Virus files include:
608769M. BMP crasos.exe Kernelmh.exe servet.exe ntmsoprq.exe RpcS.exe compmgmt.exe upxdnd.dll mppds.dll cmdbcs.dll Wsttrs.exe Ngr.exe iexpl0re.exe rundl132.exe update3.exe Servere.exe newinfo.rxk
Removal Method:
First, clear IE temporary files: Open IE point tool->internet option->internet temporary file-> point "delete Files" button-> will "delete all offline content" tick-> point "OK".
Delete the following registry key with Sreng:
Copy Code code as follows:
<cmdbcs><C:\WINDOWS\cmdbcs.exe>
<upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\update3.exe>
<mppds><C:\WINDOWS\mppds.exe>
<twin><C:\WINDOWS\system32\twunk32.exe>
<><c:\program Files\Common Files\Microsoft Shared\msinfo\newinfo.rxk>
<compmgmt><; C:\windows\system32\compmgmt.exe>
<iz46z07lw><; C:\docume~1\admini~1\locals~1\temp\crasos.exe>
<kernelmh><; C:\windows\kernelmh.exe>
<ntmsoprq><; C:\windows\system32\ntmsoprq.exe>
<qt3ii85kvbfc><; C:\docume~1\admini~1\locals~1\temp\servere.exe>
<scrnsave><; C:\windows\system32\prnmngr.exe>
<upxdnd><; C:\docume~1\admini~1\locals~1\temp\update3.exe>
<viq88><; C:\docume~1\admini~1\locals~1\temp\rundl132.exe>
<wsttrs><; C:\windows\wsttrs.exe>
<yi4jgw1ff><; C:\docume~1\admini~1\locals~1\temp\iexpl0re.exe>
Repair the following registry key with Sreng:
<AppInit_DLLs><608769M.BMP>
Remove the following service items with SRE:
Remote Procedure Call System (RPCs)/RPCs
Windows Systemdown/windowsdown
Delete the following files with Unlocker:
Copy Code code as follows:
C:\WINDOWS\system32\mppds.dll
C:\docume~1\admini~1\locals~1\temp\upxdnd.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\compmgmt.exe
C:\docume~1\admini~1\locals~1\temp\crasos.exe
C:\WINDOWS\608769M. Bmp
C:\WINDOWS\system32\servet.exe
C:\WINDOWS\wsttrs.exe
C:\WINDOWS\system32\ntmsoprq.exe
C:\WINDOWS\Kernelmh.exe
C:\WINDOWS\system32\RpcS.exe
C:\WINDOWS\system32\prnmngr.exe
C:\WINDOWS\mppds.exe
C:\docume~1\admini~1\locals~1\temp\servere.exe
C:\docume~1\admini~1\locals~1\temp\update3.exe
C:\docume~1\admini~1\locals~1\temp\rundl132.exe
C:\docume~1\admini~1\locals~1\temp\iexpl0re.exe
C:\Program Files\Common Files\Microsoft Shared\msinfo\newinfo.rxk
Finally reboot the computer. The virus was taken care of!