SysChat

SysChat (http://www.syschat.com/forum.php)
-   Security (http://www.syschat.com/tutorials/security/)
-   -   How to Remove the Raila Odinga Virus (http://www.syschat.com/how-to-remove-raila-odinga-virus-4315.html)

KarlM 02-23-2009 03:00 AM

How to Remove the Raila Odinga Virus
 
What is the Raila Odinga Virus?

The Raila Odinga virus causes this pop-up to appear: “Vote Raila Odinga, the Hummer (Nyundo) for President 2007.” All infected machines have the following programs disabled:
• Control Panel
• Task Manager
• The ‘Run’ Command
• The Command Prompt

Raila Odinga also hits Microsoft word files. It manifests itself as a .jpg file, often found on the user’s desktop. The virus also causes issues with software installation, hidden files, removable drives, and Internet access. Restarting the infected computer under ‘Safe’ mode does not resolve the problem.

The virus displays a picture of Raila Odinga upon infection. It copies itself onto your system. The Raila Odinga .exe file then replicates itself into the Windows directory and establishes a registry entry.

The Raila Odinga virus has the following characteristics:

• Deleting the file does not eliminate the virus. It returns to its previous location after deletion.
• The virus runs from the system32 driver folder.
• It automatically runs at System Startup.
• The infected computer boots slowly and hangs.
• The virus creates new .exe folders in your system.

How to Remove the Raila Odinga Virus:

1. Go to ‘My Computer’ and double-click on drive C.
2. Open the Windows folder, and double-click on the system32 folder.
3. Open the driver folder and find the anomalous word file. Note its name.
4. Point your mouse cursor to the task bar, and right-click.
5. Access the Task Manager, and click on the ‘Process’ tab.
6. Find the file with the same name as the word file you located earlier, and click on ‘End Process.’
7. Go to the system32 driver folder where the file is located. Erase all MS Word files in said folder. Close the aforementioned folder.
8. Determine where the Raila Odinga .jpg file is. Erase the file.
9. Do not double-click on the picture file.
10. Empty the Recycle Bin.
11. Restart your computer.

Oboja 03-31-2009 04:35 AM

Raila Odinga Virus Could not be romoved
 
Hello,
Thanks for your method in removing the odinga virus, but I have tried the method you gave and the word file has refused to be deleted from the driver folder. Please is there another way to delete the file?

KarlM 03-31-2009 03:07 PM

Alternative Procedures for Removing the Raila Odinga Virus
 
1. Go to Start>Programs>Accessories>System Tools>System Restore.

2. Click System Restore Settings.

3. Disable System Restore Monitoring on all partitions except the system partition (drive C).

4. Click Ok.

5. Go to Start>Programs>Accessories>System Tools>System Restore.

6. Select "Restore My Computer at an Earlier Time".

7. Select a restoration point created before the date and time of the infection (if you don't know the exact date and time your computer was infected by this malicious program, just select a restoration point created before you recently installed an application).

8. Click Next.

9. Click Next again to reboot your machine.

10. Install a legitimate anti-malware program on your machine right after your computer has restarted.

11. Do a full system scan and remove all malicious programs and associated components.

Hope this helps.

Quote:

Originally Posted by Oboja (Post 14386)
Hello,
Thanks for your method in removing the odinga virus, but I have tried the method you gave and the word file has refused to be deleted from the driver folder. Please is there another way to delete the file?


lurkswithin 04-01-2009 10:30 AM

Quote:

Originally Posted by Oboja (Post 14386)
Hello,
Thanks for your method in removing the odinga virus, but I have tried the method you gave and the word file has refused to be deleted from the driver folder. Please is there another way to delete the file?

You can also try this free program for windows XP. Don't know whether it works in Vista!

Download MoveOnBoot 1.95 - Allows you to copy, moves or delete files on the next system boot - Softpedia


All times are GMT -4. The time now is 10:12 AM.


Copyright © 2005-2013 SysChat.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54