Custom Search

Pages

Thursday, August 27, 2009

Here is the details on removing a computer virus

Prepare all the tools needed
Antivirus that is now available for Free (I recommend MSE for now)
Quick Lock 1.0    
Cure    Cure Need dotnet framework 2 in order to run. to download click here


First test to know if a computer virus is present in your computer, this test is for common computer virus that can be transported from a removable drives or Flash drives, Press Ctrl+Alt+Del , If the Task Manager will open, it is ok, but were not finish yet, Go to Start,right click it then click Explore or Press Windows + E that's for opening the Explorer, After that go to Tools and look for name Folder Option, if it is still there, sounds good but if it's not, you are infected,

Mostly all virus from Flash drives will disable Task Manager, Command prompt and Registry Editor and also remove the name Folder Option in the Tools menu. One of this known virus
is Brontok. it is a Polymorphic Virus.

If the Task Manager will not open after you pressed Ctrl+Alt+Del you can use the utility Quick Lock and Cure, Check all the CheckBox in the utility then click and Apply and but close Quick lock 1.0. Then open Process Explorer In the Process Explorer you will find explorer.exe and below Look for the name document.exe, cmd.exe, newfolder.exe, csrsc.exe, scvhost.exe, dont kill svchost.exe above the explorer.exe, dont be confuse about it, See the above picture of process hacker, ALWAYS remember mostly all USB virus stay below explorer.exe. Then if you find one of those, click it and press Del on your keyboard then kill, Then open Registry Editor and find the names of the above virus and delete all you find by pressing F3 in the function keys.

After you done all the above procedure do not restart your computer yet, Now you can Install the antivirus then Update it, after the Update you can restart now the computer.

After you have restarted the computer open the Process Explorer again and find out if the virus is still there, If not, do now a Full Scan of your computer, but if it's still there, perform again the procedure maybe you have skip something, Then if still don't work, Repeat the above procedure and Install Norton Antivirus or Eset Smart Security, If all were unsuccessful, Backup your important documents from your Root drive, usually C:\ Drive, then Reformat your computer, if there are two or more partition on your drives reformat your Root Drive c:\, Then after reformat you have now your fresh Windows, DO NOT OPEN THE DRIVES YET, ONLY THE ROOT DRIVE, THEN DOWNLOAD THE ANTIVIRUS AND SAVE IN YOUR DESKTOP AND INSTALL and perform FULL Scan, This is what i did when i got infected with the VIRUS named VIRUT WIN32 virus or win32Sality. it infects all executables or exe's in all my drives.

I also recommend you to install Process Guard from DiamondCs

This program only works on XP operating system and not on windows 7.

What is ProcessGuard?
DiamondCS ProcessGuard is a groundbreaking security system first released late in 2003 that protects Windows processes from attacks by other processes, services, drivers, and other forms of executing code on your system. ProcessGuard also stops applications from executing without the users consent, stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. ProcessGuard even stops most keyloggers and leaktests, and is recognised by many to be the most comprehensive anti-rootkit solution available.
that could stop the most dangerous trojans in the world from running
... that allowed you to control which programs can and can't run
... that secured processes from other process-based attacks
... that could prevent kernel rootkit drivers from infecting you
... that allowed you to observe the behaviour of programs
... that allowed you to block hooks and injections
... that secured physical memory from attack


Hope this tips helps.. more power
and GoodLuck.