answersLogoWhite

0

📱

Computer Viruses

Computer viruses are harmful pieces of software which can reproduce themselves and automatically spread to other computers and networks. Questions about computer virus techniques and specific computer viruses belong here.

5,673 Questions

How do you remove a Spooner-a virus and where do you get the software?

you can go to wal-mart best buy or someother electronic store and buy norton anti virus put it in your CD ROM then boot from disc to check and clear viruses

Why was a horse use in the trojen war?

because when the Greeks "fled" they left a large wooden horse because it was a gift to the god Posieden, the god of the sea and horses, asking for a safe journey home. the trojans decided to take the horse to the temple of Poseiden, which let the Greeks gain access to the city of troy.

hope this helped!

<3lm.

What is the positive effect of a virus to a computer?

Most people would say there are none, but my friend knows how to make a virus that KILLS OTHER VIRUSES! It doesn't matter what it is, the good virus kills the bad one! And then it just recedes into itself or something.

I believe that's how anti-virus programs work. But then again, when you get that virus that shuts down the anti-virus programs, my friend can just run his good virus code and poof! Gone!

From which countries do most computer viruses come from except the obvious answer US?

Hi.....friends....I am Sagar here from INDIA....the answer for thhis question is ---->"BULGERIA"!

the reason for this is during the last decade the war between russia, china,us and other europien countries lead to temperorily contracted programmers and Hackers from bulgeria in order to make viruses,trojens and All other types of cyberattacks. now most of the virus writers are from either China and Bulgeria.

What are solutions of killed or weakened viruses?

One such example would be a vaccine for viral illnesses. They can be made from attenuated (weakened) viruses or from inactivated viruses or pieces of them.

What happens to your files when your computer gets a virus?

Depending on what the virus is designed to do, anything could happen. Usually, viruses will not delete your files - people who write viruses are more interested in stealing your information than destroying it. Sometimes, however, viruses will delete your files or even corrupt your hard drive completely.

How can you remove virus called monster?

You need to run these 4 essential steps to remove all the spyware on your computer.

1. Run Malwarebytes Anti-Malware

2. Run the anti spyware removal programs spybot

3 Run Superantispyware

4. Run a complete scan with free curing utility Dr.Web CureIt!

Use Mozilla firefox or the google chrome browser for browsing unsafe websites

Install ThreatFire

ThreatFire, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

Install a good antivirus in your computer.

Keep your antivirus updated. If automatic updates are available, configure your antivirus to use them.

Keep your permanent antivirus protection enabled at all times.

How do you get rid of Dropper.delf.G Trojan Virus?

my e-mail address is webmaster@redskiesdesign.com if you want details on the following: disable system restore, then restart the computer in safe mode and run a virus scan. to my knowledge Norton AntiVirus can't do anything about it, but AVG should be able to. while in safe mode just run a full system scan.

the same goes for all Dropper.Delph trojans.

delete it

We can get rid of this Dropper.delf.G Trojan Virus from your compute by following these steps .

1 Download and intall the Malwarebytes on your computer .

2 Update your Malwarebytes .

3 Scan your computer for all the malwares in your computer .

4 Remove all the malwares , found while scanning with the malwarebytes .

5 Restart your computer .

How do you remove brontok virus manually?

Manual removal steps: Disconnect your computer from the network and disable file sharings, if any.

Disable System Restore (for Windows XP/Windows Me only).

For Windows XP:

Click Start.

Right-click My Computer, and then click Properties.

Click the System Restore tab.

Select "Turn off System Restore" or "Turn off System Restore on all drives" check box. Start your machine in Safe mode.

How to start a computer in safe mode, pls refer to: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam

Update your Anti-virus software with the latest signature files and scan your computer withthe Anti-virus to detect the worm and delete any files detected as the worm by clicking the DELETE button.

Delete the value from the registry.

You need to back up the registry before making any changes to it. In correct changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only.

How to make a backup of the Windows registry, pls refer at: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/199762382617?OpenDocument&src=sec_doc_nam

Click Start > Run. Type regedit Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. You can used a tool to resolve this problem.

Download this tool. Once downloaded, �right-click� the UnHookExec.inf file and click install. Then continue with the removal steps. http://securityresponse.symantec.com/avcenter/venc/data/tool.to.reset.shellopencommand.registry.keys.HTML

Other alternative way to enable registry, please refer to: http://www.patheticcockroach.com/mpam4/index.php?p=28

Navigate to the subkey that was detected by the anti-virus and delete the value.

Exit the Registry Editor.

If you are still unable to open your registry, you may try the following steps.

Boot up the infected computer, but do not login to the server, leave it at the login prompt.

Start up another clean computer, worm-free computer which has an updated anti-virus software running and an active firewall running preventing all inbound connections.

From the clean computer, start REGEDIT.EXE and click on File -> File -> Connect Network Registry. Connect to the infected computer.

Modify the following values in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\NT\CurrentVersion\Winlogon to the following values:

"Userinit" = "C:\WINNT\system32\userinit.exe," "Shell" = "Explorer.exe"

(make sure that you enter the correct path to where Windows is installed. For example on NT4.0 it is WINNT)

After completing the above steps, reboot the infected computer.

Using the clean computer, map the C$ share and scan it using the up to date anti-virus to remove any infected files on the infected computer. Then, you should be able to boot to the computer and then follow Steps 6 - Steps 11.

Run a full system scan using an updated version of Anti-virus software and delete any files detected as worm.

Download and run a process management tool or process viewer to kill all worm processes running on the infected machine. The process management tool or the process viewer is available according to the machine's platform and can be downloaded free from the Internet. For example users can download and use the following process viewer: http://www.sysinternals.com/Utilities/ProcessExplorer.HTML

Delete the scheduled tasks added by the worm. Click Start, and then click Control Panel. (In Windows XP, switch to Classic View.) In the Control Panel window, double click Scheduled Tasks. Right click the task icon and select Properties from pop-up menu. The properties of the task is displayed. Delete the task if the contents of the Run text box in the task pane matches the worm.

Enable the System Restore (for Windows XP/Windows Me only).

Re-scan your computer with an updated version of Anti-virus to confirm the computer is clean.

Re-connect your computer to the network once confirmed clean.

IMPROVED ANSWER WITH LINKS TO TOOLS (SOLVED BY A SENIOR IT SYSTEMS ADMIN) BY: Ian Gardiner

Brontok Virus Manual Removal Instructions

  1. Disconnect your computer from the network and disable file sharings, if any exist on the PC.
  2. Disable System Restore (for Windows XP/Windows Me only).

For Windows XP:

  1. Click Start.
  2. Right-click My Computer, and then click Properties.
  3. Click the System Restore tab.
  4. Select Turn off System Restore or Turn off System Restore on all drives check box.
  1. Start your machine in Safe mode. Reboot and repeatedly press F8. If you cannot boot into safe mode, you should still be able to get rid of the virus, however, safe mode is recommended.
  2. Update the anti-virus software for any latest updates.
  3. You will have to use the regedit function to remove a lot of infected/newly created values in the registry.
  4. Click Start>Run. Then type regedit, click OK.
    1. You will need to use Internet Explorer to download this file.
    2. Go to http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99 and download the UnHookExec.inf file at the bottom of the page. (you will have to download this file on another PC and save it on a drive and move it over to the infected PC)
    3. Once you have put this file onto the infected PC's Desktop, Right-click the file and click Install. You won't really notice anything happen, however, this will enable the regedit function.
  5. If the registry editor fails to open, the threat may have modified the registry to prevent it from opening. You can use a tool to resolve this problem:
  6. Once you can use the regedit function check to see if there is a scheduled task named A1 or something along those lines (scheduled to run at 5:08pm) in All Programs\Accessories\System Tools\Scheduled Tasks. If you can't reach that location try: Control Pannel in classic view and look for the Scheduled Tasks icon/folder. Delete the task.
    1. The tool can also be found at: http://www.kaer-media.org/penawar-brontok/Download.htm
  7. Next, before going ahead and deleting anything in the registry. You will need to use this German Brontok Removal tool
  8. Click on the link that says: PenawarB.exe and save the file.
    1. Double click the file, click Run
    2. In the bottom right hand corner click the button that says: Percubaan Percuma!
    3. On the next screen click on the button on the left that says: Tidak mengapa, saya hendak cuba dahulu…
    4. On the next screen click the button that says: Scan sekarang!
    5. Once the tool has run it will show the location of all of the infected files
    6. Click the button that says: Buang ! & Repair to delete the infected files
    7. Note: This tool is free so when you click Repair it will delete all of the files except for 10 of them. For the remaining 10 you will have to take not of the infected files' locations and manually delete them. Also, if there are less than 10 files that are infected to begin with you will have to manually delete all of them.
  9. Once the file has been saved to the infected PC's Desktop
  10. Once this is done follow the instructions below on deleting all other files and registry values. This step is very important and crucial to the final removal of the virus!

The worm may use various methods to run automatically each time Windows starts. Automatic startup methods that the worm employs may include:

  • Placing a copy of itself in the user's startup folder, i.e. %homepath%\Start Menu\Programs\Startup\Empty.pif. Delete the file.
  • Adding a scheduled task to run %homepath%\Templates\A.kotnorB.com each day at 5:08 pm. Also check to see if there is a scheduled task named A1 or something along those lines in All Programs\Accessories\System Tools\Scheduled Tasks. If you can't reach that location try: Control Pannel in classic view and look for the Scheduled Tasks icon/folder. Delete the task.
  • Adding a registry value: "Tok-Cirrhatus"

With data:

In subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. Delete the key.

  • Adding registry value: "Bron-Spizaetus"

with data: <path to Win32/Brontok worm>

in subkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Delete the key.

  • Adding registry value: Shell

    with data: "explorer.exe " <path to Win32/Brontok worm>

in registry subkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WinLogon. Delete the key.

  • Modifies registry value: AlternateShell

    with data: <Win32/Brontok file name>

    in registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot

    Note: the default setting for this key is "AlternateShell"="cmd.exe"

Win32/Brontok may attempt to lower security settings by making the following changes:

  • Prevents the user from accessing the Registry Editor by making the following registry edit:

Adds value: DisableRegistryTools

With data: 1

In subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System. Change the Data to 0.

  • Prevents the display of files and folders with the 'hidden' attribute set:

Adds value: Hidden

With data: 0

In subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced. Change the Data to 1.

  • Prevents the display of Windows system files:

Adds value: ShowSuperHidden

With data: 0

In subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced. Change the Data to 1.

  • Prevents the display of executable file extensions:

Adds value: HideFileExt

With data: 1

In subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced. Change the Data to 0.

  • Prevents access to the Folder Options menu:

Adds value: NoFolderOptions

With data: 1

In subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer. Change the Data to 0.

  • Modifies the Windows HOSTS file to prevent access to certain Internet sites, the majority of which are antivirus or security-related.
  • Attempts ping attacks against certain Web sites, presumably to launch a form of denial of service (DoS) attack.
  • Terminates applications or restarts Windows when the title of the active window contains certain strings, many of which may be representative of antivirus or system tools that might ordinarily be used to detect or remove the worm.
  • Overwrites the autoexec.bat file with the word "pause", causing systems that employ the autoexec.bat file to pause on bootup. Some variants of Win32/Brontok may modify the autoexec.bat in order to display a message during bootup.
  1. You will also want to go into msconfig. Start>Run, type msconfig. And disable any startup items (under the startup tab) that look suspicious; you may have to run an internet search to determine which are normal processes and which may be a threat.
    1. make sure the scheduled task is no longer there
    2. make sure you can open regedit
    3. re-run the scanner for any infected files. If it finds anything delete them, restart the PC, and then re-run the scanner and delete files until nothing shows up again.
    4. Make sure the registry is back to normal and that you can view hidden files and folders.
  2. Once this has been done, restart the PC, and check over everything in the following order:

How do you remove virus from system 32?

You need to run these 4 essential steps to remove all the spyware on your computer.

1. Run Malwarebytes Anti-Malware

2. Run the anti spyware removal programs spybot

3 Run Superantispyware

4. Run a complete scan with free curing utility Dr.Web CureIt!

Use Mozilla firefox or the google chrome browser for browsing unsafe websites

Install ThreatFire

ThreatFire, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

Install a good antivirus in your computer.

Keep your antivirus updated. If automatic updates are available, configure your antivirus to use them.

Keep your permanent antivirus protection enabled at all times.

When is you computer most likely to be infected with a virus?

My computer got a virus in the third year we had it and all the data was lost so you should be prepared and have some kind of memory card to hold all the data.

Can anyone helpme virus win32 autoit gp worm is in my usb?

You can download and install an Anti-virus Program software from below suggested ones:

MacAfee

Trend Micro

Microsoft Security Essentials

If i restore my computer to a certain date does that delete the virus?

One of the best features of Windows ME or XP is the System Restore option, however if a virus infects a computer with this operating system the virus may be accidentally backed up because of this feature. In order to completely remove a virus on these operating systems, you should disable System Restore before cleaning the system, then reenable it after the system is clean.

How do you get rid of narcissism in yourself?

Pathological narcissism results from a bad choice; choosing to create and display a fraudulent persona for the world to admire, fear, and approve of. The only road out of this trap is the complete detection and rejection of untruth within oneself. The truth will set you free. I guess that once a narcissist realizes how painful all their relationships ultimately become, they want to change. So that is the first step, admitting the problem. The next step would be to find someone that will hold you accountable. There are others in your life that you play and play well. This Accountability partner will be different. This will be someone who is not afraid of losing you, because your first instinct will be to cut this person down and make them feel inferior to you. Finding a person strong enough to deal with you as you learn a new way will be tough, but they are out there. Most likely it will be a fellow ex-narcissist that finally saw that their false sense of superiority was ruining their life. They will be able to take what you throw at them, but they will practice tough love and be a anvil while you pound away, not budging them. It may take years before you are free of the "i deserve better" lie. During these years you will learn that life is what YOU not OTHERS make it. You will learn that you GET what you GIVE. You will learn that YOU ARE SPECIAL, just like EVERYONE ELSE. Hopefully you will learn humility, which is humbling yourself despite the difficulty. I hope you learn true compassion, which is giving when you expect nothing in return. Also, I really hope that you look into whatever type of professional diagnosis and treatment you can afford.

What are computer viruses area of infection?

Computer viruses can infect

the hard disk

the usb drive

Any other removable media

the web browser

You have obfuskated downloader in avg virus vault how do you remove it completely?

When you moved the file to the AVG Virus Vault it was deleted from its original location, coded, and then saved in a non-executable file in a hidden folder. Your PC is no longer infected.

If you are not missing any data file and your applications are running, then you can delete these vaulted files from the AVG Virus Vault. You can do it selectively: from AVG Virus Vault program-> select files -> right click on the selection -> Delete file(s).

Or you can delete all AVG Virus Vault contents in one go: Open the AVG Control Center program -> right click on AVG Virus Vault component -> choose"Empty vault".

What are the positive effect of computer virus?

Only possible positive effects are software companies that can kill viruses are very profitable and create jobs for bright young people.

Is there a way to remove XP Antivirus for free like without any scans that you have to pay for?

Yes you can remove it with free software

* Run Malwarebytes Anti-Malware

* Run Superantispyware

* Run a complete scan with free curing utility Dr.Web CureIt!

Install a good antivirus in your computer.

Keep your antivirus updated. If automatic updates are available, configure your antivirus to use them.

Keep your permanent antivirus protection enabled at all times.

* AVG Free Edition 8.0.100

* Avast! Home Edition 4.8.1201

* AntiVir Personal 8.1.00.29

Your computer will not let you remove a infected program or virus what should you do?

youll have to do a full system reboot and system reset if that doesn't work you may have to call Microsoft/apple

How do you remove the Sasser virus?

Try using the website symantec.com. They have a whole list of Worms and cures for free.

.You can get rid of this worm by following these steps

1 Download and intall the Malwarebytes on your computer .

2 Update your Malwarebytes .

3 Scan your computer for all the malwares in your computer .

4 Remove all the malwares , found while scanning with the malwarebytes .

5 Restart your computer ,

You need to run these 3 essential programs to remove all the spyware on your computer.

If you do not have an internet security suit and only an anti virus

1. Run Malwarebytes Anti-Malware

2. Run a complete scan with free curing utility Dr.Web CureIt!

3. Run the anti spyware removal programs spybot or Superantispyware

Browsers

Use Mozilla firefox or the google chrome browser for browsing unsafe websites

Install ThreatFire

ThreatFire, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

Run an online virus scan like

Trend Micro HouseCall

Kaspersky free online virus scanner

Windows Live OneCare safety scanner

BitDefender Online Scanner

ESET Online Antivirus Scanner

F-Secure Online Virus Scanner

avast! Online Scanner

update your software by running

Secunia Online Software Inspector

Install a good antivirus in your computer.

Keep your antivirus updated. If automatic updates are available, configure your antivirus to use them.

Keep your permanent antivirus protection enabled at all times.

Which is least likely to be affected by a virus?

The least likely way to get affected is not using the internet, flash disks - disabling removable devices...however we both know this is not possible..

So you need to have an always updated antivirus. Implement proactive actions like scanning any removable devices before you open it....