Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Steps To Clean W32/Smalltroj Virus

>> Tuesday, January 19, 2010

It's incalculable how much virus is produced during the month of November-December 2009. Average scattered power has a very fast and quite troublesome.

W32/Smalltroj virus. VPCG one malware that wara-wiri at the end of this year. This virus will block access to several security websites and other websites that have been determined by the number switch, which is 209.85.225.99 ip public ip Google.

So every time a user tries to access to certain websites, including website security / antivirus, so that appears not you want the web but the website www.google.com.

Here are 9 steps to clean W32/Smalltroj. VPCG a mixed Vaksincom:

1. Turn off System Restore during the cleaning process take place.

2. Decide who will clean your computer from the network or the Internet.

3. Change the name of the file [C: \ Windws \ system32 \ msvbvm60.dll] to prevent the virus active again.

4. Perform cleaning by using the Tools Windows Live CD Mini PE. This is due to some rootkit files masquerading as services and drivers difficult to stop. Please download the software at the address http://soft-rapidshare.com/2009/11/10/minipe-xt-v2k50903.html

Then boot the computer using software Mini PE Live CD. After that deleting some files iduk virus by:

l Click the [Mini PE2XT]
l Click the [Programs]
l Click the [File Management]
l Click the [Windows Explorer]
l Then delete the following files:

o C: \ Windows \ System32
§ wmispqd.exe
§ Wmisrwt.exe
§ qxzv85.exe @
§ qxzv47.exe @
§ secupdat.dat
o C: \ Documents and Settings \% user% \% xx%. exe, where xx is a random character (example: rllx.exe) with a file size of 6 kb.
o C: \ windows \ system32 \ drivers
§ Kernelx86.sys
§% xx%. Sys, where xx is a random character who has a size of 40 KB (example: mojbtjlt.sys or cvxqvksf.sys)
§ Ndisvvan.sys
§ krndrv32.sys
o C: \ Documents and Settings \% user% \ secupdat.dat
o C: \ Windows \ inf
§ Netsf.inf
§ netsf_m.inf
  
5. Delete the registry created by the virus, by using the "Avas! Registry Editor", how:

Steps To Clean W32/Smalltroj Virus READ MORE, For Complete Article

Bring Back Task Manager, ProcessXp-Edited, Regedit, Command Prompt On Disable By Virus

>> Saturday, January 2, 2010

This article is made for you who have trouble against viruses that attack your computer. while there are some links to the download that helps you work in eradicating the virus. This artificial tools for cleaning the virus, as a substitute tools virus windows are disabled. ccpb whereas the thread on the largest internet forum in Indonesia that is kaskus.us.

F
or Task manager disabled virus, you can use this tool :
http://www.XXXansav.com/abcde/tools/etcs/TM_ccpb.exe

ProcessXp-Edited :
http://www.ziddu.com/download/7978501/689af1dbd12c0a31d394c0412ba3d8a8.exe.html

Regedit :
http://www.ziddu.com/download/7978491/29b7b98ee40a1f4c2c33be26de33b5aa.exe.html

Command Prompt :
http://www.XXXansav.com/abcde/tools/etcs/xmd_ccpb.exe

Letter X three, please remove in the link.

Bring Back Task Manager, ProcessXp-Edited, Regedit, Command Prompt On Disable By Virus READ MORE, For Complete Article

Step 7 Wipe Virus 'Conficker'

>> Friday, November 27, 2009

Virus 'Conficker.DV' using a different distribution method than its predecessor. With the sophistication, the virus tried to access the network using a slit windows 'Default Share' (ADMIN $ \ system32) to guess the administrator password.

Also 'Conficker.DV' also makes files on removable media like flash, hard drive and card reader to save the hidden files on the root drive.

While the same action as its predecessors, namely trying mengexploitasi or MS08-067 security holes Windows, Windows Server Service or svchost.exe. Many users are infected due to not enable Automatic Updates feature and do not do windows patch MS08-067.

If you have this, consider a short step 7 of the virus analyst Adi Saputra Vaksincom to eradicate the virus 'Conficker.DV' received ITGazine, Wednesday (28/1/2009):

1. Decide who will clean your computer from the network / Internet.
2. Turn off system restore (Windows XP / Vista).
3. Turn off the active virus process in services. Use the removal tool from Norman to clean the virus is active. If you do not have, can be downloaded at the site norman.
4. Delete service svchost.exe implanted fake virus in the registry. You can search the registry manually.
5. Delete Task Schedule made by the virus. (C: \ WINDOWS \ Tasks)
6. Remove string registry created by the virus. To make it easier to use the registry script below:

[Version]
Signature = "$ Chicago $"
Provider = Vaksincom Oyee

[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del

[UnhookRegKey]
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced,
Hidden, 0x00000001, 1
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced,
SuperHidden, 0x00000001, 1
HKEY_LOCAL_MACHINE
SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ SHOWALL,
CheckedValue, 0x00000001, 1
HKLM, SYSTEM \ CurrentControlSet \ Services \ BITS, Start, 0x00000002, 2
HKLM, SYSTEM \ CurrentControlSet \ Services \ ERSvc, Start, 0x00000002, 2
HKLM, SYSTEM \ CurrentControlSet \ Services \ wscsvc, Start, 0x00000002, 2
HKLM, SYSTEM \ CurrentControlSet \ Services \ wuauserv, Start, 0x00000002, 2

[del]
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Applets, dl
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Applets, ds
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Applets, dl
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Applets, ds
HKLM, SYSTEM \ CurrentControlSet \ Services \ TCPIP \ Parameters, TcpNumConnections

Use the notepad, then save with the name 'repair.inf', then 'Save As Type' to 'All Files' to avoid mistakes. Run repair.inf with right click, then select install.

As for active files on startup, you can disable via 'msconfig' or can be manually mendelete the string: 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'

7. For cleaning the virus W32/Conficker.DV optimally and prevent reinfection, should use the updated antivirus and able to detect this virus very well and patch your computer with an official patch from Microsoft in order to prevent reinfection.

Step 7 Wipe Virus 'Conficker' READ MORE, For Complete Article

Step 'Sweeps' FullHouse Virus

>> Thursday, November 26, 2009

Another virus that threatens the computer user is FullHouse virus. The characteristics of this virus is making an extra drive with the name FullHouse Drive.

The virus is made using Visual Basic programming language that in performing its action will create a separate drive on the Desktop, My computer and Control Panel that when opened will display images "Han Ji Eun" beautiful artist in the series Full House.

To clean it, consider the following steps:

Virus-scan files that are in the directory C: \ RECYCLER with antiviral agents are able to detect this virus very well. Vaksincom using Norman Security Suite.

-After the scan is finished with a virus file delete the file status (defered) means the file will be deleted when windows restart

-Clean button and then click Close at the time Norman Security Suite also will ask the computer to restart

To normalize the re-registry that was created by a virus open Notepad then copy the script below

[Version]

Signature = "$ Chicago $"
Provider = Vaksincom Oyee
[DefaultInstall]
AddReg = UnhookRegKey
DelReg = del
[UnhookRegKey]
HKCR, batfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKCR, comfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKCR, exefile \ shell \ open \ command ,,,"""% 1 ""% * "
HKCR, piffile \ shell \ open \ command ,,,"""% 1 ""% * "
HKCR, lnkfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKCR, scrfile \ shell \ open \ command ,,,"""% 1 ""% * "
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced,
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ exefile \ DefaultIcon ,,,""% 1 ""
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ exefile,,, "Application"
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ exefile \ shell \ open \ command ,,,"""% 1 ""% * "
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ regfile \ shell \ open \ command,,, "regedit.exe"% 1 ""

[del]

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ Run, Task
Manager
HKCU, Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ Run, Task Manager
HKCR, exefile, NeverShowExt
HKCR, CLSID \ (10020D75-0000-0000-C000-000000000000)
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (10020D75-0000-0000-C000-000000000000)

-Save with the name "repair.inf" select Save As Type to All Files

-Run repair.inf with right click and select install

-Delete files created by the virus with the following characteristics:

* Type the file "application"
* Extension "exe"
* Size 168 kb

-To facilitate the process of finding the virus files using "Search Windows"
with the filter *. exe file that has 168 KB size and date modified
pertanggal 7/8/2008

-Then delete "FullHouse Drive" on the Desktop, My Computer and Contol
Panel

-Recovery folder on the Flash Disk that has been in Hidden

-To show hidden folders back to the flash. Use
command "attrib" at the command prompt.

* Click "Start"
* Click "Run"
* Type "CMD", then press "Enter"

-Move the directory to the drive position Flash Disk, say E then type
command E: and press "enter"

-Then type attrib-s-h-r / s / d and then press
"enter

Step 'Sweeps' FullHouse Virus READ MORE, For Complete Article

Best Antivirus Real Free

>> Monday, August 24, 2009

Antivirus is free to search many people, especially those who are avoiding a sweeping examination or pirated software. The bill offers antivirus protection and a more comprehensive customer care. This is a list of antivirus and update his address. Update as necessary each day pop-virus new virus.

Best Antivirus Free
This free antivirus list sorted by popularity on Softpedia.

1. Avira AntiVir PersonalEdition Classic
Avira anti-virus software offers a complete and free. This software also includes protection against viruses, trojans, backdoor programs, worms, and others.
Download Avira AntiVir PersonalEdition Classic
Update Virus Definition latest Avira AntiVir PersonalEdition Classic
2. AVG Free Edition
The AVG Equipped with resident shield, email scanner, anti virus / trojan. Not heavy on the computer running.
Download AVG Free Edition
Update Virus Definition latest AVG

3. PCclear Antispyware with Free Antivirus
PCclear antispyware is Free Antivirus with equipped free anti-spyware, active registry protection & X, and sweeping history.
Download PCclear Antispyware with Free Antivirus
PCClear Site

4. Avast Home Edition
Avast Home Edition offers anti-virus, worm, trojan, boot-time scanner, a screen saver feature antivirus scaner make this work as a screen saver.
Download Avast Home Edition
Update Virus Definition latest Avast Home Edition

5. Gucup Antivirus (GAV)
Gucup antivirus capable men-virus and malware scan. Can detect the virus in a ZIP or rar file. created by AtmaJaya University of Yogyakarta Indonesia.
Download Gucup Antivirus
Gucup Antivirus Website

6. BitDefender Free Edition
BitDefender antivirus is also a free anti-spyware offering updates every hour.
Download BitDefender Free Edition
Update Virus Definition latest Bit Defender

7. RemoveIT Pro
RemoveIT Pro is a free anti-virus also detect and remove Spyware, Malware, Worm, Trojan and Adware.
Download RemoveIT Pro
Website RemoveIT Pro

8. Comodo AntiVirus
Comodo AntiVirus offers complete antivirus protection tehadap anti spyware, trojans, and other malware. Plus email scanning feature and worm blocker.

Tips :
  • Always update the antivirus program (virus definition and engine) in order to avoid new viruses. If possible updates every week or at least every month.
  • Do not install more than one antivirus in a system, because it will slow down the system.
  • Many viruses that icon just like ordinary files (eg like Microsoft Word or JPG), when the file is a virus and have the extension EXE (executable). To avoid this, open Windows Explorer, Tools -> Folder Options -> View. Check the option Show Hidden Files and folders, uncheck the option Hide Extensions for Known Files Type, uncheck the option Hide Protected Operating System Files.
  • Be careful opening EXE or COM files from the Internet or another computer. Always scan files received from outside the computer, let alone downloaded from the Internet.
  • List of top ranked anti-virus on the number of downloads on Softpedia. The most common antivirus download is a popular antivirus and believed many people (plus a good advertising). The above list is not sorted by performance.

Best Antivirus Real Free READ MORE, For Complete Article

Clean Virus DEADLOCK, manually

>> Thursday, August 20, 2009

Be a positive message with the words that inspire patriotism. But, be happy, sweet words that brought a new local computer virus called Deadlock. See the message below.

Free our country from Terrorism Indonesia, anarchist, and KKN (collusion, corruption & nepotism) in the Kubu Government of the Republic of Indonesia (Civil, military & police) and the catch, and fight Penjarakan? Without exception. Clean us from Portitusi Affairs, Social Gambling and Crime. Merdekakan ourselves from poverty, misery and injustice! Democratic Party together? SBY & Boediono, Indonesia Joint Building Fair, & Makmur Sejahtera

Atas Nama Bangsa Indonesia (Top Names of Indonesia)
Pangerant Deadlock (Prince DEADLOCK)

I'm Everyone, No one but
I'm Everything, but nothing
I'm Everywhere, but nowhere

If your computer suddenly displays an image by displaying the message (see image 1), you are advised to immediately take action. The computer you already attacked the virus is active and off.

The virus will display the message in the desktop has been taken over. Usually this message appears only in the time specified. Along with the emergence of this message and all files on all drives will be deleted, including the program and the Windows file system.

For clean virus deadlock from your computer with manual. so follow intruction below :

1. Disable [System Restore] during the cleaning process. Enter the menu Start>> Control Panel>> System>> System Restore>> Select turn off
2. Turn off the virus active in memory, use Task Manager replacement tools, such as Process Explorer, and then turn off the process that has the name mysql.exe and apache.exe

Please download these tools on the following url: here

3. So that this virus can not be active again should block the file before the execution can not be registered with the Software Restriction Policies. This feature only exists on the computer with the operating system Windows XP Professional / Windows Server 2003/Windows Vista and Windows Server 2008, the following manner:

- Click the [Start]
- Click the [Run]
- In the RUN dialog box, type the command SECPOL.MSC and click the [OK] button
- After the screen appears the Local Security Settings, right-click on Software Restriction Policies menu and click Create New Policies
- At the Software Restriction Policies menu, click Additional Rules
- Right-click on Additional Rules and select New Hash Rule ..., then the display appears akan New Hash Rule
- In the column hash files click the Browse button and navigate to the directory [C:-Windows-system32-apache.exe]
- Then click the button [Open]
- In the column-level select Security [Disallowed]
- In the description column should be filled or emptied only
- Click [Apply]
- Click [Ok]

Note:
If your computer is not installed Windows XP Professional/2003 Server/Vista/2008 skip this step.

4. Delete the registry string is modified by the virus. To speed up the process of repairing copy the script below on the notepad program and save it with the name repair.inf then run the file with the
- Right-click the file repair.inf
- Click [Install]

[Version]
Signature="$Chicago$"
Provider=Vaksincom

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software-CLASSES-batfile-shell-open-command,,,"""%1"" %*"
HKLM, Software-CLASSES-comfile-shell-open-command,,,"""%1"" %*"
HKLM, Software-CLASSES-exefile-shell-open-command,,,"""%1"" %*"
HKLM, Software-CLASSES-piffile-shell-open-command,,,"""%1"" %*"
HKLM, Software-CLASSES-regfile-shell-open-command,,,"regedit.exe "%1""
HKLM, Software-CLASSES-scrfile-shell-open-command,,,"""%1"" %*"
HKLM, SOFTWARE-Microsoft-Windows NT-CurrentVersion-Winlogon, Shell,0, "Explorer.exe"
HKLM, SYSTEM-ControlSet001-Control-SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM-ControlSet002-Control-SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM-CurrentControlSet-Control-SafeBoot, AlternateShell,0, "cmd.exe"
HKCU, Software-Microsoft-Windows-CurrentVersion-Policies-Explorer, NoDriveTypeAutoRun,0x000000ff,255
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-policies-Explorer, NoDriveTypeAutoRun,0x000000ff,255


[del]
HKCU, Software-Microsoft-Windows-CurrentVersion-Run, apache
HKLM, Software-Microsoft-Windows-CurrentVersion-Run, mysql

5. Remove the main virus file in the directory

- C:-Windows-system32-apache.exe
- C:-Windows-system32-mysql.exe

6. For optimal cleaning and prevent re-infection, install and use anti-virus scan with a up-to-date.

You can also use Norman Malware Cleaner, please download the tools at the following address here

Note:
If your computer is infected Deadlock can not do this booting Windows with the error message appears NTLDR Is Missing re-install should do, while for the data that have been removed, please use your recovery with the recovery software as GetData Back / Easy Recovery / Recovery My Files, but this will not guarantee all data will be saved.

Clean Virus DEADLOCK, manually READ MORE, For Complete Article

My Rank



Update News

Get the latest update of this site via email, Enter your email address:

We Don't Use Your Email For Spam Activity.

Link Banner

Copy Code Below, Insert Into Your Technology Site And Bestechno Team Can Review Your Web

  © Blogger templates Palm by Ourblogtemplates.com 2008

Back to TOP