Friday, October 3, 2008

NTDetec1 virus removal

Another name for Ntdetec1.exe is W32.Ceted. W32.Ceted is a worm that copies itself to all shared and removable drives.

Most Common Symptoms Of Ntdetec1.exe Virus are:
  1. Task Manager doesn’t open or it is blocked.
  2. Regedit or registry editing has been disabled.
  3. Folder Options are not visible under File Menu --Tools
  4. Creates a hidden folder C:\ntdetec1

Analysis:

NTdetec1.exe executes itself with the following name list process.

  • \ntdetec1\ntdetec1.exe
  • \ntdetec1\cmrss.exe
  • \ntdetec1\run.exe
  • \ntdetec1\shell32.exe

Removal Procedure For Ntdetec1.exe:

  1. Open Start >> Run and type cmd and press enter.
  2. Type the following commands :
    taskkill /im cmrss.exe
    taskkill /im ntdetec1.exe
    taskkill /im shell32.exe
    attrib ntdetec1 -s -h /s /d
  3. Locate the folder ntdetec1 in your operating system root directory and delete it permanently.
  4. Type regedit in run window and press enter. This will open registry editor. Locate the key as shown below and delete it.
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\ Run\"winlogon" = "C:\ntdetec1\run.exe"

Subscribe free via email

Enter your email address:

Delivered by FeedBurner

...