Search:  In

 Jambu - Description


 Browse by name

 
 | misc | a | b | c | d | e | f | g | h | i | j | k | l | m | n | o | p | q | r | s | t | u | v | w | x | y | z |

Description:
W32.Jambu is a worm that spreads through removable storage devices and network shares.


Alias:

Category:
Worm

Automatic Removal: Most effective removal tool is: Easy SpyRemover

Manual Removal:



Stop Runnin Processes:



Unregister DLLs:



Clean Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Macromedia 8" = "%System%\Flash Player.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"W32SYS" = "%System%\w32sys.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"MSN Setup" = "C:\Program Files\Common Files\Microsoft Shared\MSN.msn"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\JambanMu
HKEY_CLASSES_ROOT\.empty
HKEY_CLASSES_ROOT\.fold
HKEY_CLASSES_ROOT\.ie
HKEY_CLASSES_ROOT\.lagu
HKEY_CLASSES_ROOT\.msn
HKEY_CLASSES_ROOT\.pik
HKEY_CLASSES_ROOT\.texz
HKEY_CLASSES_ROOT\.vidz
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"ShowSuperHidden" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"HideFileExt" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "0"
HKEY_CLASSES_ROOT\comfile\DefaultIcon\"(Default)" = "%SystemDrive%\System32\shell32.dll,130"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\"NoFolderOptions" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoFind" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoRun" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoFolderOptions" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableRegistryTools" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe "%System%\6666.com""
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\"DisableCMD" = "2"


Remove Files:
%Windir%\system\Flash Player.exe
%System%\6666.com
%System%\Flash_8_Player.exe
%System%\w32sys.exe
\MESSAGE FROM HELL.HTML
\FlashGame.exe
%Windir%\Media\AUTORUN.INF
%Windir%\Media\Macromedia_Setup.exe
   


Latest Spyware Threats
    RegistryGreat
    XPAntivirus
    Windows Antivirus 2008
    IE AntiVirus
    SpywareQuake 4
    Antivirus XP
    SecurePCCleaner
    Trojan.FakeAlert
    SpamBlockerUtility
    AntispywareBot
    AntiSpywareExpert
    DoctorAdwarePro



Copyright © PcRepairCentral, 2005.