Conficker B++ manual removal:
Kill processes:
svchost.exe explorer.exe services.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHO WALLCheckedValue = dword:00000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, netsvcs = %Previous data% and %Random%
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\
DisplayName = %ServiceName%
Type = dword:00000020
Start = dword:00000002
ErrorControl = dword:00000000
ImagePath = ?€?%SystemRoot%\system32\svchost.exe -k netsvcs?€?
ObjectName = ?€?LocalSystem?€?
Description = %description%
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[random]\Parameters
ServiceDll = %MalwarePath%
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\Parameters\?€?ServiceDll?€? = ?€?Path to worm?€?
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\?€?ImagePath?€? = %SystemRoot%\system32\svchost.exe -k netsvcs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
?€?TcpNumConnections?€? = dword:0?—00FFFFFE
Unregister DLLs:[Random].dll
Delete files:%System%\\[Random].tmp %Temp%\\[Random].tmp
Post Comment: