New worm (disables cmd/regedit)

Discussion in 'Gaming and Tech' started by Maeve Keeva, May 10, 2009.

  1. Maeve Keeva

    Maeve Keeva Ban'd

    Joined:
    Aug 18, 2008
    Messages:
    211
    Likes Received:
    0
    There is a new worm going around that is really difficult to get rid off as it goes undetected by most applications, I used both gmer, f-secure, nod32, anti-malware, spybot S&D, ComboFix, you name it. How to spot if you have it is relatively easy, you cannot run cmd.exe, nor regedit and in my case, my browsers randomly crashed and steam crashed at login, also any anti-virus applications or anti-malware applications will refuse to update.

    How to fix it:
    Do not boot in safemode.
    Copy regedit, rename it, run it.
    Search for a key with “aux2″ it should point to a file with a very random name in your Windows folder, mine was nvdagela.xkd it is likely to be something completely different for everyone.
    Create a notepad file, rename it exactly the same as the worm, overwrite the worm with the file you made then reboot.
    After reboot, run regedit, delete the “aux2″ key, delete the worm in C:/Windows.

    Putting this here since it took a while to find a proper solution.
     
  2. Tubbimora

    Tubbimora New Member

    Joined:
    Feb 19, 2008
    Messages:
    1,326
    Likes Received:
    0
    Thanks for the headsup.