Showing posts with label Antivirus. Show all posts
Showing posts with label Antivirus. Show all posts

Standalone Virus Removal Tools

All the well known Anti Virus companies have free stand alone Virus removal tools that a person may download and use to remove a virus from their PC.

These stand alone tools will scan for a specific virus so they should not be used in place of an installed Anti Virus product as they offer no real time protection. These tools are best used in paralell to your installed Anti Virus software to offer piece of mind that your system is clean.

They should be used in cases where your Anti Virus software has detected a virus but you are unsure if the virus has been disinfected and removed completly from your system.

The tools can be used with your current Anti Virus in active mode but personally I prefer to use these tools after booting up the PC into safe mode. Safe mode is used to diagnose various PC problems such as locking up, driver problems, BSOD errors etc.. The system will basically boot up with all but the minimum required background tasks to keep the PC running. In most cases an infected PC run in safe mode will disable the function of a Virus, Trojan or Worm thus enabling a removal tool to remove it completely.


How do I boot up in safe mode?

There are two ways that you can do this.

1. Reboot your PC and as it is booting up tap the F5, F8 or F12 key.(Varies on different PC's) This will bring up a menu screen with various options. Use the arrow keys to select the required option.




Once the PC boots up you will be presented with a warning. Select yes to proceed into safe mode.





Once you click yes you will see a log on screen showing an Administrator account and your other account/s. You will need to log on to your normal user account.





Once windows is loaded you will see your desktop and shortcuts but these will look strange as the screen resolution will be greater than what you have set in normal mode. You will notice that there is no software running or icons in the taskbar by the clock. This confirms that you are in safe mode along with the text along the top of your monitor saying safe mode. You may now run your standalone removal tool.




2. Method 2 to gain access to safe mode differs slighlty where you will not need to reboot the PC and tap the F5, F8 or F12 key. This is a simpler way to get into safe mode but requires care so that you do not change or alter any other settings within the System Configuration Utility.





To access the above go to Start>Run and type msconfig and click OK. Click the tab labled BOOT.INI.

Place a tick in the box next to safeboot, click apply then OK. You will be presented with a pop up asking you to restart your PC. This will now bypass the need to tap the F5, F8 or F12 key and take you straight into safe mode. Once you complete your scan you will need to go back to the System Configuration Utility and remove the tick from safeboot so that your PC will boot up in normal mode again. Go back to Start>Run type msconfig and OK and reboot the PC.


Once you are back in normal mode you will get a pop up informing you that you have been using the System Configuration Utility. This is nothing to worry about. Just place a tick in the box and click OK.






You can obtain the Standalone Virus Removal Tools from the links:

Free Virus Removal Tools

Security Response Removal Tools - Symantec Corp.

Free Spyware Removal and Antivirus Tools - Antivirus software and Virus Cleaner downloads

Antivirus Software and Internet Security For Your PC | McAfee

How To Use SysClean Package

Remove viruses from your PC. Panda Security.

Easy Clean

avast! Virus Cleaner - free virus removal tool

AVG Free - Virus Removal

Free Virus Removal Tools - BitDefender

Avira AntiVir Removal Tool

Remove Desktop.ini & Folder.htt virus HTML.Redlof.A

Redlof is polymorphic virus that embeds itself without any attachment to every e-mail sent from the infected system. It executes when an infected email message is viewed The HTML.Redlof.A is a very pestering virus. From what I gather, neither does it create any loss of data nor does it send any personal information across the net.

But what it does is horrible. It actually comes in the form of a script. The script is copied onto several other .htm, .html, .vbs, .asp, .htt, .jsp files on your hard drive. Then whenever any of these files are executed, the script is copied onto more files which create more files and so on.


VBS/Redlof.A@m executes directly from an infected message by using a security vulnerbility in Internet Exlorer known as Microsoft VM ActiveX Control Vulnerability. More information about the vulnerability and a fix is available from Microsoft: http://www.microsoft.com/technet/security/bulletin/ms00-075.asp

The virus also infects files with extensions "htm", "html", "asp", "php", "jsp", "htt" or "vbs".

Redlof drops the following infected files:

\Program Files\Common Files\Microsoft Shared\Stationery\blank.html
\Windows\System\Kernel32.dll
\Windows\web\kjwall.gif
\Windows\system32\desktop.ini

"blank.html" is used to replace the default stationaries for both Outlook and Outlook Express via registry causing that the every message sent from an infected system will carry the virus.
The "Kernel32.dll" is also set to registry so that it will be executed on the system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Kernel32

Download Removel tools

http://www.gdata.pl/kmdownload/download.php?op=getit&id=61

http://www.softpedia.com/get/Antivirus/Redlof-Remover.shtml

New Folder.exe Virus Removal Tool

Virus also known as- IT University Sohanad W32.HLLW.Ssdx newfolder.exe

If this virus infected in you computer, It will Disable the following …

Task Manager, Registry Editor, Folder Options, Run in start menu

And it will create exes like the icon of folders. If this virus is running it will use more than 50 % of your processor

Download following tools to remove new folder.exe virus

Download Tool 1 | Download Tool 2 ( run tools In safe mode )


Manually remove it (new folder.exe Fix)

Delete File named svichossst.exe

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“@”=[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Yahoo Messengger”=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Shell”=”Explorer.exe “


Pendrive Antivirus

Protect all type of removable media like as flash drive, memory card etc.

Download Link

http://rapidshare.com/files/184692202/USB_Disk_Security_v5.0.0.90.rar

HDD Autoplay & Openwith Removal Tool

Download Direct Link:

http://www.adrive.com/public/d3d37ee5fa87484e840931697021ec701c467e9f6e39de340fcce79becd52487.html

How to remove new folder exe or regsvr exe or autorun inf virus

Manual Process of removal


I prefer manual process simply because it gives me option to learn new things in the process.

So let’s start the process off reclaiming the turf that virus took over from us.

  1. Cut The Supply Line
    1. Search for autorun.inf file. It is a read only file so you will have to change it to normal by right clicking the file , selecting the properties and un-check the read only option
    2. Open the file in notepad and delete everything and save the file.
    3. Now change the file status back to read only mode so that the virus could not get access again.
    4. Autorun INF: cutting the supply line
    5. Click start->run and type msconfig and click ok
    6. Go to startup tab look for regsvr and uncheck the option click OK.
    7. Click on Exit without Restart, cause there are still few things we need to do before we can restart the PC.
    8. Now go to control panel -> scheduled tasks, and delete the At1 task listed their.
  2. Open The Gates Of Castle
    1. Click on start -> run and type gpedit.msc and click Ok.
    2. Opening the gate of castle: starting the gepedit or msconfig
    3. If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from Windows XP Home Edition: gpedit.msc and then follow these steps.
    4. Go to users configuration->Administrative templates->system
    5. Find “prevent access to registry editing tools” and change the option to disable.
    6. Opening the gate of castle: Group Edit Policies
    7. Once you do this you have registry access back.
  3. Launch The Attack At Heart Of Castle
    1. Click on start->run and type regedit and click ok
    2. Go to edit->find and start the search for regsvr.exe,
    3. Launch the attack in the heart of castle: registry search
    4. Delete all the occurrence of regsvr.exe; remember to take a backup before deleting. KEEP IN MIND regsvr32.exe is not to be deleted. Delete regsvr.exe occurrences only.
    5. At one ore two places you will find it after explorer.exe in theses cases only delete the regsvr.exe part and not the whole part. E.g. Shell = “Explorer.exe regsvr.exe” the just delete the regsvr.exe and leave the explorer.exe
  4. Seek And Destroy the enemy soldiers, no one should be left behind
    1. Click on start->search->for files and folders.
    2. Their click all files and folders
    3. Type “*.exe” as filename to search for
    4. Click on ‘when was it modified ‘ option and select the specify date option
    5. Type from date as 1/31/2008 and also type To date as 1/31/2008
    6. Seek and destory enemy soldiers: the search option
    7. Now hit search and wait for all the exe’s to show up.
    8. Once search is over select all the exe files and shift+delete the files, caution must be taken so that you don’t delete the legitimate exe file that you have installed on 31st January.
    9. Also selecting lot of files together might make your computer unresponsive so delete them in small bunches.
    10. Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)
  5. Time For Celebrations
    1. Now do a cold reboot (ie press the reboot button instead) and you are done.

I hope this information helps you win your own battle against this virus. Soon all antivirus programs will be able to automatically detect and clean this virus. Also i hope Avast finds a way to solve this issues.

As a side note i have found a little back dog( winpatrol ) that used to work perfectly on my old system. It was not their in my new PC, I have installed it again , as I want to stay ahead by forever closing the supply line of these virus. You can download it form Winpatrol website.

Test UR Anti-virus

To test if your antivirus is in good shape you should do as in continuing:
Open Notepad and copy this text:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

the text should be in one horizontal line
Then save file as "eicar.com" including quotation-marks
After some seconds saving this file your antivirus should come with the message that this file is infected virus asking permision for its deletetion/clean.
This file is secure and its not gonna infect your computer in whatever way.It is a standart text developed by the European Institute for Computer Anti-virus Research (EICAR).Every antivirus is programed to load this file as a virus.

If your antivirus is not going to hack this file as a virus ,in your screen will appear DOS window with this text EICAR-STANDARD-ANTIVIRUS-TEST-FILE".If this happens then you should probably find some other Antivirus up to date,meaning your PC might
already being infected from viruses and your curent antivirus do not recognize them

Grab this Widget ~ Blogger Accessories