How to Remove the Win32 Autorun Worm?

Computer systems running Windows without proper virus protection and malicious program activity detection are prone to getting affected with malware from the Internet, mobile hard disks and USB memory sticks.

Such a malicious worm called Win32 has been known to secretly and maliciously integrate itself into program or data files on any target computer system running the Microsoft Windows Operating System without proper security measures in place.

The Win32 virus has been observed to spread by integrating itself into more files each time the host program is run. Also known as Win32 Autorun Worm, it can resemble as a legitimate Windows System32 file and exploit your Windows OS to download bad files from other websites.

The Win32 Autorun Worm has also been known to infect any target computer system through undesirable email attachments, media codecs, pornographic material and various kinds of image downloads. The Win32 Autorun Worm has proved to be a serious security threat in many cases where it has been reported to steal secret assemblage and should be removed as soon as it is detected on any computer system.

Win32 Autorun Worm Aliases:

As with any notoriously dangerous computer virus or piece of malware, the Win32 Autorun Worm goes by various aliases that may reside on your computer including but not limited to:

1. Worm.Win32.Autorun.nox
2. Worm.Win32.Autorun.dlw
3. Worm.Win32.Autorun.m
4. Worm.Win32.Autorun.bli
5. Worm.Win32.Autorun.cpe
6. Worm.Win32.Autorun.Isw
7. Worm.Win32.Autorun.nuu
8. Worm.Win32.Autorun.cea
9. Worm.Win32.Autorun.aye
10. Worm.Win32.Autorun.bnb
11. Worm.Win32.Autorun.cgi
12. Worm.Win32.Autorun.hr

Usual Win32 Autorun Worm Symptoms to look for:

1. Your computer system causes unfamiliar Windows sound errors.
2. Your computer system experiences corrupt or nonexistent registry entries causing crashes and showing the blue screen of death.
3. Your computer desktop screen and screensavers are hijacked by annoying messages.
4. Your computer’s web browser Pop-up blocker becomes inadequate to prevent pop-ups taking you to crazy unwanted websites with more viruses and worms.
5. Your computer’s web browser’s default start page auto re-directs to perverted websites
6. You computer system experiences extreme slowdown as well as significantly noticeable sluggishness in performance

Win32 Autorun Worm Activities:

1. It uses various security holes in the Windows Operating System to download detrimental files wrapped with spyware, adware and malware.
2. It monitors all your system activity as well as monitors your browsing habits thus creating pop-up advertisements that follow these patterns.
3. It bypasses any computer antivirus software installed on you computer system as well appears as legitimate files for Internet access in your firewall.

Win32 Autorun Worm Virus Removal Instructions

After reading the above symptoms and identifying that your computer system has been infected with the notorious Win32 Autorun Worm, let’s attempt to get rid of it with the following simple steps:

1. You will first have to open Windows Task Manager by pressing Ctrl + Shift + Esc keys.
2. Click on “Processes” and then click “Show Processes from All Users”.
3. Right-click “Run.exe” and select “End Process”.
4. Right-click “Svchost.exe” and select “End Process”.
5. Close Windows Task Manager.

Deleting all Win32 Autorun Worm related Windows Registry entries:

1. Let’s first open the Windows Registry Editor by typing the command “regedit” in the “Search Programs and Files” box and then hitting ”Enter.”
2. Delete the following registry entry manually:
“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run”
3. Finally close the Windows Registry Editor and you are done here.

Deleting all Win32 Autorun related files from your computer system:

1. So let’s get this pain in the back out of our computer permanently by clicking the Windows Start Menu and then “Search Programs and Files”.
2. Search and delete all of the following files and don’t forget to permanently delete them by hitting shif+delete keys together:
- “SystemDrive\Run.exe”
- “SystemDrive\autorun.inf”
- “Programfiles\Internet Explorer\iesettings.ceb”
- “Programfiles\Internet Explorer\svchost.exe”
3. Finally, restart your computer and you should be done away with the Win32 Autorun Worm forever until you end up surfing the Internet without proper antivirus and worm protection or connected unscanned hardware such as hard disks and USB drives to your computer.

Source: devicemag.com

How to remove Wireshark Antivirus (Virus Removal Tutorial)

The Wireshark Antivirus is a rogue anti-spyware program (we’ll stick to the virus name, although it’s not its textbook definition) that mimics the behavior of legitimate antivirus software. The purpose is to convince you that your computer has a virus/security problem so that you pay money to have these viruses removed. The trick is that Wireshark Antivirus is the actual infection in your computer and that instead of giving your credit card number to these criminals, the only thing you need to do is remove Wireshark Antivirus using the removal guide below.


Wireshark Antivirus gets on your computer when you download an infected image, browsed infected porn sites and such. Once installed, the virus will be programmed to start when your Windows OS loads. Once on your computer, it will perform a fake virus scan and tell you that your computer is infected. Then the Wireshark Antivirus tells you that you have to pay for the full version to remove these infections. Remember that Wireshark Antivirus is actually the virus itself and that you shouldn’t pay that money under any circumstances.

How To Remove Wireshack- Steps

Ok, so now that you have a brief idea of what Wireshark Antivirus is, let’s learn how to remove Wireshark Antivirus completely free, by following our simple removal guide.

Please remember that each step is equally important.

Step 1. Because Wireshark Antivirus might mess with your Internet connection, you might have to download the tools we are going to use on another computer and then transfer them to the desktop of the infected computer using a CD/DVD or an USB stick.

The files we are going to need are:

Malwarebytes Anti-Malware – MBAM will scan your computer for any viruses and remove them

iExplore.exe – A great tool developed by Lawrence Abrams. It will stop the Wireshark Antivirus process (close it for good), so we can remove it.

Step 2. Once you transferred the files, it’s time to close Wireshark Antivirus so that we can remove it. Because Wireshark Antivirus will not go away easily, we are going to use eXplore.exe to kill the process. Run eXplore.exe until Wireshark Antivirus is gone. If it doesn’t work the first time, try running it multiple times simultaneously. It might not work at first, but keep going at it, as the WiresharkAntivirus virus will eventually be closed.

Step 3. Now that we have closed Wireshark Antivirus, we should remove it (and any related files). For this, we will use Malwarebytes’ Anti-Malware. Run the setup from the desktop, and proceed with the standard MBAM install settings (remember to check the “automatically update MBAM” box).

Step 4. When MBAM is up and running, go to “Scanner” and perform a full scan of your computer. Don’t worry, the scan is supposed to take quite a while, but that’s a price you should be willing to pay. When the scan is complete, check all the infections MBAM detected and select “remove selected”. Now wait for MBAM to remove WiresharkAntivirus (as well as other infections it detected) from your computer.

Step 5. Now I would suggest you use CCleaner to remove all temporary files from your computer. This is a trick I use each time I’m trying to remove a virus from an infected computer. Here is a tutorial on how to do that.

Step 6 (OPTIONAL): If you really want to be sure you got the little bugger out for good, I recommend that you use another malware removal tool, called SuperAntiSpyware. You can download the free edition here. Just install it and perform a scan. If it catches anything, remove it.

At this point, you should have removed Wireshark Antivirus and any related files from your computer. Leave a comment if anything went wrong and I’ll get back to you as soon as possible.

Source: free-pc-guides.com

USB Malware Flaw Hits Windows

A new type of malware is targeting Microsoft operating systems via infected USB drives.

The newly discovered Stuxnet malware uses a flaw in Windows to infect PCs using shortcut icons, Microsoft said.

"The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the user clicks the displayed icon of a specially crafted shortcut," Microsoft said in a security warning. "This vulnerability is most likely to be exploited through removable drives."

"Currently, we have seen only limited, targeted attacks on this vulnerability," Microsoft added, but said it expects other malware writers to start using the USB shortcut flaw too.

Security firm Trend Micro agreed. "Despite the numerous potential techniques for proliferation being offered by the web, USB malware continue to be distributed by cybercriminals, which only proves their effectiveness," JM Hipolito wrote on the Trend Micro blog.

The flaw affects Windows OSes from XP to 7, as well as Server 2003 and 2008. Microsoft has issued a pair of workarounds, advising users to disable the icon for shortcuts or the WebClient service, which it sees as the "most likely remote attack vector."


Source: pcpro.co.uk

Tips and tricks Using Antivirus

A computer virus is a frightening specter for computer users, some time ago I had written about what a computer virus. To overcome the problem of computer viruses requires a reliable antivirus, there are many antivirus software that you can use to eradicate a virus that attacks your pc / notebook you. Before Virus Scan you can have look at these tips.

Among the many anti-viruses, there are 10 best antiviruses which can eradicate the virus that attacks your computer. But the use of antivirus also may not arbitrarily, in order to work effectively. There are a few tips you can use to secure your computer safe from computer viruses. Although not able to counteract the virus 100% but it can minimize the entry of virus into your computer. Here are tips and tricks to use antivirus:
  • Avoid the use of two or more antivirus simultaneously, except if it is needed.
  • Check the Virus Vault (quarantine viruses) regularly and if it is too much of its contents, delete the real virus or a file that is not used anymore. If many files of the same size, the possibility that the virus, so deleted it or leave one alone.
  • Always activate the Resident Shield / Guard, because it is always monitoring these files at any time.
  • Activate the facility Report, and save his report on the folders that are easy to find.

In addition there are a few tips and tricks to streamline the process of virus scan, virus scan on the computer process can take quite some time, even hours if the files you very much, then, could you do the following things:

  • Non-enable (disabled) scans Archive (a compressed file, like zip, rar, cab, etc.), but had plenty of time to scan for viruses. Because if this is enabled scanning process can be very long. Also if there is virus inside zip / archive the original files are not harmful in it not running.
  • Avoid setting to simply delete / heal / remove files that are considered as a virus, better choose Quarantine (Move to Quarantine) or rename. Unless already sure that the file was a virus, not a document or program that is infected with a virus.
  • If there is an option scan certain files / options (smart extensions) and all files, then better choose smart extensions, scans will be much faster.
  • In the Scheduler scans (Scan automatically every time), be sure to set the times when the computer is rarely used or in the off (non enabled / disabled) only and scan in doing it manually. Because sometimes we do not know that the antivirus is doing a scan that can take very long, so the work computer is very slow.
  • If the scan is in the process, you should not run other programs, let alone the weight. Also be sure to turn off the screensaver when the computer was left out.
For you who rarely used internet an computer (offline), there are some additional tips and tricks that you need to do, namely:
  • Download virus definition (update) once a week, more often is better.
  • If any facility or Email Anti Spyware Scanner, or other facilities associated with an Internet connection, just switch off to reduce memory and CPU usage. If the computer is sometimes connected to the Internet, spyware scans can be done manually, every few days or once a week.
  • Turn off Auto Update facility, updates done manually, by downloading virus database or when connecting to the Internet only.

If you often connect to the Internet (online), there are a few tips you can use antivirus settings to counteract the virus infecting your computer, including:

  • Enable Auto Update, once a day is enough, more is often better.
  • If there is an email facility, or anti-spyware scanner, preferably activated, unless use of other anti-spyware programs.

 
©2009 Antivirus Support | by TNB