Friday, November 9, 2007

To delete deadliest virus if any effected your Computer...........

Of course, there are many anti-virus softwares. Some may not be detected. That is why i am suggesting the method.

Virus always create Autorun files on USB storage so that when you plug your USB media or open any drive , the virus automatically launches on the computer.

Indication of Virus is,  it will display Chinese type of letters in the place of drive’s name. Keep in mind that don’t double click on such drive.

Then try the following steps:

1) Go to Start-> My Computer

2)  double click on My computer on Desktop ,

- choose Tool and select “Folder options

- click on “View” tap select “Show Hidden files and folders” and uncheck "Hide Extention for known file types"  and “Hide protected operating system file” (this selections are important to find the files you need to delete)

- then click "OK"

3)  open Windows Task Manager (ctrl-alt-del) and select the “Processes” tap

- Click on "Image name" to sort File

- find “wscript.exe” and click on “End Process” (if there is more than one process with that name you have to end all of them)

- close the “Task Manager

4)  then  click on Start and select “Search” and search for “autorun.inf” (Search the computer)

- you will then delete all the files that contains the text MS32DLL.dll.vbs (the virus) by pressing: SHIFT + DELETE.     (Of course there should not be Autorun.inf in the C root).

5)  you will also delete the virus from the system (C:\WINDOWS\ MS32DLL.dll.vbs) by pressing  SHIFT + DELETE

6)  Next step is to edit the Register (Like always you have to be very care fool in the registry tools. Some mistake there can crash your computer)

- first, click on “Start” and select “Run” and type in “Regedit” and press “Enter”.

- select HKEY_LOCAL_MACHINE --> Software -->Microsoft -->Windows --> Current Version --> Run.

- find there “MS32DLL” and delete that entry.

7)  Then select                                                        HKEY_CURRENT_USER --> Software --> Microsoft --> Internet Explorer --> Main. There you find  “Window Title “Hacked by Godzilla” ” and you should delete that entry. You can close the registry now.

8)  next you will click on Start --> Run and type in “gpedit.msc” and press “Enter”. then you will open “Group Policy”.

- there you will select User Configuration --> Administrative Templates --> System --> and there you will double click on “Turn Off Autoplay

- in the window there you should select “Enabled” and select “All drives” (they say in this Thai webside that select all turn of Autoplay will be safer for not getting viruses). Now you can close the Group Policy.

9)  Next you will click on Start --> Run and type “msconfig” and press “Enter”.

- Open “System Configuration Utility”.

- click on “Startup” tap

- find the file MS32DLL, choose Enable All, then uncheck "MS32DLL"

- click Apply then OK to close

- then exit the “System Configuration Utility” and select “Exit Without Restart” when prompt.

10)  After this double click on My Computer and select “Tools” and “Folder Options” and “View” tap to change back there.

- select "Hide Extension for known file types" and “Hide protected operating system file” and “Don’t show hidden files and folders”.

- then you will empty the “Recycle bin” and “Restart” your computer.

This helps me with my computer and I don’t get any “Autoplay” on my hard drive now.

1 comments:

lavender boy said...

i didnt find wscript.exe in processes