WELCOME .... YOU ARE THE VISITOR NUMBER ....

Saturday, April 19, 2008

UDM_StrikesBack or ViRusMaWar

What are the symptoms that shows your computer have been affected by UDM_StrikesBack or ViRusMaWar ::.

1) Task Manager have been disabled
2) Folder Option have been disabled
3) Regedit have been disabled
4) Search have been disabled
5) You can find UDM_StrikesBack.html in your drive
6) Your Internet Explorer browser shows title "VirusMawar menguCapKan SelAmaT TaHun BaRu Cina, Terutama kpd WarGa UDM+++"

What you should do to remove this virus ::.

1) Go to Run then type cmd
2) Paste this line in command window
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
3) Again, go to Run type regedit
4) In Registry editor find keyword "disabletaskmgr" then modify it to 0
5) Open your Task Manager and stop all process with name "wscript.exe"
6) Search for keyword "nofolderoption" then modify it to 0
7) You also may found keyword "NoFind" there, do same thing as before, modify it to 0
8) Open your Folder Option and in View tab, check for show hidden files and uncheck hide operating system files
9) Now you can delete the virus with name "ViRusMaWar3.js" which located in location such as "C:\WINDOWS\system32" , and all drive in your computer.
10) You also need to delete files named "Autorun.inf" and UDM_StrikesBack.html file in every drive and removable drive that have been connected with your PC before.
11) Lastly restart your computer and remember to restore back your Folder Option to previous setting.

No comments: