Results 1 to 5 of 5

Thread: How to remove Win32.Zhelatin.anv

  1. #1
    Join Date
    Feb 2010
    Posts
    155

    How to remove Win32.Zhelatin.anv

    My computer system is behaving in an abrupt manner means it is not behaving properly. When I scanned my computer system, my antivirus software gave me an alert message that Win32.Zhelatin.anv is detected on my computer system. I have deleted this Win32.Zhelatin.anv virus from my computer system many times but it comes back repeatedly. Therefore, I need to know the perfect method to delete this Win32.Zhelatin.anv virus from my computer system.

  2. #2
    Join Date
    Apr 2008
    Posts
    3,424

    Re: How to remove Win32.Zhelatin.anv

    Win32.Zhelatin.anv is a worm that spreads through the internet, it camouflage as an attachment in the email. First this worm extract the email address from the victims computer and then send the infected message to all the email address. This worm is also a portable executable file. The size of this file is around 50,583 bytes

  3. #3
    Join Date
    May 2008
    Posts
    3,516

    Re: How to remove Win32.Zhelatin.anv

    The worm creates a file with a random name and an .exe extension in the current directory, and then launches it.
    It then creates the following entries in the system registry:
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
    "Agent" = "%System%\alsys.exe"
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Agent" = "%System%\alsys.exe"
    This ensures that the worm will be launched each time Windows is booted on the victim machine.

  4. #4
    Join Date
    Apr 2008
    Posts
    3,339

    Re: How to remove Win32.Zhelatin.anv

    For removing this Win32.Zhelatin.anv worm follow these steps.
    1. Reboot the computer in Safe Mode (at the start of the boot sequence, press and hold F8, then choose Safe Mode from the Windows boot menu).
    2. Delete the original worm file (the location will depend on how the program originally penetrated the victim machine).
    3. Delete the following files:
    %System%\alsys.exe
    %System%\wincom32.ini
    %System%\wincom32.sys
    4. Delete the following system registry entries:
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
    "Agent" = "%System%\alsys.exe"
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Agent" = "%System%\alsys.exe"

  5. #5
    Join Date
    Jan 2006
    Posts
    4,221

    Re: How to remove Win32.Zhelatin.anv

    To avoid problems like virus, worms and other malware software you must follow some preventive software. These preventive measures are mentioned below.
    1. Do not download pirated software, because they may contain the backdoor.
    2. Update your antivirus software regularly
    3. Scan your system on the regular basis
    4. Enable your firewall setting and use strong passwords for preventing your system

Similar Threads

  1. Replies: 2
    Last Post: 28-07-2011, 12:47 PM
  2. rsaenh.dll: Win32.Zhelatin.Variants.siggen-1
    By Osman84 in forum Networking & Security
    Replies: 5
    Last Post: 10-04-2010, 01:56 AM
  3. Help to remove Win32/VB.JI
    By Lawford in forum Networking & Security
    Replies: 4
    Last Post: 28-03-2010, 03:01 AM
  4. Help to remove Win32/Wowpa.RN
    By Osman84 in forum Networking & Security
    Replies: 4
    Last Post: 25-03-2010, 12:08 AM
  5. Zhelatin.agg Email Worm
    By Cavan in forum Networking & Security
    Replies: 3
    Last Post: 29-09-2009, 11:26 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,131,147.19314 seconds with 17 queries