Monday, May 2, 2011

Stuxnet remover tool - stuxnet winsta remover

Virus, worm, trojan or Winsta Stuxnet that attack software for industrial automation that is SCADA ( Supervisory Control and Data Acquisition ), WinCC and PCS 7 from Siemens is annoying. But due to viruses, worms, trojans or winsta stuxnet is his exploitation of the Windows operating system and also uses the name of the file belongs to Windows ( winsta.exe ) and the attacking SCADA software from Siemens, of course, the antivirus maker certainly has analyzed stuxnet / winsta this. Update antivirus software regularly is the most appropriate solution to prevent the entry of stuxnet or winsta into our computer.

But what if viruses, worms, trojans or winsta stuxnet has been entered into our computer.....

How to Remove & Repair Virus Stuxnet Winsta


Remove using Dr Web CureIt Removal Tools
Download Removal Tools for stuxnet called Dr.Web CureIt. CureIt files can be downloaded at the FreeDrWeb.com site (www.freedrweb.com/download+cureit/). Removal tools CureIt 45.78 Mb in size in the claims is able to clean a virus or worm or trojan Stuxnet winsta which is annoying.

Repair Windows Registry
Windows Registry is infected with a virus or worm or trojan Stuxnet winsta need to be repaired.
copy the scripts below:

[Version]
Signature=”$Chicago$”
Provider=Vaksincom Oyee
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del[UnhookRegKey]
HKCU, SoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced, ShowSuperHidden,0×00010001,1
HKCU, SoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced, SuperHidden,0×00010001,1
HKCU, SoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced, HideFileExt,0×00010001,0
HKLM, SOFTWARECLASSESbatfileshellopencommand,,,”"”%1″” %*”
HKLM, SOFTWARECLASSEScomfileshellopencommand,,,”"”%1″” %*”
HKLM, SOFTWARECLASSESexefileshellopencommand,,,”"”%1″” %*”
HKLM, SOFTWARECLASSESpiffileshellopencommand,,,”"”%1″” %*”
HKLM, SOFTWARECLASSESregfileshellopencommand,,,”regedit.exe “%1″”
HKLM, SOFTWAREMicrosoftWindows NTCurrentVersionWinlogon, Shell,0, “Explorer.exe”
[del]
HKLM, SYSTEMCurrentControlSetServicesMRxCls
HKLM, SYSTEMCurrentControlSetServicesMRxNet
HKLM, SYSTEMControlSet001ServicesMRxCls
HKLM, SYSTEMControlSet002ServicesMRxNet
HKLM, SYSTEMCurrentControlSetServicesEnumRootLEGACY_MRXClS
HKLM, SYSTEMCurrentControlSetServicesEnumRootLEGACY_MRXNET
HKLM, SYSTEMControlSet001ServicesEnumRootLEGACY_MRXClS
HKLM, SYSTEMControlSet002ServicesEnumRootLEGACY_MRXNET
..

Paste the script above in a text editor program ( eg notepad or notepad ) then save it as repair.inf. Once saved, right-click the file and select install and restart the computer.

To prevent the rest of the trojan that tries to be active again, clear the temporary files using Cleaner software

Infection Prevention
Copy the script below to prevent the virus stuxnet / winsta infect our computer again.
@echo off
del /f c:windowssystem32winsta.exe
rem rd c:windowssystem32winsta.exe
md c:windowssystem32winsta.exe
del /f c:windowssystem32driversmrxnet.sys
rem rd c:windowssystem32driversmrxnet.sys
md c:windowssystem32driversmrxnet.sys
del /f c:windowssystem32driversmrxcls.sys
rem rd c:windowssystem32driversmrxcls.sys
md c:windowssystem32driversmrxcls.sys
attrib +r +h +s c:windowssystem32winsta.exe
attrib +r +h +s c:windowssystem32driversmrxnet.sys
attrib +r +h +s c:windowssystem32driversmrxnet.sys

Paste and save, the script above with the name winsta.bat. Double click the file winsta.bat.

To obtain maximum results, do re-scan our computer using antivirus. Get last update Artav Antivirus here.

Tags: stuxnet remover tools , stuxnet remover tool , stuxnet antivirus , stuxnet winsta remover , restore virus atau delete avg , remover winsta , remover Stuxnet Winsta , remover stuxnet , stuxnet tool , stuxnet virus deleted windows blank , anti stuxnet , winsta remover , anti virus untuk virus stuxnet , virus removal tool , virus removal tol, cara membasmi worm Stuxnet , Stuxnet Winsta removal , atasi virus stuxnet , cara membersihkan virus stuxnet , cara menangani virus winsta -curelt ,

No comments:

Post a Comment