RSS Feed

Wanadoo France Orange




wanadoo france orange
What is the free software to remove the virus win32/pe patch?

I have subscribed to Orange, France but I am using Firefox often. From yesterday onwards whenever I open the orange browser a window shows an alert that a wanadoo (old name of Orange-internet) file is infected by Win32/PE Patch. AVG seems not removing this. I get this information again and again whenever I open the Orange browser. How can I remove this?

turn off system restore...delete the"SRDISKID.DAT" in the _restore folder...either the one on c:, d:, e:, ect. depends how many partitions and drives you have.
check your msconfig startup items. Make sure there is not 2 IEXPLORE's running there. If there is, look to see if one has a zero (0) instead of an oh (o). Delete/disable it if it has a zero, as well as delete it's corresponding registry key.restart the computer.
make sure you have a good software firewall to make sure it is not "sending out" any info.

Virus Name: Rbot.FAY
Pervasiveness:
3 of 5
Destructiveness:
3 of 5
Wildness:
2 of 5
Type: Worm
Aliases: [Win32/]Rbot.FAY; [Win32/]Spybot.4wq!Worm (InoculateIT); [Win32/]Packed.Win32.PePatch.aw (Kaspersky); [Win32/]Rbot.FAY;

Date Modified: 11-May-2006
Date Published: 11-May-2006

Description:

Win32.Rbot.FAY is an IRC controlled backdoor (or "bot") that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is highly configurable, and is being very actively developed, however the core functionality is quite consistent between variants.

This particular variant of Rbot is distributed as a 71,578 byte, Win32 executable that exhibits the following specific characteristics:

When executed this variant copies itself to the %System% directory as W1nUpdate.exe and makes the following modifications to the registry to ensure that this file is executed at each Windows system start:

HKLMSoftwareMicrosoftWind owsCurrentVersionRunMicrosoft Windows Update Service = "w1nupdate.exe"
HKLMSoftwareMicrosoftWindowsCurrentVersionRunServicesMicrosoft Windows Update Service = "w1nupdate.exe"

Note: '%System%' and '%Windows%' are variable locations. The determines the location of these folders by querying the operating system. The default location for the System directory for Windows 2000 and NT is C:WinntSystem32; for 95,98 and ME is C:WindowsSystem; and for XP is C:WindowsSystem32. The default installation location for the Windows directory for Windows 2000 and NT is C:Winnt; for 95,98 and ME is C:Windows; and for XP is C:Windows.

provider Wanadoo (France) France Télécom Interactive - musique et présentation 1997


Technorati Tags: , , , , ,

Be the first to comment.

Leave a Reply