Know more about Worm:Win32/Rotrumas.A
Worm:Win32/Rotrumas.A is a worm that spreads via removable drives. It may also replace found picture files with its own picture and may remove contents of document files.Once installed on the targeted computer system, Worm:Win32/Rotrumas.A downloads malevolent files and modifies the Windows Registry by generating certain registry entries so that its copy is initiated automatically whenever Windows starts.It searches the infected computer for removable drives and, if found, adds its copy in the root folder of the drive. The worm also creates a malicious file to automatically load its copy when the drive is accessed and if ‘Autorun’ is enabled. Worm:Win32/Rotrumas.A can change file and folder display settings. It can also change certain settings in the way that files and folders shown in Windows Explorer. The infection can remove the Folder Options menu item from the Tools menu and display hidden files and folders.In addition, it steals information that involves email addresses from the affected computer.How to remove Worm:Win32/Rotrumas.A step by step?
Step 1. Start your computer and tap F8 constantly before Windows loads. Highlight Safe Mode with Networking in Windows Advanced Options menu with the up and down arrow keys. Then press Enter. Step2. Press Ctrl + Alt + Delete to open Task Manager. Click Processes tab, select the all process related to the worm and terminate them. [random].exe
Step 3. Remove registry entries created by the worm. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” “0″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell” = “explorer.exe [system folder]\?ht?msys19.exe” HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “HideFileExt” “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “lsass” = “[system folder]\deter177\lsass.exe” HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “?ht?msys19.exe” = “[system folder]\ctfmon.exe”
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer “NoFolderOptions” “1″
Step3. Delete files dropped by the worm. Search for the files below and wipe them out.
[system folder]\deter177\sv?h?st.exe
[system folder]\deter177\smss.exe psador18.dll
[system folder]\deter177\?ht?msys19.exe
CDROM.exe
[system folder]\deter177\ctfmon.exe
[system folder]\deter177\lsass.exe
No comments:
Post a Comment