Yadurna manual removal:
Kill processes:
csrss.exe, dalang mistiq.exe, dokument.exe, hp bunga citri lestari.exe, kota p4hlawan.exe, lo5tword.exe, lsass.exe, majnun was h3ere.exe, sma negeri 4.exe, smss.exe, spoolsv.exe, svchost.exe, tugas.exe, windows [X1].exe, w32 wayang.exe, w4y4n9.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\csrss
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dalang mistiq
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dokument
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gatotkaca
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hanuman
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\HP Bunga Citra Lestari
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Kota P4hlawan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lo5tword
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lsass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Majnun was h3re
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SMA Negeri 4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spoolsv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tugas
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows [X1]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\w32 Wayang
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\w4y4n9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe [filename].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System=[filename].exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ReportBookOk=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCScan=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoTrayContextMenu=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu=1
Delete files:csrss.exe, dalang mistiq.exe, dokument.exe, hp bunga citri lestari.exe, kota p4hlawan.exe, lo5tword.exe, lsass.exe, majnun was h3ere.exe, sma negeri 4.exe, smss.exe, spoolsv.exe, svchost.exe, tugas.exe, windows [X1].exe, w32 wayang.exe, w4y4n9.exe, gatotkaca.scr
Delete directories:C:\WINDOWS\Administrator durjana
C:\WINDOWS\Microsoft Administrator
C:\WINDOWS\nakula sadewa
C:\WINDOWS\Software Administrator
C:\WINDOWS\w4y4n9
C:\WINNT\Administrator durjana
C:\WINNT\Microsoft Administrator
C:\WINNT\nakula sadewa
C:\WINNT\Software Administrator
C:\WINNT\w4y4n9
C:\WINDOWS\System32\Administrator durjana
C:\WINDOWS\System32\Microsoft Administrator
C:\WINDOWS\System32\nakula sadewa
C:\WINDOWS\System32\Software Administrator
C:\WINDOWS\System32\w4y4n9
C:\WINNT\System32\Administrator durjana
C:\WINNT\System32\Microsoft Administrator
C:\WINNT\System32\nakula sadewa
C:\WINNT\System32\Software Administrator
C:\WINNT\System32\w4y4n9
C:\Documents and Settings\[Current User]\Application Data\Administrator durjana
C:\Documents and Settings\[Current User]\Application Data\Microsoft Administrator
C:\Documents and Settings\[Current User]\Application Data\nakula sadewa
C:\Documents and Settings\[Current User]\Application Data\Software Administrator
C:\Documents and Settings\[Current User]\Application Data\w4y4n9
[X2]:\w4y4n9
Misc:[X1] is a random number.
[X2] is a drive letter.
The worm doesn't create all the listed files and registry entries. It usually creates only a few of them. Above are the complete lists of possible filenames and registry keys.
Post Comment: