Remove Trojan

Your Ad Here

Thursday, September 11

10. Dr Watson PostMortem error :

Can you check to see if Dr Watson is configured as the default debugger?

In the registry, check:
HKEY_LOCAL_MACHINE\Software\Micros­ oft\WindowsNT\CurrentVersion \AeDebug

The key will be called: Debugger and the value will be something like: Drwtsn32 -p %ld -e %ld

If so, perhaps remove that key, and see if that solves the problem (if Dr Watson crashing is causing the lockup). If you are still gettin the lockup, then the problem is somewhere else (e.g. the original NJStar problem). Try uninstalling that application.

If you need to reinstall Dr Watson as your default debugger, run:
Drwtsn32 -i
at a command prompt

Labels: , ,

ClickThru.com Network!

9. Explorer.Exe Virus :

We've found multiple infections in a few machines over the years. It's known as the dlder.exe Trojan and it drops another "explorer.exe" file in a separate folder,
normally in 'C:\Windows\explorer\Explorer.exe'.

Please note that you have a legitimate original
"explorer.exe" in 'C:\Windows\explorer.exe'

It also drops a startup file in your registry so it will run silently at startup...normally
in your Local Machine Registry: [HKLM\SOFTWARE\games\Clicktilluwin]. However; we have also found
the Clicktilluwin entry in ‘HKCU’ over the past few months. That said, you should do a search find on your total
registry for the phrase 'Clicktilluwin'. Go to the link above and follow cexx.org's manual removal, then search your
regedit for the 'Clicktilluwin' reg-key and you should be fine.

Anytime that you have explorer.exe running over....say....25,000K to 30,000K in the
task manager, it's usually indicative of infection.

Labels: , , ,

ClickThru.com Network!

8. Killer.exe Virus :

If this virus infected in you computer, It will Disable the following …

Task Manager, Registry Editor, Folder Options, Run in start menu

And it will create exes like the icon of folders. If this virus is running it will use more than 50 % of your processor

Solution:
Go to google search page and type "Ravmon_Removal_Tool_3.2" then download it and run in normal mode.

it will take only few minutes to remove the virus,restart the computer now ur system is free from virus.

Labels: , , ,

ClickThru.com Network!

7. New Folder.exe Virus :

If this virus infected in you computer, It will Disable the following …

Task Manager, Registry Editor, Folder Options, Run in start menu

And it will create exes like the icon of folders. If this virus is running it will use more than 80 % of your processor


Manually remove it (new folder.exe Fix):

Delete File named svichossst.exe

[HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Policies\System]
“@”=[HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run]
“Yahoo Messengger”=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Shell”=”Explorer.exe “

Labels: , ,

ClickThru.com Network!

6. Funny UST Scandal.avi.exe Virus :

Some of the problems caused by this virus are ,

1. Show Hidden Files and Folders not working.
2. My Computer Drives open another explorer window.
3. When you run a program, just in 2 or 3 minutes the program dissappears
(Actually runs in background but you can not see its window in foreground).

Manual Removal

Caution : While the manual process is going on, do not open any My Computer drive.

1. Open up cmd by typing cmd in Start –> Run.

2. Type in cmd

taskkill /f /im smss.exe

taskkill /f /im killer.exe

3. The virus placed some files at the root of every drive so you need to clean them.

Repeat the following commands on cmd for all your drives (Here it is applied for C drive)

del /a:h /f c:\autorun.inf

del /a:h /f c:\smss.exe

del /a:h /f c:\funny ust scandal.avi.exe

4. Now you need to delete files in windows folder so type :

del /a:h /f c:\windows\killer.exe

del /a:h /f c:\windows\autorun.inf

del /a:h /f c:\windows\smss.exe

del /a:h /f c:\windows\funny ust scandal.exe

5. Now you need to delete one more file :

del /a:h /f “%userprofile%\Start Menu\Programs\Startup\lsass.exe”

6. Use PowerExes to delete startup entries like.

smss.exe

lsass.exe(if it does not remove then only uncheck it)

killer.exe

7. To restore Folder Option Settings Follow this page

Show Hidden Files And Folders Not Working

8. To Remove the virus from Flash Drive, Insert a flash drive cancel any Autoplay box.

Open cmd and type (Replace x by your usb drive letter)
del /a:h /f x:\autorun.inf

del /a:h /f x:\smss.exe

del /a:h /f x:\funny ust scandal.avi.exe

Labels: , ,

ClickThru.com Network!

5. smss.exe trojan Virus :

Some of the problems caused by this virus are :

1. Show Hidden Files and Folders not working.
2. My Computer Drives open another explorer window.
3. When you run a program, just in 2 or 3 minutes the program dissappears
(Actually runs in background but you can not see its window in foreground).
Solution:

http://www.webroot.com/consumer/downloads/ and click on, Spy Sweeper with AntiVirus NEW VERSION

download this file and run to remove the virus.

Labels: , , ,

ClickThru.com Network!

4. Autorun.inf virus :

Cause :
u cannot able to open any drive by double click.
no external drives can be opened by double clicking.

Solution:
1. Boot your system in Safemode
2. Open your flash drive via Command Prompt (do this via Start->Run->cmd.exe).
3. Change your logged drive to your USB flash drive
(e.g. if your flash drive is at drive E: then type E: on the command prompt then press enter)
4. Type ATTRIB -H -R -S AUTORUN.INF then press enter

After reboot, you can now access your drive.

Labels: , ,

ClickThru.com Network!

3. SVhost.exe Virus :

Close Port 445:

1. Start Registry Editor (Regedit.exe) by clicking Start menu, and then click the Run icon.

2. In the small box that Opens, type: regedit then click the OK button.
The Registry Editor will now have opened.
3. Locate the following key in the registry:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBT\Parameters
In the right-hand side of the window find an option called TransportBindName.
Double click that value, and then delete the default value,
thus giving it a blank value.

Close Port 135:

1. Then you must now navigate to the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
2. You will see there is a String Value called: EnableDCOM
Set the value to: N (it should currently be Y)
3. Close the Registry Editor. Shutdown and Restart your computer.

Well thats all :) but if you want you can disable NETbios.

Update: For whole those who are looking for an alternate solution to
fix this error please consider my latest post to Fix Generic Host Error

Labels: , , ,

ClickThru.com Network!

2. See Hidden Files Form Pen Drive Contains Virus :




Solution:


Follow the following steps:
1)Press Ctrl+Alt+del,and go to processes,end the explorer process.
2)Press new task,and type cmd to open command prompt
3)Go to c: (rootlevel) drive and type dir/ah,u can see a file autorun,
delete it using del filename /a/s/f/q,also see if any unknown exe file is present there delete that too.
4)No go to C:\Windows\System32,press dir /ah and look for the same exe file as hidden file,delete that and any .dll file with same name.Remeber the exe file name,it's the virus.
5)Go to every drive and repeat the same procedure.If any pendrives are connected,repeat the same procedure there too.
6)Go to regedit,by pressing newtask in the taskmgr,open Hkey_Local_Machine,then select software,now press edit and type the virus name and do search & delete.
7)Close regedit and open msconfig in taskmgr,select startup and unchk any file u think is associated with virus(generally not a system process)
8)Restart Explorer by typing explorer in newtask in taskmgr.

please follow the above steps for good solution.

Labels: , ,

ClickThru.com Network!

1. Shutdown virus :

Cause:

In the past day or so, many users have experienced a problem with Windows 2000 and Windows XP computers automatically shutting down and giving a message that there is a problem with the LSASS, or Local Security Authority Service (or a file named lsass.exe).

Solution:

1. Save any work you have open, and close all programs.
2. Click Start, Settings, Control Panel, Add or Remove Programs.
3. Scroll to the bottom of the list where you will see “Hot Fixes”. Check to see if you have the “hot fix” needed to combat this worm: KB835732
4.If you do NOT have this fix installed, visit www.microsoft.com/technet/security/bulletin/MS04-011.mspx
5. Select the path for the operating system you are using (Windows 2000 or Windows XP).
6. Download the patch for your operating system.
7. Find your download, double click it and let it install.
8. Reboot your machine after the installation.

Labels: , ,

ClickThru.com Network!
Clicky Web Analytics