|
| |||||||||
| Tags: dorfba, malicious website, msn messenger, restarterf, storm worm, virus |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| ||||
| ||||
| How to remove Dorf.BA and Restarter.F
My PC is infected with Dorf.BA and Restarter.F virus. what are this types of virus. How to remove it. Dorf.BA is a virus that spreads through email. It is part of the infection Storm Worm.It comes in the form of a message without an attachment with an invitation to open an e-card surprise to April 1. |
|
#2
| ||||
| ||||
| Re: How to remove Dorf.BA and Restarter.F
Dorf.BA The virus spreads by email in the form of a message without an attachment with the title and body are variable, usually sent by spam. The sender of the message is a spoofed email address or generated automatically. Some titles Message are April's Fool, Gotcha! All Fool!, Happy All Fools Day, Happy April Fools, Surprise, etc. The message body is a short text urging the recipient to click a hyperlink (IP address of the form xx.xx.xx.xx, XX is a number between 0 and 255): All Fools' Day 71.***.***.** |
|
#3
| ||||
| ||||
| Re: How to remove Dorf.BA and Restarter.F
The diferent name of the virus first viru Dorf.BA is TR / Crypt.XPACK.Gen, I-Worm/Nuwar.R, Trojan.Crypt.AP, Trojan.Crypted-16, Trojan.Packed.419, Email-Worm.Win32.Zhelatin.wt, etc. And in the same way for Restart.F is TR / Crypt.XPACK.Gen, Trojan.IRCBot-1698 (ClamAV), W32/Smalltroj.CXEI (F-Secure), Trojan.Win32.Restarter.f, Win32/IRCBot.ADS (NOD32), etc.
__________________ Truly, if there is evil in this world, it lies within the heart of mankind. -Edward D. Morrison Old soldiers never die- they just fade away. |
|
#4
| ||||
| ||||
| Re: How to remove Dorf.BA and Restarter.F Restarter.F The virus spreads via the MSN Messenger software and comes in the form of a message purportedly sent by a contact connected with a link to a malicious website. If the recipient clicks on this link they are prompted to download and / or open a file with a. Com, generated on the fly by including his name in the username of the recipient, for greater personalization. If this file is opened, the virus copies itself to the hard drive, then modifies the registry to run automatically every time the computer sends regularly to all MSN contacts then opens a backdoor, is putting awaiting instructions from an IRC channel to take remote control of computers. |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "How to remove Dorf.BA and Restarter.F" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Unable to remove internal devices from safely remove hardware list? | LaMarcus | Hardware Peripherals | 4 | 11-09-2011 11:18 AM |
| How to remove External Drive from computer if 'Safely Remove Hardware' disappears | Author | Operating Systems | 1 | 13-04-2011 07:24 PM |
| Remove the safely remove hardware icon from the task bar | Tungesh | Customize Desktop | 2 | 11-08-2009 12:13 AM |
| Virus MSN Win32.Restarter.F | Katlin | Networking & Security | 4 | 17-04-2009 02:33 PM |
| Remove item from Safely Remove Hardware using registry? | Rawling | XP Hardware | 5 | 20-01-2007 05:50 PM |