Archive

Archive for the ‘Virus Removal Tips’ Category

Prevent or Protect computer from Conficker Worm / Virus attack - Remove Conficker Worm / Virus from your computer

March 31st, 2009 bala No comments

What is Conficker Worm / Virus

· Conficker is a worm that can affect your computer and spread itself on the Network without your interaction.

· It spread through file sharing on the network and removable disk when it execute Auto run function when it is plugged in to USB drive

· Conficker worm disable important services on your computer.

· Conficker prevent computer from doing Windows Update and Antivirus update by disabling update service on your computer.

How to protect from being affected by Conficker Worm

· US-CERT recommended that Windows users apply Microsoft security patch MS08-067 to help provide protection against the worm.

Click here to download the patch for Windows XP

Click here to download patch for Windows Vista

· This patch prevents an attacker from remotely taking control of an infected computer system and installing additional malicious software.

· Keep your Antivirus updated and perform a complete scan.

· Disable Autoplay features (Autoplay is the pop-up that ask you what to do when you plug in any USB drive or when you insert CD/DVD). Click here to disable Autorun features.

Remove Conficker Worm

· Do complete Virus scan with the updated Antivirus software

· Remove the Scheduled Task.

Click Start -> Run -> CMD -> type AT /Delete /Yes and press enter

· Remove the Startup entries from the registry

Click Start -> Run -> Regedit -> Ok

Navigate to following locations and remove suspected entries from the left pane of the windows

§ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

§ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

· Make sure TCP Receive Window Auto-tuning is enabled for Windows Vista

Click Start -> Run -> CMD -> type netsh interface tcp set global autotuning=normal press enter

After performing these steps do Windows Update (http://update.microsoft.com/windowsupdate/ )

Repeated windows update KB967715 offers every time the computer reboots. ( “disable Autorun registry key” ) - KB 967715

March 20th, 2009 Rishi 23 comments

What is this update (KB967715) is for?

As we know USB flash drives can spreads Virus if it has got infected , it spreads by executing the autorun.inf file that virus creates on the flash drive, the autorun.inf is driver files that has inbuilt commands to execute a xyz.exe virus on the same drive flash ( since somebody has to execute it ) which replicates on to the root folder of the drive; for all the drives available on the computer , and slow down the pc as it might be sending your personal info to the company who created the virus , this updates disables the feature of autorun feature in windows and changes user experience for the drives for which Autorun is disabled. The double-click and right-click shortcut menu functionality might be different because the Autorun.inf file is no longer read.

So the update KB967715 is an important update and it is necessary to be installed on the computer to prevent Virus when using Flash drive or Thumb drive

Suggestions

Follow the steps below for the successful installation of the update KB967715

1. Download the update manually (Find the download links below)

2. Save it to the desktop

3. Boot the computer to the safemode (Keep tapping F8 when you turn on the computer)

4. Install the update by double click on the file that we saved in desktop

5. Restart the computer to complete the installation

Download links for the windows update KB967715

For Windows XP

http://www.microsoft.com/downloads/details.aspx?FamilyID=c7dbcde3-7814-47c5-849e-e64ecfb35d74

For Windows XP (X86)

http://www.microsoft.com/downloads/details.aspx?FamilyID=ca802f38-0566-4ac4-8808-6515623c35c5

For Windows 2003 Server (X86)

http://www.microsoft.com/downloads/details.aspx?FamilyID=32b845ac-7681-468c-812b-2dcebdae9b40

For Windows 2003 Server (X64)

http://www.microsoft.com/downloads/details.aspx?FamilyID=7b866fb7-9bb7-4fce-b395-d0a4ee38a115

For Windows 2000

http://www.microsoft.com/downloads/details.aspx?FamilyID=3c6039f1-d84d-4294-8457-35aa8b4dcab8

Rishi
MS Shell User &
Media technologist

Free Online Virus Scan from Norton

October 8th, 2008 bala No comments

We see in most of the computers Antivirus Software is not up to date, though they have purchased the software. If the Antivirus is not up to date then it fails to scan or control the latest threat on the web.

To have your computer completely protected we would recommend to ran a online virus scan from Norton.

Click here to ran a Free Online Virus Scan.

This process might take an hour to complete depends on the size of your disk space. Once the scan is completed it will show you the status.

If it shows your computer is affected then call us at 1-877-356-0001 or initiate a chat from www.support1000.com for computer support to remove any threats from your computer.

How to remove Win32.NetSky.q E-mail worm

July 21st, 2008 bala No comments

Description: Win32.NetSky.q is a worm that infects Windows 95, Windows 98, Windows 2000, Windows Me, Windows NT, Windows XP.

Type: Worm

What it does to your computer.

This electronic mail mass propagation worm has been detected in 0.3% of the infected computers. It had been one of the highly spread worms in 2004, the year in which it was created.

In order to spread through E-mail, it uses a vulnarability in Internet Explorer which allows it to automatically execute just by displaying the message in Outlook. The main objective of this worm is to self-propagate. It also carries out a Denial of Service (DoS) attack from the infected systems against different web sites on given dates.

It tries to mislead the user into thinking that their computers have serious errors or viruses with banners or pop-up windows when visiting web pages,offering a free tool to correct the issues, but in reality it is a Trojan horse. Once installed, the program continues to detect false problems in your system and asks the user to register the program, on paying, to fix the issue. The creators of this worm are paid from the sale of the program duping the users with false errors and virus. The damage caused is greater than just economic damage since it creates a false sense of security for the users, who may think that they have bought the tool which would protect them from worms such as these.

How to delete Win32/Netsky.Q worm files in Windows XP and Vista:

One of the ways to remove W32/Netsky.Q is by downloading specific removal tools availabe from Antivirus companies such as Symantec. You can download

the removal tool from the below given link,
http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FxNetsky.exe.

How to remove Win32.NetSky.q manually?

To remove Win32.Netsky.Q worm manually, you need to delete Win32/Netsky.Q worm files

How to remove Win32.Netsky.Q worm files in Windows XP and Vista:

* Click Windows Start menu, and in “Search,” click “For Files and Folders“
* You will get a pop up asking you, “What do you want to search for?” Click “All files and folders.”
Type any file name in the search box, and select “Local Hard Drives.”
* Click “Search” and when you find the file, delete it.

How to stop Win32.Netsky.Q worm processes:

* Click the Start menu, select Run.

* Type taskmgr.exe into the the Run command box, and click “OK.” You can also launch the Task Manager by pressing keys ALT + CTRL + DELETE or CTRL +Shift + ESC.
* Click Processes tab, and find Win32/Netsky.Q worm processes.
* Once you’ve found the Win32/Netsky.Q worm processes, right-click and select “End Process” to stop Win32/Netsky.Q worm.

www.Support1000.com