You've got to be two steps beyond the average computer user in order to delete this worm. Its getting late, so I'll make this sh0rt and sw33t.
Disable System Restore (Windows Me/XP).
Finding () stopping (a)) process (if applicable)
- Press Ctrl+Alt+Delete once.
- Click THE Task Manager.
- Click THE Processes tab.
- DoubleCLICK the Image Name column header to alphabetically sort the processes.
- Scroll through the list and look for ntservice.exe.
- If you find the file, click it, and then click End Process.
- CLOSE DA Task Manager
Finding () stopping (the)) service.
- Click Start, and then click Run.
- Type services.msc, and then click OK.
- Locate and select the service, "Application."
- Click Action, and then click Properties.
- Click Stop.
- Change Startup Type to Manual.
- Click OK and close the Services window.
- Restart your computer.
Revert the modifications made to the admin account.
Update the virus definitions. EXP: Use LiveUpdate for Norton.
Run a full system scan and delete all the files detected as BAT.Mumu.A.Worm or Hacktool.Hacline.
the worm effects: 10.bat hack.bat hfind.exe ipc.bat: . muma.bat:ntservice.bat: ntservice.exe: nwize.exe nwiz.exe ss.bat AND AT LEAST 10 MORE. I DON'T FEEL LIKE NAMING THEM ALL.
Good Luck' |