Not finding what you are looking for?
Operating Systems Logo

Related Topics:

26 people viewed this question

Ask a Question

Usually answered in minutes!

Top Operating Systems Experts

Les Dickinson
Les Dickinson

Level 3 Expert

18299 Answers

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

Prashant  Sharma
Prashant Sharma

Level 3 Expert

1127 Answers

Are you an Operating System Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...