7/24/10

How to Remove Virus shortcut Harry Potter

How to Remove Virus shortcut Harry Potter ?
Searched on facebook friend complained that her computer was attacked Shortcut virus, a type virus harry potter, there is no harm in me trying to give a little review and how to eradicate this virus.
Your computer (Windows XP with this particular) have a virus / malware folder shortcut harry potter ... lnk, microsoft, new folders steps Insha Allah I will give below can help overcome them.

According to my analysis of how the virus / malware is as follows:


* Virus / malware will put the file database.mdb, thumb.db, Autorun.inf, folder shortcut harry potter .... Lnk, folder shortcut microsoft, new folders and shortcuts on my document folder.
* Virus / malware will enable the file wscript.exe and thumb.db files residing in the folder windows system32 folder to run database.mdb files on my document.
* Shortcut folders had to be linked to files thumb.db.
* If you open this shortcut folders it will activate the file and the file wscript.exe thumb.db and will create a duplicate of an existing shortcut folder on your computer, thumb.db file and the autorun.inf file on all drives C.
* If your computer is virus / malware was then the whole drive C: you will have duplicate an existing shortcut folder on your computer, thumb.db file and the autorun.inf file. A scan will also drive, CD ROM, flash and your network as a medium of spreading the virus / malware.

There are two methods to remove the virus.

Method 1 by using an updated antivirus. Antivirus which can recognize the virus (author only has this antivirus 3), namely: 1. AVG: detected as VBS Worm. AVG will delete all the duplicate shortcut folders and files of the virus earlier.
2. Norton Antivirus 2009: detected as VBS Runauto. Norton will delete all files on drive C. thumb.db You can delete the Autorun.inf file and all copies of the shortcut folder manually.
3. Avira Antivir Premium: detect it as malware DR / Agent.JP.
4. Antivir will delete all files on drive C. thumb.db

You can delete the Autorun.inf file and all copies of the shortcut folder manually. Method 2 with the manual method. 1. Turn off System Restore.
2. Turn off the process wscript.exe virus using tools CProcess / CurrProcess (you can download via google). Run CProcess, search on name wscript.exe process tab then right click and click the kill procesess selected.
3. Open windows explorer, click tools menu options, folder options, view, click Show hidden files and folders, click / uncheck the Hide extensions for Known file types and Hide protected operating system files.Klik OK.
4. Open My Documents. Delete files database.mdb.
5. Click the Search button. Click All Files and Folders. In the All or part of the file name type: thumb.db, click on the Look in my computer. Delete all files that have been found. Repeat the steps above and delete all files that are found again.
6. Click the Search button. Click All Files and Folders. In the All or part of the file name type: Autorun.inf, click on the Look in my computer. Delete all files that have been found. Repeat the steps above and delete all files that are found again.
7. In step 6 actually a virus is gone or no longer active but there are still remaining duplicate shortcut folders created by virus / malware was.
8. If you want to eliminate them, you must be careful at all between the shortcut created by the virus with congenital shortcut on windows. Key features of the shortcut folders created by a virus that is when we appoint these folders will display a link from the shortcut that is in the direction Windows/System32. That we have to delete the shortcut.
9. How to find the folder shortcut: Click the Search button. Click All Files and Folders. In the All or part of the file name type: *. lnk, click on the Look in my computer. You should choose based on the characteristics of the shortcut folders created by the above virus.
10. You can delete the registry created by this virus using HijackThis tool. (Can download via google). Click Scan only and search system in the HKCU \ ... \ ... database.mdb, HKLM \ ... \ .... associated with windowsxp cd (I forget the name of its length, this is also for that but sometimes there are sometimes not), also HKCU \ ... \ .... disableregedit = 1. click the button fixed.
11. Now restart your computer. Actually if we do not delete the registry last (step 10) is not a problem, but at the time of restart windows will display two dialog boxes are essentially the first to find the file that we remove this database.mdb, who both asked to enter the cd windowsxp. click Ok aja uda ga problem. Then we'll likely regedit was disabled by a virus. This is also problematic if you ga ga brain often manipulated the windows registry. Method To counteract the virus comes back

This virus works if we click the new folder shortcut harry potter, microsoft. After we click the shortcut folder then he will find a file that is located in the folder wsript.exe windows system32 folder. With active wscritp.exe the virus will start spreading. So the key to active the virus is in the file wscript.exe. For that we have to turn off the road renaming wscript.exe.

The trick is:

1. Open windows explorer, click tools menu options, folder options, view, click Show hidden files and folders, click / uncheck the Hide extensions for Known file types and Hide protected operating system files.Klik OK.

2. Open the folder C: \ Windows \ system32 \ dllcache. Folder is a collection of backup files from the files in the System32 folder. Find the file wsript.exe then right click to rename eg wscriptx.exe. Then open the C: \ Windows \ system32, find the file then right click rename wsript.exe such a wscriptx.exe too.
Thus my explanation of the shortcut virus, may be useful

79 comments:

  1. Ok sobat linknya dah saya pasang juga ya

    ReplyDelete
  2. great tutorials, but this tutorials same with me :D...

    ReplyDelete
  3. @jurug :great blog with a tutorial as above, thank you for your visit
    @ Linktea : thank you for your visit

    ReplyDelete
  4. I'm coming.
    great blog,,
    thx for visit my blog

    ReplyDelete
  5. heheh..maksudnya klo ada sobat2 yg bingung bisa mencari solusinya di blog ini gitu...

    ReplyDelete
  6. Great web site. Plenty of helpful information here. I
    am sending it to a few friends ans also sharing in delicious.
    And certainly, thanks for your sweat!

    my web blog: Ohio Movers

    ReplyDelete
  7. Hi, Neat post. There is a problem with your website in internet
    explorer, could check this? IE nonetheless is the marketplace leader
    and a large element of folks will miss your fantastic
    writing because of this problem.

    Here is my blog post golfsmith canada promotion code

    ReplyDelete
  8. Wow, wonderful blog structure! How lengthy have you been blogging for?
    you made running a blog glance easy. The total look of your web site is wonderful, let alone the content!


    My web site: golf clubs reviews irons

    ReplyDelete
  9. Yes! It operates additionally with a Lexmark E210 with this operation .
    .. Thank you significantly! I'm extremely pleased to continuously use my printer!

    Also visit my site ... xerox phaser 8560 driver

    ReplyDelete
  10. I've recently started a blog, the data you offer on this website has solved the problem tremendously. Appreciation for your complete time & work.

    My web blog ... ,cheap earring Studs for women

    ReplyDelete
  11. It is appropriate time to make some plans for the future and it's time to be happy. I have read this post and if I could I desire to suggest you few interesting things or tips. Perhaps you can write next articles referring to this article. I desire to read even more things about it!

    Look into my web site ... Avis binoa

    ReplyDelete
  12. I do accept as true with all of the concepts you've introduced for your post. They are very convincing and will certainly work. Nonetheless, the posts are too quick for beginners. May you please prolong them a bit from subsequent time? Thanks for the post.

    My blog post ... Pilgrim jewellery website

    ReplyDelete
  13. Hey There. I found your blog using msn. This is a really well written article.
    I'll be sure to bookmark it and return to read more of your useful info. Thanks for the post. I will certainly return.

    My weblog: xerox 8560 driver

    ReplyDelete
  14. I loved as much as you'll receive carried out right here. The sketch is attractive, your authored material stylish. nonetheless, you command get got an impatience over that you wish be delivering the following. unwell unquestionably come further formerly again as exactly the same nearly a lot often inside case you shield this increase.

    Take a look at my web blog :: xerox 8560 maintenance kit

    ReplyDelete
  15. I'm really enjoying the theme/design of your site. Do you ever run into any internet browser compatibility issues? A few of my blog visitors have complained about my site not working correctly in Explorer but looks great in Chrome. Do you have any suggestions to help fix this issue?

    Stop by my site: public golf courses in kissimmee

    ReplyDelete
  16. Really wonderful, should try it today.

    Feel free to surf to my web page :: xerox phaser 8560 toner

    ReplyDelete
  17. I've liked the page plus totally deeply in love with Polish With the Rough (with Diamond) ring. It can be soooooo pretty.

    Here is my web page: web site

    ReplyDelete
  18. Hello arе using Wordpresѕ for your sіte platfoгm?
    I'm new to the blog world but I'm trying to get startеd аnd set up my оwn.
    Do you need anу coding knoωledge to make your own blog?
    Any hеlp woulԁ be really apprесiаted!


    Fеel free tο vіsit my web site: get on facebook

    ReplyDelete
  19. When someone writes an post he/she maintains the plan of
    a user in his/her mind that how a user can understand it.

    Therefore that's why this paragraph is perfect. Thanks!

    Also visit my weblog :: xerox 8560 phaser

    ReplyDelete
  20. You should buy the ring at our store in Newtown

    My page ... usjr.classrecord.com

    ReplyDelete
  21. Thank you so much for drivers. really useful site!

    Here is my page; http://shelljewelry.org

    ReplyDelete
  22. Why visitors still use to read news papers when in this technological world everything is accessible
    on net?

    Stop by my weblog Private cloud

    ReplyDelete
  23. I'm extremely impressed with your writing skills and also with the layout on your weblog. Is this a paid theme or did you modify it yourself? Either way keep up the excellent quality writing, it is rare to see a great blog like this one nowadays.

    Feel free to visit my homepage - miznaem.com

    ReplyDelete
  24. It's actually a cool and useful piece of information. I'm glad that
    уou simply shareԁ this hеlpful info
    with us. Pleasе stay us informed liκе this.
    Thanks for ѕharing.

    Нeгe is my web site: http://Dreamfc.net/

    ReplyDelete
  25. I am mot impressed with your guidance on making tags.

    I am using the Open Workplace method. Can you recommend, I discover the
    type is also near the edge of each label, when I do a test.
    Can I relocate the text to the center of the tag?
    Anticipate
    hearing from you and I will certainly be visting you once more.


    Look into my site; xerox phaser 8560dn

    ReplyDelete
  26. A fascinating discussion is worth comment. There's no doubt that that you ought to write more about this issue, it might not be a taboo subject but generally folks don't talk about such subjects.
    To the next! Kind regards!!

    Also visit my web site :: pilgrim jewellery uk online ()

    ReplyDelete
  27. I drop a comment whenever I especially enjoy a article
    on a site or if I have something to contribute to the conversation.
    It's caused by the fire communicated in the article I read. And after this article "How to Remove Virus shortcut Harry Potter". I was actually excited enough to post a thought ;-) I do have 2 questions for you if it's
    allright. Could it be simply me or do some of the remarks look
    like coming from brain dead visitors? :-P And, if you are posting on additional online sites, I would like to keep up with anything
    new you have to post. Could you list every one of your communal sites like
    your twitter feed, Facebook page or linkedin profile?


    Also visit my weblog :: micro chip cat flap

    ReplyDelete
  28. sir, kindly send me the video.

    my weblog: xerox phaser 8560dn

    ReplyDelete
  29. Hi, I would like to subscribe for this weblog to get most recent
    updates, therefore where can i do it please help out.


    Here is my site pilgrim jewellery denmark

    ReplyDelete
  30. Such a Brillant Article!
    Gorgeous Jewellery, so versatile & your thinking to mix and match just
    magnificent. Might find me spakling in which I am going.

    ...

    Visit my blog; ,cheap earring shop

    ReplyDelete
  31. I know this if off topic but I'm looking into starting my own weblog and was wondering what all is needed to get setup? I'm assuming having a blog like yours would
    cost a pretty penny? I'm not very web smart so I'm not 100% certain.
    Any suggestions or advice would be greatly appreciated. Thank you

    Also visit my webpage ... xerox 8560 solid ink

    ReplyDelete
  32. Actually Interesting. Many thanks for the Facts. I love your site.


    Also visit my homepage ... xerox phaser 8560mfp
    ()

    ReplyDelete
  33. What's up to every body, it's my first visit of this web
    site; this weblog consists of amazing and truly excellent data for
    readers.

    Here is my web page :: LG 42LS5600 Review

    ReplyDelete
  34. When I initially left a comment I seem to have clicked the -Notify me when new comments are added- checkbox and now each
    time a comment is added I recieve 4 emails with the same comment.
    There has to be an easy method you are able to remove
    me from that service? Appreciate it!

    Visit my webpage how to get rid of acne

    ReplyDelete
  35. Hello my family member! I wish to say that this article is awesome,
    great written and come with almost all vital infos.
    I would like to peer extra posts like this .


    My web blog; pilgrim jewellery debenhams

    ReplyDelete
  36. Consider all-time low of among the notice emails and you can pull out any time.


    Here is my homepage: xerox phaser 8560 (blogspot.fr)

    ReplyDelete
  37. Wow, this piece of writing is pleasant, my sister
    is analyzing these things, therefore I am going to inform her.


    My blog post ... xerox 8560 service manual

    ReplyDelete
  38. Bijoy bayanno bangla tutorial-Software with Bangla to english writing

    https://www.youtube.com/watch?v=TW4mB7ts-4Q

    Facebook like page: https://www.facebook.com/videogurubd

    thank you. Admin

    ReplyDelete
  39. At PTS Mot in Basildon, Essex UK, we understand the importance of having a reliable car for your daily life. You have places to go and you need to have a vehicle that can get you there. That’s what we are here for! Click here for more details.

    ReplyDelete
  40. this post very help full . this video can be help full https://www.youtube.com/watch?v=qg3lFtZKr0k

    ReplyDelete
  41. Thanks for this awesome information And Guys here is the app by using this you can download paid app from google play store in free download by using this link Download Now

    ReplyDelete
  42. Some truly wonderful work on behalf of the owner of this internet site , perfectly great articles .
    Titanium Pendants UK

    ReplyDelete
  43. Thanks for sharing quality information. I love to share it.

    ReplyDelete
  44. Looking to download, install and Activate AVG Antivirus? Visit avg.com/retail to Install and Activate the AVG Retail antivirus in Windows, Mac & Android.

    ReplyDelete

  45. Dear Author, I loved your content and quality information. Thanks for sharing.


    AVG Retail | AVG Support Number | www.avg.com/retail | avg.com/retail

    ReplyDelete

  46. Great to see quality information with unique design and structure. keep it up.


    avg.com/retail | www.avg.com/retail | AVG Retail

    ReplyDelete
  47. Thanks for sharing such a great information with us. Your Post is very unique and all information is reliable for new readers. Keep it up in future.

    HP Printer Support Number | HP Printer Assistant | HP Support Assistant | HP Printer Assistant

    ReplyDelete
  48. Looking for Microsoft Windows XP Support? As Microsoft has been stopped support for Windows XP. We are providing third party certified Microsoft Windows XP Support in usa. Contact us on Microsoft Windows XP Support Number.

    ReplyDelete
  49. Dear Blogger! Thanks for writing nice, quality and informative content. I love to share it.

    Apple Support Toll Free Number | Apple Customer Support

    ReplyDelete
  50. Useful Blog! I would like to thank for the efforts you have made in writing this post. If any one facing issues with Microsoft Windows 8 then contact Microsoft Windows 8 Support Number.

    ReplyDelete
  51. Brother Industries, Ltd. is an electrical equipment company based in Japan. The company has introduced brother printer toll free number to give technical assistance to the customers who are facing any sort of issues with their purchased printer.
    Epson printer support phone number
    HP printer support phone number

    ReplyDelete
  52. Webroot antivirus is one of the proven best Antivirus software. If you own a device or system and you are connecting it to internet or another device then you must have antivirus software.This can be done with the help of effective internet security and anti-virus products from webroot.com/safe that safeguards all devices used on digital platforms.

    ReplyDelete
  53. Epson Printer Support team is not only focused on one problem, but we give full attention to all the problems that you might be facing with your Printer.
    To know more Epson printer customer support

    ReplyDelete
  54. Nice article.
    Do you looking for solving issues for printers then you can feel free to contact us canon printer customer support and also on canon printer toll free number .

    To enjoy our services more, you can also contact the professionals by Brother Printer Support | Epson printer support number

    ReplyDelete
  55. Email stands for messages which are circulated by electronic means from one device to another user's device with the help of internet connection.
    To troubleshoot these error is very necessary, get assistance at Email customer support phone number by directly connects to the support team.

    Read more:recover hacked email account | zoho mail password recovery

    ReplyDelete
  56. IncrediMail is the email service provider which provide best and amazing services and solutions for fixing all your IncrediMail related issues. The certified professionals are proficient enough and have a vast knowledge regarding IncrediMail. To reach us, call on IncrediMail support toll free number and get support for all issues.

    dell printer customer support | verizon customer support number

    ReplyDelete
  57. On the off chance that you need proficient help for your HP Printer, at that point connect with our specialists at HP Printer Support Number 1-877-301-0214 and sort out every single specialized multifaceted nature that are disturbing you. Our specialists comprehend the estimation of time and this is the fundamental reason we for the most part center on moment arrangements which are conveyed to destitute one with no holding up system. Consequently, quit stressing and contact our specialists at HP Printer Assistant to invalidating all printing glitch as.Hp Printer Assistant in like manner printing knowledge to Other Scales.

    ReplyDelete
  58. In an age of technology, very few activities immerse you in a time where you think of nothing but the task at hand, Locked In A Room does. With your chosen team, delve into another world of mysteries and puzzles whilst working together to release the rooms secrets. team building events southampton

    ReplyDelete
  59. If you are looking to buy bing ads promo codes or bing coupons, look no further. We have been providing bing coupon codes since last many years and have numerous satisfied clients. Bing $100 coupon

    ReplyDelete
  60. Bullguard Login is a superb web technology which allow you to access all of your database like as product,services,etc. You can activate your bullguard antiviurs within minute ,can renew your subscription,change your password. And if you are new to Bullguard , so can create new account.
    Whenever is there any trouble with your bullguard. So must call to Support expert/ executive.

    Bullguard Login
    Office Login
    Mcafee Login
    AVG Login
    Norton Login
    webroot login
    webroot.com/safe
    Turbotax Login

    ReplyDelete
  61. Now you can download office offline and online both. Office facilitates to activate it online.For that you have need of activation key and go to official site, login your account and enter valid key and activate it.Other wise you can install and then put key and activate offline also on your computer system successfully. If you get any of problem on your computer so contact to the support team .

    Bullguard Login
    Office Login
    Office Login
    Mcafee Login
    AVG Login
    Norton Login
    webroot login
    webroot.com/safe
    Turbotax Login

    ReplyDelete
  62. Great job did by you . This blog is really a inspiration for me and very nice it is.Amazing it is. Bullguard Login
    webroot Login

    ReplyDelete
  63. Thank you for sharing this genuine blogspot with us. I like your post and now I am gone share it to my profile of facebook. Garmin by clicking on this link get know about me more.

    ReplyDelete
  64. Hii! I am Emma ava, I am working as a technician. If you are facing any kind of issues with how to change outlook passwordthen just feel free to contact us at our technician team.

    ReplyDelete
  65. The blog has the whole subject well covered each and every, information has been explained properly.
    How do I fix Avastui EXE application error?

    ReplyDelete
  66. I don’t know in what words I can be thankful enough to the admin for posting this here only I know the way this post has been helpful for me.How Does BullGuard Game Booster Work?

    ReplyDelete
  67. I am really amazed after reading this post because this post has all the informational content. It is not easy to write such type of content on this topic but the writer has done a great job. How to troubleshoot AVG MSI error 27046?

    ReplyDelete
  68. After reading this post, I must say that the writer has knowledge of modern technology. This post is written after a good research on the topic and hence every piece of information seems reliable. How to fix issues related to Yahoo verification code generation?

    ReplyDelete
  69. I was stuck with BullGuard information and I got all of them from this post. I must appreciate the efforts of the writer.Bullguard Helpline Number in London

    ReplyDelete
  70. This blog helped me a lot as I was stuck because my Canon Printer was not working with an error message. The step has given here I followed and I am happy now HP Printer Phone Number UK

    ReplyDelete
  71. This comment has been removed by the author.

    ReplyDelete
  72. This post really saved my day. Thank you so much for posting dude.
    William Thomas
    Jewelry photo retouching service

    ReplyDelete

Please leave a comment here
Comment spam and other promotions will be deleted