Results 1 to 4 of 4

Thread: How to remove W32.Babelloh virus

  1. #1
    Join Date
    Apr 2009
    Posts
    3,974

    How to remove W32.Babelloh virus

    I am using Windows Xp. Due to some strange behavior of my system, i came to know that i am infected by W32.Babelloh virus. And i got sure when i saw all these files:
    %DriveLetter%:\RECYCLER
    %DriveLetter%:\autorun.inf
    %DriveLetter%:\RECYCLER\desktop.exe
    %DriveLetter%:\RECYCLER\desktop.ini
    %SystemDrive%\spoolsv32.exe
    %SystemDrive%\wmiprvse.exe

    I tried to remove it by running antivirus, but no response.Guys i need urgent help regarding the same from you all.

  2. #2
    Join Date
    Apr 2008
    Posts
    3,424

    Re: How to remove W32.Babelloh virus

    Its very long processto Remove W32.Babelloh Virus, so do it carefully because it need some changes in registry:-


    1. First of all right click on My Computer, click on Properties and go to System Restore tab and tick the option saying “Turn off system restore”.


    2. Update the virus definitions.


    3. Reboot computer in SafeMode


    4. Run a full system scan and clean/delete all infected file(s)


    5. Delete/Modify any values added to the registry.Navigate to and delete the following registry entries:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
    \”PolicyRun” = “%SystemDrive%\spoolsv32.exe”
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    \”winmgmt” = “%SystemDrive%\wmiprvse.exe”
    HKEY_USERS\S-1-5-21-1961063573-973683775-492528769-500\Software\Microsoft\Windows
    \CurrentVersion\Run\”winmgmt” = “%SystemDrive%\wmiprvse.exe”
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    \”Shell” = “Explorer.exe %SystemDrive%\spoolsv32.exe”
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks
    \”ImagePath” = “%SystemDrive%\spoolsv32.exe”
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks
    \”ImagePath” = “%SystemDrive%\spoolsv32.exe”
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks
    \”ImagePath” = “%SystemDrive%\spoolsv32.exe”

    6. Navigate to and restore the following registry entries to their original values, if needed:


    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\”ServiceCurrent” = “11″
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks\”Type” = “10″
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\”ServiceCurrent” = “11″
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks\”Type” = “10″
    HKEY_USERS\S-1-5-21-1961063573-973683775-492528769-500\Software\Microsoft\Windows
    \CurrentVersion\Explorer\Advanced\”ShowSuperHidden” = “0″
    HKEY_USERS\S-1-5-21-1961063573-973683775-492528769-500\Software\Microsoft\Windows
    \CurrentVersion\Policies\Explorer\”NoDriveTypeAutoRun” = “B5″
    6. Exit registry editor and restart the computer.

  3. #3
    Join Date
    Apr 2008
    Posts
    3,339

    Re: How to remove W32.Babelloh virus

    If the risk creates or modifies registry subkeys or entries under HKEY_CURRENT_USER, it is possible that it created them for every user on the compromised computer.In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software.

    Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.

  4. #4
    Join Date
    Feb 2009
    Posts
    673

    Re: How to remove W32.Babelloh virus

    The best way to prevent your computer is through constantly updating your antivirus, and spyware software. It is beyond critical that you have both Virus and Spyware Software, and Keep them up to date and run regular scans.

Similar Threads

  1. Want to remove this BAT.Ftp.dm virus
    By Kalanidhi in forum Networking & Security
    Replies: 4
    Last Post: 30-03-2010, 06:31 AM
  2. How to remove this VBS.Lee virus?
    By Sydney_7 in forum Networking & Security
    Replies: 4
    Last Post: 23-03-2010, 05:59 AM
  3. How to remove dx.dll virus
    By Abel18 in forum Networking & Security
    Replies: 5
    Last Post: 23-02-2010, 02:31 AM
  4. How to remove RPC virus
    By AbrahamL in forum Networking & Security
    Replies: 5
    Last Post: 09-02-2010, 06:01 AM
  5. How to Remove MBR Virus?
    By cheap_kaspersky in forum Hardware Peripherals
    Replies: 9
    Last Post: 07-07-2009, 06:16 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,717,394,262.06038 seconds with 16 queries