A virus ‘ Conficker.DV ‘ using the distribution method that is different from preceding. With sophiscated, the virus tried to access the network using a hole windows’ Default Share ‘(ADMIN $ \ system32) with the random administrator password.
In addition ‘Conficker.DV’ also create a file on removable media such as flash, hard drive and card reader to save the file hidden on the root drive.
While the action the same as preceding, that is trying exploit MS08-067– Windows hole, or Windows Server Service SVCHOST.exe. Many users infected because they didn’t turn on of the Automatic Updates feature and do not patch Windows MS08-067.
If this is happened to you don’t be panic. Do these 7 steps to repair your system:
1. Disconnect the computer that will be cleared from the network / internet.
2. Turn off system restore (Windows XP / Vista).
3. Turn off the virus that active in the services. Use the removal tool from Norman to clean the virus that active. If you do not have, it can be downloaded at Norman.
4. Delete the fake virus service svchost.exe on registry. You can search manually in the registry.
5. Delete Task Schedule is created by the virus. (C: \ WINDOWS \ Tasks)
6. Remove the registry string is created by the virus. To facilitate the registry can use the script below:
[Version]
Signature=”$Chicago$”
Provider=Vaksincom Oyee
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,
Hidden, 0×00000001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,
SuperHidden, 0×00000001,1
HKLM,
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL,
CheckedValue, 0×00000001,1
HKLM, SYSTEM\CurrentControlSet\Services\BITS, Start, 0×00000002,2
HKLM, SYSTEM\CurrentControlSet\Services\ERSvc, Start, 0×00000002,2
HKLM, SYSTEM\CurrentControlSet\Services\wscsvc, Start, 0×00000002,2
HKLM, SYSTEM\CurrentControlSet\Services\wuauserv, Start, 0×00000002,2
[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, dl
HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, ds
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, dl
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, ds
HKLM, SYSTEM\CurrentControlSet\Services\Tcpip\Parameters, TcpNumConnections
Use notepad, then save with the name ‘repair.inf’, then ‘Save As Type’ to ‘All Files’ so that the error does not occur. Run repair.inf with right click, then select install.
Meanwhile, for the active file on startup, you can disable through ‘msconfig’ or can be manually delete on the string: ‘HKLM, SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run’
7. For cleaning the virus W32/Conficker.DV optimally and prevent re-infection, you should use and update anti-virus that is able to detect this virus with both your computer and the patch with the official patch from Microsoft to prevent re-infection.