1. Home >
  2. Computers & Internet >
  3. Security >
  4. Resolved Question
Walker Walker
Member since:
28 May 2006
Total points:
376 (Level 2)

Resolved Question

Show me another »

How to remove the message 'Windows cannot find '''C:\WINDOWS\KesenjanganSosia… from desktop at start?

It does no obvious harm otherwise.
  • 3 years ago
Smart Six by Smart Six
Member since:
14 May 2006
Total points:
149 (Level 1)

Best Answer - Chosen by Asker

Actually "%windir%\kesenjangansosial.exe" or
KesenjanganSosial.exe is a worm W32.Brontok-L.
W32/Brontok-L attempts to send itself to email addresses harvested from the computer. The worm will also attempt to modify various Windows Explorer settings.
KesenjanganSosial.exe spreads by e-mail.

How it works?

When first run W32/Brontok-L copies itself to:

<User>\Local Settings\Application Data\br6591on.exe
<User>\Local Settings\Application Data\csrss.exe
<User>\Local Settings\Application Data\inetinfo.exe
<User>\Local Settings\Application Data\lsass.exe
<User>\Local Settings\Application Data\services.exe
<User>\Local Settings\Application Data\smss.exe
<Windows>\KesenjanganSosial.exe
<Windows>\ShellNew\RakyatKelaparan.exe
<System>\cmd-brontok.exe

The following registry entries are created to run br6591on.exe and RakyatKelaparan.exe on startup:

HKCU\Software\Microsoft\Windows\Curren…
Tok-Cirrhatus-2784
<User>\Local Settings\Application Data\br6591on.exe

HKLM\SOFTWARE\Microsoft\Windows\Curren…
Bron-Spizaetus
<Windows>\ShellNew\RakyatKelaparan.exe

The following registry entry is changed to run KesenjanganSosial.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<Windows>\KesenjanganSosial.exe"

(the default value for this registry entry is "Explorer.exe" which causes the Microsoft file <Windows>\Explorer.exe to be run on startup).

The following registry entry is set, disabling the registry editor (regedit):

HKCU\Software\Microsoft\Windows\Curren…
DisableRegistryTools
1

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\Curren…
NoFolderOptions
1

HKCU\Software\Microsoft\Windows\Curren…
DisableCMD
0

HKCU\Software\Microsoft\Windows\Curren…
Hidden
0

HKCU\Software\Microsoft\Windows\Curren…
HideFileExt
1

HKCU\Software\Microsoft\Windows\Curren…
ShowSuperHidden
0



All Related files with this worm are:

%Windows%\KesenjanganSosial.exe
%Windows%\ShellNew\RakyatKelaparan.exe
%System%\cmd-brontok.exe
%System%\br6591on.exe

Removal :

Try to delete them and replace %Windows% with your windows directory and %System% with your Windows/System directory.

To Removal it , Kill KesenjanganSosial.exe process and remove KesenjanganSosial.exe from Windows startup using RegRun Startup Optimizer.

You can get a copy of RegRun from their website http://www.greatis.com/security/buy.htm
or can try a free version at www.download.com.

Thanks
  • 3 years ago
Asker's Rating:
5 out of 5
Asker's Comment:
I used RegistryWorks lite because the worm which caused it also disabled the regedit.

There are currently no comments for this question.

Other Answers (6)

Answers International

Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. Click here for the Full Disclaimer.

Help us improve Yahoo! Answers. Tell us what you think.