Blog Archive

Perempuan apabila sembahyang lima waktu, puasa bulan Ramadhan, memelihara kehormatannya serta taat akan suaminya, masuklah dia dari pintu syurga mana sahaja yang dikehendaki.(Women are five times when prayer, fasting month of Ramadan, will maintain his honor and obey her husband, she entered the door of heaven where the desired sake only.)

Senin, 13 Desember 2010

How to Manually Clean the Navidad Trojan

google-site-verification=ConJMH783GAFpknpANwlOsajeF2uHunuHjbBhFZBAcw
What is Navidad Trojan Virus?
This new Internet trojan travels via email. Every response has the subject, "RE:" and the worm as an attachment (NAVIDAD.EXE). This worm also displays a message box upon execution and maps the opening of Windows executables so that it is executed instead of the executable that is called. This causes most Windows programs to not work.

How to Clean/Delete the Navidad Trojan?
The registry needs to edited to delete this Trojan
The easiest solution to cleaning this trojan virus is to download a program to clean up the registry entries and delete the dropped file, WINSVRC.VXD. This download can be found at 

http://www.antivirus.com/vinfo/security/fix_navi.com.

After cleaning the system, restart it and run an anti-virus program to detect and clean any other infected files.
How to Manually Clean the Navidad Trojan
  1. Click on Start, Find, Files or Folders
  2. Search for REGEDIT.EXE
  3. Rename REGEDIT.EXE to REGEDIT.COM
  4. Run REGEDIT.COM
  5. In the left panel of the Registry Editor, click on the "+" at left of the names to go to the registry below: HKEY_CLASSES_ROOT\exefile\shell\open\command
  6. In the right panel, double-click on the entry with the data
    (Default) = "%systemdir%\WINSVRC.EXE"%1""%*"
    where %systemdir% is the Windows system directory; e.g., \WINDOWS\SYSTEM for Win 9x, and \WINNT\SYSTEM32 for NT/2K.
  7. In the Edit window that appears, delete the entire first part of the string, leaving behind "%1"%*"
  8. As in step 5, go to the registry entry below:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
  9. Click on the entry below, then press "DELETE"
    Win32BaseServiceMOD = %systemdir%\WINSVRC.EXE
  10. Go to the registry entry below:
    HKEY_CURRENT_USER\Software\Navidad
  11. Delete this key
  12. Reboot your system
  13. Scan your system with an up-to-date virus scanner
  14. Rename REGEDIT.COM back to REGEDIT.EXE

Tidak ada komentar:

Search Islamic Directory
Keyword: