Wednesday 10 February 2010

Backdoor.Mulkerv

Manual Removal of Backdoor.Mulkerv

1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. Update the virus definitions.
3. Reboot computer in SafeMode [how to]
4. Run a full system scan and clean/delete all infected file(s)
5. Delete/Modify any values added to the registry. [how to edit registry]
Restore the following registry entries to their previous values, if required:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”MaxHashTableSize” = “800″
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”MaxUserPort” = “FFFE”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”TcpMax ConnectResponseRetransmissions” = “2″
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”TcpTimedWaitDelay” = “1E”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”TCPFinWait2Delay” = “1E”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”TcpMaxPortsExhausted” = “5″
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”TcpMaxHalfOpen” = “500″
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”TcpMaxHalfOpenRetried” = “400″
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”TcpMaxDataRetransmissions” = “A”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”KeepAliveTime” = “493E0″
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip \Parameters\”KeepAliveInterval” = “3E8″
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre nt Version\Internet Settings\”MaxConnectionsPer1_0Server” = “2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre nt Version\Internet Settings\”MaxConnectionsPerServer” = “2″
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr ent Version\Internet Settings\”MaxConnectionsPer1_0Server” = “2″
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr ent Version\Internet Settings\”MaxConnectionsPerServer” = “2″
6. Exit registry editor and restart the computer.

Credit: precisesecurity

Wednesday 10 February 2010 - 18:16:42 | admin | Read/Post Comment: 0
printer friendly email to someone

Main Menu

· Home

Counter

This page today ...
total: 1
unique: 1

This page ever ...
total: 4402
unique: 1559

Site ...
total: 8122
unique: 2054

Last seen

  • admin
    [ 1 day, 21 hours, 44 mins, 45 secs ago ]
  • gbigplay
    [ 2 days, 23 hours, 28 mins, 19 secs ago ]
  • peter
    [ 1 week, 4 days, 4 mins, 0 secs ago ]
  • thip
    [ 1 week, 4 days, 4 hours, 10 mins, 1 sec ago ]
  • Ath
    [ 2 weeks, 5 days, 4 hours, 18 mins, 51 secs ago ]
  • sook
    [ 2 weeks, 5 days, 4 hours, 20 mins, 44 secs ago ]
  • pang
    [ 3 weeks, 1 day, 6 hours, 21 mins, 37 secs ago ]
  • air
    [ 1 month, 1 day, 1 hour, 55 mins, 25 secs ago ]
  • Baocai
    [ 1 month, 1 week, 2 days, 4 hours, 23 mins, 35 secs ago ]
  • many
    [ 1 month, 4 weeks, 12 hours, 25 mins, 47 secs ago ]
Render time: 0.5611 sec, 0.3360 of that for queries.