Followers

Powered by Blogger.
Monday, September 27, 2010

W.32.Changeup.C removing guide

W32.Changeup.C is a malicious computer worm that infect via removable USB drives and unsecured shared drives. This worm is known for exploiting the Microsoft .lnk file vulnerability. One thing you want to keep in mind, regardless of what antivirus software you feel most comfortable with, keep it updated…ALWAYS.

removing w.32.changeup.c guide image

Having your antivirus updated can mean the difference between running a virus scan and cleaning it off successfully, or having to take your computer to the local shop to be worked on and potentially losing precious pictures and files.
So if you’re here, and you haven’t kept your antivirus software up to date, you can still try to remove W32.Changeup.C in SAFE MODE with what you have.

Safe Mode is basically a “safe” way to boot your computer so that the virus doesn’t load, nor do a lot of other applications that you normally see when you’re on your computer. This prevents device drivers and unwanted software from running, so that you can run your antivirus scan. However, Safe Mode doesn’t always work since I have seen some viruses that even disable it too.

But let’s see what we can do with this W32.Changeup.C.

To boot your computer into Safe Mode:
- Turn off your computer
- Turn it back on, and when you see the first “signs of life” (anything on the screen), start tapping the F8 key on your keyboard..about once per second (if your computer beeps at you, then you can stop tapping).
- You will be given a list to choose from. Choose the one with SAFE MODE only.
- You will then receive a YES/NO prompt, click Yes.

You’ve now successfully booted your computer into Safe Mode, so go ahead and run a full system scan with your current antivirus software.

but, if your computer still infected, you should do it by self or manual.
This step-by-step manual guide completely removes W32.Changeup.C. If you have any problem during the removal process, please contact Tee Support agent 24/7 online for more detailed instructions.

1. Delete files:

%UserProfile%\[RANDOM].exe, %DriveLetter%\[RANDOM].exe
%DriveLetter%\[RANDOM].scr, %DriveLetter%\autorun.inf
%DriveLetter%\x.exe, %DriveLetter%\New Folder.lnk
%DriveLetter%\Passwords.lnk, %DriveLetter%\Documents.lnk
%DriveLetter%\Pictures.lnk, %DriveLetter%\Music.lnk
%DriveLetter%\Video.lnk, %DriveLetter%\[RANDOM FILE NAME].dll
%DriveLetter%\[RANDOM FILE NAME].lnk

2. Delete registry entries

(Take Note: Back up the Windows registry before editing it, so that you can quickly restore it later if something goes wrong.)

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”[RANDOM FILE NAME]” = “%UserProfile%\[RANDOM FILE NAME].exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\”ShowSuperHidden” = “1″


and last way to remove the virus you could use Online Virus Scanner, another way to remove a virus from a computer without the need to install additional anti-virus application is to perform a thorough scan with free Online Virus Scanner that can be found on websites of legitimate computer security provider.

0 comments:

About Me