In the post How to remove Virus Ramnit, which has been explained that this virus will inject a file that has the extension EXE, DLL and HTM / HTML both program files and Windows file system, therefore cleansing should be done in DOS mode. To facilitate cleaning please use Hiren's BootCD, Use the latest version to get the antivirus with the latest virus database. In Hiren's BootCD already Dr.Web Cure It!
Or you can download the Dr.Web Live CD here:
http://www.freedrweb.com/livecd/?lng=en
1. For cleaning can be done optimally, you should scan all USB flash or external HDD, this is by Comodo Internet Security Premium, this can be done after the cleaning process is complete virus, I suggest you to use Comodo Internet Security Premium Antivirus and Firewall with a blend of strong. You can get it for free at Http://www.comodo.com
2. Before doing the cleaning should block viral duplicate files by using the "Software Restriction Policies". This feature is only there on the operating system Windows XP Pro, Vista, 7, Server 2003 and Server 2008 in the following manner:
1. Click the [Start]
2. Click [Run]
3. In the Run dialog box, type secpol.msc and then click the [OK]
4. Once the screen appears "Local Security Policy", right-click menu [Software Restriction Policies "and click" Create New Policies "or" New Software Restriction Policies "if using Windows Vista / 7
5. Then right click on the "Additional Rules", then select "New Hash Rule ..."
After that screen will display "New Hash Rule" In the column "Hash Files", click the [Browse](example C: \ Windows \ Explorermgr.exe) and specify one of the viruses that have duplicate file icon "folder" with a size of 105 KB and click the [Open]. In the "Security Level", select [Disallowed]. Then click the [OK]
Use the Live CD on the Dr.Web GUI mode so you had no trouble using Dr.Web Live CD, Linux Desktop Display As yet very easy to use. Then the scan to finish,
After that restart your computer
Or if you use Hiren's BootCD you can directly use the Live CD mode by selecting the Mini Windows XP (For those of you who are not familiar with Linux)
Read More …
Showing posts with label Virus Shortcut. Show all posts
Showing posts with label Virus Shortcut. Show all posts
Steps to cleaning Win/32 Ramnit
Label: Antivirus, Hiren's, Linux, Ramnit, Registry, Virus, Virus Shortcut 52 komentarHow to remove virus W32/Ramnit
Label: Antivirus, Boot CD, Hiren's, Ramnit, Sality, Virus, Virus Shortcut 62 komentar
One more line of recalcitrant virus latest version, a new virus variant is similar Sality obstinate, his name W32/Ramnit.
This morning one of the computers in the office and the new weird virus in my opinion, almost similar to the virus but more powerful shortcut. This virus belonged to the trojan / backdoor, it will be active if the target computer connected to the Internet and one of weapon. dangerous and nauseating computer users to download other viruses, "
Viruses have also downloaded the names and sizes vary so complicate anti-virus program for detection and cleaning your computer
From my studies after recovering office computer. Dr.Web Cure It is in the package Hiren's BootCD 13.0 and there was still some virus files on my flash, I try to analyze this virus:
First is the emergence of the Internet Explorer pop-up broser containing an offer or advertisement of investment, games and promotional programs. The second symptom is the change icon removable media (USB Flash, External HDD, and the like) into a folder icon. When a user accessible USB flash will get a warning "Access Denied". In addition it appears also the message "compressed zip folders" when USB flash access. Another symptom is the appearance of many files with the file name "Copy of Shortcut to (1). Lnk" s / d "Copy of Shortcut to (4). Lnk" in the USB Flash, this is very disturbing at all, but the virus is still not able to penetrate Folder protection with Unicode Characters I Made Unique.
USB Flash used this virus as a medium for spreading itself by using the autorun feature of Windows. For bodies active virus can be automated, W32/Ramnit also create the file autorun.inf and 4 (four) other shortcut files with the name "Copy of Shortcut to (1). Lnk" s / d "Copy of Shortcut to (4). lnk ".
After W32/Ramnit successfully infects a computer it will also mengifeksi file [C: \ Windows \ Explorer.exe and C: \ Windows \ System32 \ Winlogon]. After successfully carry out the action, this virus will call the other parent files assigned to be active in memory. To trick the user he will then call the application [C: \ Program files \ Internet Explorer \ Iexplore.exe].
Spend bandwidth and virtual memory
If the computer suddenly show information "Virtual Memory Minimum Too Low" while you're not doing anything so beware. Because the virus will always do an internet connection and call the website constantly with different content. Connection is done continuously resulted in a slow computer at the time of use. In some cases the virus can also cause the "Virtual Memory Minimum Too Low" It's very frustrating because our memory is full of unnecessary files from the file the virus.
How to Clean W32/Ramnit?
Because W32/Ramnit attack EXE files, DLLs and HTM / HTML, the best healing method is through DOS mode. Tools like Hiren's BootCD 13.0 is combined with an antivirus program Dr Web Cure It is a combination of the most effective when cleaning virus this Ramnit
The following are detailed steps to clean the virus Ramnit
Hopefully helpful
Read More …
This morning one of the computers in the office and the new weird virus in my opinion, almost similar to the virus but more powerful shortcut. This virus belonged to the trojan / backdoor, it will be active if the target computer connected to the Internet and one of weapon. dangerous and nauseating computer users to download other viruses, "
Viruses have also downloaded the names and sizes vary so complicate anti-virus program for detection and cleaning your computer
From my studies after recovering office computer. Dr.Web Cure It is in the package Hiren's BootCD 13.0 and there was still some virus files on my flash, I try to analyze this virus:
First is the emergence of the Internet Explorer pop-up broser containing an offer or advertisement of investment, games and promotional programs. The second symptom is the change icon removable media (USB Flash, External HDD, and the like) into a folder icon. When a user accessible USB flash will get a warning "Access Denied". In addition it appears also the message "compressed zip folders" when USB flash access. Another symptom is the appearance of many files with the file name "Copy of Shortcut to (1). Lnk" s / d "Copy of Shortcut to (4). Lnk" in the USB Flash, this is very disturbing at all, but the virus is still not able to penetrate Folder protection with Unicode Characters I Made Unique.
USB Flash used this virus as a medium for spreading itself by using the autorun feature of Windows. For bodies active virus can be automated, W32/Ramnit also create the file autorun.inf and 4 (four) other shortcut files with the name "Copy of Shortcut to (1). Lnk" s / d "Copy of Shortcut to (4). lnk ".
After W32/Ramnit successfully infects a computer it will also mengifeksi file [C: \ Windows \ Explorer.exe and C: \ Windows \ System32 \ Winlogon]. After successfully carry out the action, this virus will call the other parent files assigned to be active in memory. To trick the user he will then call the application [C: \ Program files \ Internet Explorer \ Iexplore.exe].
Spend bandwidth and virtual memory
If the computer suddenly show information "Virtual Memory Minimum Too Low" while you're not doing anything so beware. Because the virus will always do an internet connection and call the website constantly with different content. Connection is done continuously resulted in a slow computer at the time of use. In some cases the virus can also cause the "Virtual Memory Minimum Too Low" It's very frustrating because our memory is full of unnecessary files from the file the virus.
How to Clean W32/Ramnit?
Because W32/Ramnit attack EXE files, DLLs and HTM / HTML, the best healing method is through DOS mode. Tools like Hiren's BootCD 13.0 is combined with an antivirus program Dr Web Cure It is a combination of the most effective when cleaning virus this Ramnit
The following are detailed steps to clean the virus Ramnit
Hopefully helpful
Read More …
How to remove virus shortcuts without an AntiVirus?
Label: Antivirus, autorun.inf, Smadav, Software, Vaksin.com, Virus, Virus Shortcut 13 komentarYesterday I tried to access Google Analytics blog, almost 90% of visitors from more than 30 countries found this blog with a keyword shortcut around the virus, the virus was present this shortcut is rampant throughout the world. For that I will try to discuss the return of the virus.
PIF Virus / Starter or better known as the virus shortcut upset victim with a lot of shortcuts that are created by the virus. Fuss, if ways of handling this virus is not right then he actually will come back again, again and again
Here are some ways of a virus analyst at MG Vaksincom Lat shortcut to stop the flood caused this virus:
1. Previously turning off system restore process.
2. Turn off the process of Wscript file located in C: \ Windows \ System32, by using tools such as CProcess, HijackThis or can also use the Task Manager of Windows.
3. Once off the process of Wscript, we need to delete or rename the file so as not to be used temporarily by the virus.
For the record, if we are to rename the file wscript.exe it automatically, it will be copied again in the folder. Therefore, we must find where the file wscript.exe others, usually in C: \ Windows \ $ NtServicePackUninstall $, C: \ Windows \ ServicePackFiles \ i386.
Unlike other VBS viruses, we can change the Open With from the vbs file into Notepad, the virus that matters is berextensi MDB Microsoft Access file. So Wscript DATABASE.MDB will run the file as if he is VBS file.
4. Delete an existing parent file in C:\Documents and Settings\\My Documents\database.mdb, for every time the computer boots will not load the file. And do not forget we also open MSCONFIG, disable the run command.
5. Now we are going to delete the files autorun.inf. Microsoft.INF and Thumb.db. Way, click the START button, type CMD, and moved to the drive to be cleaned, for example, drive C:\, then we have to do is:
Type C:\del Microsoft.inf/s, this command will be to delete all files microsoft.inf the whole folder on drive C:. Meanwhile, if you want to move the drive to stay just renamed drive example: D:\del Microsoft.inf/s.
For the autorun.inf file, type C:\del autorun.inf /s/ah/f, the command would be to delete the autorun.inf file (syntax /ah/ f) is used because the file is taking attrib RSHA, as well as to file Thumb . db also do the same thing.
6. To delete files older than 4 files, we must find a way search files with extensions. Lnk size 1 kb. In the 'More advanced options' make sure the option 'Search system folders' and 'Search hidden files and folders' are both checked.
Please be careful, not all files shortcut / LNK file size of 1 kb is a virus, we can distinguish it from an icon, size and type. For a shortcut icon is created virus always uses icons 'folder', size 1 kb and type 'shortcut'. While the correct folder should not have 'size' and its type is 'File Folder'.
7. Fix the registry has been changed by the virus. To speed up the process of repair registry copy the script below on the program 'notepad' and save with the name 'repair.inf'. Run the file in the following manner:
- Right-click repair.inf
- Click Install
[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del
[UnhookRegKey]
HKLM, Software \ CLASSES \ batfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, Software \ CLASSES \ comfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, Software \ CLASSES \ exefile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, Software \ CLASSES \ piffile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, Software \ CLASSES \ regfile \ shell \ open \ command,,, "regedit.exe"% 1 ""
HKLM, Software \ CLASSES \ scrfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKLM, SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon, Shell, 0, "Explorer.exe"
HKLM, SYSTEM \ ControlSet001 \ Control \ SafeBoot, AlternateShell, 0, "cmd.exe"
HKLM, SYSTEM \ ControlSet002 \ Control \ SafeBoot, AlternateShell, 0, "cmd.exe"
[Del]
HKLM, SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run, Winupdate
HKCU, SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run, explorer
Please leave comments, suggestions or constructive criticism, may be useful to readers.
How do I delete the autorun.inf file created by SmadAV Antivirus?
Label: Antivirus, autorun.inf, Smad Lock Remover, Smadav, Vaksin.com, Virus, Virus Shortcut 38 komentarBefore that, I apologize for the last few days I do not post because it is too busy with work.
to atone for it all this time I will discuss about how menhapus autorun.inf in flash is created by antivirus SmadAV.
For those of you who use artificial SmadAV antivirus Indonesia may find Autorun.inf folder that is created automatically to protect your drive. Perhaps you are one of those who ask how to delete a folder as where Autorun.inf SmadAV it from your computer
Here's how you can use to remove these folders SmadAV Autorun.inf.
First: You can use the setting of SmadAV itself.
* Open SmadAV and click on the Settings tab
o Remove the Checklis in writing: "Aktifkan Smad-Lock pada saat flashdisk dicolok."
You can also delete the folder by typing a few commands in notepad and save with the extension *. bat samples: removeautorun.bat.
rd/s/q D:\con\aux\nul. Autorun.inf This is locked by Smad? V to protect your Flash-Disk from virus infection.
rd/s/q D:\con\aux
rd/s/q D:\con
Note: D in the code represents the location of your flash, replace and adjust with the existing drive letter on your computer. If you've completed typed and saved, removeautorun.bat Double-click the file.
Second: Using Smad Lock Remover or Unlocker
so hopefully can help you delete the file
Subscribe to:
Posts (Atom)
Copyright © 2009-2012 Computer Knowledge. All rights reserved.




