Laman

Sabtu, 05 Maret 2011

What is Win32 Virut and how to remove it?

The Win32/Virut trojan usually infects certain .exe and .scr files in your system, giving a remote attacker access to your computer through a remote IRC server. In other words, this virus lets anonymous hackers poke around in your computer, which is never a good thing.

AVG had released already Removal Tool for Win32/Virut http://free.avg.com/us-en/win32-virut (follow the instructions on that AVG site) and in most cases it works well.
You may also try AVG Rescue CD: http://www.avg.com/eu-en/avg-rescue-cd-download
And the manual guide : http://www.avg.com/eu-en/download-documentation
info : http://www.avg.com/us-en/226386

Unless you like the idea of combing through your hard drive and finding every Win32/Virut-infected file, the best way to remove this virus is to let AVG Anti Virus take care of it

How Do You Remove Win32/Virut Files?
While you should only manually remove Win32/Virut files if you’re comfortable editing your system, you’ll find it’s fairly easy.

How to delete Win32/Virut files in Windows XP/Vista/7:
1.Click your Windows Start menu, then click “Search.”
2.A pop up will ask, “What do you want to search for?” Click “All files and folders.”
3.Type a Win32/Virut file in the search box, and select “Local Hard Drives.”
4.Click “Search.” Once the Win32/Virut file is found, delete it.

How to stop Win32/Virut processes:
1.Click the Start menu, select Run.
2.Type taskmgr.exe into the the Run command box, and click “OK.” You can also launch the Task Manager by pressing keys CTRL + Shift + ESC (you may download and use Process Explorer or Hijackthis if Task Manager  has been blocked by virus)
3.Click Processes tab, and find Win32/Virut processes.
4.Once you’ve found the Win32/Virut processes, right-click them and select “End Process” to kill Win32/Virut


Remove Win32/Virut registry keys:
Backup your registry before you edit it. Then…
1.Click the Start menu, and click “Run.” An “Open” field will appear. Type “regedit” and click “OK ” to open up your Registry Editor. In Windows 7, just type “regedit” into the “Search programs and files” box in the Start menu (you may download and use Process Explorer or Hijackthis if Registry Editor has been blocked by virus)

2.Registry Editor opens as a two-paned window: the left side lets you select registry keys,the right side shows the values of any selected registry key.
3.To find a Win32/Virut registry key, select “Edit,” then select “Find,” and in the search bar type any of Win32/Virut ‘s registry keys.
4.When the Win32/Virut registry key appears, to delete the Win32/Virut registry key, right-click it, and select “Modify,” then select “Delete.


Delete Win32/Virut DLLs:
  1. Open the Start menu, and click “Run.” Type “cmd” in Run, and click “OK.” (In Windows 7, just type “regedit” into the “Search programs and files” box in the Start menu.)
  2. To change your current directory, type “cd” in the command box, press “Space,” and enter the full directory where the Win32/Virut DLL is located. If you’re not sure where the Win32/Virut DLL is located, enter “dir” in the command box to display a directory’s contents. To go one directory back, type “cd ..” in the command box and press “Enter.”
  3. When you’ve found a Win32/Virut DLL, type “regsvr32 /u SampleDLLName.dll” (e.g., “regsvr32 /u jl27script.dll”) and press “Enter.”

If you want to restore any Win32/Virut DLL you removed, type “regsvr32 DLLJustDeleted.dll” (e.g., “regsvr32 jl27script.dll”) into your command box, and press “Enter.”

If Win32/Virut change your homepage, I recommended to set it up to blank URL
1.Select Start menu > Control Panel > Internet Options > General.
2.Type blank page URL for safety (e.g., “about:blank”).
3.Click “Use Default,” “Apply,” and “OK.


Removal Tip
Is your computer acting funny after deleting Win32/Virut files? Try Reimage, software that selectively reinstalls broken Windows files.
Also, to save time finding Win32/Virut files, download AVG Anti Virus / Internet Security, run the free scan, and manually remove Win32/Virut files it finds

Tidak ada komentar:

Posting Komentar