Rodun manual removal:
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCloseKey=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active\Rodune
Delete directories:C:\Windows\Book
C:\Winnt\Book
C:\Windows\Car
C:\Winnt\Car
C:\Windows\Game
C:\Winnt\Game
C:\Windows\Girl
C:\Winnt\Girl
C:\Windows\Movie
C:\Winnt\Movie
C:\Windows\Music
C:\Winnt\Music
C:\Windows\Study
C:\Winnt\Study
C:\Windows\Text
C:\Winnt\Text
C:\Windows\Woman
C:\Winnt\Woman
Misc:The virus uses files with various names.
Post Comment: