Showing posts with label Virus removel tools. Show all posts
Showing posts with label Virus removel tools. Show all posts

Net-Worm.Win32.Kido virus Remover

If you are connected with a network and if any PC in the network attacked with Win32.Kido virus, sometimes your Kaspersky Internet security notifies you this message, “Intrusion.Win.NETAPI.buffer-overflow.exploit! Attacker IP address: xxx.xxx.xxx.xxx. Protocol/service: TCP on local port 445.” and access to that computer is blocked.

The name of this virus is “Net-Worm.Win32.Kido” virus. When a PC attacked with this virus, it tries to access other PCs through network at port 445.

Methods of disinfection:

To remove this virus from the attacked PC, just follow the following steps:

* Download and install the patch from Microsoft that covers the vulnerability

http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx
http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx
http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx

* Restart the PC.

* Download the archive KK_v3.4.6.zip and extract the contents into a folder on the infected PC.
Download : http://data2.kaspersky.com:8080/special/KK_v3.4.6.zip


* Then run KK.exe.

* Wait until the scan is complete.

* At last restart the PC.

Remember that, showing the message “Intrusion.Win.NETAPI.buffer-overflow.exploit” is not the problem of that PC, rather it is the problem of another PC on the network.

How to delete autorun.inf virus from usb



If your computer infected with autorun virus, you will get an open with wizard when you double click on a drive. you can manually delete the autorun.inf file using following steps
Microsoft released patch to prevent Autorun Virus


First you Restart your computer to safe mode !

Open command prompt ( Go to Start >> RUN and type CMD)

Go to the drive. ("cd e:" - use your drive letter )

Go to the root directory (cd \ )

then change the attributes of the autorun file

attrib -h -r -s autorun.inf

-h = remove Hidden property
-r = remove Read only property
-s = remove System file property

Now you delete the file

del -h -r -s autorun.inf

Only open that drive after the restart.

Thats it ....


list of free online Anti virus scanners

Autorun virus - Microsoft patch KB971029

AutoRun is a Windows feature that allows files or programs to immediately run as soon as a removable media device, such as a USB stick or CD-ROM, is connected to a computer.AutoRun feature could allow malicious code to spread. One of the vectors by which the infectious Conficker, or Downadup, worm propagates is through pen drives / other removable storage medias

Microsoft has fixed a problem that prevents users from selectively disabling AutoRun features in an effort to stop the Conficker worm from spreading.

Microsoft said it recommends all customers to install the update, which affects all supported Windows versions.

Read : Manually remove autorun.inf from your drive


Download links

The following files are available for download from the Microsoft Download Center:

Update for Windows Server 2008 (KB971029)

Windows6.0-KB971029-x86.msu

Update for Windows Server 2008 for Itanium-based Systems (KB971029)

Update for Windows Server 2008 x64 Edition (KB971029)

Windows6.0-KB971029-x64.msu

Update for Windows Vista (KB971029)

Windows6.0-KB971029-x86.msu

Update for Windows Vista for x64-based Systems (KB971029)

Windows6.0-KB971029-x64.msu

Update for Windows Server 2003 x64 Edition (KB971029)

WindowsServer2003.WindowsXP-KB971029-x64-ENU.exe

Update for Windows Server 2003 for Itanium-based Systems (KB971029)

WindowsServer2003-KB971029-ia64-ENU.exe

Update for Windows Server 2003 (KB971029)

WindowsServer2003-KB971029-x86-ENU.exe

Update for Windows XP (KB971029)

WindowsXP-KB971029-x86-ENU.exe


list of free online Anti virus scanners


Prevent Virus infections through removable medias : KB971029

Ref : http://support.microsoft.com/kb/971029

Unwise.exe Virus Removal Tool

Unwise_.exe Virus affected in internet browsing. That virus blocked all sites and Run that Virus in computer running process. Below are manual removal instructions for unwise.exe so you can remove the unwanted file from your PC. Always be sure to back up your PC before you modify anything.

Use Windows Task Manager to Remove unwise.exe Processes

  1. To open the Windows Task Manager, use the combination of CTRL+ALT+DEL or CTRL+SHIFT+ESC.
  2. Click on the “Image Name” button to search for ” unwise.exe” process by name.
  3. Select the ” unwise.exe” process and click on the “End Process” button to kill it.

Use Windows File Search Tool to Find unwise.exe Path

  1. Go to Start > Search > All Files or Folders.
  2. In the “All or part of the the file name” section, type in ” unwise.exe” file name(s).
  3. To get better results, select “Look in: Local Hard Drives” or “Look in: My Computer” and then click “Search” button.
  4. When Windows finishes your search, hover over the “In Folder” of ” unwise.exe”, highlight the file and copy/paste the path into the address bar. Save the file’s path on your clipboard because you’ll need the file path to delete unwise.exe in the following manual removal steps.

Registry Clearing

Take START then Command Prompt–>Type regedit then Click OK.After one window open .Click on Ctrl+F and type umwise_.exe.Click Search Button and all (unwise_.exe)entries deleted.

Detect and Delete Other unwise.exe Files

  1. To open the Windows Command Prompt, go to Start > Run > cmd and then press the “OK” button.
  2. Type in “dir /A name_of_the_folder” (for example, C:\Spyware-folder), which will display the folder’s content even the hidden files.
  3. To change directory, type in “cd name_of_the_folder”.
  4. Once you have the file you’re looking for type in del “name_of_the_file”.
  5. To delete a file in folder, type in “del name_of_the_file”.
  6. To delete the entire folder, type in “rmdir /S name_of_the_folder”.
  7. Select the ” unwise.exe” process and click on the “End Process” button to kill it.
Prevent Virus infections through removable medias

Yahoo setting.doc link request virus



Today i was monitoring my Squid Log, I found one unusual URL in the log. and its requesting frequency is very high. I remotly accessed that pc and checked but i didn't find any browser opened there.Then i reinitialized that it is a bandwidth killing worm called Win32.Worm.AutoIt So Proxy administrators must check this link request in your log and find the Infected pcs.

Following are the link request coming from the infected PC.

http://www.yahoo.com/setting.xls
http://www.yahoo.com/setting.doc
http://yahoo.com/setting.xls
http://yahoo.com/setting.doc

Download autoit virus removal tool
http://www.softpedia.com/get/Antivirus/W32-AutoIt-Trojan-Cleaner.shtml

Find more details here

Steps to Prevent from Fake antivirus software scams

10 Steps to prevent Fake antivirus

1. Use Firefox as your browser rather than Internet Explorer.

2. Keep your computer updated with the latest anti-virus and anti-spyware software, and be sure to use a good firewall.

3. Never open an email attachment unless you are POSITIVE about the source.

4. Do NOT click on any pop-up that advertises anti-virus or anti-spyware software, especially a program promising to provide every feature known to mankind. (Also remember: the fakes often mimic well-known brands such as Grisoft AVG, Norton and McAfee.)

5. If a virus alert appears on your screen, do NOT touch it. Don't use your mouse to eliminate or scan for viruses, and DON'T use your mouse to close the window. Instead, hit control + alt + delete to view a list of programs currently running. Delete the "rogue" from the list of running programs, and call your computer maker's phone or online tech support service to learn if you can safely use your computer.

6. Do not download freeware or shareware unless you know it's from a reputable source.

7. Avoid questionable websites. Some sites may automatically download malicious software onto your computer.

8. Reset your current security settings to a higher level.

9. Although fake software may closely resemble the real thing, it's rarely an exact match. Look for suspicious discrepancies.

10. Check out this list of rogue/fake anti-virus and anti-spyware products.


List of rogue / fake antivirus / anti spyware products


Advanced Cleaner[3]
AlfaCleaner
AntiSpyCheck 2.1
AntiSpyStorm
AntiSpywareBot [4]
AntiSpywareExpert
AntiSpywareMaster
AntiSpywareSuite
AntiSpyware 2008 XP
Antivermins
Antivirgear
Antivirus 2008
Antivirus 2009
AntiVirus Gold [5]
Antivirus Master
Antivirus XP 2008 [6]
Awola 6.0
Brave Sentry
BestsellerAntivirus
Cleanator
ContraVirus
Doctor Antivirus
DriveCleaner [7]
Disk Knight
EasySpywareCleaner
Errorsafe
free-viruscan.com
IE Antivirus
IEDefender
InfeStop
KVMSecure
MacSweeper
MalCrush 3.7
MalwareCore
MalwareAlarm
Malware Bell 3.2
Microsoft AntiVirus
PCSecureSystem [8]
PC Antispy [9]
PC Clean Pro [10]
PC SpeedScan Pro
PestTrap [11]
Perfect Cleaner
PAL Spyware Remover
PCPrivacytool
PC-Antispyware
PSGuard
SecurePCCleaner
Security toolbar 7.1
SpyAxe [12]
Spy Away
SpyCrush
Spydawn [13]
SpyGuarder
SpyHeal
Spylocked [14]
SpySheriff [15]
SpySpotter
Spyware Cleaner
Spyware Quake [16]
Spyware Stormer
SpywareStrike
Spy-Rid
SpyWiper
System Live Protect [17]
SystemDoctor
TrustedAntivirus
TheSpyBot
UltimateCleaner
VirusHeat
Virus Isolator
VirusProtectPro
VirusRanger
Vista Antivirus 2008
WinAntiVirus Pro 2006
WinFixer [18]
WinSpywareProtect
WorldAntiSpy
XP Antivirus
XoftSpySE
Zinaps 2008


Prevent from rogue Fake antivirus software scams

Antivirus2008 removal instructions - fake antivirus

Antivirus2008 removal instructions - fake antivirus

Antivirus 2008 is not an Antivirus software. It is a malware . Its attacking computers via internet. Antivirus2008 is distributed through malicious websites that sell other fake anti spyware tools as well.

Antivirus2008 is an unreliable program that displays exaggerated scan results in order to gain a purchase. See above image, DO NOT trust this scan result. Remove immediately if you've been infected. And install a best Anti virus.


Related files

AntiVirus2008.exe AntvrsInstall.exe AntvrsInstall[1].exe Antvrs.exe, xpa_2008.exe Antivirus-2008.exe, av2008xp.exe, Win Antivirus 2008.exe AntvrsInstall.exe shlwapi.dll, wininet.dll, shlwapi.dll, wininet.dll, AntiVirus2008.exe, Uninstall Antivirus.lnk, AntiVirus 2008.lnk, AntvrsInstall.exe, AntvrsInstall[1].exe, AntiVirus 2008.lic, Antvrs.exe, xpa_2008.exe, Antivirus-2008.exe, av2008xp.exe, Win Antivirus 2008.exe, AntvrsInstall.exe


How to remove / uninstall Antivirus 2008 ?

Do it in safe mode


  1. Uninstall: Uninstall Antivirus 2008 by using the "Add/Remove Programs" utility.
  2. Kill processes : Kill all the .exe files specified in the above list
  3. Unregister DLLs: Unregister specified in the above list ( command : regsvr32 /u filename.dll)
  4. Delete files : Search for the files listed above and delete them
  5. Delete directories: "%ProgramFiles%\ANTIVIRUS 2008"

Godzilla virus removal MS32DLL.dll.vbs

This virus is spreading through the pen drive / external HDDs. They use the autorun function of windows to run this. Its create files in windows folder in the name of MS32DLL.dll.vbs. and create file named autorun.inf in the root directory of each drive. So whenever we double click on the drive, the script will run from c:\windows\MS32DLL.dll.vbs


After infection

We can not Double Click to open any Drive on our computer. But we can Right Click to Open or Explore.


There is a text “Hacked By Godzilla” on Title Bar of Internet Explorer.


It will effect regedit, task manager, hidden folders/ files etc …

Related files
MS32DLL.dll.vbs
Autorun.inf
Flashy.exe


How to remove -
Download Removal tool Or do the following

Open task manager and end following process
1. wscript.exe
2. mslogon.exe
3. systemnt.exe
4. wscript.exe
5. flashy.exe
6. sondmsg.exe

Open command prompt and do the following
Change attributes of the file
Attrib –s –r –h autorun.inf
Remove autorun.inf from root directory.
Del autorun.inf
Delete MS32DLL.dll.vbs from windows directory
Delete c:\windows\MS32DLL.dll.vbs
Open registry editor
Delete following values
HKLM\Software\Microsoft\Windows\CurrentVersion\Run - MS32DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Run - flashy.exe
HKU\Software\Microsoft\InternetExplorer\Main - "window Title"
HKU\Software\Microsoft\Windows\CurrentVersion\Policies\system - disabletaskmgr
HKU\Software\Microsoft\Windows\CurrentVersion\Policies\system - disableregistrytools
HKU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer - NoFolderOptions
Now restart the PC

How to avoid spreading
To avoid spreading this, disable autorun in windows.
And there is a small tric

Just create a folder named autorun.inf in all the root directory. And change the all the atribs to “+” so that they can’t chant put the files to root direct easly
Eg :
MD autorun.inf & Attrib +h +s +r autorun.inf

Remove amvo.exe Trojan.AutoRun.A virus

This virus is also spreading through autorun of pen drive (AUTORUN.INF )

content of the autorun file
[AutoRun]
open=nideiect.com
;shell\open=Open(&O)
shell\open\Command=nideiect.com
shell\open\Default=1
;shell\explore=Manager(&X)
shell\explore\Command=nideiect.com

This will affect yahoo messenger login

How To remove it manually ?

Do it in safe mode

1, Plug your pen drive and start working.
2, search for autorun.inf and delete the filr if you found in root of your partitions and pendrive
3, search for following file and remove them

xn1i9x.com
n1deiect.com
ntde1ect.com
nudeiect.com
ntdelect.com
nideiect.com
ek.com
d.com
usdeiect.com
80avp08.com
dosocom.com
xfoolavp.com
uxdeiect.com
avpo.exe
amvo.exe
kavo.exe
amvo.exe
amvo0.dll
ampo.exe
amvol.dll
xfoolavp.com

4, open registry and take a backup of registry
5, search for “amvo.exe” and delete all the entry related to that file
6, Open “MSconfig” and remove startup entry of “amvo.exe”
7, update and scan with your antivirus

8,Restart Your PC

The exception breakpoint Yahoo messenger login error

When Sign In into yahoo messengers it just flash and automatically closing.

Also getting following error.

yahoo

The exception breakpoint
A breakpoint has been reached
(0x80000003) occurred in the application at location 0x1001c3a7

Reinstall or upgraded to a latest versions is not a solution for this case (I tried up to version 9 )

To solve the Problem

Right click on the shortcut of yahoo messenger

Click on Properties > Advanced > Check the box ' Run with different credentials '

yahoo2
Click on Compatibility > Check the box ' Turn off advanced text services for this program’

yahoo3

Now Run Yahoo messenger

Now you will get a “Run as” window

yahoo4

Click on “The following user” and login as administrator

Now you can login to yahoo messenger.

Next time you login, remove tick from

“Click on Properties > Advanced > Check the box ' Run with different credentials '”

For Permenent solution Remove amvo.exe Trojan.AutoRun.A virus

Enjoy Yahoo Chatting

Please give a feedback.

Remove Desktop.ini & Folder.htt virus HTML.Redlof.A

Redlof is polymorphic virus that embeds itself without any attachment to every e-mail sent from the infected system. It executes when an infected email message is viewed The HTML.Redlof.A is a very pestering virus. From what I gather, neither does it create any loss of data nor does it send any personal information across the net.

But what it does is horrible. It actually comes in the form of a script. The script is copied onto several other .htm, .html, .vbs, .asp, .htt, .jsp files on your hard drive. Then whenever any of these files are executed, the script is copied onto more files which create more files and so on.


VBS/Redlof.A@m executes directly from an infected message by using a security vulnerbility in Internet Exlorer known as Microsoft VM ActiveX Control Vulnerability. More information about the vulnerability and a fix is available from Microsoft: http://www.microsoft.com/technet/security/bulletin/ms00-075.asp

The virus also infects files with extensions "htm", "html", "asp", "php", "jsp", "htt" or "vbs".

Redlof drops the following infected files:

\Program Files\Common Files\Microsoft Shared\Stationery\blank.html
\Windows\System\Kernel32.dll
\Windows\web\kjwall.gif
\Windows\system32\desktop.ini

"blank.html" is used to replace the default stationaries for both Outlook and Outlook Express via registry causing that the every message sent from an infected system will carry the virus.
The "Kernel32.dll" is also set to registry so that it will be executed on the system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Kernel32

Download Removel tools

http://www.gdata.pl/kmdownload/download.php?op=getit&id=61

http://www.softpedia.com/get/Antivirus/Redlof-Remover.shtml

New Folder.exe Virus Removal Tool

Virus also known as- IT University Sohanad W32.HLLW.Ssdx newfolder.exe

If this virus infected in you computer, It will Disable the following …

Task Manager, Registry Editor, Folder Options, Run in start menu

And it will create exes like the icon of folders. If this virus is running it will use more than 50 % of your processor

Download following tools to remove new folder.exe virus

Download Tool 1 Download Tool 2 ( run tools In safe mode )


Manually remove it (new folder.exe Fix)

Delete File named svichossst.exe

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“@”=[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Yahoo Messengger”=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Shell”=”Explorer.exe “


list of free online Anti virus scanners

Microsoft patch to prevent spreading Virus through removable medias : KB971029

list of windows updates since sp3 KB936929


Remove Winfixer / win antivirus Pro 2007

( Also known as: Virtumonde, Msevents,and Vundo, Trojan.vundo )


WinAntiVirus Pro is a dangerous, When WinAntiVirus Pro infects your computer system, it will hijack your browser to an unfamiliar webpage like, onlinestability.com or winantivirus.com, WinAntiVirus is also a program that sends false positive scan reports and an array of pop-up advertisements, in order to entice the user into purchasing the full product. This bad application can find its way into your computer without your knowledge or consent. This spyware is associated with the famous spyware application, WinFixer.

Running Processes:

mav_startupmon.exe
uwa7pcw.exe
rtasks.exe
WinAv.exe
wa7pinst.exe


Registry Values:

2178F3FB-2560-458f-BDEE-631E2FE0DFE4
6F520BE0-9B54-4558-816F-224E67997DF3
459F4226-1AAB-43B6-9DC1-B6313EF83749
1AC5C88A-DEA7-462b-A232-04AF5CA42E7E
723D54C7-7483-4EB8-8EED-CE5B2AEA534D


Files:

WinAv.exe
uwa7pcw.exe
mav_startupmon
mav_startupmon.exe
rtasks
rtasks.exe
wa7pinst.exe
IH.exe
WinAntiVirus Pro 2007.lnk
Reinstall or Uninstall WinAntiVirus Pro 2007.lnk
WinAntiVirus Pro 2007 Manual.lnk
uwasffNT.exe
was6.exe
WinAntiVirusPro2007FreeInstall.exe
WinAntiVirus Pro 2007.lnk
WinAntiVirus Pro 2007 Scanner.lnk
WinAntiVirus Pro 2007 Scanner Online Manual.lnk
AsAgents.dll
unins000.exe
unins000.dat
Updater.exe
uwas6chk.dll
uwasffNT.exe
WinAntiVirus Pro 2007 Manual.lnk
WapCHK.dll
rpt.dll
awvtr.dll
yayyvsp.dll
fcyxx.dll
gebxyax.dll
asmngr.dll
fopnl.dll
IEFWBHO.dll
Scnkrnl.dll
settings.dll
sqlite3.dll
WAV6COM.dll
winpgi.dll
BORLNDMM.dll
SCANADWR.dll
SCANBCDR.dll
SCANLDR.DLL
SCANDOS1.dll
SCANEMUL.dll
SCANFUNC.dll
SCANMCRL.dll
SCANOTHR.dll
SCANSCR.dll
SCANTOOL.dll
SCANTROJ.dll
SCANWIN1.dll
UNACPU.dll
UNADBX.dll
unamscan.dll
UNMIME.dll
UNPACK.dll
UNPACKS.dll
UNPACKS2.dll
UNPEPACK.dll
pmmnt.exe or pmsnrr.exe


How To Remove Winfixer

2. Run VundoFix.exe

3. Place a check in the checkbox labeled 'Run VundoFix as a task'. You will receive a message stating that VundoFix will close and re-open in a minute or less.

4. When VundoFix re-opens, click the OK button.

5. Click the Scan for Vundo button; when it's finished scanner, click the "Remove Vundo" button.

6. You will receive a prompt asking if you want to remove the files, click Yes. The desktop will go blank temporarily.

7. When complete, restart your computer. The Spyware infection should now be cleaned from y our computer.


If you are still having problems and cannot remove WinFixer / Trojan.Vundo:

1. Download VirtumundoBegone http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

2. Reboot your computer into Safe Mode.

3. Double click VirtumundoBeGone.exe and follow the on-screen instructions.

4. Exit when complete, and restart the computer.


Fix From Symantec : http://securityresponse.symantec.com/avcenter/FixVundo.exe

Perlovga Removal Tool (copy.exe)

Error message: Windows cannot find 'copy.exe'

This virus is spreading through usb flashdisk. An autorun file will work to copy this file to your local disk. so be careful whenever you connect a pendrive

Solution:
Start your computer in Safe mode and run Perlovga Removal Tool. If you have infected floppy/flash disks you can insert them and click start. You must be write enabled your usb disk during the scan process you can repeat this for every disk you have.

Related files :
Copy.exe
Copy2.exe
Temp2.exe
Autorun.inf


This tool also work with :

Trojan-Dropper.win32.Small.apl
Win32.Perlovga.bBackdoor
Win32.small.loW32
QQRob-ABXVirus.Vbs.Small.a

Download Perlovga Removal Tool

Remove Heap41a / win32.USBworm Worm



A worm named w32.USBWorm is making problems in some computers . It will block Firefox, Orkut and Youtube. All of the searching for a fix.. Send ths page link to your friends..


Error Messages

Orkut is banned you fool, The administrators didnt write this program guess who did?? MUHAHAHA!!

I DNT HATE MOZILLA BUT USE IE OR ELSE...

USE INTERNET EXPLORER U DOPE


Heap41a / win32.USBworm Worm - Removel tool


Mr. Sarath Lakshman developed a remover tool for this worm.

Download it and fix the Problem


http://slynux.org/downloads/Worm-fix.exe.zip

http://sarathlakshman.info/22

cant view hidden files After this problem ? Click here

Get updates via Email :