The Win32.Zafi.B is one of the most common worms infecting thousands of computers around the world. Several companies, including companies developing software 10 software in India and antivirus software vendors have developed to protect against the worm timely updates. And there are many online readers an infected computer can be established. The user must gain confidence and get the antivirus software, the worm immediately deletes the system.
The worm Zafi.B harm a computer to disable or overwrite the existing antivirus software or machines to do anything against the virus. Therefore, a user need to execute or use the free online scanner and removal tools mentioned above. In the event that the antivirus installed on a system is overwritten, you must remove and reinstall when the system is free of the worm.
To eliminate the primary infection, which have to do is delete some files in the Windows system directory and delete registry entries. To delete the registry entries must be familiar with the Registry Editor. If not, the best option is the use of automatic removal tools. It is also recommended that if a person is running the registry editor, he or she should back up the registry before editing it (but also must realize that the worm Zafi.B backup contains the entries) in the case, registry editing is wrong at some point in time. Once the system is clean and well-functioning, the backup with the worm is removed.
It is also found that even the computer of a person who works at a software company high and has an adequate knowledge of these malicious programs are infected with this worm. However, there is no reason to fear, because here are the steps to manually remove the worm Win32.Zafi.B:
1. First, the system is disabled if the operating system is Windows XP and Windows ME. This is to prevent windows to create a checkpoint restoration, while changes in the system. If not, the worm can infect again later.
2. The next step is to restart the computer in Safe Mode. This is necessary because the worm creates Zafi.B running processes and files can not be deleted because Windows does not allow to delete the files related to ongoing processes. Prevents automatic restart windows drivers load and autorun entries, allowing a system to implement relatively clean. This worm also blocks the use of Regedit, which will be needed later.
3. A full system scan with a virus database update and the definition of a virus must be done after the above steps. If this is not possible, an online security scan is performed.
4. Depending on the antivirus, a list of the files detected as infected with the worm or associated with W32/Erkz W32/Zafi.B or viruses. These are the list of files that are copies of the worm is stored in a system folder or shared folders. Antivirus can be configured to automatically delete the files, if not, you can remove manually.
5. Now edit the registry. Backing up the registry should be done before editing. Run entries associated with the worm should be removed from the registry and remove the key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun - ". _Hazafibb" = "% System% Exe"
Also delete the key - HKEY_LOCAL_MACHINESOFTWAREMicrosoft_Hazafibb
6. Now, exit the System Registry Editor.
7. Disable System Restore and restart the computer
8. Full system scan should be performed again to ensure that the system is clean.
It is also proposed that any individual or outsourcing firm must be careful when downloading or clicking a link, so the risk of computer virus that can be avoided.
The worm Zafi.B harm a computer to disable or overwrite the existing antivirus software or machines to do anything against the virus. Therefore, a user need to execute or use the free online scanner and removal tools mentioned above. In the event that the antivirus installed on a system is overwritten, you must remove and reinstall when the system is free of the worm.
To eliminate the primary infection, which have to do is delete some files in the Windows system directory and delete registry entries. To delete the registry entries must be familiar with the Registry Editor. If not, the best option is the use of automatic removal tools. It is also recommended that if a person is running the registry editor, he or she should back up the registry before editing it (but also must realize that the worm Zafi.B backup contains the entries) in the case, registry editing is wrong at some point in time. Once the system is clean and well-functioning, the backup with the worm is removed.
It is also found that even the computer of a person who works at a software company high and has an adequate knowledge of these malicious programs are infected with this worm. However, there is no reason to fear, because here are the steps to manually remove the worm Win32.Zafi.B:
1. First, the system is disabled if the operating system is Windows XP and Windows ME. This is to prevent windows to create a checkpoint restoration, while changes in the system. If not, the worm can infect again later.
2. The next step is to restart the computer in Safe Mode. This is necessary because the worm creates Zafi.B running processes and files can not be deleted because Windows does not allow to delete the files related to ongoing processes. Prevents automatic restart windows drivers load and autorun entries, allowing a system to implement relatively clean. This worm also blocks the use of Regedit, which will be needed later.
3. A full system scan with a virus database update and the definition of a virus must be done after the above steps. If this is not possible, an online security scan is performed.
4. Depending on the antivirus, a list of the files detected as infected with the worm or associated with W32/Erkz W32/Zafi.B or viruses. These are the list of files that are copies of the worm is stored in a system folder or shared folders. Antivirus can be configured to automatically delete the files, if not, you can remove manually.
5. Now edit the registry. Backing up the registry should be done before editing. Run entries associated with the worm should be removed from the registry and remove the key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun - ". _Hazafibb" = "% System% Exe"
Also delete the key - HKEY_LOCAL_MACHINESOFTWAREMicrosoft_Hazafibb
6. Now, exit the System Registry Editor.
7. Disable System Restore and restart the computer
8. Full system scan should be performed again to ensure that the system is clean.
It is also proposed that any individual or outsourcing firm must be careful when downloading or clicking a link, so the risk of computer virus that can be avoided.