Step removed manually:
1. Windows in safe mode, please restart.
2. Worm changes to fix the value of the registry.
The following registry please correct the value. Rectification registry values, please see.
Location:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \
CurrentVersion \ Winlogon
Value (before):
Userinit = “<Windows FORUDA> \ userinit.exe”
Value (after):
Userinit = “<Windows SHISUTEMUFORUDA> \ userinit.exe”
3. Windows search function (Start] → [search] → [All files and folders to choose), using the worm was created following the unwanted file and delete the cases detected Please.
* MSWINSCK.OCX
* Kdcoms.dll
4. Worm have added “AUTORUN.INF” is removed.
1. Windows search function (Start] → [search] → [All files and folders to choose), using, “AUTORUN.INF” to find and detect if a text file, such as Notepad. Please use the open.
2. Following a string exists to make sure the file exists, please delete.
[AutoRun]
open = Secret.exe
; shell \ open = Open (& O)
shell \ open \ Command = Secret.exe
shell \ open \ Default = 1
; shell \ explore = Manager (& X)
shell \ explore \ Command = Secret.exe
3. Above “AUTORUN.INF” there is a drive to open the INF file, please delete.
5. Restart the computer in normal mode, please. The latest version (engine and pattern file) with the introduction of anti-virus products, scanners, please run. The worm is “WORM_AUTORUN.EB” and detected. All files are detected, please delete.
6. All drive search and detected nothing if the process is complete.
"Free Scan kill WORM_AUTORUN.EB

Leave a Comment
You must be logged in to post a comment.