In the previous post already discussed about the virus Stuxnet. Of course you already know this virus, because this virus has been attacked in various countries. And most of the victims were Iran. One of sign if you are attacked by computer virus, is your hard drive suddenly will not feel full when you save a large file on your hard drive.
However, don't worry, because every disease there must be a cure, including disease / viruses this computer. There are at least three ways to stamp out the virus or Winsta Stuxnet this, and here's how
:
Use the Web CureIt RedR
The first thing you should do, if your computer has been attacked by this virus is, download the removal tool specifically for Stuxnet named Dr. Web CureIt, Download here. Removal tools that are sized at 45.78 Mb is capable of cleaning the virus that claims the world is troubling.
Repair Your Registry
Next thing you should do, repair registry computer, how to copy the script below:
[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del
[UnhookRegKey]
HKCU, Software Microsoft WindowsCurrentVersionExplorerAdvanced, ShowSuperHidden, 0 × 00010001.1
HKCU, SoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced, SuperHidden, 0 × 00010001.1
HKCU, SoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced, HideFileExt, 0 × 00010001.0
HKLM, SOFTWARECLASSESbatfileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSEScomfileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSESexefileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSESpiffileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSESregfileshellopencommand,,, "regedit.exe"% 1 ""
HKLM, SOFTWAREMicrosoftWindows NTCurrentVersionWinlogon, Shell, 0, "Explorer.exe"
[Del]
HKLM, SYSTEMCurrentControlSetServicesMRxCls
HKLM, SYSTEMCurrentControlSetServicesMRxNet
HKLM, SYSTEMControlSet001ServicesMRxCls
HKLM, SYSTEMControlSet002ServicesMRxNet
HKLM, SYSTEMCurrentControlSetServicesEnumRootLEGACY_MRXClS
HKLM, SYSTEMCurrentControlSetServicesEnumRootLEGACY_MRXNET
HKLM, SYSTEMControlSet001ServicesEnumRootLEGACY_MRXClS
HKLM, SYSTEMControlSet002ServicesEnumRootLEGACY_MRXNET
Then paste the script above in a text editor program such as Notepad or Notepad + + and save the name repair.inf. The next step, right-click the file and select install and restart your computer.
Now for the prevention for the rest of the Trojan is active again, clear the temporary files using software such as ATF Cleaner or can also use a program that is the default Windows Disk Clean-Up.
How to Prevention
Sometimes though we have cleaned, the virus will come back to attack our computers. For that prevent viruses infecting your computer back with a copy script below.
@ Echo off
del / fc: windowssystem32winsta.exe
brake rd c: windowssystem32winsta.exe
md c: windowssystem32winsta.exe
del / fc: windowssystem32 drivers mrxnet.sys
brake rd c: windowssystem32driversmrxnet.sys
md c: windowssystem32driversmrxnet.sys
del / fc: windowssystem32driversmrxcls.sys
brake rd c: windowssystem32driversmrxcls.sys
md c: windowssystem32driversmrxcls.sys
attrib + r + h + sc: windowssystem32winsta.exe
attrib + r + h + sc: windowssystem32driversmrxnet.sys
attrib + r + h + sc: windowssystem32driversmrxnet.sys
Then paste the text editor and save it as winsta.bat. click 2 times winsta.bat these files. To obtain maximum results, do re-scan your computer using antivirus is updated and identify the virus. Here's Antivirus that can recognize virus stuxnet:
• PC Tools recognize Stuxnet with names Malware.Stuxnet
• Symantec recognizes Stuxnet by name Stuxnet W32
• Kaspersky Lab recognize Stuxnet with name Trojan-Dropper.Win32.Stuxnet.e
• McAfee recognize Stuxnet with names Stuxnet
• Sophos recognize Stuxnet by name Troj / Stuxnet-A
• Microsoft recognizes Stuxnet with name TrojanDropper : Win32/Stuxnet.A
• Ikarus recognize Stuxnet with name Trojan-Dropper.Win32.Stuxnet
• AhnLab identify by name Win-Trojan/Stuxnet.517632.F Stuxnet
Use the Web CureIt RedR
The first thing you should do, if your computer has been attacked by this virus is, download the removal tool specifically for Stuxnet named Dr. Web CureIt, Download here. Removal tools that are sized at 45.78 Mb is capable of cleaning the virus that claims the world is troubling.
Repair Your Registry
Next thing you should do, repair registry computer, how to copy the script below:
[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del
[UnhookRegKey]
HKCU, Software Microsoft WindowsCurrentVersionExplorerAdvanced, ShowSuperHidden, 0 × 00010001.1
HKCU, SoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced, SuperHidden, 0 × 00010001.1
HKCU, SoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced, HideFileExt, 0 × 00010001.0
HKLM, SOFTWARECLASSESbatfileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSEScomfileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSESexefileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSESpiffileshellopencommand ,,,"""% 1 ""% * "
HKLM, SOFTWARECLASSESregfileshellopencommand,,, "regedit.exe"% 1 ""
HKLM, SOFTWAREMicrosoftWindows NTCurrentVersionWinlogon, Shell, 0, "Explorer.exe"
[Del]
HKLM, SYSTEMCurrentControlSetServicesMRxCls
HKLM, SYSTEMCurrentControlSetServicesMRxNet
HKLM, SYSTEMControlSet001ServicesMRxCls
HKLM, SYSTEMControlSet002ServicesMRxNet
HKLM, SYSTEMCurrentControlSetServicesEnumRootLEGACY_MRXClS
HKLM, SYSTEMCurrentControlSetServicesEnumRootLEGACY_MRXNET
HKLM, SYSTEMControlSet001ServicesEnumRootLEGACY_MRXClS
HKLM, SYSTEMControlSet002ServicesEnumRootLEGACY_MRXNET
Then paste the script above in a text editor program such as Notepad or Notepad + + and save the name repair.inf. The next step, right-click the file and select install and restart your computer.
Now for the prevention for the rest of the Trojan is active again, clear the temporary files using software such as ATF Cleaner or can also use a program that is the default Windows Disk Clean-Up.
How to Prevention
Sometimes though we have cleaned, the virus will come back to attack our computers. For that prevent viruses infecting your computer back with a copy script below.
@ Echo off
del / fc: windowssystem32winsta.exe
brake rd c: windowssystem32winsta.exe
md c: windowssystem32winsta.exe
del / fc: windowssystem32 drivers mrxnet.sys
brake rd c: windowssystem32driversmrxnet.sys
md c: windowssystem32driversmrxnet.sys
del / fc: windowssystem32driversmrxcls.sys
brake rd c: windowssystem32driversmrxcls.sys
md c: windowssystem32driversmrxcls.sys
attrib + r + h + sc: windowssystem32winsta.exe
attrib + r + h + sc: windowssystem32driversmrxnet.sys
attrib + r + h + sc: windowssystem32driversmrxnet.sys
Then paste the text editor and save it as winsta.bat. click 2 times winsta.bat these files. To obtain maximum results, do re-scan your computer using antivirus is updated and identify the virus. Here's Antivirus that can recognize virus stuxnet:
• PC Tools recognize Stuxnet with names Malware.Stuxnet
• Symantec recognizes Stuxnet by name Stuxnet W32
• Kaspersky Lab recognize Stuxnet with name Trojan-Dropper.Win32.Stuxnet.e
• McAfee recognize Stuxnet with names Stuxnet
• Sophos recognize Stuxnet by name Troj / Stuxnet-A
• Microsoft recognizes Stuxnet with name TrojanDropper : Win32/Stuxnet.A
• Ikarus recognize Stuxnet with name Trojan-Dropper.Win32.Stuxnet
• AhnLab identify by name Win-Trojan/Stuxnet.517632.F Stuxnet