Saturday, September 22, 2007

Dealing with VIRUS/WORMS


Been into battling survival mode these past weeks. Its hard to compile all the good (and the bad) stories Ive been into..

To Disable Temporarily:

just download this:
http://download.sysinternals.com/Files/ProcessExplorer.zip

When it turns red or e.g: Explorer.exe is under Explorer.exe ~ etc.. Kill It!

Or

Use this if you have difficulties in Process Explorer:

http://download.bleepingcomputer.com/spyware/KillBox.exe


Your Weapons

First, you have to enable those disabled applications, others are from gpedit.msc. To make things easy, just download the specific problem from this site:

http://www.kellys-korner-xp.com/xp_tweaks.htm
http://www.kellys-korner-xp.com/taskbarplus!.htm

after this, show all the hidden and system files. also show the file extension @ Folder Options


To Kill:

1. run "MSCONFIG" : Check out the "service"(check- hide all Microsoft services) and "Startup" tab
VIEWING ONLY DON'T MODIFY HERE


2. run "REGEDIT" :

go to:

HKEY_CURRENT_USER - SOFTWARE - MICROSOFT - WINDOWS - CURRENT - RUN

and

HKEY_LOCAL_MACHINE - SOFTWARE - MICROSOFT - WINDOWS - CURRENT - RUN

check the file first (properties) then delete if suspicious

also try 1 of these best Start Up Manager i found on net:
http://www.snapfiles.com/get/startuplist.html
http://www.mlin.net/StartupCPL.shtml
http://codestuff.mirrorz.com/

Sys-Internal's
http://download.sysinternals.com/Files/RootkitRevealer.zip
or
Some several Rootkit revealer found here:
http://www.antirootkit.com/software/


3. Scheduled Tasks:

delete if suspicious


4. STARTUP: Go to

C:\Documents and Settings\"USER"\Start Menu\Programs\Startup

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

Also clear the "Prefetch"

To increase the startup time of your applications, Windows pre-loads portions of programs in a folder called Prefetch. Since Windows will automatically repopulate the Prefetch folder with valid program entries, emptying the entire contents of the folder won’t do any harm(also to eliminate Prefetch infections). You can do this by going to:

C:\Windows\Prefetch

open the Prefetch folder, click on Edit, Select All, and then hit the Delete key


5. Search C:\Documents and Settings\ for all *.exe and check C:\windows\system32\ (susicious files - view by date)

Delete Explorer.exe and Lsass.exe if found under "C:\Documents and Settings\"

svchost.exe is the correct name, not svhost.exe

try to properties all the suspicious files to verify

all this* system files resides under windows folder only.


6. Here's the links to standalone virus/spyware removal tools from different vendors:-

Symantec
Sophos
BitDefender
F-Secure
Kaspersky
Grisoft AVG (go to Support - Download -Virus removal tool)
Panda (needs free registration)
Norman
McAfee


TO REMOVE JAY.EXE
download this:
http://www.filecrunch.com/file/~5yumvf



1 comment:

Anonymous said...

Yes undoubtedly, in some moments I can phrase that I jibe consent to with you, but you may be considering other options.
to the article there is stationary a question as you did in the fall issue of this solicitation www.google.com/ie?as_q=sony sound forge audio studio 9.0c ?
I noticed the utter you have not used. Or you functioning the pitch-dark methods of development of the resource. I take a week and do necheg