07 April 2009

VIRUS CONFICKER / KIDO / DOWNADUP

At this time the virus conficker is a serious enough threat. For that I will give way to overcome the attack of the virus.The characteristics of the virus attack is : network connection lost frequently, the error message Generic Host Process , Disable Task Manager, Disable Regedit.

Steps killing virus conficker attacks:
  1. Prepare the tools Microsoft Malicious Removal, Download tools
  2. Prepare tools Avira Premium Antivir, Download Avira
  3. Prepare tools Webroot Desktop Firewall, Download Webroot Firewall
  4. Patch Windows with the latest patch, please search using google or go directly to the microsoft site.
  5. Prepare everything in the cd, try burning it on cd computer clean from viruses
  6. Click Start, RUN and type cmd. on C prompt type Attrib -a -h -r -s /D /S,
    Wait until the process is complete, If you are finished, type this command at the prompt: rmdir /S c:\recycler and answer with "Y". If there is another partition then do this at the prompt partition.
  7. Type this command on prompt : del desktop.ini
  8. Setup the latest service pack windows .
  9. Run Microsoft Malicious Removal Tools, wait until finished this process.
  10. If Finished and then do process setup Avira Premium Antivir .
  11. Continue with installl Webroot Desktop Firewall.
  12. Do Enable Regedit, Enable Task Manager, Enable Msconfig, Disbale autoplay/autorun.
  13. Script for EnableTask Manager (just copy this script on Notepad ) : reg add hkcu/Software/Microsoft/Windows/CurrentVersion/Policies/System /v DisableTaskManager /t REG_DWORD /d 0 /f, Save and give name with TM.inf, and then right click on this file, choose Install.
  14. Script for Enable Regedit : reg add hkcu/Software/Microsoft/Windows/CurrentVersion/Policies/System /v DisableRegistryTools /t REG_DWORD /d 0x0, appear after the words below "Value Disable Registry Tools exists, Overwrite y/n" and then answer "Y"
  15. Script for Disable Autoplay :
[Version]
Signature="$Chicago$"
Provider=Vaksincom

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255

Save and give name : DisAutoplay.inf, and then right click on this file, choose Install.



Regard,

IT KNOWLEDGE

No comments:

Post a Comment