Your Ad Here

Virus Problems..

common symptoms..

1.folder options will not be visible
2.taskmanager disabled
3.regedit disabled
4.on double clicking on any window.. it will open in new window even if your settings are correct
etc etc..

HOW TO REMOVE VIRUS MANUALLY.
Tools required

1.restriction removal tool
link: http://www.softpedia.com/get/Security/Security-Related/RRT-Remove-Ristrictions-Tool.shtml
http://www.esnips.com/doc/c90f7814-42e8-4586-bc4e-4140696e8fc7/RRT

2.unhackme
http://www.greatis.com/unhackme/download.htm

3.hijackthis
http://www.esnips.com/doc/83f6253f-00a5-4763-bd59-8252244158fd/hijackthis_sfx
http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html

4.process explorer
from microsoft site





If your pc is affected with some virus the most common of all is your folder otion will be disabled,you may not be able to open task manager, etc etc..


now 1st step is to identify the virus process
process explorer will help u and u may see the path of the installed file on ur system

now use restriction removal tool to remove the task bar ..folder option restrictions...etc...

now our aim is to remove the running virus process..
use hijackthis and select the virus process. it will remove the process from startup registry also..

finally try unhackme.. to remove the rootkits



many virus can be removed in this way but many still remain on ur pc.. in such situations.. try to google for its removal methods manually.. once the restrictions are removed u may be able to use taskmanager and able to use regedit command

Restriction Removal Tool [RRT]


Simple to Use

Just click on restriction

and after selecting them click on "Check All"

Hijack This



Its used to remove the entries of the process from registry.

You may use this to view all the running process and their path.

Just scan once..mark the ones to be deleted and then click on "fix checked"

if you wish you may save the log file also


I think i have give useful information about removing viruses manually from your system

still if you find some problem you are free to contact me either through my communities

1.Hacking and Virus Writing [http://www.orkut.com/Community.aspx?cmm=26828468]
2.Virus Writing [http://www.orkut.com/Community.aspx?cmm=1450780]

Posted by Cyber Trunks

Removal of Driveguard.exe virus is very easy. just open taskmanager and end the process driveguard.exe and also of any .tmp extension is running then also end that process. Now remove its entry from startup by going to msconfig. also dont forget to del your temp files.

How i found it:
Today one of my frnd came to me for some files from my system.. he inserted his pen drive and clicked here ..there... result: pc got infected

i found the process driveguard . exe in task manager

it was trying to access site
http://www.freewebs.com/microsotf/
and download some Update-KB684903-x86. exe file..
http://rapidshare.com/files/127625927/Update-KB684903-x86.rar.html

which was detected by nod as a trojan

the site is still alive as the admins of freewebs are damn lazy to take actions

download link for driveguard file
http://rapidshare.com/files/127625326/WinDriveGuard.rar.html

read the text file.. it claims it to be "spyware removal tool"

Posted by Cyber Trunks

amvo

removal methods

Amvo virus attacks Yahoo! messenger,
It consists of 3 files,
windows\system32\amvo.exe
windows\system32\amvo1.dll
windows\system32\amvo0.dll

just delete these 3 files and the virus is gone, and donot forget to remove the startup entry for amvo.exe, either from msconfig or regedit or any 3rd party tool

1. Open Task Manager
2. End Task Explorer.exe
3. Select Run from File Menu
4. Type cmd (press enter)
5. In Command Prompt Type: cd %windir%\system32
6. Type: attrib -s -h -r amvo*.*
7. Type del amvo*.*
8. Remove startup entries and virus is gone :)


http://mtaram.wordpress.com/2008/01/03/computer-troubleshooting-virus-issues/

Posted on January 3, 2008 by mtaram

Recently I had a big time trouble with my computer as all the drives failed to open on double clicking and showed me a application selection window instead. After searching through the running processes and other settings I found that the show hidden files options in the folder options was also not working.

With the help of one of my friends [MOHIT] I fixed the issues.

The problem was due to amvo.exe amvo0.dll ampo.exe amvol.dll xfoolavp.com usdeiect.com and autorun.inf present in every drive’s root.

The fix works as follows…

open task manager (if ur task manager doesnt open and shows errors and warnings then use this tool
http://www.brothersoft.com/rrt-(remove-restrictions-tool)-60879.html
and end task the above mentioned processes if u see them in the running process list from the processes pane. Then goto applications pane and click on new task and type in cmd or command. Once at the command prompt type in “cd\” without the quotes to goto the root of the current drive. Then type “del /f /a /s /q”

where of the files above mentioned (this menthod can also be used to force delete any unwanted file ) use this method to delete all above mentioned from the root of every drive.

After this open registry editor by clicking on new task and typing in “regedit” without quotes. Then goto HKCU > software >microsoft >windows >current version > explorer > advanced > then look for the hidden key in the right pane and change the value to 1 from 2.

And to fix the issues with drives not opening or search opening up on double click download this .reg
http://megamachine.infinites.net/open.reg
(right click and save target as) file and double click it and add to your registry.

or do this…

copy every under this line paste in notepad save with .reg extension on ur desktop and double click it

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\Directory\shell]
@=”Open”
[HKEY_CLASSES_ROOT\Directory\shell\Explo

re]
[HKEY_CLASSES_ROOT\Directory\shell\Explore\command]
@=”%SystemRoot%\\Explorer.exe /e,/root,\”%1″
[HKEY_CLASSES_ROOT\Directory\shell\Explore\ddeexec]
@=”[ExploreFolder(\”%l\”, %I, %S)]”
“NoActivateHandler”=”"
[HKEY_CLASSES_ROOT\Directory\shell\Explore\ddeexec\application]
@=”Folders”
[HKEY_CLASSES_ROOT\Directory\shell\Explore\ddeexec\topic]
@=”AppProperties”
[HKEY_CLASSES_ROOT\Directory\shell\find]
“SuppressionPolicy”=dword:00000080
[HKEY_CLASSES_ROOT\Directory\shell\find\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\
65,00,00,00
[HKEY_CLASSES_ROOT\Directory\shell\find\ddeexec]
@=”[FindFolder(\”%l\”, %I)]”
“NoActivateHandler”=”"
[HKEY_CLASSES_ROOT\Directory\shell\find\ddeexec\application]
@=”Folders”
[HKEY_CLASSES_ROOT\Directory\shell\find\ddeexec\topic]
@=”AppProperties”
[HKEY_CLASSES_ROOT\Directory\shell\Open]
“BrowserFlags”=dword:00000010
“ExplorerFlags”=dword:00000012
[HKEY_CLASSES_ROOT\Directory\shell\Open\
command]
@=”%SystemRoot%\\Explorer.exe /idlist”
[HKEY_CLASSES_ROOT\Directory\shell\Open\ddeexec]
@=”[ViewFolder(\”%l\”, %I, %S)]”
“NoActivateHandler”=”"
[HKEY_CLASSES_ROOT\Directory\shell\Open\ddeexec\application]
@=”Folders”
[HKEY_CLASSES_ROOT\Directory\shell\Open\ddeexec\topic]
@=”AppProperties”
[HKEY_CLASSES_ROOT\Directory\shell\Openddeexec]
[HKEY_CLASSES_ROOT\Directory\shell\Openddeexec\ifexec]
@=”[]”
[HKEY_CLASSES_ROOT\Folder\shell]
@=”open”
[HKEY_CLASSES_ROOT\Folder\shell\explore]
“BrowserFlags”=dword:00000022
“ExplorerFlags”=dword:00000021
[HKEY_CLASSES_ROOT\Folder\shell\explore\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\
65,00,20,00,2f,00,65,00,2c,00,2f,00,69,00,64,00,6c,00,69,00,73,00,74,00,2c,\
00,25,00,49,00,2c,00,25,00,4c,00,00,00
[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec]
@=”[ExploreFolder(\”%l\”, %I, %S)]”
“NoActivateHandler”=”"
[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec\application]
@=”Folders”
[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec\ifexec]
@=”[]”
[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec\topic]
@=”AppProperties”
[HKEY_CLASSES_ROOT\Folder\shell\open]
“BrowserFlags”=dword:00000010
“ExplorerFlags”=dword:00000012
[HKEY_CLASSES_ROOT\Folder\shell\open\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\
65,00,20,00,2f,00,69,00,64,00,6c,00,69,00,73,00,74,00,2c,00,25,00,49,00,2c,\
00,25,00,4c,00,00,00
[HKEY_CLASSES_ROOT\Folder\shell\open\ddeexec]
@=”[ViewFolder(\”%l\”, %I, %S)]”
“NoActivateHandler”=”"
[HKEY_CLASSES_ROOT\Folder\shell\open\ddeexec\application]
@=”Folders”
[HKEY_CLASSES_ROOT\Folder\shell\open\ddeexec\ifexec]
@=”[]”
[HKEY_CLASSES_ROOT\Folder\shell\open\dde
exec\topic]
@=”AppProperties”
[HKEY_CLASSES_ROOT\Drive\shell]
@=”open_[1]”
[HKEY_CLASSES_ROOT\Drive\shell\find]
“SuppressionPolicy”=dword:00000080
[HKEY_CLASSES_ROOT\Drive\shell\find\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\
65,00,00,00
[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec]
@=”[FindFolder(\”%l\”, %I)]”
“NoActivateHandler”=”"
[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec\application]
@=”Folders”
[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec\topic]
@=”AppProperties”
[HKEY_CLASSES_ROOT\Drive\shell\open]
[HKEY_CLASSES_ROOT\Drive\shell\open\command]
@=”%SystemRoot%\\Explorer.exe /idlist,%I,%L”
[HKEY_CLASSES_ROOT\Drive\shell\open\ddeexec]
[HKEY_CLASSES_ROOT\Drive\shell\open\ddeexec\topic]
@=”AppProperties”



another solution [simple]

Posted by Cyber Trunks

Many time many of us have faced this problem that on double clicking the drives they don't open instead it will ask to "open with" ..

what the hell.. how can u open your drives with some other soft??

its happening because your system is affected with some virus which has created autorun.inf file in your drives.

try to find the root cause of it.. some copy.exe virus or some stupid virus has caused it and is still active.

so open the task manager and see the process tab and try to identify the unknown process and click on end task after selecting it

process explorer from microsoft might help u if you are not good in these stuffs.. you may download it after googling for link

after killing the process delete its entry from startup too..[registry startup also]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

then our task is to remove the autorun.inf file

click on start>run>then type cmd and press enter

type the following commands



cd\

attrib -s -h -r autorun.inf

del autorun.inf


repeat these commands for each drive you have

for changing drives in cmd you may type

like for d:

just type

d: and press enter

simple :-)

Posted by Cyber Trunks


Portable Autorun Virus Remover 2.3 | 1.45 MB

Autorun Virus Remover provides protection against any malicious programs trying to attack via USB drive. When a USB device is inserted into your computer, Autorun Virus Remover will automatically scan it, block and delete autorun virus, trojans, and malicious code. Also, it can detect and remove USB virus such as autorun.inf virus in your computer. Autorun Virus Remover can also remove the autorun virus due to which you can't open your hard disk and USB drive (Pen drive, Memory card) by double clicking. Autorun Virus Remover USB antivirus software to permanently protect offline computer against any USB virus without the need for signature updates. This light and easy to use solution is compatible with all software and doesn't slow down your computer at all.


File: portable_autorun_virus_remover_2.3_-_www.freshwap.net.rar
Download
File-Size: 1.41 MB

Posted by Cyber Trunks

Drivemonitor.exe flashguard.exe driveguard.exe
all are same..invariants of Win32.Worm.Autoit.AL

Spreading: low
Damage: medium
Size: 212 Kb
Discovered: 2008 Jul 24

The presence of

%programfiles%\FlashGuard\FlashGuard.exe
%windrive%\FlashGuard\ReadMe.txt
%windrive%\FlashGuard\FlashGuard.exe

The presence of autorun.inf on removable drives that contains

[autorun]
open=System\Security\DriveGuard.exe -run
shell\Open=&Open
shell\Open\Command=System\Security\DriveGuard.exe -run
shell\Explore=&Explore
shell\Explore\Command=System\Security\DriveGuard.exe -run


technical description:
This worm tries to impersonate a friendly application one that wants to protect your removable drives from other pieces of malware.


The malicious file would copy itself to %programfiles%\FlashGuard\FlashGuard.exe

It also includes a readme file that reads:
"This tiny software is used to protect removable storage devices from
worms that are spread from one PC to another. "


It creates the following registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\FlashGuard
with the value "%windrive%\FlashGuard\FlashGuard.exe" -run

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\FlashGuard
with the value "%windrive%\FlashGuard\FlashGuard.exe" -run


Copies the readme file to %windrive%\FlashGuard\ReadMe.txt

It checks if any of the following processes are running,
iexplore.exe,alg.exe,csrss.exe,cssrs.exe,cssrss.exe,explore.exe,
expIorer.exe,csrss.exe,iexplorer.exe,lexplore.exe,lsass.exe,lssas.exe,
lssass.exe,scshost.exe,scvhost.exe,scvhsot.exe,smss.exe,smsss.exe,
spoolss.exe,spoolsv.exe,spoolvs.exe,ssms.exe,sssms.exe,ssvhost.exe,
svchost.exe,svchsot.exe,serivces.exe,taskmgr.exe,wilnogon.exe,winl0g0n.exe,
winlgoon.exe,winlogno.exe,winlogon.exe,wlnlogon.exe
and if is not one of:
\Program Files\Internet Explorer\iexplore.exe,
\system32\svchost.exe,
\system32\lsass.exe,
\system32\csrss.exe,
\system32\alg.exe,
\system32\winlogon.exe,
\system32\smss.exe,
\system32\spoolsv.exe,
\system32\taskmgr.exe
the process would terminated and the file would get renamed with a ".bak" extension


this worm will remove all files from C:\heap41a that are related to other malicious programs

it enables TaskManager if is disabled

will infect any removable drive writing autorun.inf and a copy of itself
in %drv%\System\Security\DriveGuard.exe with hidden attribute

payload:

will download from http://[removed]/lndexnew.jpg
and http://[removed]/lndexnew.txt
executable files that will be copied to temporary directory with a random name
and reg key HKLM\software\microsoft\windows\currentversion\RunOnce\temp_cleanup
with value "%temp_path%\[random].exe" will be created
All downloaded files are backdoors

Posted by Cyber Trunks
Your Ad Here