Is your computer infected with WORM_JER.A? This step-by-step guide can help you safely and quickly remove WORM_JER.A. If you have any problem during the removal process, please contact Tee Support agents 24/7 online for more detailed instructions.

WORM_JER.A Description

WORM_JER.A is determined by Tee Support Labs as malicious trojan horse that may represent security risk for the compromised system and its network environment.WORM_JER.A is able to modify other files by infecting, prepending, or overwriting them them with its own body.WORM_JER.A is also capable to block security software by modifying firewall settings and by disabling security services, eg. Windows Update, Norton Autoprotect, Kaspersky Anti-virus, etc. To modify the hosts file of the system,WORM_JER.A can aslo block the access to the security web pages. If there were some type of system executable file modified, which might indicate the presence of a PE-file infector. Remove WORM_JER.A timely once it is detected on a computer.

WORM_JER.A has security threat shows in the following aspects

  1. WORM_JER.A often infect computer without your permission at the background.
  2. WORM_JER.A allow hacker remotely access to the computer.
  3. WORM_JER.A can spread via network if the infected drive is shared at the network.
  4. Your antivirus software (Trend Micro) may alert you to get rid of this infection WORM_JER.A.

WORM_JER.A Step-by-Step Removal Instructions

1)  The associated processes of WORM_JER.A to be stoped are listed below:

  34byl.exe, SYSTEMIL.EXE, Documents.exe, 34byl.exe, svc2.exe

2)  The associated files of WORM_JER.A to be deleted are listed below:

  c:\2.txt, %Windir%\Temp\111.tmp
  %CommonPrograms%\Startup\SYSTEMIL2.EXE, c:\Documents.exe
  %Windir%\SYSTEMIL.EXE, %AppData%\hil.exe
  %Windir%\Temp\ res_ab4.exe, %AppData%\stwwx.exe
  %Windir%\Temp\ fb_spam_ab4.exe, %AppData%\yaor.exe
  %Windir%\Temp\ main.exe, %Temp%\2rogvoir.exe
  %Temp%\34byl.exe, %Windir%\Temp\34byl.exe
  %Temp%\4wa3x6e21.bat, %FontsDir%\mlog
  %FontsDir%\services.exe, %Windir%\svc2.exe
  %System%\nwcwks.dll, %Windir%\Tasks\fbagent.job
  %Windir%\Temp\1.jpg, %Windir%\Temp\12.tmp
  %Windir%\Temp\13.tmp, %Windir%\Temp\14.tmp
  %Windir%\Temp\2.jpg, %Windir%\Temp\7pp8em6k5.exe
  %Windir%\Temp\9cho4.log, %Windir%\Temp\file.exe
  %Windir%\Temp\index.html, %Windir%\Temp\ins3mlxqr.exe
  %Windir%\Temp\o6jv.exe

3)  The registry entries of WORM_JER.A that need to be removed are listed as follows (Take Note: Back up the Windows registry before editing it, so that you can quickly restore it later if something goes wrong.):

  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tbsolute
  HKEY_LOCAL_MACHINE\SOFTWARE\Alexa Internet
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWCWORKSTATION
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWCWORKSTATION\0000
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWCWORKSTATION\0000\Control
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Parameters
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Security
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Enum
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION\0000
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION\0000\Control
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation\Parameters
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation\Security
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation\Enum
  HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\New Windows
  HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats


Bookmark and Share
VN:F [1.9.18_1163]
Rating: 0.0/10 (0 votes cast)

Tee Support

Services | Review

Tee Support is an award-winning online tech service 24/7. Tee Support experts provide sophisticated manual solutions:

  • terminate latest, stubborn virus/spyware that an antivirus program can not!
  • specific solution for your specific system: Safe, Effective, Complete.
  • many more services covering various PC problems to meet your requirements.

A good spyware remover can safeguard your computer at real-time automatically. So, pick up one of your favorite to protect your system easily.

However, professional online technical support is highly recommended if you want a more specific, accurate and effective solution toward your specific issue in your specific computer system.

Malwarebytes Anti-Malware

Download | Review

Malwarebytes is one of the most popular and widely used anti-virus and malware-removal software applications for both home and corporate computer users alike.

Spyware Doctor

Download | Review

Award-winning Spyware Doctor with AntiVirus software protects your PC against privacy and tracking threats. Spyware Doctor with AntiVirus detects, removes and secures your PC from potential spyware, viruses, worms and tracking threats.

SpyHunter

Download | Review

SpyHunter is a powerful, real-time anti-spyware application designed to assist computer users in protecting their PC from trojans, rootkits and others.