This guide will show you how to remove Stuxnet worm rootkit (W32.Stuxnet) from your Windows 7, Vista and Windows XP computers and USB drives. Before starting I would like to spend a couple of words about such a worm/virus. It has been around on the Internet for some time, but recently it looks like there has been a fresh outbreak which has caused a lot of issues and problems to companies and regular users. Stuxnet Worm has been primarly designed to spread via USB drives (removable medias) by exploiting a vulnerability called Microsoft Windows Shortcut ‘LNK’ Files Automatic File Execution (Shortcut “LNK/PIF”) which is a reference to a local file, a kind of shortcut which, if clicked or automatically executed, will run the files it refers to. These “shortcuts” (if available on the USB drive) are used by the worm to automatically execute and install malware on the computer. Once Stuxnet virus has managed to breach a system, it will use it to launch other attacks to other machines which are on the same network. After that it will also try to gain total control and admin privileges over those PCs. Such a worm is also know as: Troj/Stuxnet-A, W32/Stuxnet-B, Trojan-Dropper:W32/Stuxnet, WORM_STUXNET.A. Let’s see how to delete Stuxnet trojan from computer thanks to an easy manual procedure.
- As a first step you will have to turn off your Windows System Restore. In order to do it, follow the below guide:
- Now, let’s reboot the system and access the Safe Mode configuration.
- Use your favorite antivirus and scan the computer. Be aware that if your antivirus is not able to detect and remove the Stuxnet Worm you will have to update it or change it. You can use AVG free antivirus.
- Now, we will have to access the Services Panel. To do it, click Start – in the Search field (Run… if you have XP), type: Services.msc and press Enter.
- Locate the following services:
- Right-click each service and select Stop.
- Again for each service, right click – Select Propierties and change startup type to manual.
- Click OK.
- Restart the PC.
- Now, use this removal Stuxnet Worm procedure to get rid of its leftovers. Locate these files and uninstall them. If you can not locate some of them it means that your antivirus deleted them:
- Now open your Windows Registry. To do it, click Start – In the Search field (Run…if you have XP), type regedit and press Enter.
- Locate and delete the following Windos regitry entries:
- Done!
1. Right-click on the “computer icon” on your computer desktop.
2. Click Properties from the menu (it should be last option).
3. Click System Protection, located on the window left pane.
Now, the procedure will split because there are different steps to follow depending on your operating system.
a. If you own Windows Vista, after clicking System Protection you should be able to see checkboxes next to your hard disks/partitions. Untick the drive you want to turn off the System Restore for. After that click the Turn System Restore Off bottom from the pop-up window.
b. If you own Windows 7 after clicking System Protection, click Configure located at the end of the window, right under the list of drives available. Now, click the Turn Off System Protection radio button and click the OK button to confirm.
c. If you have Windows XP, follow this guide.
1. Reboot your Windows.
2. Right after that, keep pressing the F button on your keyboard, repetively.
3. This will let you gain access to the Advanced Option Screen.
4. Select Safe Mode from the list.
MRXCLS
Startup Type: Automatic
Image Path: %System%\\drivers\\mrxcls.sys
MRXNET
Startup Type: Automatic
Image Path: %System%\\drivers\\mrxnet.sys
C:\WINDOWS\system32\drivers\mrxcls.sys
C:\WINDOWS\system32\drivers\mrxnet.sys
C:\WINDOWS\inf\mdmcpq3.PNF
C:\WINDOWS\inf\mdmeric3.PNF
C:\WINDOWS\inf\oem6C.PNF
C:\WINDOWS\inf\oem7A.PNF
~WTR4132.tmp
“Copy of Copy of Copy of Copy of Shortcut to.lnk”
“Copy of Copy of Copy of Shortcut to.lnk”
“Copy of Copy of Shortcut to.lnk”
“Copy of Shortcut to.lnk”
~WTR4141.tmp
HKEY_LOCAL_MACHINE\ SYSTEM\CurrentControlSet\ Services\MRxCls\ “ImagePath” = “%System%\drivers\mrxcls.sys”
HKEY_LOCAL_MACHINE\ SYSTEM\ CurrentControlSet\ Services\MRxNet\ “ImagePath” = “%System%\drivers\mrxnet.sys”

Tags: antispyware, video
Related ArticlesLatest Articles
- How to Automatically Login (Access) to Windows 8
- How to See and Read Unread, Archived and Sent Messages on Facebook
- Switch to the New Facebook Profile Layout (Timeline)
- How to Discover and Recover All Stored Passwords in your Windows Computer
Leave a Comment
Users Important Words
how to remove stuxnet - How To Remove Copy Of Shortcut Virus ink - stuxnet-like shortcut - pif stuxnet a virus - remove w32 stuxnet trojan - stuxnet like shortcut virus - stuxnet wurm/rootkit - stuxnet-like remover -Web Talk is best viewed in Firefox.
Comments
Angry Birds for PC. A Must-Have Game on Your Computer!: Hi, Denise here! Link exchange is nothing else however it...
How to Start Internet Explorer 9 in Safe Mode: In step #2, if you press ENTER, you will launch IE rather than leaving...
How to copy text from a protected Web Page: You really rock man…..i wanted to copy a answer from a secured page and...
An Incredible Way to Reveal Passwords Behind Asterisks: If the password is saved in your browser then you can try going...
How to enable Telnet in Windows Vista and Windows 7: Thank you very much. Its working!!!!
How to uninstall Google Toolbar (and other browser toolbars): uninstall webfinna toolbar
How to uninstall Google Toolbar (and other browser toolbars):
How to Disable or Turn Off Windows Live Mail SkyDrive Permanently: How do I UNINSTALL skydrive which is a...
How to Uninstall TuneUp and TuneUp Utilities from your Computer: it never worked for me
How to Turn On Facebook Chat on Hotmail and Windows Live Messanger: Unfortunately wlm 2011 doesn’t give facebook chat...