Results 1 to 4 of 4

Thread: How to remove Dorf.BA and Restarter.F

  1. #1
    Join Date
    May 2009
    Posts
    1,010

    How to remove Dorf.BA and Restarter.F

    My PC is infected with Dorf.BA and Restarter.F virus. what are this types of virus. How to remove it. Dorf.BA is a virus that spreads through email. It is part of the infection Storm Worm.It comes in the form of a message without an attachment with an invitation to open an e-card surprise to April 1.

  2. #2
    Join Date
    May 2008
    Posts
    3,516

    Re: How to remove Dorf.BA and Restarter.F

    Dorf.BA The virus spreads by email in the form of a message without an attachment with the title and body are variable, usually sent by spam. The sender of the message is a spoofed email address or generated automatically. Some titles Message are April's Fool, Gotcha! All Fool!, Happy All Fools Day, Happy April Fools, Surprise, etc. The message body is a short text urging the recipient to click a hyperlink (IP address of the form xx.xx.xx.xx, XX is a number between 0 and 255): All Fools' Day 71.***.***.**

  3. #3
    Join Date
    Jan 2006
    Posts
    3,792

    Re: How to remove Dorf.BA and Restarter.F

    The diferent name of the virus first viru Dorf.BA is TR / Crypt.XPACK.Gen, I-Worm/Nuwar.R, Trojan.Crypt.AP, Trojan.Crypted-16, Trojan.Packed.419, Email-Worm.Win32.Zhelatin.wt, etc. And in the same way for Restart.F is TR / Crypt.XPACK.Gen, Trojan.IRCBot-1698 (ClamAV), W32/Smalltroj.CXEI (F-Secure), Trojan.Win32.Restarter.f, Win32/IRCBot.ADS (NOD32), etc.

  4. #4
    Join Date
    May 2008
    Posts
    2,945

    Re: How to remove Dorf.BA and Restarter.F

    Restarter.F The virus spreads via the MSN Messenger software and comes in the form of a message purportedly sent by a contact connected with a link to a malicious website. If the recipient clicks on this link they are prompted to download and / or open a file with a. Com, generated on the fly by including his name in the username of the recipient, for greater personalization. If this file is opened, the virus copies itself to the hard drive, then modifies the registry to run automatically every time the computer sends regularly to all MSN contacts then opens a backdoor, is putting awaiting instructions from an IRC channel to take remote control of computers.

Similar Threads

  1. Replies: 4
    Last Post: 11-09-2011, 10:18 AM
  2. Replies: 1
    Last Post: 13-04-2011, 06:24 PM
  3. Found Tango in add/remove programs unable to remove it
    By Sarasi in forum Windows Software
    Replies: 6
    Last Post: 17-07-2010, 02:01 PM
  4. Virus MSN Win32.Restarter.F
    By Katlin in forum Networking & Security
    Replies: 4
    Last Post: 17-04-2009, 01:33 PM
  5. Missing change/remove icon in add/remove programs
    By Victor Kam in forum Windows XP Support
    Replies: 2
    Last Post: 12-05-2007, 08:13 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,879,701.08914 seconds with 16 queries