<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Istanto Blog - Online Business, Short Reviews, Computers and Internet, Tips and Trick, Make Money Online. &#187; Conficker</title>
	<atom:link href="http://www.istanto.net/tag/conficker/feed" rel="self" type="application/rss+xml" />
	<link>http://www.istanto.net</link>
	<description>Online Business, Short Reviews, Computers and Internet, Tips and Trick, Make Money Online.</description>
	<lastBuildDate>Sun, 08 Jan 2012 02:56:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>How to Remove Conficker.A and Conficker.B Variant</title>
		<link>http://www.istanto.net/how-to-remove-conficker-a-and-conficker-b-variant.html</link>
		<comments>http://www.istanto.net/how-to-remove-conficker-a-and-conficker-b-variant.html#comments</comments>
		<pubDate>Fri, 10 Jun 2011 11:42:35 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[conficker memory checker]]></category>
		<category><![CDATA[conficker removal tool]]></category>
		<category><![CDATA[conficker.a]]></category>
		<category><![CDATA[conficker.b]]></category>
		<category><![CDATA[CPU]]></category>
		<category><![CDATA[LOL]]></category>
		<category><![CDATA[remove conficker.a conficker.b variant]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=2491</guid>
		<description><![CDATA[This is really strange case on one of my cycber cafe computer. I used ESET/NOD32 antivirus to check all computers in my networks but the result is clean. One I notice is explorer.exe and svchost.exe use to much CPU usage and Memory. I sense there is something strange because usually this computer can run faster. [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">This is really strange case on one of my cycber cafe computer. I used ESET/NOD32 antivirus to check all computers in my networks but the result is clean. One I notice is <em>explorer.exe</em> and <em>svchost.exe</em> use to much CPU usage and Memory. I sense there is something strange because usually this computer can run faster.</p>
<p style="text-align: justify;">After checked it with this <a href="http://net.cs.uni-bonn.de/uploads/media/conciller.exe" target="_blank">small tools memory checker</a> finally I found the problem, my computers infected with Conficker.B Variant, It&#8217;s really funny when commercial antivirus say my computer clean.. LOL..</p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2011/06/conficker.jpg"><img class="aligncenter size-medium wp-image-2493" title="conficker" src="http://www.istanto.net/wp-content/uploads/2011/06/conficker-300x146.jpg" alt="" width="300" height="146" /></a></p>
<p style="text-align: justify;">The Conficker.B variant a little strange, I still can open Microsoft website. The important key to sense if your computers infected is if your computer run slow than usual. Check with that small memory tools and you may find something <img src='http://www.istanto.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><span style="color: #339966;">How to to remove Conficker.A and Conficker.B Variant</span></span></p>
<p style="text-align: justify;"><span style="color: #000000;">I&#8217;m to lazy for writing manual step, because conficker has to many variant I won&#8217;t you blame me if some conficker variant manual removal won&#8217;t work for yourself. Just download this <a href="http://download.cnet.com/Conficker-Removal-Tool/3000-2239_4-10911447.html" target="_blank">conficker removal tools</a> and before run it make sure you&#8217;re disconnected from any local network or Internet. There is fourth (4) step you have to follow using this tools.</span></p>
<p style="text-align: justify;"><span style="color: #000000;">After you <del>kicked out</del> this conficker <span style="text-decoration: underline;"><strong>you should update your computers security</strong></span><strong>!!!</strong> It&#8217;s to prevent this worm back and anoying you once again. This really happen to me when I&#8217;m to lazy for update my windows the virus back again in just 1 hours haha..</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Have a nice day everyone <img src='http://www.istanto.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/how-to-remove-conficker-a-and-conficker-b-variant.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>8 Tools Kido/Conficker/Downadup Remover</title>
		<link>http://www.istanto.net/8-tools-kido-conficker-downadup-remover.html</link>
		<comments>http://www.istanto.net/8-tools-kido-conficker-downadup-remover.html#comments</comments>
		<pubDate>Tue, 28 Apr 2009 22:19:21 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[Short Reviews]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Downadup]]></category>
		<category><![CDATA[HKCU]]></category>
		<category><![CDATA[HKLM]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[MRT]]></category>
		<category><![CDATA[Norman Malware Cleaner]]></category>
		<category><![CDATA[remover]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=1093</guid>
		<description><![CDATA[Hi all sorry for not blogging for 3 weeks, I&#8217;m just back after busy middle test in my campus. This come to my attention after analyze &#8220;keyword&#8221; that bring people reaching my blog. Many of them looking for virus removal. After reading on people trends many of them are infected by Kido/Conficker/Downadup so&#8230; here&#8217;s the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Hi all sorry for not blogging for 3 weeks, I&#8217;m just back after busy middle test in my campus. This come to my attention after analyze &#8220;<span style="text-decoration: underline;">keyword</span>&#8221; that bring people reaching my blog. Many of them looking for virus removal. After reading on people trends many of them are infected by Kido/Conficker/Downadup so&#8230; here&#8217;s the short review for 8 tools to remove this virus and 5 steps to make sure your system clean.</p>
<p style="text-align: justify;">1. <span style="text-decoration: underline;"><strong>Kaspersky AVP Removal Tool</strong></span></p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/04/kaspersky-avp-removal-tool.jpg"><img class="alignnone size-full wp-image-1094" title="kaspersky-avp-removal-tool" src="http://www.istanto.net/wp-content/uploads/2009/04/kaspersky-avp-removal-tool.jpg" alt="kaspersky-avp-removal-tool" width="265" height="208" /></a><br />
</strong></span></p>
<p style="text-align: justify;"><a href="http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/setup_7.0.0.290_29.04.2009_00-51.exe" target="_blank">Download Here</a></p>
<p style="text-align: justify;">2. <strong><span style="text-decoration: underline;">Norman Malware Cleaner</span></strong></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/04/norman-malware-cleaner.jpg"><img class="alignnone size-medium wp-image-1095" title="norman-malware-cleaner" src="http://www.istanto.net/wp-content/uploads/2009/04/norman-malware-cleaner-300x194.jpg" alt="norman-malware-cleaner" width="300" height="194" /></a></p>
<p style="text-align: justify;"><a href="http://norman.com/Virus/Virus_removal_tools/24789/" target="_blank">Download Here</a></p>
<p style="text-align: justify;">3. <span style="text-decoration: underline;"><strong>McAfee AVERT Stinger</strong></span></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/04/mcafee-avert-stinger.jpg"><img class="alignnone size-full wp-image-1096" title="mcafee-avert-stinger" src="http://www.istanto.net/wp-content/uploads/2009/04/mcafee-avert-stinger.jpg" alt="mcafee-avert-stinger" width="246" height="208" /></a></p>
<p style="text-align: justify;"><a href="http://download.nai.com/products/mcafee-avert/stinger1001546.exe" target="_blank">Download Here</a></p>
<p><span id="more-1093"></span></p>
<p style="text-align: justify;">4. <span style="text-decoration: underline;"><strong>Microsoft Malicious Software Removal Tool</strong></span></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/04/microsoft-malicious-software-removal-tool.jpg"><img class="alignnone size-full wp-image-1097" title="microsoft-malicious-software-removal-tool" src="http://www.istanto.net/wp-content/uploads/2009/04/microsoft-malicious-software-removal-tool.jpg" alt="microsoft-malicious-software-removal-tool" width="265" height="246" /></a></p>
<p style="text-align: justify;">You can get this program free by updated your windows, this tool location on %systemroot%\WINDOWS\system32\<strong>MRT.exe</strong></p>
<p style="text-align: justify;">5. <span style="text-decoration: underline;"><strong>KidoKiller (Kaspersky)</strong></span></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/04/kidokiller-kaspersky.jpg"><img class="alignnone size-medium wp-image-1098" title="kidokiller-kaspersky" src="http://www.istanto.net/wp-content/uploads/2009/04/kidokiller-kaspersky-300x231.jpg" alt="kidokiller-kaspersky" width="300" height="231" /></a></p>
<p style="text-align: justify;"><a href="http://data2.kaspersky.com:8080/special/KKiller_v3.4.3.zip" target="_blank">Download Here</a></p>
<p style="text-align: justify;">6. <span style="text-decoration: underline;"><strong>Fix Downad (Trend Micro)</strong></span></p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/04/fix-downad-trend-micro.jpg"><img class="alignnone size-medium wp-image-1099" title="fix-downad-trend-micro" src="http://www.istanto.net/wp-content/uploads/2009/04/fix-downad-trend-micro-300x169.jpg" alt="fix-downad-trend-micro" width="300" height="169" /></a><br />
</strong></span></p>
<p style="text-align: justify;"><a href="http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/SysClean-WORM_DOWNAD.zip" target="_blank">Download Here</a></p>
<p style="text-align: justify;">7. <span style="text-decoration: underline;"><strong>W32.Downadup Removal (Symantec)</strong></span></p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><strong><a href="http://www.istanto.net/wp-content/uploads/2009/04/w32downadup-removal-symantec.jpg"><img class="alignnone size-medium wp-image-1100" title="w32downadup-removal-symantec" src="http://www.istanto.net/wp-content/uploads/2009/04/w32downadup-removal-symantec-300x99.jpg" alt="w32downadup-removal-symantec" width="300" height="99" /></a><br />
</strong></span></p>
<p style="text-align: justify;"><a href="http://download.cnet.com/Symantec-W32-Downadup-Removal-Tool/3000-2239_4-10911656.html" target="_blank">Download Here</a></p>
<p style="text-align: justify;">8. <span style="text-decoration: underline;"><strong>EConfickerRemover (ESET/NOD32)</strong></span></p>
<p style="text-align: justify;"><a href="http://www.istanto.net/wp-content/uploads/2009/04/econfickerremover.jpg"><img class="alignnone size-medium wp-image-1101" title="econfickerremover" src="http://www.istanto.net/wp-content/uploads/2009/04/econfickerremover-300x150.jpg" alt="econfickerremover" width="300" height="150" /></a></p>
<p style="text-align: justify;"><a href="http://www.ziddu.com/download/4262835/EConfickerRemover.rar.html" target="_blank">Download Here</a></p>
<p style="text-align: justify;">After using this tools you might need to do a little manual modification to make sure your system 100% safe from this <span style="text-decoration: line-through;">shit</span>.</p>
<p style="text-align: justify;">1. <span style="text-decoration: underline;">Deleted all scheduled task has been made by virus.</span></p>
<p style="text-align: justify;">2. <span style="text-decoration: underline;">Deleted all firewall rules has been made by virus.</span></p>
<p style="text-align: justify;">3. <span style="text-decoration: underline;">Install this <a href="http://www.istanto.net/wp-content/uploads/2009/04/repair1.inf">repair.inf</a></span></p>
<p style="text-align: justify;">[Version]<br />
Signature=&#8221;$Chicago$&#8221;<br />
Provider=Nobody</p>
<p>[DefaultInstall]<br />
AddReg=UnhookRegKey<br />
DelReg=del</p>
<p>[UnhookRegKey]<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden, 0&#215;00000001,1<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, SuperHidden, 0&#215;00000001,1<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue, 0&#215;00000001,1<br />
HKLM, SYSTEM\CurrentControlSet\Services\BITS, Start, 0&#215;00000002,2<br />
HKLM, SYSTEM\CurrentControlSet\Services\ERSvc, Start, 0&#215;00000002,2<br />
HKLM, SYSTEM\CurrentControlSet\Services\wscsvc, Start, 0&#215;00000002,2<br />
HKLM, SYSTEM\CurrentControlSet\Services\wuauserv, Start, 0&#215;00000002,2</p>
<p>[del]<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, dl<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, ds<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, dl<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, ds<br />
HKLM, SYSTEM\CurrentControlSet\Services\Tcpip\Parameters, TcpNumConnections</p>
<p style="text-align: justify;">4. <span style="text-decoration: underline;">Clean all temporary files.</span></p>
<p style="text-align: justify;">5. <span style="text-decoration: underline;">Checks your hosts file.</span></p>
<p style="text-align: justify;">Good luck!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/8-tools-kido-conficker-downadup-remover.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Remove Worm Kido</title>
		<link>http://www.istanto.net/remove-worm-kido.html</link>
		<comments>http://www.istanto.net/remove-worm-kido.html#comments</comments>
		<pubDate>Sat, 04 Apr 2009 17:07:43 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Tips & Trick]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Downadup]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[problem]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=1083</guid>
		<description><![CDATA[Worm kido also known as Conficker or Downadup, on 1st April 2009 there is some rumors out there said this worm will generated new varian. I Personally not hear big problem on that date. Many computers has been infected by this worm because it&#8217;s spreading through network. Kaspersky AntiVirus has free removal tools for this [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Worm kido also known as Conficker or Downadup, on 1st April 2009 there is some rumors out there said this worm will generated new varian. I Personally not hear big problem on that date. Many computers has been infected by this worm because it&#8217;s spreading through network. Kaspersky AntiVirus has free removal tools for this worm.</p>
<p style="text-align: justify;">First before we remove this worm, to prevent it&#8217;s spreading in networks and infected many computers please follow this step.</p>
<ul style="text-align: justify;">
<li>Install Patch from Microsoft for MS08-067, MS08-068, and MS09-001.</li>
<li>Make sure Administrator password not easy to guess.</li>
<li>Turn off autoplay on removable devices.</li>
</ul>
<p><span style="color: #008000;"><span style="text-decoration: underline;"><strong>Follow this step to remove Kido</strong></span></span></p>
<p>1. Download <a href="http://data2.kaspersky.com:8080/special/KKiller_v3.4.3.zip" target="_blank">KKiller_v3.4.3.zip</a>, extract it.</p>
<p style="text-align: justify;">2. Run KKiller.exe program. When scan process completed you might see many command prompt in your desktop, just press any key to close it. If you want to close it automatically please use parameter &#8220;-y&#8221;</p>
<p style="text-align: justify;">3. Wait untill scan process completed, then restart your computer and scan it again with your trusted AntiVirus.</p>
<p style="text-align: justify;">Good Luck <img src='http://www.istanto.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/remove-worm-kido.html/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>7 Simple Step to Remove Virus &#8220;Conficker&#8221; W32/Conficker.DV</title>
		<link>http://www.istanto.net/7-simple-step-to-remove-virus-conficker-w32confickerdv.html</link>
		<comments>http://www.istanto.net/7-simple-step-to-remove-virus-conficker-w32confickerdv.html#comments</comments>
		<pubDate>Sat, 14 Feb 2009 02:54:51 +0000</pubDate>
		<dc:creator>Istanto</dc:creator>
				<category><![CDATA[Computer And Internet]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[cleaning conficker]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[HKLM]]></category>
		<category><![CDATA[remove conficker]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Virus Spreading]]></category>
		<category><![CDATA[W32/Conficker.DV]]></category>

		<guid isPermaLink="false">http://www.istanto.net/?p=990</guid>
		<description><![CDATA[Hello world! Are your network attacking by Conficker? hahaha.. don&#8217;t get mad this virus can be removed using 7 simple step only. Anyway this virus  make some people mad because it&#8217;s attacking network (they might have more trouble when try to clean it) and of course your protection , If we look more deeply this [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Hello world! Are your network attacking by Conficker? hahaha.. don&#8217;t get <span style="text-decoration: line-through;">mad</span> this virus can be removed using 7 simple step only. Anyway this virus  make some people <span style="text-decoration: line-through;">mad</span> because it&#8217;s attacking network (they might have more trouble when try to clean it) and of course your protection <img src='http://www.istanto.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  , If we look more deeply this virus using mostly <strong>lame</strong> virus technique included all in one packet *lol*&#8230;. but in advanced the virus maker understand and really know hows really weak windows protection so he make you all <span style="text-decoration: line-through;">mad</span> <img src='http://www.istanto.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p style="text-align: justify;">How to detect if your computer infected by conficker? There many sign like&#8230;. <span style="text-decoration: underline;">Error message Generic Host Process</span>, <span style="text-decoration: underline;">You can&#8217;t access some important site</span> ex: www.microsoft.com,  www.symantec.com,  www.norman.com,  www.clamav.com,  www.grisoft.com,  www.avast.com, etc. <span style="text-decoration: underline;">You can&#8217;t update your antivirus</span>, Many <span style="text-decoration: underline;">application not working</span> like usually specially network application, and many more sign.</p>
<p style="text-align: justify;">This virus created with UPX compression with size 162kb, You might get trouble when try to killed this virus process because it&#8217;s (again) using lame technique by running .dll files following fake svchost.exe file. Virus is not automatically active, it will starts download some images files and created temporary files then building himself (again) <strong>LAME!</strong> *lol*</p>
<p style="text-align: justify;">Once virus build completed it will starts to disabled some windows services, Virus will blocking any <span style="text-decoration: underline;"><strong>string</strong></span> he found on each active application, here is the list:</p>
<p><span id="more-990"></span></p>
<p style="text-align: justify;">Ccert.<br />
sans.<br />
bit9.<br />
windowsupdate<br />
wilderssecurity<br />
threatexpert<br />
castlecops<br />
spamhaus<br />
cpsecure<br />
arcabit<br />
emsisoft<br />
sunbelt<br />
securecomputing<br />
rising<br />
prevx<br />
pctools<br />
norman<br />
k7computing<br />
ikarus<br />
hauri<br />
hacksoft<br />
gdata<br />
fortinet<br />
ewido<br />
clamav<br />
comodo<br />
quickheal<br />
avira<br />
avast<br />
esafe<br />
ahnlab<br />
centralcommand<br />
drweb<br />
grisoft<br />
nod32<br />
f&#8217;prot<br />
jotti<br />
kaspersky<br />
f&#8217;secure<br />
computerassociates<br />
networkassociates<br />
etrust<br />
panda<br />
sophos<br />
trendmicro<br />
mcafee<br />
norton<br />
symantec<br />
microsoft<br />
defender<br />
rootkit<br />
malware<br />
spyware<br />
virus</p>
<p style="text-align: justify;">wow, they all killed by one shoot hahaha *lol* lame technique (again) virus will try download and executed some images files from some website, I want to giving site list in here but I think you will get bored when read it so let&#8217;s skip this! Virus will make firewall rule that can make your computer attacked from outside and totally control your computer (scary&#8230;. some people know this as botnet).</p>
<p style="text-align: justify;"><span style="text-decoration: underline;"><strong>Virus Spreading</strong></span>:</p>
<ol>
<li>Brute force default share administrator account (There is dictionary).</li>
<li><strong>Lame</strong> autorun.inf and hidden file on recycler folder (mostly on each drive with hidden attributes)</li>
<li>SVCHOST.exe exploited (that&#8217;s why there is microsoft update).</li>
</ol>
<p>Alright enough, before you guy&#8217;s really get <span style="text-decoration: line-through;">mad</span> here is the <span style="color: #008000;"><span style="text-decoration: underline;"><strong>7 simple steps to remove conficker</strong></span>:</span></p>
<p>1. Unplug every computers from network.</p>
<p>2. Deactivated system restore service (XP/Vista)</p>
<p style="text-align: justify;">3. Kill active virus in background service, you can use <a href="http://download.norman.no/public/Norman_Malware_Cleaner.exe" target="_blank">Norman Malware Cleaner</a>. (Since this virus using UPX compression, the easiest way to detect it is by using <a href="http://www.ansav.com/download/" target="_blank">Ansav Utility</a> and killed any UPX packet in background)</p>
<p style="text-align: justify;">4. Delete fake SVSHOST.exe in registry.</p>
<p><a href="http://www.istanto.net/wp-content/uploads/2009/02/svchost.jpg"><img class="alignnone size-medium wp-image-993" title="svchost" src="http://www.istanto.net/wp-content/uploads/2009/02/svchost-300x65.jpg" alt="svchost" width="300" height="65" /></a></p>
<p>5. Delete <span style="text-decoration: underline;">&#8220;Schedule Task</span>&#8221; that virus created (%systemrot%\WINDOWS\Tasks)</p>
<p>6. Repair your registry using code below or <a href="http://www.istanto.net/wp-content/uploads/2009/02/repair.inf">download repair.inf</a></p>
<p>[Version]<br />
Signature=&#8221;$Chicago$&#8221;<br />
Provider=Nobody</p>
<p>[DefaultInstall]<br />
AddReg=UnhookRegKey<br />
DelReg=del</p>
<p>[UnhookRegKey]<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden, 0&#215;00000001,1<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, SuperHidden, 0&#215;00000001,1<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue, 0&#215;00000001,1<br />
HKLM, SYSTEM\CurrentControlSet\Services\BITS, Start, 0&#215;00000002,2<br />
HKLM, SYSTEM\CurrentControlSet\Services\ERSvc, Start, 0&#215;00000002,2<br />
HKLM, SYSTEM\CurrentControlSet\Services\wscsvc, Start, 0&#215;00000002,2<br />
HKLM, SYSTEM\CurrentControlSet\Services\wuauserv, Start, 0&#215;00000002,2</p>
<p>[del]<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, dl<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, ds<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, dl<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, ds<br />
HKLM, SYSTEM\CurrentControlSet\Services\Tcpip\Parameters, TcpNumConnections</p>
<p style="text-align: justify;"><strong><span style="color: #ff0000;">*NOTE:</span> </strong>For files active on startup you can disabled it from msconfig or using hijackthis or deleted it manually in registry “HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run”</p>
<p style="text-align: justify;">7. Scan with your best and updated antivirus to stop virus coming back in the future, and update your computer with this patch <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</a></p>
<p><strong><span style="color: #ff0000;"><span style="text-decoration: underline;">99. Pay me (joke) <img src='http://www.istanto.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </span></span></strong></p>
<p>Good luck <img src='http://www.istanto.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.istanto.net/7-simple-step-to-remove-virus-conficker-w32confickerdv.html/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
	</channel>
</rss>

