Solving different virus/malware attacks
Written by Pavan Kumar on May 4, 2008
Though I don’t receive much mails from contact page or through comments regarding viruses, almost every friend of mine ask me for solutions for modern day viruses/malwares which disables the task manager, folder options, hidden files, registry… and to be specific, one of my friend was infected by sharokh.exe, they used to spread through pen drives. Here I am going to share the solution for that and most of the threats of that kind.
- You need Remove Restrictions tool and your antivirus with full updates.
- Restart your computer in safe mode. This will avoid all startup programs being run at system startup and only most needed services will be launched by the windows.
- Clear all data in temp folder [usually c:\documents and settings\[user name]\local settings\temp], better key in that, as "local settings" being a hidden folder may not be visible for you.]
- In system configuration utility [Click Start> Run > msconfig, click ok ], goto start up tab and remove all items which seem to be suspecious, they usually are found with names like service.exe, smss.exe, services.exe, csrss.exe, lsass.exe, svchost.exe, svvhost.exe… or any system file name but found in non system folders. Note down the location of such files and delete those files. Be careful, you may delete the system files or driver files. Don’t perform if you are unsure.
- In same system configuration utility, goto services tab and check all and close it without restart. This is required as the such malwares might have disabled your antivirus or antispyware services for next start up. Even disabling some services may slow down your start up.
- Check even service.msc for same issue and correct it.
- Run RRT tool downloaded from above said location. Check all the needed ones, if you are unsure, check all the options and click remove. This will help almost all problems your system got affected.
- You are also recommended to check for rootkits and fix them.
- Now, restart your sytem in normal mode, and check your task manager for unknown processes, if any such ones found, kill them. With your updated antivirus program, scan the entire system.
There are different free tools available from sergiwa for virus solutions. You may get it from sergiwa downloads page.
People who liked this also read:
Hmmm never knew a tool like remove restriction existed..