You are on page 1of 3

Cum sa eliminati W32.Downadup.B Double click on downloaded file, chose "Extract all files...

" Faceti dublu clic pe fisierul descarcat, a ales "Extras toate fisierele ..." from the File menu, a nd follow the wizard's instructions. din meniul File, si urmati instructiunile e xpertului lui. You can use any other archiver, like WinZip. Puteti utiliza orice alt arhivare, cum ar fi WinZip. This will create a folder called bd_rem_tool. A cest lucru va crea un folder denumit bd_rem_tool. 3. 3. Double click on the file "bd_rem_tool_gui.exe" (or just "bd_rem_tool_gui") . Faceti dublu clic pe fisierul "bd_rem_tool_gui.exe" (sau doar "bd_rem_tool_gui "). Make sure that all files have been extracted from the zip archive, because a ll the contents are required for the removal tool to run. Asigurati-va ca toate fisierele au fost extrase din arhiva zip, deoarece toate continutul sunt necesar e pentru instrumentul de eliminare a rula. Follow the tool's instructions. Urmat i instructiunile instrumentului. 4. 4. If you have Restricted Access (not Admin) on Windows Vista and XP, right c lick the "bd_rem_tool_gui" program and choose "Run as Administrator". Daca ati r estrictionat accesul (nu Admin) pe Windows Vista si XP, faceti clic dreapta "bd_ rem_tool_gui" programul si alegeti "Run as Administrator". Enter the computer Ad ministrator User-name and Password when prompted. Introduceti administrator de c omputer numele de utilizator si parola atunci cnd vi se solicita. 5. 5. Reboot your computer when scanning is finished. Reporniti calculatorul atu nci cnd scanarea este terminat.

Manual pentru indepartarea de procedura 1. 1. If an anti-virus program is present, update the definition file. Daca un p rogram anti-virus este prezent, actualizati fisierul cu definitii. 2. 2. Reboot Windows in Safe Mode Reporniti Windows n Safe Mode - After turning on the power, press F8 on the keyboard. - Dupa pornirea de puter e, apasati tasta F8 de pe tastatura. - From the menu, select Safe Mode. - Din meniu, selectati Safe Mode. 3. 3. Run a full system scan and clean/delete all infected files. Executati o sc anare completa a sistemului si curatati / sterge toate fisierele infectate. 4. 4. Delete/Modify any values added to the registry if present. Sterge / modifi ca orice valori adaugate la registrul daca este prezent. - To edit the registry, click on Start. - Pentru a edita registry, faceti clic p e Start. Search or Run regedit. Cautati sau Run regedit. 5. 5. Exit registry editor and restart Windows. nchideti Registry Editor si repor niti Windows. Temporarily Disable System Restore (Windows Me/XP/Vista/7) . [how to] Dezactivat i temporar System Restore (Windows Me/XP/Vista/7). [Cum sa] 2. 2. Update the virus definitions. Actualizarea definitiilor de virusi. 3. 3. Reboot Windows in Safe Mode. [how to] Reporniti Windows n Safe Mode. [Cum s a] 4. 4. Find and Stop the Service: Gasiti si de a opri serviciul: - Click Start > Run. - Faceti clic pe Start> Run. - Type services.msc, and then click OK. - Tastati services.msc, apoi faceti clic

pe OK. - Locate and select the service that was detected. - Gasiti si selectati servici ul pe care a fost detectat. Service name: [PATH TO WORM] Numele serviciului: [PATH LA WORM] Display name: [WORM GENERATED SERVICE NAME] Numele de afisare: [WORM GENERAT Nam e Service] Startup Type: Automatic Startup Type: Automatic - Click Action > Properties. - Faceti clic pe Proprietati de actiune>. - Click Stop. - Faceti clic pe Stop. - Change Startup Type to Manual. - Schimbati tipul de pornire n Manual. - Click OK and close the Services window. - Faceti clic pe OK si nchideti fereast ra Servicii. 5. 5. Run a full system scan and clean/delete all infected file(s) Executati o s canare completa a sistemului si curatati / sterge toate fisier infectat (e) 6. 6. Delete/Modify any values added to the registry. [how to edit registry] Ste rge / modifica orice valori adaugate la registru. [cum de a edita registry] Navigate to and delete the following registry entries: Navigati la si de a sterg e intrari de registry: HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run\ [RANDOM NAME] = ru ndll32.exe [RANDOM FILE NAME].dll , ydmmgvos HKEY_CURRENT_USER \ Software \ Microsof t \ Windows \ versiune curenta \ Run \ "[Aleator Denumire]" = "rundll32.exe" [FI LE NAME RANDOM]. Dll ", ydmmgvos" HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Applets\ dl = 0? HKEY_C URRENT_USER \ Software \ Microsoft \ Windows \ versiune curenta \ Applet-urile \ "dl" = "0" HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version\Applets\ dl = 0? HKEY_ LOCAL_MACHINE \ Software \ Microsoft \ Windows \ versiune curenta \ Applet-urile \ "dl" = "0" HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Applets\ ds = 0? HKEY_C URRENT_USER \ Software \ Microsoft \ Windows \ versiune curenta \ Applet-urile \ "DS" = "0" HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version\Applets\ ds = 0? HKEY_ LOCAL_MACHINE \ Software \ Microsoft \ Windows \ versiune curenta \ Applet-urile \ "DS" = "0" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[WORM GENERATED SERVICE NAM E]\ DisplayName = [WORM GENERATED SERVICE NAME] HKEY_LOCAL_MACHINE \ SYSTEM \ Current ControlSet \ Services \ [Name Service WORM GENERAT] \ "DisplayName" = "[WORM Nam e Service GENERAT]" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[WORM GENERATED SERVICE NAM E]\ Type = 4? HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ [WORM GEN ERAT Name Service] \ "de tip" = "4" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[WORM GENERATED SERVICE NAM E]\ Start = 4? HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ [WORM GE NERAT Name Service] \ "Start" = "4" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[WORM GENERATED SERVICE NAM E]\ ErrorControl = 4? HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ [ Name Service WORM GENERAT] \ "ErrorControl" = "4" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[WORM GENERATED SERVICE NAM E]\ ImagePath = %SystemRoot%\system32\svchost.exe -k HKEY_LOCAL_MACHINE \ SYSTEM \ C urrentControlSet \ Services \ [Name Service WORM GENERAT] \ "ImagePath" = "% Sys temRoot% \ system32 \ svchost.exe-k HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[WORM GENERATED SERVICE NAM E]\Parameters\ ServiceDll = [PATH TO WORM] HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentContr olSet \ Services \ [WORM Name Service GENERAT] \ Parameters \ "ServiceDLL" = "[C ALE DE WORM]" Restore the following registry entries to their previous values, if required: Re staurare urmatoarele intrari de registry la valorile lor anterioare, daca este n

ecesar: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ TcpNumConn ections = 00FFFFFE HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Tcp ip \ Parameters \ "TcpNumConnections" = "00FFFFFE" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\explorer\Advanced\ Folder\Hidden\SHOWALL\ CheckedValue = 0? HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ versiune curenta \ Explorer \ Advanced \ Folder \ Hidden \ SHOWALL \ "CheckedValue" = "0" 7. 7. Exit registry editor and restart Windows. nchideti Registry Editor si repor niti Windows.

You might also like