ERROR: The process with PID 3892 child of PID 732 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 732 child of PID 560 could not be terminated.Reason: One or more child processes of this process were still running.ERROR: The process with PID 792 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 860 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 944 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 1096 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 1244 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 1280 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 1300 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).SUCCESS: The process with PID 1988 child of PID 560 has been terminated.ERROR: The process with PID 2024 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 2240 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 3848 child of PID 560 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process with PID 560 child of PID 516 could not be terminated.Reason: One or more child processes of this process were still running.ERROR: The process with PID 572 child of PID 516 could not be terminated.Reason: This process can only be terminated forcefully ( with /F option ).ERROR: The process "system.exe" not found.ERROR: The process "nthlpsvc1.exe" not found.ERROR: The process "nthlpsvc2.exe" not found.ERROR: The process "dirlock.exe" not found.
for %%i in (C D E F G H I J) do del /f /a %%i:\autorun.infDEL /F /A %systemdrive%\Classified.exeRD /S /Q "%AllUserprofile%\Application Data\Microsoft\Keyboard"RD /S /Q "%AllUserprofile%\Application Data\PolariSys"RD /S /Q %Windir%\classifiedDEL /F /A "%AllUserprofile%\Desktop\Classified.exe"DEL /F /A "%AllUserprofile%\Documents\Classified.exe"DEL /F /A "%AllUserprofile%\Documents\My Music.exe"DEL /F /A "%AllUserprofile%\Documents\My Pictures.exe"DEL /F /A "%AllUserprofile%\Documents\My Videos.exe"DEL /F /A "%AllUserprofile%\Start Menu\Programs\Startup\Classified.exe"DEL /F /A "%Userprofile%\My Documents\Classified.exe"DEL /F /A "%Userprofile%\My Documents\My Music.exe"DEL /F /A "%Userprofile%\My Documents\My Pictures.exe"DEL /F /A "%systemdrive%Documents and Settings.exe"DEL /F /A %systemdrive%\Inetpub.exeDEL /F /A %systemdrive%\goats.exeDEL /F /A "%ProgramFiles%\Classified.exe"DEL /F /A "%systemdrive%\Program Files.exe"DEL /F /A %systemdrive%\Read1st!.exeDEL /F /A %Windir%\addins\Classified.exeDEL /F /A %Windir%\addins.exeDEL /F /A %Windir%\AppPatch\Classified.exeDEL /F /A %Windir%\AppPatch.exeDEL /F /A %Windir%\classified\Classified.exeDEL /F /A %Windir%\Classified.exeDEL /F /A %Windir%\Config\Classified.exeDEL /F /A %Windir%\Config.exereg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Sessionmngr /freg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v LSAShell /freg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v WinSys /freg add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /freg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v DisableSR /t REG_DWORD /d 1 /freg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /t REG_SZ /d Explorer.exe /freg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v AppData /t REG_SZ /d "%WinDir%\system32\config\systemprofile\Application Data" /freg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v Cache /t REG_SZ /d "%SystemDrive%\Documents and Settings\LocalService\Local Settings\Temporary Internet Files" /freg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v CheckedValue /t REG_DWORD /d 2 /freg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v DefaultValue /t REG_DWORD /d 2 /freg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v CheckedValue /t REG_DWORD /d 1 /freg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v DefaultValue /t REG_DWORD /d 2 /f
hmmm... not effective para sa worm_autorun.fly 'yong classified.exe + sality! kahit na class-x.bat wala magawa sa worm_autorun.fly!kelangan talaga boot sa live cd na may updated avira at ito lng ang pinaka the bestna paraan matanggal ang worm_autorun.fly.Refs.: http://www.trendmicro.co.jp/vinfo/virusencyclo/default5.asp?VName=WORM_AUTORUN.FLY&VSect=Thttp://en.wikipedia.org/wiki/Daprosy_Worm
tama ka theyeye23 dahil sa sality nagmukhang malakas classified.exe. salot talaga 'yang sality na yan.
@theeye23thanks sa info at nalaman ko na cossta family of worms pala ang kbdrv16.com dati kc tinatawag lang namin 'yang scrap worm! hehe.
sa palagay ko lang, ang classified.exe na worm ay tanga yan eh tapos na-infect ng sality kaya hirap na tanggalin! clone lang siya ng brontok kaya brontok mas mahirap tanggalin.
yup, agree ako jan. applicable 'yang sinasabi mo sa lahat ng trojan worms. para sa akin, maraming mga trojan worms gawa ng mga estudyante na nagpapayabang. nakapag-aral lng ng kaunting VB6 eh gusto na gumawa ng worm para sikat.tingnan mo mga conversation ng mga IT students makakarinig ka talaga na sila daw gawa ng "ganitong" trojan at "ganyang" trojan.ang yayabang!!! kala nila wala penalty sa mahuling gumagawa ng mga trojan at worms!
Good news po!Meron na ko link para matanngal classified.exe sa inyong computer!Follow nyo lng po ito:http://digg.com/security/Classified_exe_RemoverGood luck!