Infection level : Fatal
Difficulty to solve : High
How to remove :
- auorun.inf
- search in start menu
- uncheck read-only option from properties of the file; apply
- open the file; delete entire text; finally save the empty file
- open file properties; make it read-only again
- windows search
- In Windows Explorer goto Organize > Folder and search optons > View > Show hidden files, folders and drives; check & apply
- search in start menu
- type "regsvr.exe"
- delete all the found items
- task scheduler
- search in start menu
- click on task schedular library
- kill "At1" process
- msconfig utility
- press windows logo key + R; run dialog box will appear
- type "msconfig"; hit enter
- switch to startup tab
- uncheck redundant enteries; apply; restart PC
- regedit
- search in start menu
- right click; run as administrator
- press ctrl + F; find dialog box appears
- type "regsvr.exe" in Find what field; delete all the found enteries
- in left pane; go to : HKEY_LOCAL_ MACHINE > SOFTWARE > Microsoft > Windows NT > CurrentVersion > Winlogon
- double click shell ; Edit String dialog box appears
- change the Value Data to Explorer.exe; restart PC
Tips :
- You may also go for Safe Mode
- Press F8 (it may vary with OS) at System Startup before the Windows logo appears to recall Advanced Startup Options including Safe Mode
How it affects the system? ..(disadvantages)
- Upto 100% CPU usage
- High load on Processor + fast rotation of CPU fan + System heatup + Battery drains fast + Slow speed of System (performance downs)
- Tempers with the Windows registry resulting Windows Startup problems + false cross references (sometime garbage values) among applets e.g. invalid administrative privileges + malfunction of the Programs
- Disables Task manager + Registry Editor
- Corrupts 3rd party Softwares; they even fail to start; even more if you re-installs a program which got infected earlier, it'll corrupt it again. It has the potential to corrupt running processes too.
- Network usage increases redundantely. Some additional Network related processes e.g. svhost.exe are added to consume data
- Windows UAC settings are turned off
End Note
- It'll impart more headache when you have to mess up with for hours & weeks
- It certainly offers a though role play for Developers, Virus Researchers & Anti-virus providers
- Though I eliminated it an year ago when I encountered it for the first time but till few days before I failed to eliminate the virus perfectly even after repeating the entire procedure 2-4 times (2 times in Safe mode)
External Links for references
- How to Remove Regsvr_exe eHow
- bitdefender w32.sohanad