<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8297506829752175090</id><updated>2011-11-28T05:04:37.909+05:30</updated><title type='text'>Common Virus Problems</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://virusprobs.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://virusprobs.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Manoj KS</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8297506829752175090.post-3243719222924239679</id><published>2007-12-26T21:05:00.000+05:30</published><updated>2007-12-26T21:07:56.147+05:30</updated><title type='text'>Brontok Worm</title><content type='html'>&lt;span style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;Brontok is a computer worm which spreads through emails and USB drives. There are so many variants of brontok but they basically work similarly.How do I know if my system is infected?&lt;br /&gt;You can’t start Regedit.exe&lt;br /&gt;When trying to start any other registry editor, the system restarts&lt;br /&gt;The system also restarts when executing certain EXE files&lt;br /&gt;The presence of the following files:&lt;br /&gt;%WINDIR%\eksplorasi.pif&lt;br /&gt;%UserProfile%\Local Settings\Application Data\smss.exe&lt;br /&gt;%UserProfile%\Local Settings\Application Data\services.exe&lt;br /&gt;%UserProfile%\Local Settings\Application Data\lsass.exe&lt;br /&gt;%UserProfile%\Local Settings\Application Data\csrss.exe&lt;br /&gt;%UserProfile%\Local Settings\Application Data\inetinfo.exe&lt;br /&gt;%UserProfile%\Local Settings\Application Data\winlogon.exe&lt;br /&gt;%UserProfile%\Start Menu\Programs\Startup\Empty.pif&lt;br /&gt;%UserProfile%\Templates\WowTumpeh.com&lt;br /&gt;%WINDIR%\%CURRENT_USER%’s Setting.scr&lt;br /&gt;%WINDIR%\ShellNew\bronstab.exe&lt;br /&gt;All these files have the size of the worm’s main executable: 42,028 bytes(About 42 KB).&lt;br /&gt;&lt;br /&gt;What does it do?&lt;br /&gt;Disable Folder Options&lt;br /&gt;Disable Registry Editor&lt;br /&gt;Installs itself in the startup&lt;br /&gt;When in memory, it will restart the system if any program involving the registry is started&lt;br /&gt;&lt;br /&gt;How to remove Brontok?&lt;br /&gt;&lt;br /&gt;Download and run this &lt;a href="http://www.box.net/shared/yrmlj7oytz"&gt;brontok removal tool&lt;/a&gt; from Bitdefender. This tool will kill the brontok process, restore folder options and registry editor and fix system startup.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8297506829752175090-3243719222924239679?l=virusprobs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusprobs.blogspot.com/feeds/3243719222924239679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8297506829752175090&amp;postID=3243719222924239679' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/3243719222924239679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/3243719222924239679'/><link rel='alternate' type='text/html' href='http://virusprobs.blogspot.com/2007/12/brontok-worm.html' title='Brontok Worm'/><author><name>Manoj KS</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8297506829752175090.post-6546945953215866056</id><published>2007-12-26T20:57:00.000+05:30</published><updated>2007-12-26T21:05:16.823+05:30</updated><title type='text'>Unable To Open Hard Drive On Double Click</title><content type='html'>&lt;span&gt;&lt;span&gt;In some situation especially when anti-virus program has cleaned, healed, disinfected or removed a worm, trojan horse or virus from computer, there may be error happening whenever users try to open or access the drive by double clicking on the disk drive icon in Explorer or My Computer window to try to enter the drive’s folder. The problem or symptom happens in hard disk drive, portable hard disk drive or USB flash drive, and Windows will prompt a dialog box with the following message:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Windows Script Host&lt;br /&gt;&lt;br /&gt;Can not find script file autorun.vbs.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Sometimes you will be asked to debug the VBScript with error code of 800A041F - Unexpected ‘Next’.&lt;br /&gt;&lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Choose the program you want to use to open this file with:&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;In this case, the “Always use the selected program to open this kind of file” option is grayed out.&lt;br /&gt;&lt;br /&gt;The symptom occurs because when autorun.vbs is created by trojan horse or virus. The virus normally loads autorun.inf file to root folder of all hard drive or USB drive, and then execute autorun.bat file which contains script to apply and merge autorun.reg into the registry, with possible change to the following registry key to ensure that virus is loaded when system starts:&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]&lt;br /&gt;Userinit=userinit.exe,autorun.exe&lt;br /&gt;&lt;br /&gt;Finally, autorun.bat will call wscript.exe to run autorun.vbs.&lt;br /&gt;&lt;br /&gt;When antivirus or security software detected the autorun.vbs file as infected, the file will be deleted or removed or quarantined. However, other files (autorun.*） and registry value still referring to autorun.vbs, and this document no longer exists, hence the error when users double click to open a drive folder.&lt;br /&gt;&lt;br /&gt;To correct and solve this error, follow this steps:&lt;br /&gt;1.Run Task Manager (Ctrl-Alt-Del or right click on Taskbar)&lt;br /&gt;2.Stop wscript.exe process if available by highlighting the process name and clicking End Process.&lt;br /&gt;3.Then terminate explorer.exe process.&lt;br /&gt;4.In Task Manager, click on File -&gt; New Task (Run…).&lt;br /&gt;5.Type “cmd” (without quotes) into the Open text box and click OK.&lt;br /&gt;6.Type the following command one by one followed by hitting Enter key:&lt;br /&gt;del c:\autorun.* /f /s /q /a&lt;br /&gt;del d:\autorun.* /f /s /q /a&lt;br /&gt;del e:\autorun.* /f /s /q /a&lt;br /&gt;&lt;br /&gt;c, d, e each represents drive letters on Windows system. If there are more drives or partitions available, continue to command by altering to other drive letter. Note that you must also clean the autorun files from USB flash drive or portable hard disk as the external drive may also be infected.&lt;br /&gt;7.In Task Manager, click on File -&gt; New Task (Run…).&lt;br /&gt;8.Type “regedit” (without quotes) into the Open text box and click OK.&lt;br /&gt;9.Navigate to the following registry key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&lt;br /&gt;10.Check if the value name and value data for the key is correct (the value data of userint.exe include the path which may be different than C drive, which is also valid, note also the comma which is also needed):“Userinit”=”C:\WINDOWS\system32\userinit.exe,”&lt;br /&gt;&lt;br /&gt;If the value is incorrent, modify it to the valid value data.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8297506829752175090-6546945953215866056?l=virusprobs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusprobs.blogspot.com/feeds/6546945953215866056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8297506829752175090&amp;postID=6546945953215866056' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/6546945953215866056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/6546945953215866056'/><link rel='alternate' type='text/html' href='http://virusprobs.blogspot.com/2007/12/unable-to-open-har-drive-on-double.html' title='Unable To Open Hard Drive On Double Click'/><author><name>Manoj KS</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8297506829752175090.post-3412457652917599061</id><published>2007-12-26T20:53:00.000+05:30</published><updated>2007-12-26T20:54:44.607+05:30</updated><title type='text'>autorun.inf In Pen Drive</title><content type='html'>&lt;span style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;This virus is activated when we double click open the Pen Drive.&lt;br /&gt;The autorun file in that drive runs a .exe file to activate the virus.&lt;br /&gt;So, you must remove these two files (autorun.inf and a .exe file) from the pen drive.&lt;br /&gt;Otherwise, the virus will roll back whole things what we have done to remove them.&lt;br /&gt;These files may be hidden system files, to show the files, follow these steps:&lt;br /&gt;&lt;br /&gt;1. Select Run from Start menu.&lt;br /&gt;2. Type cmd and hit Enter.&lt;br /&gt;3. Type the pen drive letter with a colon (for eg: J: ) and hit Enter.&lt;br /&gt;4. Now type as following:&lt;br /&gt;attrib -h -a -r -s and hit Enter.&lt;br /&gt;5. Now, from My Computer, right click (do not double click) on the pen drive and select Open.&lt;br /&gt;6. Delete the files autorun.inf and a .exe file from there.&lt;br /&gt;Restart the system.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8297506829752175090-3412457652917599061?l=virusprobs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusprobs.blogspot.com/feeds/3412457652917599061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8297506829752175090&amp;postID=3412457652917599061' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/3412457652917599061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/3412457652917599061'/><link rel='alternate' type='text/html' href='http://virusprobs.blogspot.com/2007/12/autoruninf-in-pen-drive.html' title='autorun.inf In Pen Drive'/><author><name>Manoj KS</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8297506829752175090.post-7904499711067600357</id><published>2007-12-25T16:32:00.000+05:30</published><updated>2007-12-25T16:37:05.220+05:30</updated><title type='text'>Run Command Disabled</title><content type='html'>&lt;span style="font-family: arial;font-size:100%;" &gt;Open Group Policy(&lt;a href="http://systemprobs.blogspot.com/2007/12/task-manager-disabled.html"&gt;How?&lt;/a&gt;).Now you would see something like this.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/__gukWOcBWbQ/R3DkMfbdAGI/AAAAAAAAACI/DVN-29cvjPk/s1600-h/system5.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/__gukWOcBWbQ/R3DkMfbdAGI/AAAAAAAAACI/DVN-29cvjPk/s400/system5.gif" alt="" id="BLOGGER_PHOTO_ID_5147865277330686050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;&lt;br /&gt;Now you can see the option change it to enabled and then Not configured/&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8297506829752175090-7904499711067600357?l=virusprobs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusprobs.blogspot.com/feeds/7904499711067600357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8297506829752175090&amp;postID=7904499711067600357' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/7904499711067600357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/7904499711067600357'/><link rel='alternate' type='text/html' href='http://virusprobs.blogspot.com/2007/12/run-command-disabled.html' title='Run Command Disabled'/><author><name>Manoj KS</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/__gukWOcBWbQ/R3DkMfbdAGI/AAAAAAAAACI/DVN-29cvjPk/s72-c/system5.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8297506829752175090.post-7104917419097167657</id><published>2007-12-25T16:25:00.000+05:30</published><updated>2007-12-25T16:31:04.452+05:30</updated><title type='text'>Registry Editor Disabled</title><content type='html'>&lt;span style="font-family: arial;font-size:100%;" &gt;Open Group Policy(&lt;a href="http://systemprobs.blogspot.com/2007/12/task-manager-disabled.html"&gt;How?&lt;/a&gt;).&lt;br /&gt;Then you would see something like this:&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/__gukWOcBWbQ/R3DiyfbdAFI/AAAAAAAAACA/TR2OJhQFU4k/s1600-h/system4.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/__gukWOcBWbQ/R3DiyfbdAFI/AAAAAAAAACA/TR2OJhQFU4k/s400/system4.gif" alt="" id="BLOGGER_PHOTO_ID_5147863731142459474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;Now you can see the option change it to enabled and then Not configured.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8297506829752175090-7104917419097167657?l=virusprobs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusprobs.blogspot.com/feeds/7104917419097167657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8297506829752175090&amp;postID=7104917419097167657' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/7104917419097167657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/7104917419097167657'/><link rel='alternate' type='text/html' href='http://virusprobs.blogspot.com/2007/12/registry-editor-disabled.html' title='Registry Editor Disabled'/><author><name>Manoj KS</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/__gukWOcBWbQ/R3DiyfbdAFI/AAAAAAAAACA/TR2OJhQFU4k/s72-c/system4.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8297506829752175090.post-3171377501485777287</id><published>2007-12-25T16:00:00.001+05:30</published><updated>2007-12-25T16:24:58.574+05:30</updated><title type='text'>Task Manager Disabled</title><content type='html'>&lt;span style="font-family: arial;font-size:100%;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Problem:&lt;/span&gt;&lt;br /&gt;When you press Ctrl+Alt+Del, it shows Task Manager Disabled by Your Administrator.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Cure:&lt;/span&gt;&lt;br /&gt;To cure this problem, simply open Run command(Start --&amp;gt; Run) and type gpedit.msc and hit Enter. Then you will get the following screen:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;(Most probably, your Run command would also have been disabled. In t&lt;/span&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;hat case, open Start--&amp;gt;Programs--&amp;gt;Accessories--&amp;gt;Command Prompt. Then type gpedit.msc there and hit Enter to open Group Policy).&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/__gukWOcBWbQ/R3DeD_bdABI/AAAAAAAAABg/TAwAcAsndBg/s1600-h/system1.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/__gukWOcBWbQ/R3DeD_bdABI/AAAAAAAAABg/TAwAcAsndBg/s320/system1.gif" alt="" id="BLOGGER_PHOTO_ID_5147858534232031250" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;OR&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/__gukWOcBWbQ/R3Dfl_bdADI/AAAAAAAAABw/yJFDIm1a5So/s1600-h/system2.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/__gukWOcBWbQ/R3Dfl_bdADI/AAAAAAAAABw/yJFDIm1a5So/s400/system2.gif" alt="" id="BLOGGER_PHOTO_ID_5147860217859211314" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Group Policy&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/__gukWOcBWbQ/R3DgK_bdAEI/AAAAAAAAAB4/67y_dTyDiKY/s1600-h/system3.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/__gukWOcBWbQ/R3DgK_bdAEI/AAAAAAAAAB4/67y_dTyDiKY/s400/system3.gif" alt="" id="BLOGGER_PHOTO_ID_5147860853514371138" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;&lt;br /&gt;Here you will find RemoveTask Manager and all. Now what you will do first enable the feature by double clicking on the option and selecting the enable option and then again changing back to Not Configured.&lt;br /&gt;Now see your task manager is back.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8297506829752175090-3171377501485777287?l=virusprobs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusprobs.blogspot.com/feeds/3171377501485777287/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8297506829752175090&amp;postID=3171377501485777287' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/3171377501485777287'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8297506829752175090/posts/default/3171377501485777287'/><link rel='alternate' type='text/html' href='http://virusprobs.blogspot.com/2007/12/task-manager-disabled.html' title='Task Manager Disabled'/><author><name>Manoj KS</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/__gukWOcBWbQ/R3DeD_bdABI/AAAAAAAAABg/TAwAcAsndBg/s72-c/system1.gif' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
