Showing posts with label virus removal. Show all posts
Showing posts with label virus removal. Show all posts

How to remove Wireshark Antivirus (Virus Removal Tutorial)

The Wireshark Antivirus is a rogue anti-spyware program (we’ll stick to the virus name, although it’s not its textbook definition) that mimics the behavior of legitimate antivirus software. The purpose is to convince you that your computer has a virus/security problem so that you pay money to have these viruses removed. The trick is that Wireshark Antivirus is the actual infection in your computer and that instead of giving your credit card number to these criminals, the only thing you need to do is remove Wireshark Antivirus using the removal guide below.


Wireshark Antivirus gets on your computer when you download an infected image, browsed infected porn sites and such. Once installed, the virus will be programmed to start when your Windows OS loads. Once on your computer, it will perform a fake virus scan and tell you that your computer is infected. Then the Wireshark Antivirus tells you that you have to pay for the full version to remove these infections. Remember that Wireshark Antivirus is actually the virus itself and that you shouldn’t pay that money under any circumstances.

How To Remove Wireshack- Steps

Ok, so now that you have a brief idea of what Wireshark Antivirus is, let’s learn how to remove Wireshark Antivirus completely free, by following our simple removal guide.

Please remember that each step is equally important.

Step 1. Because Wireshark Antivirus might mess with your Internet connection, you might have to download the tools we are going to use on another computer and then transfer them to the desktop of the infected computer using a CD/DVD or an USB stick.

The files we are going to need are:

Malwarebytes Anti-Malware – MBAM will scan your computer for any viruses and remove them

iExplore.exe – A great tool developed by Lawrence Abrams. It will stop the Wireshark Antivirus process (close it for good), so we can remove it.

Step 2. Once you transferred the files, it’s time to close Wireshark Antivirus so that we can remove it. Because Wireshark Antivirus will not go away easily, we are going to use eXplore.exe to kill the process. Run eXplore.exe until Wireshark Antivirus is gone. If it doesn’t work the first time, try running it multiple times simultaneously. It might not work at first, but keep going at it, as the WiresharkAntivirus virus will eventually be closed.

Step 3. Now that we have closed Wireshark Antivirus, we should remove it (and any related files). For this, we will use Malwarebytes’ Anti-Malware. Run the setup from the desktop, and proceed with the standard MBAM install settings (remember to check the “automatically update MBAM” box).

Step 4. When MBAM is up and running, go to “Scanner” and perform a full scan of your computer. Don’t worry, the scan is supposed to take quite a while, but that’s a price you should be willing to pay. When the scan is complete, check all the infections MBAM detected and select “remove selected”. Now wait for MBAM to remove WiresharkAntivirus (as well as other infections it detected) from your computer.

Step 5. Now I would suggest you use CCleaner to remove all temporary files from your computer. This is a trick I use each time I’m trying to remove a virus from an infected computer. Here is a tutorial on how to do that.

Step 6 (OPTIONAL): If you really want to be sure you got the little bugger out for good, I recommend that you use another malware removal tool, called SuperAntiSpyware. You can download the free edition here. Just install it and perform a scan. If it catches anything, remove it.

At this point, you should have removed Wireshark Antivirus and any related files from your computer. Leave a comment if anything went wrong and I’ll get back to you as soon as possible.

Source: free-pc-guides.com

What is Antivirus 2010?

This post provides information about Antivirus 2010 and give some virus removal tips for protect your computer. Antivirus 2010 is a very insistent that you want to download yourself and protect your computer.

Do not fall for it. Antivirus 2010 will not protect you against malware. In fact, it is malware. It is a rogue program pretending to protect against infection, while infecting your computer.

If you receive a pop-up warning of danger and it is suggested to install this wonderful program, click Yes and no, click No, no. Close the window.

And if you think you became infected, download, install and run the free version of SuperAntiSpyware any Malabytes and Anti-Malware.

How to Recover from Multiple Virus Infestations

Have a desktop collecting dust, because it seems like it has enough viruses to contaminate the entire internet? Think the PC won't turn on anymore?

We're going to go through a few steps to get that once reliable desktop or laptop back on its feet again.

Turn on the computer; continuously press F8 during boot-up.

You will recieve a "Safe Mode" selection screen.

Choose just the "Safe Mode" option and press enter.

Once windows boots up, sign in as Administrator or your own account (administrator is preferred)

Go to start > run.. (search bar if in Vista)

Type "MSCONFIG" and press enter.

This will bring up the Microsoft Configuration Utility.


Go to the Services tab.

Check the box that says "Hide All Microsoft Services"

Click Disable All.

Go to the Startup tab and disable everything (uncheck all items).

Click Apply, Ok, and Restart.

Your computer will now boot straight into a clean run of Windows.

Once booted up, log in and open Internet explorer (or Mozilla Firefox if you have it)

Go to http:\\Malwarebytes.org and download MalwareBytes Free.

Install it, let it update, and run a scan. Remove anything that is found.

Close MalwareBytes.


Download Spybot: Search and Destroy from http://spybot.com

Install it, run a scan, remove all items found.

Click Mode > advanced from the top toolbar.

Click on tools in bottom left, then in the right-pane check ActiveX and BHO's

On the left, under tools, Click ActiveX

Delete all of the items listed to the right.

On the left, under tools, Click BHO's

Delete all of the items listed to the right.

Click Spybot S&D from top left, and click immunize.

Then click Immunize all in the mid-top.

To increase effectiveness follow the tips below and check the linked anti virus supprot expert for how to make your PC like-new.

How to Delete the NLSDL.EXE Virus

The NLSDL.exe virus, alternatively knows as the worm.Win32.VB.ck virus, pretends to be a critical Microsoft Windows file. The fake NLSDL.exe will open when your computer boots up. The file then will connect to a remote server and attempt to download malicious files. To remove virus from your system, you will need to delete several files it copies to your computer's

Navigate to the AVG website if you don't already have an antivirus utility installed on your computer. Download and run the installation file for the antivirus utility.

Restart your computer and wait for the logo of your computer's manufacturer to appear on the monitor. Press the F8 key to bring up a new menu.

Scroll down to the "Safe Mode" option and press Enter. Bring up the Start menu once the operating system finishes loading. Click on the "Search" option.

Type the phrase "6d4e036f-cb53-4ebb-9c47-fdc78b67be70.exe" into the Windows Vista search box. Right-click on the file and choose the "Delete" option. Search for and delete the "worm2007.exe" file.

Search for "NLSDL.exe." Look through the files that appear and find the version that is not in the Windows folder. The fake version will be installed into a random folder other than Windows. Right-click on the file and delete it.

Search for "regedit" and double-click the registry editor's icon when it appears in the search results. Click on the folder HKEY_CURRENT_USER.

Navigate through the subfolders Software, Yahoo and Pager to get to View. Right-click and delete the folders YMSGR_Launchcast and YMSGR_buzz.

Close the registry editor's window. Make sure your antivirus definitions are up to date and run a full system scan.

After the virus scan is completed, restart your computer.

Why Antivirus Software's Are Necessary

Antivirus software are very necessary for our computer to secure and protect our very important and costly personal data from virus or other malwares. Due the continuous improvement in the field of the computer and internet technologies on one side these developments helped in making this world as glsonalobal village, where one per can contact to the another person sitting in any part of the world and also in the several other fields of the life from Business to the Education . But in spite of all these developments it also makes us prone to the several sort of threats For example Virus Trojan Spam email and worms.

If you want to protect your computer then you should install antivirus software program, there are many anti-virus software's available in market these days. Viruses are small part of the malicious code that protects you. Anti-virus has expanded to include worms, Trojans, viruses, jokes and hoaxes and even spyware and adware. If you're anti-virus product doesn't detect and block spyware you can try a product like Adware Pro which will protect your system from spyware or adware.

This anti-virus software's scans and detects the malicious programs in the computer. But we must keep one thing in mind that installing the anti-virus programe does not mean that our computer data is safe from any sort of threat as these computer threats are released in the Internet on the daily basis. So to be upgraded against all these new threats we should have a continuous update of our anti-virus . The updation process adds the new virus definition to the Antivirus software which makes the anti-virus to detect the new virus or others threats and delete them from the computer.

For example recently a worm called as the Conflicker was released on the Internet it uses the svchost.exe file of the windows based computers to attack. but this worm is not able to cause much of damage as all the antivirus software's companies has released the updates for this worm and Microsoft also released the patch to protect the computer against this So to be safe and secure against all the Internet threats we should use good antivirus software's and to protect our data from all the latest threats we should update the antivirus software at least once in weak.

After installing antivirus software update the antivirus software and you have to scan your system with Antivirus software, you can schedule the scan as you want to given time you can manually scan your system to detect and remove spyware. There are free software available on net like Malware Byte, Spybot, Super Anti Spyware, Trojan Remover etc. Follow these steps to keep your computer protect from spyware, malware and viruses.

Source: http://EzineArticles.com/?Why-Antivirus-Softwares-Are-Necessary&id=2477655

Autorun Virus Removal - How to Pull Out Your Computer System From Autorun Virus

Autorun virus, as it signifies exploits the Auto run feature in Windows Operating System, which is misused to move programs stored in extractable media similar the DVDs, CD ROMs, USB Devices, and Storage Sticks.

The Auto run virus is a Windows PE EXE record that spreads itself on a machine by making duplex copies of autorun.inf files on a computer system. Each second you artifact a removable media or backup move your drives in Windows Soul, the virus files signaling executing. The Auto run virus creates a plenty enter called logon.bat and modifies the scheme registry to secure that each second you execute your system the virus is launched automatically.

The virus may clandestinely link to a leering website and set a rootkit on your machine. The rootkit may put a key logger to steal your own assemblage much as statement lottery, usernames, passwords accomplishment roster message, ethnic precaution, and other radio sensitive information. It is hence, highly crucial that you disappear autorun virus from your machine as soon as doable.

The autorun virus can be removed both manually and by using any autorun virus separation slave. The practice cremation time of the virus depends on the intensity of the attachment of the virus to the system. To get rid of the virus manually, you can perform these computer repair steps:

1. End the auto run knowledge finished Task Handler.
2. Revive the grouping in uninjured mode and outside the dictation.
3. Identify all grouping and .exe files on the C (or your Operating System actuation).
4. Wound invisible, scheme, and see exclusive attributes for autorun.inf and ntdelect.com (not ntdetect.com)
5. Remove both the files.
6. Restate these steps for all the drives on your machine.
7. Examine for kavo.exe in C:\windows\system32\ and withdraw it.
8. Outside registry editor and remove all the entries of kavo.exe under:
HKEY_LOCAL_MACHINE\SOFTWARE
HKEY_CURRENT_USER\SOFTWARE

The drill separation of autorun virus is recommended only to computer experts because removing or editing windows registry can crusade intense casualty to your method if you delete the wrongheaded files.

Want to mash those nettlesome pop up ads and get your PC gushing equivalent new? Get the issue fixed with some computer support today.


Source: http://EzineArticles.com/?Autorun-Virus-Removal---How-to-Pull-Out-Your-Computer-System-From-Autorun-Virus&id=2523476

How to uninstall Spyware Doctor

This post provides spyware support step by step method to uninstall Spyware Doctor.

Follow the steps mention below to uninstall Spyware Doctor 5 and 6:

Ensure that you have fully exited the application. To fully exit from Spyware Doctor please right click on the Spyware Doctor icon in the notification area (next to the clock on the Windows taskbar) and select Shutdown from the menu that appears. Please also close any instances of Internet Explorer or other browsers.
Perform an uninstall of Spyware Doctor from: Start > Programs > Spyware Doctor > Uninstall Spyware Doctor.
Make sure that the Spyware Doctor folder (which by default would be under 'C:\Program Files') no longer exists. If the 'Spyware Doctor' folder still exists, delete the folder.
Spyware Doctor 4:

Right click on the Spyware Doctor icon (if it exists) in the notification area (next to the clock on the Windows taskbar) and select Exit from the menu that appears.
Perform an uninstall of Spyware Doctor from: Start > Programs > Spyware Doctor > Uninstall Spyware Doctor.
Make sure that the Spyware Doctor folder (which by default would be under 'C:\Program Files') no longer exists. If the 'Spyware Doctor' folder still exists, please delete the folder.

Download Norton AntiVirus Virus Definitions May 08, 2009

Norton AntiVirus Virus Definitions description Contains the latest free virus databases for Norton AntiVirus Virus (NAV)

Signature file updates ensure that your PC is protected from the latest viruses. It is very important to make sure that you have the latest signature on your PC.

As new threats emerge, Symantec immediately builds new Virus Definitions Updates and makes them available for download.

Note: The i32 Intelligent Updater package cannot be used to update Symantec AntiVirus Corporate Edition 8.0, 9.0, or 10.0 servers or Norton AntiVirus Corporate Edition 7.6 servers, but can be used to update Corporate Edition clients. The x86 Intelligent Updater package can be used to update Corporate Edition clients and servers.

Which virus definition file do you need?

External Mirror 1 & External Mirror 2 - Supports the following versions of Symantec antivirus software:
· Norton AntiVirus 2003 Professional Edition
· Norton AntiVirus 2003 for Windows 98/Me/2000/XP Home/XP Pro
· Norton AntiVirus 2004 Professional Edition
· Norton AntiVirus 2004 for Windows 98/Me/2000/XP Home/XP Pro
· Norton AntiVirus 2005 for Windows 98/Me/2000/XP Home/XP Pro
· Norton AntiVirus 2006 for Windows 2000/XP Home/XP Pro
· Norton AntiVirus 2007 for Windows XP Home/XP Pro/Vista
· Norton AntiVirus for Microsoft Exchange (Intel)
· Norton SystemWorks (all versions)
· Norton Utilities for Windows 95/98 (all versions)
· Symantec AntiVirus 3.0 for CacheFlow Security Gateway
· Symantec AntiVirus 3.0 for Inktomi Traffic Edge
· Symantec AntiVirus 3.0 for NetApp Filer/NetCache
· Symantec AntiVirus 8.0 Corporate Edition Client
· Symantec AntiVirus 8.1 Corporate Edition Client
· Symantec AntiVirus 9.0 Corporate Edition Client
· Symantec AntiVirus 10.0 Corporate Edition Client
· Symantec AntiVirus 10.1 Corporate Edition Client
· Symantec AntiVirus 10.2 Corporate Edition Client
· Symantec Mail Security for Domino 4.0
· Symantec Mail Security for Domino 5.0

External Mirror 3 & External Mirror 4 - Supports the following versions of Symantec antivirus software:
· Norton AntiVirus 2008 for Windows XP Home/XP Pro/Vista
· Norton Internet Security 2008 for Windows XP Home/XP Pro/Vista

External Mirror 5 & External Mirror 6 - Supports the following versions of Symantec antivirus software:
· Norton AntiVirus 2003 Professional Edition
· Norton AntiVirus 2003 for Windows 98/Me/2000/XP Home/XP Pro
· Norton AntiVirus 2004 Professional Edition
· Norton AntiVirus 2004 for Windows 98/Me/2000/XP Home/XP Pro
· Norton AntiVirus 2005 for Windows 98/Me/2000/XP Home/XP Pro
· Norton AntiVirus 2006 for Windows 2000/XP Home/XP Pro
· Norton AntiVirus 2007 for Windows XP Home/XP Pro/Vista
· Norton AntiVirus for Microsoft Exchange (Intel)
· Symantec AntiVirus 3.0 CacheFlow Security Gateway
· Symantec AntiVirus 3.0 for Inktomi Traffic Edge
· Symantec AntiVirus 3.0 for NetApp Filer/NetCache
· Symantec AntiVirus 8.01 (Build 457 and above) Corporate Edition Client
· Symantec AntiVirus 8.01 (any Build prior to 457) Corporate Edition Client or Server
· Symantec AntiVirus 8.1 Corporate Edition Client
· Symantec AntiVirus 9.0 Corporate Edition Client
· Symantec AntiVirus 10.0 Corporate Edition Client
· Symantec AntiVirus 10.1 Corporate Edition Client
· Symantec AntiVirus 10.2 Corporate Edition Client
· Symantec AntiVirus for Bluecoat Security Gateway for Windows 2000 Server/2003 Server
· Symantec AntiVirus for Clearswift MIMESweeper for Windows 2000 Server/2003 Server
· Symantec AntiVirus for Microsoft ISA Server for Windows 2000 Server/2003 Server
· Symantec Mail Security for Domino 4.0
· Symantec Mail Security for Domino 5.0
· Symantec Mail Security for Microsoft Exchange Server 4.x
· Symantec Mail Security for Microsoft Exchange 4.5
· Symantec Mail Security for SMTP v 4.x
· Symantec Web Security 3.0 for Windows
· Symantec AntiVirus Scan Engine for Windows

This all inclusive updater will update all of the products listed above. This is useful for updating multiple machines and products with one single package.

External Mirror 7 & External Mirror 8 - Supports the following versions of Symantec antivirus software for 64-bit platforms:
· Norton AntiVirus 2008 for Windows XP/Vista for 64-bit OS only
· Norton Internet Security 2008 for Windows XP/Vista for 64-bit OS only

External Mirror 9 & External Mirror 10 - Supports the following versions of Symantec antivirus software for 64-bit platforms:
· Symantec AntiVirus 8.1 Corporate Edition Client for 64-bit OS only
· Symantec AntiVirus 9.0 Corporate Edition Client for 64-bit OS only
· Symantec AntiVirus 10.0 Corporate Edition Client for 64-bit OS only
· Symantec AntiVirus 10.1 Corporate Edition Client for 64-bit OS only
· Symantec AntiVirus 10.2 Corporate Edition Client for 64-bit OS only

More Related Search
Malware: Another Pandemic Of Which You Should Be Aware Windows 7 RC contain Trojan Conficker Computer Virus Poses New Threat Install Antivirus How to download AVG Removal Utility

Windows 7 RC contain Trojan

Pirated copies of Windows 7 Release Candidate (RC) on file-sharing sites contain malware, according to users who have downloaded the upgrade.

Windows 7 RC, which Microsoft Corp. will officialy launch today, leaked two weeks ago, with copies first appearing on BitTorrent tracking sites on April 24.

Some of the pirated builds include a Trojan horse, numerous users said in message forums and in comments on BitTorrent sites such as Mininova.org.

"Just a warning for anyone downloading the new RC builds of windows 7. Quiet [sic] a lot of the downloads have a trojan inbedded [sic] in the setup EXE," said someone identified as Frank Fontaine on a Neowin.net discussion thread. "The Setup EXE is actually a container, it appears to be a self-extracting EXE. There are 2 files inside, Setup.exe and codec.exe."

Fontaine's antivirus software identified the "codec.exe" file as a generic Trojan.

"Suspicious codec.exe!" reported someone labeled as "UltimateGTR" on Mininova, commenting on one of the 32-bit builds.

Another Mininova commenter, "WuNgUn," identified the malware as the "Falder" Trojan, which downloads fake security software, dubbed "scareware," to PCs and installs a rootkit to hide from legitimate antivirus products.

More
Download windows 7
Antivirus Support for Windows 7
System requirment for Windows 7
Windows 7 Release Candidate: Download instructions

AutoRun offers no chance to worms with Windows 7

Microsoft Windows 7 has included autorun function to protect your pc from Worm. You no need to install anti-virus to extra protection.

The continuing circulation of the Conficker worm has prompted Microsoft to make changes to the AutoRun function in the Windows 7 release candidate, due for release tomorrow. As well as exploiting vulnerabilities in Windows and guessing simple passwords, Conficker also penetrates computers by using the Windows AutoRun function, which allows programs to be run automatically when a USB flash drive is connected or CD inserted.

Conficker programmers have also taken into account the behaviour of AutoRun under Vista, where the AutoRun function requires confirmation from the user. After connecting an infected USB flash drive, the AutoRun dialogue box shows a fake icon to fool users into thinking that clicking on it will open a folder. Instead, it runs the worm. Suspicions should be raised by the apparent duplication of the menu item for opening the folder, but nevertheless this trick has clearly been, and remains, fairly effective.

To stop users from falling into this trap in future, Microsoft has completely removed the option of running a program from the dialogue box for writeable media such as USB sticks, memory cards and external drives. The change does not, however, apply to CDs and DVDs. Testing will be required to determine what this means for U3 USB drives, which emulate a CD-ROM.

See also On this site
How Do You Remove Conficker Worm Files?
How to remove Conficker Worm registry keys
Online Virus Removal
Variant of Conficker worm

Conficker Computer Virus Poses New Threat

The Conficker worm computer virus updated itself late Wednesday, bringing a new threat to the millions of PCs currently infected by it.

The discovery was made by Internet security company Trend Micro, who stated in a press release that the ybercriminals behind the notorious Conficker worm may finally be gearing up for more serious attacks.ԍ

As many as 12 million computers could be infected by the worm. Microsoft is offering a $250,000 bounty for its creator.

The worm can be used to steal data from computers. It can also control infected computers to be used in what is called a otnet.The army of computers in the botnet can then be used by a hacker to launch cyberattacks against anything from Web sites to government computer networks.

Such an attack was launched against the U.S. Pentagon in 2007 by Chinese hackers. The Pentagon was forced to temporarily shut down its network and lost an unknown amount of information.

The activation of the Conficker worm came the same day (Wednesday) as reports of cyber spies infiltrating the U.S. power grid. The Wall Street Journal reported that Chinese and Russian spies were behind it, leaving software in the system that could shut down the U.S. electric grid.

Canadian researchers also discovered late last month the Chinese ԇhostNetԗa spyware system that is being used to monitor and steal documents from 1,295 computers in 103 countries. Among their targets were the Dalai Lama, the media, and hundreds of government and private offices.

Whether the Conficker worm has any connection to the other attacks is yet to be known.

On Oct. 26, 2008, just three days after the discovery of the worm was announced by Microsoft, Chinese hackers created a toolkit that would allow anyone to exploit the system gap. The kit was originally sold for $37.80 but was later made available for free download.

The surprisingly rapid spread of the Conficker worm is attributed to its ability to pass between computers on USB memory sticks. It is also able to invade computer networks. The worm spreads through vulnerabilities in Microsoftӳ operating system, Windowsءlthough an update is now available to repair the vulnerabilities.

The update of the worm was originally suspected to be taking place on April 1. According to Trend Micro the new variant of the worm, known as WORM_DOWNAD.E, runs using a random file name and random service name. It updated itself through P2P communications. The new file was discovered in the Windows Temp folder.

Its effects are yet to be known.

Strangely, according to a BBC report, researchers from the Symantec internet security company said the new update has instructions for the worm to remove virus itself on May 3, 2009, yet a gap in the machine will remain open so that its creators can still control the compromised PC

How antivirus software and System Restore work together

With System Restore in Windows XP, you can restore your computer to a previous state, and you do not lose private data files (such as Word documents, graphic files, and e-mail). System Restore actively monitors computer file changes and some program file changes to record or store earlier versions before the changes occurred. You do not have to take computer snapshots because System Restore automatically creates identifiable restore points that you can use to revert to a previous time. Restore points are created when significant computer events occur (such as the installation of a program or a driver) and periodically (each day).

To help protect critical computer and program files, System Restore monitors, records, and in some cases copies these files before they are modified. For example, when a process or a program (such as an upgrade, an inadvertent user change, a driver installation, or a virus) modifies a critical computer file or program file, System Restore records and saves a copy of the file before the change occurs. If a problem occurs, a restore operation can replace files with previously saved versions of those files. Antivirus support programs use auto-detection or scanning mechanism to monitor critical and personal files on the computer for signs of infectivity. The antivirus program then takes action to clean, remove, or quarantine (isolate) files that known viruses have infected. System Restore also tracks an antivirus program when it modifies (cleans), moves, or deletes a monitored, critical, computer or program file.

During a restoration, an active antivirus program scans for infected files. If the antivirus program detects any infected files, the antivirus program tries to modify, move, or delete the infected files. If the antivirus program successfully cleans the infected files, System Restore restores the cleaned files. However, if the antivirus software cannot clean a file, the antivirus software deletes or quarantines the file. As a result, the restoration does not work because these actions to the file cause an inconsistent restoration state. As a result, System Restore reverts to the state immediately before the restoration.

Signature files for antivirus programs are updated as viruses become known. As a result, a restoration that did not work several days ago might succeed after the antivirus program is updated. However, if you undo and retry a restoration to a point that succeeded before, the restoration may not work if a new signature or definition detects a virus that the antivirus program cannot clean on a backed-up file.

Easy Steps to Protect Your Computer From Conficker Warm

The “Conficker” worm / virus also known as “Downadup” infection, is actually a virus code programmed in such a way that it can infect your computer and spread itself to other computers across a network automatically, without human interaction.This post provide antivirus support for remove conficker warm from your computer in 5 easy steps.

Step1
If you have a Mac or a Linux machine, breath a sigh of relief; you don't have the right code to be infected. If you're running Windows as your platform of choice, listen up, because this is critical; time is of the essence. You may experience any number of symptoms which are common like loss of Internet connection and loss of local network connection and which are less common like Automatic updates and Microsoft services being disabled.

Step2
Update your anti-virus software. Disconnect your computer from the Internet and scan your system, if you believe you are already infected. To stop the spread of the worm, see step 3. If possible, back up your data ASAP.

Step3
Disable Auto-play in Windows. For Vista: Start > Control Panel > click Play CD's or other media automatically > uncheck Use Autoplay for all media and devices. > click OK. For XP: Start > Run Enter GPEDIT.MSC >
The Group Policy dialogue box will appear. On left panel, double-click Computer Configuration > Administrative Templates > System > Double-click the Turn autoplay off option. The reason behind disabling autoplay is that Conficker can be spread through USB flash drives infected with code that starts on auto-play when the infected drive is inserted into the computer. Disabling auto-play is a good way to ensure against any malicious code automatically gaining access to your computer.

Step4
If you have the Conficker worm, DO NOT DO A SYSTEM RESTORE. Like most malware, Conficker hangs in the restore points and reactivates when you do a system restore. Utilize a decent anti-virus solution such as AVG, Avast!, or Malwarebyte's Anti-Malware. Again, disconnecting your computer from the Internet is critical to prevent the spread of the worm or the continued use of your computer by the worm for devious purposes. Windows Malicious Software Removal Tool can be used to detect and remove the Conficker worm as an option as well.

Step5
Regardless if you are on a network or a standalone computer, download the Microsoft update patch KB958644 (MS08-067) This will fix a security vulnerability that is exploited by the Conficker worm. For more information on how to exactly deploy this update across a network as well as additional information on Conficker, please visit the link in the Resources section.

BEWARE OF VIRUSES & PARASITES

By now, most computer users know that they have to protect against viruses. You need a good antivirus support program running on your computer in real time, monitoring and checking as files are accessed, as well as running periodic scans of all files. You need to use an up-to-date virus definition file with this AV program (sometimes these are updated almost every day, so automated updating is preferable). The virus protection on your computer should be so solid that there is rarely any doubt that you are virus-free — the only room for doubt being whether a new virus snuck in before your antivirus software’s manufacturer had a definition file that would catch it. If suspicious, run your AV program to check the system as part of zeroing in on a problem that suddenly develops on your computer. You can also try one or more of the free online virus scanners listed on my Parasites & Other Computer Security Issues page.

But there are also nonviral invaders that have become as big a problem as viruses. In fact (perhaps because people are less aware of these and less mindful of protecting themselves), these parasites may be an even greater risk to your computer’s proper running. Adware, spyware, browser hijackers, automatic diallers, and other forms of nonviral malware — some intentionally if misguidedly installed by the user, some foisted on you without your awareness — are, at least in a few cases, as destructive.

And, since they often are badly written, they commonly announce themselves unintentionally by breaking some functionality on the computer. Therefore, checking for these is an important early step in troubleshooting computer problems, especially if the problems appear suddenly. If there is a serious browser or Windows Explorer/My Computer problem not related to a bad or damaged browser install, failing hardware, or user error, 90% of the time the problem will be the result of one of these parasites. Because Internet Explorer is integrated into the kernel of all Windows versions after Win95, these “browser problems” can manifest as general performance degradation or error conditions in the Windows shell. If you’ve ruled out the obvious in troubleshooting browser failures, the eruption of many error messages, inability to launch programs, or sudden (in contrast to gradual) serious slowing of your computer, checking for parasites should probably be your next diagnostic step.

For an onderly seven-step approach for identifying and removing these parasitic invaders, see Quick Fix Protocol page.

Several of these parasites are intentionally added to the computer by the user because the program looks like a cool toy. For example, Hotbar is a popular browser add-on that causes big problems on most computers. Many people install Gator (now renamed Claria) to manage online passwords. People install the insidious and pernicious IEPlugin to get “faster, smarter web browsing,” and live to regret it. And so forth. Other parasites are snuck onto your computer often without your knowledge. An important early step in all troubleshooting of Windows problems, therefore, is the isolation and removal of such parasites.

How to detect boot sector virus

This post provide further information about how to detect and remove virus from boot sector. Boot-sector viruses infect computer systems by copying code either to the boot sector on a floppy disk or the partition table on a hard disk. During startup, the virus is loaded into memory. Once in memory, the virus will infect any non-infected disks accessed by the system. Examples of boot- sector viruses are Michelangelo and Stoned.

Boot-sector viruses are spread to computer systems by booting, or attempting to boot, from an infected floppy disk. Even if the disk does not contain the MS-DOS system files needed to successfully boot, an attempt to boot from an infected disk will load the virus into memory. The virus hooks itself into memory as if it were a device driver. The virus moves the Interrupt 12 return, allowing itself to remain in memory even after a warm boot. The virus will then infect the first hard disk in the system.

Because the virus moves the Interrupt 12 return, the MS-DOS system memory will be 2K (2048 bytes) smaller than normal. This can be verified by running the MS-DOS CHKDSK command.

For example, if your system has 640K, CHKDSK will report:
655360 Total Bytes Memory

If the system is infected with a boot-sector virus, CHKDSK will report:
653312 Total Bytes Memory

Some systems use 1K (1024 bytes) of memory for the BIOS. Other systems use 2K (2048 bytes) of memory for shadow RAM. You must take this into account before CHKDSK can be used as an accurate measure of whether or not a system is infected with a virus. Please refer to the hardware manufacturer to see if the system uses part of the MS-DOS 640K of memory.

Once a system is infected with a boot-sector virus, any non-write-protected disk accessed by this system will become infected. For example, simply doing a DIR command on a floppy disk will cause the disk to become infected with the virus. Note: MS-DOS version 5.0 disks are shipped without a notch; therefore, they are write-protected. The chances of these disks containing a virus are close to none. The MS-DOS 5.0 disk files are compressed, so the actual file sizes are different. You can determine a compressed file by the underscore character (_) that is the last character of the filename extension. To expand a compressed file, use the EXPAND utility on Disk 5 (5.25-inch disk set) or Disk 3 (3.5-inch disk set).

 
©2009 Antivirus Support | by TNB