INTERESTING SITES LIST BELOW "DO NOT MISS THEM!!!"(SPONSORED LISTING)
SEARCH IN THIS BOX TO KNOW THE PAGERANK OF YOUR SITE
Showing posts with label removing virus. Show all posts
Showing posts with label removing virus. Show all posts

Saturday, June 21, 2008

SOME TIPS ON REMOVING AND DETECTING VIRUS

SOME TIPS ON REMOVING AND DETECTING VIRUS
• Do nothing and watch your Network Connection.
Virus, Spyware and Worm always do their activity in silent by themselves or perfect crime as much as possible. But their activities can be detected with simple way, if you connect to the internet or in a network that connected to the internet, just do nothing with your computer and watch the network connection. If network connection show sending and receiving data all the time, it could be your computer have some of them. But makesure do not do any activity on your computer.
If you cannot see the network connection, click Start -> Setting -> Control Panel -> Network Connection, there are icon with two monitors and keep blinking whenever there’s sending and receiving data.
Check the Speed and Compare
•So what’s next?, Check the Speed and Compare. Maybe on number 1 you still cannot makesure your pc has been infected but you know your PC’s speed. Is it much slower or a bit slower? If your PC’s speed much slower than before, you can add more possibility that your PC has been infected.
• Check your Anti Virus Status.
Most of smart Viruses, they able to shut down the Anti virus’s process and freely take over your pc, installing and duplicate themselves or calling their buddy on it. No wonder if they will make your PC suffer loaded by virus and spyware also their buddy. So if your anti virus is not active, be aware of their visit. Shutting down anti virus, usually done by virus, not worm or spyware.
• Check your MSCONFIG
When virus, worm and spyware was infected, they will put themselves to be run automatically when windows start. You can check what kind of application that run in your PC. Clik start> on run type “msconfig” then enter. New window come up and open Startup Tab, check all applications one by one, usually their name is similar with name of application example, quick time with qt.exe,etc. If you suspect one of them as a virus, Uncheck the file and reboot. If your computer fell better, that file maybe the virus or spyware and rename the file become *.bak. But virus is smart, after you restart the computer, that file has been checked again. That’s mean you have to think over against them and war haven’t not over yet.
• Remember the history.
“Please help, my computer go wild since two days ago”, for me that helpful statement to find virus. That statement could be refer to date when virus was infected. That means on that day, a new file contain virus was created. So let’s search and destroy, click start -> search -> for files or folder.
On Search area, you will find unchecked Date and do check it. Choose file created on below and fill in the date your computer start not good.
This way quite good enough to detect a virus, you will find lists of file that created on that day, not much on the list,that’s why it is easy. And next is to classified the executable file which have *.exe, *.bat, *.pif. Usually the same file is appear in startup tab (no.5).
Suspect a file with above condition and makesure that’s not belong to your application such as MS WORD,EXCEL, etc. you can rename it in
follow these steps mentioned above one by one.......................ok.......people.........

Manually Removing Viruses From PC

Manually Removing Viruses From PC
Have you ever been in the possition that you know you have an virus but you dont have any antivirus?? Its almost impossible to remove it manual without knowing about a few tips & tricks.
After reading this turtorial im sure you will know how to manual remove most of the virus lurking around. But that dosnt mean you shouldnt have any anti virus on you computer!
Anyway, lets get starting with the turtorial.. I suppose you already know what safe mode is. If you dont try pressing the F8 key some times when you start your computer. You havto do this when your computer is about to start the first windows components. In win2k or xp i think you can press space and then F8 when it ask you if you want to go back to previous working setting.
Enough talk about how to start you computer in safe mode, but if you want to manual remove viruses you almost everytime haveto do this in safe mode becouse in safemode most viruses dosnt start. Only some few windows component is allowed to run in safemode. So here is what to do.
Step: 1: Start your computer in safemode.
2: If you know where the virus are hiding delete the executable file.
3: Open the registry and go to the keys below and add an : in front of the value of the string that you think its the virus. Like this, if string is "virus" and its value is "c:\virus.exe" change its value to ":c:\virus.exe". The : is like comenting out the value. But if you are sure its the virus you can just delete the string.


Here are the keys you maybe want to look at:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce
4: The virus can start itself from some other places to. win.ini is the most common files that viruses can use. Soo you should find the files named win.ini and system.ini and look through them and see if you find anything.
5: Look through the startup folder that is normaly located in your profile directory \Start Menu\Programs\Startup.
6: Try searching for the virus executable to see if its hiding some other place.
7: Finally look through the list of services that windows is running. This list is often located under control panel - administrative tools - services. After this 7 steps just reboot your computer in normal mode and try to figure out if the virus is still there..If not SUCCESS if yes, try to go back to safe mode and hunt some more. Off course this 7 steps will not work on every virus out there, but many of them.

-Be carefull with the registery, dont mess it up, if u do ur computer is ****** lol, depends on wat u mess up, i suggest u made a system restore point first, so incase someting happens you can go back on it. -

1. You can edit the hidden autorun.inf file in the root directory! with some cmd commands like chkdsk etc... also u can do this... open autorun.inf see the contents in it (using notepad) if anything comes with shell= or openshell= see the file name... it maybe .vbs / .exe / .cmd / .dll... anything... search tht file... delete that file first and then delete the autorun.inf.. in most cases u can find more than 1 file in the shell scripts (the line that has a word shell in autorun.inf).
2. Edit system.ini file (ok whn i say edit , it means open in notepad) see the contents..
It may come up with some different stuf and associate any .exe .dll etc... however some .dlls are stored by s/w and some by virus so it maybe difficult to find out which one is malicious. Show the file to some knowledgelble person or in tht case u can post this issue here! and you will be guided correctly.

In most cases, task manager is turned off, so to chek the background processes u can download hijack this! from internet.. its about 700kB and its FREE!! Google for the s/w.

Wednesday, June 18, 2008

NEWFOLDER.EXE VIRUS SOLUTION

NEWFOLDER.EXE,AUTOPLAY VIRUS,SSCVIIHOST.exe,


if u r infected with this virus then the following problems will occur in ur pc:

1. u'll find New Folder.exe file in the root path of every storage media you have?

2. u'll find a new folder inside every folder you have?

3. When you doubleclick on one of your hard drive partitions, it shows you some unexpected results?

4. When you rightclick on one of your hard drive partitions, you see a new item called "Autoplay" on top of other items with bold face?

5. When you right click on one of your hard drive partitions, you see some new items with garbage text?

6. When your Antivirus detects and deletes the malware that causes all of that and restart your system, you see an error message similar to: "Windows cannot find SSCVIIHOST.exe..."?

If your answer was ‘Yes’ to any of the above questions then the chances are that you may be infected with the Sohanad virus (otherwise known as New Folder.exe) or one of its variants:

IM-Worm.Win32.Sohanad.as
IM-Worm.Win32.Sohanad.ao
IM-Worm.Win32.Sohanad.am


The problem is that this virus is particulary cumbersome to remove, even by reputable anti-virus programs. But their is a solution and it is called SRT (or Sohanad Removal Tool)!

What does this tool do?
It detects and reoves all traces of the Sohanad virus from your system, including floppy disks and USB flash disks (the latter ones must be write enabled during the scan process).

It also removes the leftovers of this virus by removing the 'autorun.inf' files and cleaning up you system registry, so you won’t see the 'autoplay' item anymore.

How to use it?
Start your computer in Safe mode and run this tool. If you have infected floppy/flash disks you can insert them and click start. You can repeat this process for every disk you have.