Hi there
The easiest way to deal with this Virus is, you have to use another clean computer with updated anti virus. let say PC-1 is infected and PC-2 is clean also fully updated anti virus. THIS IS WINXP Tested procedure, other could be and could not be the same, follow this steps.
1. Remove your infected Hard drive from PC-1
2. Put your Hard Drive as a Secondary or you can use USB-IDE or USB-SATA interface and plug in to PC-2
3. Boot your PC-2 (clean computer) ... !!
4. Scan your Infected Hard Drive ... light up your cigarette, a cup of coffee/tee .. and relax :) until it finished.
5. Put back your hard drive where it came from (PC-1)
6. Boot your PC-1
7. While login you will see some error message like could not find bla bla bla... just "NOTE " that message. You will need it .. :) we will fix it using REGEDIT
8. Update your Anti virus ... you or maybe better new Install Anti Virus and do update :(
9. do anti virus "Full System Scan" again ...
10. now click START > RUN
11 Type regedit
12. If Regedit won't show. !!! you should download UnHookExec.inf from symantec http://securityresponse.symant ec.com/avc...
or read it http://www.symantec.com/securi ty_respons...
13. after download that file, Right-click the UnHookExec.inf file and click install.
14. Regedit should work this time. click START > RUN & type Regedit
15. go to this section
HKEY_LOCAL_MACHINE\
SOFTW ARE\
Microsoft\
Windows NT\
CurrentVersion\
Winlogon
go to "UIHost" change the value with (double click)
"logonui.exe"
also go to "Userinit" change the value with
"C:\WINDOWS\system32\u serinit.... couse this line wont see all so "\userinit...." should be "\userinit.exe,"
16. Now we will remove the rest registry entry that you already noted (see step 7).
on REGEDIT press CTRL-F and fill the Find field with one of your note (step 7) then enter ....
once you got and remove it... FIND AGAIN and AGAIN until nothing can't find. repeat with other warning note
17. Try Reboot Your computer ...should be Clean by now
If you got some warning message like could not find bla bla ... just note what it is and follow STEP 16.
Answered by
Reeta K
, an ibibo Master,
at
2:15 PM on June 11, 2008