Spyware Removal

Remove Odelud


What is Odelud and removal instructions

Odelud is a worm that spreads through network shares and by copying itself to removable media and fixed drives. The parasite terminates running antiviruses, security-related programs as well as some other applications. It also disables Task Manager, Registry Editor, Command Prompt and the Run utility. Odelud modifies important system settings. Furthermore, it attempts to infect all the executable files it finds. It also deletes some system files and enables sharing of local drives providing unauthorized access to user confidential information. The worm secretly runs on every Windows startup and every time a .vbs or .reg file is opened.

Odelud manual removal:

Delete registry values:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe,[multiple spaces]mycomp.scr
HKEY_CLASSES_ROOT\VBSFile\Shell\Open\Command\(Default)=%System%\logonui.scr
HKEY_CLASSES_ROOT\regfile\Shell\Open\Command\(Default)=%%Windir%\System\services.scr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\DisableCMD=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
Delete files:
deulledo-x.scr, dokumen penting.scr, film.scr, gambar.scr, inetinfo.scr, lagu.scr, logonui.scr, mycomp.scr, services.scr
Misc:
Exact file location:
services.scr - C:\WINDOWS\System or C:\WINNT\System
deulledo-x.scr - the root of both removable and fixed drives
logonui.scr, mycomp.scr - C:\WINDOWS\System32 or C:\WINNT\System32
inetinfo.scr - C:\WINDOWS\System32\drivers or C:\WINNT\System32\drivers
dokumen penting.scr, film.scr, gambar.scr, lagu.scr - C:\MSOCache\dlcache

     
Related Spyware Removal

 

 

Previous£ºOemji   Next£ºObsorb Trojan
| 1-9 | O | P | Q | R | S | T | U | V | W | X | Y | N | M | L | A | B | C | D | E | F | G | H | I | J | K | Z
Copyright © SpywareDot 2004-2009| Spyware Removal.  All rights reserved.