Wednesday, April 9, 2008

Manually Removing PC Viruses!

Manually Removing PC Viruses!

Have you ever been in the possition that you know you have an virus but you dont have any antivirus?? Its almost impossible to remove it manual without knowing about a few tips & tricks.

After reading this turtorial im sure you will know how to manual remove most of the virus lurking around. But that dosnt mean you shouldnt have any anti virus on you computer! Anyway, lets get starting with the turtorial.. I suppose you already know what safe mode is. If you dont try pressing the F8 key some times when you start your computer. You havto do this when your computer is about to start the first windows components. In win2k or xp i think you can press space and then F8 when it ask you if you want to go back to previous working setting.

Enough talk about how to start you computer in safe mode, but if you want to manual remove viruses you almost everytime haveto do this in safe mode becouse in safemode most viruses dosnt start. Only some few windows component is allowed to run in safemode. So here is what to do. Step:

1: Start your computer in safemode.

2: If you know where the virus are hiding delete the executable file.

3: Open the registry and go to the keys below and add an : in front of the value of the string that you think its the virus. Like this, if string is "virus" and its value is "c:\virus.exe" change its value to ":c:\virus.exe". The : is like comenting out the value. But if you are sure its the virus you can just delete the string. Here are the keys you maybe want to look at: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce

NOTE-Firefox user might not able to view full path.For full path edit your text size smaller by pressing ctrl-.

4: The virus can start itself from some other places to. win.ini is the most common files that viruses can use. Soo you should find the files named win.ini and system.ini and look through them and see if you find anything.

5: Look through the startup folder that is normaly located in your profile directory \Start Menu\Programs\Startup.

6: Try searching for the virus executable to see if its hiding some other place.

7: Finally look through the list of services that windows is running. This list is often located under control panel - administrative tools - services. After this 7 steps just reboot your computer in normal mode and try to figure out if the virus is still there.. If not SUCCESS if yes, try to go back to safe mode and hunt some more. Off course this 7 steps will not work on every virus out there, but many of them.

Note:-
-Be carefull with the registery, dont mess it up, if u do ur computer is Gone , depends on wat u mess up, i suggest u made a system restore point first, so incase someting happens you can go back on it. -

The World's best Viruses

The World's best Viruses
1.W32.Bagle.AF
2.W32.Bagle.H
3.W32.Hiton.A
4.W32.MyDoom.F
5.W32.Netsky.Z
6.W32.Netsky.D
7.W32.Netsky.B
8.W32.Sober.F
9.W32.Sober.D
10.W32.Sober.C
11.W32.Sober
12.W32.Dumaru
13.W32.Sobig.F
14.W32.BugBear.B
15.W32.LovSan/Blaster1
16.W32.Sinapps
17.W32.Sunday
18.W32.Delta
19.W32.Gold
20.W32.Retro
21.W32.Koshi.1.9
22.Linux.ADM
23.Linux.Coco
24.W32.NBC
25.W32.Clickit
26.W32.Parasit
27.W32.PolySnakebyte
28.W32.RousSarcoma

29.W32.Hllw.Sydney@MM

30.CIH
31.I Love You
32.Melissa
33.w32nimda
34.Wagner 782
35.Casino
36.Harddrive-killer pro 5
37.Code red 1
38.Code red 2
39.Pokemon Pikachu
40.AIDS
41.hdfill
42.Blackday
43.Bulbasaur
44.Mirc.El_Che_is_alive
45.Kpmv.W2000.Poly
46.Mbop!
47.C-worm
48.Batschell
49.bat.antifa
50.Bat/BatXP.Iaafe
51.Bat\\bun
52.Bat.Bush
53.BAT.Dolomite.worm
54.bat.****
55.bat/hotcakes
56.bat.ina
57.bat.junkboat
58.bat.soulcontrol
59.BatXP.Saturn
60.BAT/Calvin&Hobbes
61.claytron
62.HoloCaust
63.p2p.Opax
64.PERL.Nirvana
65.VBS/Artillery
66.vbs.eva
67.VBS/Evade
68.Vbs.Evion
69.w32.merkur.c
70.W32/Outsider
71.W32/Outsider B
72.W32/Outsider C
73.W32/Outsider D
74.W32/Outsider E
75.W32/Perrun
76.W97/Blackout
77.W97M/Authority
78.W97M/Chester
79.W97M/SFC
80.WinREG.Sptohell
81.Virenpaket 0
82.Virenpaket 1
83.Virenpaket 2
84.Virenpaket 3
85.Virenpaket 4
86.Virenpaket 5
87.Virenpaket 6
88.Virenpaket 7
89.Virenpaket 8
90.Virenpaket 9
91.Virenpaket 10
92.Virenpaket 11
93.Zed\'s Word Macro Virus Constructor
94.Windows Scripting Host Worm Constructor 1.0
95.Special Format Generator 2.0