Is your computer infected with WORM_JER.A? This step-by-step guide can help you safely and quickly remove WORM_JER.A. If you have any problem during the removal process, please contact Tee Support agents 24/7 online for more detailed instructions.

WORM_JER.A Description

WORM_JER.A is determined by Tee Support Labs as malicious trojan horse that may represent security risk for the compromised system and its network environment.WORM_JER.A is able to modify other files by infecting, prepending, or overwriting them them with its own body.WORM_JER.A is also capable to block security software by modifying firewall settings and by disabling security services, eg. Windows Update, Norton Autoprotect, Kaspersky Anti-virus, etc. To modify the hosts file of the system,WORM_JER.A can aslo block the access to the security web pages. If there were some type of system executable file modified, which might indicate the presence of a PE-file infector. Remove WORM_JER.A timely once it is detected on a computer.

WORM_JER.A has security threat shows in the following aspects

  1. WORM_JER.A often infect computer without your permission at the background.
  2. WORM_JER.A allow hacker remotely access to the computer.
  3. WORM_JER.A can spread via network if the infected drive is shared at the network.
  4. Your antivirus software (Trend Micro) may alert you to get rid of this infection WORM_JER.A.

WORM_JER.A Step-by-Step Removal Instructions

1)  The associated processes of WORM_JER.A to be stoped are listed below:

  34byl.exe, SYSTEMIL.EXE, Documents.exe, 34byl.exe, svc2.exe

2)  The associated files of WORM_JER.A to be deleted are listed below:

  c:\2.txt, %Windir%\Temp\111.tmp
  %CommonPrograms%\Startup\SYSTEMIL2.EXE, c:\Documents.exe
  %Windir%\SYSTEMIL.EXE, %AppData%\hil.exe
  %Windir%\Temp\ res_ab4.exe, %AppData%\stwwx.exe
  %Windir%\Temp\ fb_spam_ab4.exe, %AppData%\yaor.exe
  %Windir%\Temp\ main.exe, %Temp%\2rogvoir.exe
  %Temp%\34byl.exe, %Windir%\Temp\34byl.exe
  %Temp%\4wa3x6e21.bat, %FontsDir%\mlog
  %FontsDir%\services.exe, %Windir%\svc2.exe
  %System%\nwcwks.dll, %Windir%\Tasks\fbagent.job
  %Windir%\Temp\1.jpg, %Windir%\Temp\12.tmp
  %Windir%\Temp\13.tmp, %Windir%\Temp\14.tmp
  %Windir%\Temp\2.jpg, %Windir%\Temp\7pp8em6k5.exe
  %Windir%\Temp\9cho4.log, %Windir%\Temp\file.exe
  %Windir%\Temp\index.html, %Windir%\Temp\ins3mlxqr.exe
  %Windir%\Temp\o6jv.exe

3)  The registry entries of WORM_JER.A that need to be removed are listed as follows (Take Note: Back up the Windows registry before editing it, so that you can quickly restore it later if something goes wrong.):

  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tbsolute
  HKEY_LOCAL_MACHINE\SOFTWARE\Alexa Internet
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWCWORKSTATION
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWCWORKSTATION\0000
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWCWORKSTATION\0000\Control
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Parameters
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Security
  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Enum
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION\0000
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWCWORKSTATION\0000\Control
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation\Parameters
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation\Security
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation\Enum
  HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\New Windows
  HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext
  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats


VN:F [1.9.18_1163]
Rating: 0.0/10 (0 votes cast)
Bookmark and Share

Get a Safer, Cleaner & Faster PC!

A good spyware remover can safeguard your computer at real-time automatically.

  • Terminate latest, stubborn virus/spyware
  • Safe, effective and complete
  • Fix various PC problems

So, pick one of your favorite to protect your system easily.


Malwarebytes Anti-Malware

Download | Review

Malwarebytes is one of the most popular and widely used anti-virus and malware-removal software applications for both home and corporate computer users alike.

SpyHunter

Download | Review

SpyHunter is a powerful, real-time anti-spyware application designed to assist computer users in protecting their PC from trojans, rootkits and others.