answersLogoWhite

0


Best Answer

How to remove Surabaya Virus

Overview -

W32/Drowor.worm may get send around using a deceiving filename Google Earth .scr.

Symptoms -

* Modified autoexec.bat to display a message upon system start: "Don't kill me, I'm just send message from your computer"

* your folder has file size 40K

* Modified PE binary files

Removal

1. del autorun.info in drive c:

Press Start -> Run -> cmd press Enter

attrib autorun.inf -s -h -r press Enter

DEL autorun.inf

3. Press Start -> Run -> regedit press Enter

"HKEY_LOCAL_MACHINE", then "SOFTWARE" then "Microsoft" then "Windows NT" then "Current Version" then "WinLogon".

and on the right windows (under data) modify or delete "LegalNoticeCaption" & "LegalNoticeText".

you should be fine.

go to start, run, type in regedit and find;

4. Show Hidden files

Start --- Run --- regedit --- OK

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\

CurrentVersion\Explorer\Advanced\Folder\

Hidden\SHOWALL

CheckedValue = "0" change to "1"

Recommend Good Antivirus Program

Avira AntiVir PE Classic:

Avast 4 Home Edition:

start in safe mode with internet & do two free online scans:

http://www.bitdefender.com/scan8/ie.HTML

http://housecall.antivirus.com

http://www.superantispyware.com

Free version is excellent.

security installed in your PC, a firewall, antispyware and anti virus program.

Looks like a worm and I would suggest that you download both of these free

program and update, run an indepth scan and then reboot to be on the safe side.

http://www.emsisoft.com A2Squard Free from Austria,

will find worms, rogue dialers, keyloggers, adware, spyware,

worms, trace spyware and tracking cookies.

www.avast.com

it is a free antivirus and the most efficient one too.....

you can register it for home use for free.......run a boot time

scan....all problems will be solved!!!

Run your antivirus and use deep scan or scan & clean online at http://www.mcafee.com/apps/downloads/sec...

How to remove Surabaya Virus

Symptoms -

• Modified autoexec.bat to display a message upon system start: "Surabaya is my birthday"….."Don't kill me, I'm just send message from your computer"…and then some blah - blah in some Thai language I guess.

• Your folder has file size 40K

• All your hard disk partitions become autorun…if you right click on any partition or any drive letter it'll give the "autorun" option instead "open".

• All your existing original folders become hidden and are replaced by another dummy folder with same file name but with size of 40KB. If you right click on any file, the menu which opens will show "test", "configure"….etc options but no "open" option.

Removal Steps:

Step 1:

Press Start -> Run -> cmd (or command) -> press Enter

Type in command box- CD\

Type again in command box- c:

Type again in command box- attrib -s -h -r /d /s -> press Enter

Type again in command box- del autorun.inf -> press Enter

Type again in command box- del thumb*.* -> press Enter

Repeat the same with your other hard drive partitions as well…say if you have 3 drive partitions viz. "C", "D" & "E"…for this:

Type again in command box- d:

Type again in command box- attrib -s -h -r /d /s -> press Enter

Type again in command box- del autorun.inf -> press Enter

Type again in command box- del thumb*.* -> press Enter

Type again in command box- e:

Type again in command box- attrib -s -h -r /d /s -> press Enter

Type again in command box- del autorun.inf -> press Enter

Type again in command box- del thumb*.* -> press Enter

If you have any USB hard drive on pen drive connected, do the above procedure with its drive name. For example if your USB drive name is "G"…

Type again in command box- g:

Type again in command box- attrib -s -h -r /d /s -> press Enter

Type again in command box- del autorun.inf -> press Enter

Type again in command box- del thumb*.* -> press Enter

Type again in command box- exit

Step 2:

Press Start -> Run -> regedit ->press Enter

Click on following (in left side window):

"HKEY_LOCAL_MACHINE"->"SOFTWARE" -> "Microsoft" -> "Windows NT" -> "Current Version" -> "WinLogon".

Now on the right side window (under data) delete "LegalNoticeCaption" & "LegalNoticeText".

Step 3:

Go to Start menu -> Programs -> Accessories -> System Tools -> System restore

This'll open a box where you'll get the option - "Restore my system to an earlier time"... Select any old date on which you think your system was working fine…push on next..next…till the system restore starts…

System restore takes a few minutes to complete depending on your computer speed….so be patient….after system restore completes….Your computer will restart…..the problem should have been solved.

Step 4:

Press Start -> Run -> regedit ->press Enter

Press Ctrl + F

In the find window type Surabaya if at all you find any entries in the registry with this name…"Surabaya"…delete them

Step 5:

This virus makes your system's show hidden file option in folder menu to get disabled. To make your computer to show Hidden files, and to get your computer again back into normalcy…

Start --- Run --- regedit --- OK

HKEY_LOCAL_MACHINE -> Software -> Microsoft -> Windows ->

Current Version -> Explorer -> Advanced -> Folder -> Hidden -> Show All

On the right side window, locate this: CheckedValue = "0"

Modify this value to 1. (right click on the Checked value under Name column -> Modify)

Note:

This virus usually reaches to your computer through any USB drive (pen drive or hard disc). Whenever you plug your USB drive into any other computer, infected with this virus, the virus will infect this drive and will infect the next computer, in which the drive is plugged in next time. So its always advisable not to open the pen drive directly. Instead always right click on the drive and select open option. If at all you see the first option as "autorun", after you right click on the USB drive, this means that the drive is infected.

User Avatar

Wiki User

12y ago
This answer is:
User Avatar

Add your answer:

Earn +20 pts
Q: How can you remove the surabaya virus from a slaved hard disk?
Write your answer...
Submit
Still have questions?
magnify glass
imp
Related questions

How do you remove no disk error virus?

"No Disk" Its not a virus........ Its ur disk problem . . . .


How to fix a virus on computer if no websites can be visited?

You will have to buy some Anti Virus software on a Disk like McAfee for example. You can then scan your whole computer and remove the virus.


How do you remove virus from ram?

RAM is cleaned when you power off your computer. Your virus is not on the RAM, it is on the hard disk and moves from there into RAM when you start up your computer. You need to remove the virus from the hard disk and then reboot it to clean the RAM.


How can you get rid of a computer virus?

Make sure that you have anti-virus software on your computer. Get the anti-virus software to scan your hard disk. If a virus is found, the software will either remove it or quarantine it.


How do you remove Trojan virus after you erased hard drive and reinstalled windows xp?

If you have erased the hard disk then the Trojan is gone.


If you download a movie which has virus into your removable disk can your computer infected by the virus?

Yes, if the removable disk is connected to your computer then it will be infected.


Is disk doctor a virus?

YES


How could i remove recycler from my hard disk?

The Recycler Virus takes advantage of the Windows Autorun feature in order to sneak into your computer. Since this virus copies itself to all active drives in your PC, it can eventually consume precious space. It will also try to contact other malicious sites the moment you go online so your system can slow down to a crawl. Remove this virus right away from your hard disk by running a scan. The virus will be detected and you can remove it automatically. This site is very helpful in providing detailed removal instructions: http://www.spyware-fix.net/remove-recycler-virus.html


How do you take backup of virus infected hard disk?

pls tell some idea to take backup of virus infeced hard disk


Which tool can be used to remove these unwanted files?

Ccleaner is one of the good software program to remove unwanted and temp files. Another anti-virus program software like MacAfee and trend micro are good at keeping your system safe from Trojan horse or virus threat.


How do you fix a virus when mouse and keyboard do not work because of it?

You'll need to boot from something else, a rescue disk, the original installation disk or another disk that lets you repair the damage caused by the virus.


A virus infects the Master Boot Record of a hard disk drive?

Boot virus