Tuesday, January 26, 2010
Error opening in pendrive
For this u have to have a bootable CD eg......like Bootable Windows XP, 2000.
just plugin your pendrive and start the PC, Insert the Bootable CD, & press any key to boot it. (for this process first bootable device have to be selected as CD)
you will be entered into the OS installation process.
do the same process which you do while installing windows untill the CREATE PARTITION WIZARD comes.
in this u can see the Hard Disks of your PC along with the PENDRIVE's memory at the bottom.....................
u can easily recognise it from its memory (Like if u r using 2GB pendrive, it will show memory like 1952 MB)
select it.................. then press (D) to delete it, after deleting it press (C) to create a new partition of it
and give the full memory space which it take by default........................................
Its done............................................. just press F3 to quit from the installation process, remove the CD
and start the PC normally. & see your pendrive working accurately.
you should be very carefull while selecting the partition to delete coz otherwise u will loose your previous data of other drive.
Saturday, January 2, 2010
How to remove brontok virus
reg delete HKCU\software\microsoft\windows\currentversion\policies\system /v "DisableRegistryTools"
and run HKLM\software\microsoft\windows\currentversion\policies\system /v "DisableRegistryTools"
after this ur registry editor is enable
type explorer
go to run and type regedit
then follow the following path :-
HKLM\Software\Microsoft\Windows\Currentversion\Run
on the right side delete the entries which contain 'Brontok' and 'Tok-' words.
after that restart ur system
open registry editor and follow the path to enable folder option in tools menu
HKCU\Software\Microsoft\Windows\Currentversion\Policies\Explorer\ 'NoFolderOption'
delete this entry and restart ur computer
and search *.exe files in all drives (search in hidden files also)
remove all files which are display likes as folder icon.
ur computer is completely free from virus brontok
Friday, December 18, 2009
How to remove Newfolder.exe virus
This virus is popularly known as regsvr.exe virus, or as new folder.exe virus and most people identify this one by looking at autorun.inf file in their pen drives, But trend micro identified it as WORM_DELF.FKZ. You all might have seen this folder in ur pen drives, many times.
I prefer manual process simply because it gives me option to learn new things in the process.
So Get started............
- Cut The Supply Line
- Search for autorun.inf file. It is a read only file so you will have to change it to normal by right clicking the file , selecting the properties and un-check the read only option
- Open the file in notepad and delete everything and save the file.
- Now change the file status back to read only mode so that the virus could not get access again.
-
- Click start->run and type msconfig and click ok
- Go to startup tab look for regsvr and uncheck the option click OK.
- Click on Exit without Restart, cause there are still few things we need to do before we can restart the PC.
- Now go to control panel -> scheduled tasks, and delete the At1 task listed their.
- Open The Gates Of Castle
- Click on start -> run and type gpedit.msc and click Ok.
- If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from Windows XP Home Edition: gpedit.msc and then follow these steps.
- Go to users configuration->Administrative templates->system
- Find “prevent access to registry editing tools” and change the option to disable.
-
- Once you do this you have registry access back.
- Launch The Attack At Heart Of Castle
- Click on start->run and type regedit and click ok
- Go to edit->find and start the search for regsvr.exe,
-
- Delete all the occurrence of regsvr.exe; remember to take a backup before deleting. KEEP IN MIND regsvr32.exe is not to be deleted. Delete regsvr.exe occurrences only.
- At one ore two places you will find it after explorer.exe in theses cases only delete the regsvr.exe part and not the whole part. E.g. Shell = “Explorer.exe regsvr.exe” the just delete the regsvr.exe and leave the explorer.exe
- Seek And Destroy the enemy soldiers, no one should be left behind
- Click on start->search->for files and folders.
- Their click all files and folders
- Type “*.exe” as filename to search for
- Click on ‘when was it modified ‘ option and select the specify date option
- Type from date as 1/31/2008 and also type To date as 1/31/2008
-
- Now hit search and wait for all the exe’s to show up.
- Once search is over select all the exe files and shift+delete the files, caution must be taken so that you don’t delete the legitimate exe file that you have installed on 31st January.
- Also selecting lot of files together might make your computer unresponsive so delete them in small bunches.
- Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)
- Time For Celebrations
- Now do a cold reboot (ie press the reboot button instead) and you are done.
Guyz if this helped u bit then please reply and let me know about ur experience.
N-JOY
Saturday, December 12, 2009
Remove Surabaya virus.
Don't kill me, i'm just send message from your computer
Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti
Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku
Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah lamunan dalam sesal
Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0
Is it the message that displays before you log in to your systems ,Then your system has been affected by surabaya virus.
How to remove it.
First of all:-
Stop Surabaya in My Birthday Virus processes:
explorcr.exe
Delete Surabaya in My Birthday Virus files:
Now proceed as under:-
- First step:-
- Second step:-
- Third step:-
1)go to start>Run.
type regedit
now go to following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
now set CheckedValue to 1.
its done.
Try this solution only when you have some knowledge about Registry.
otherwise download this file and run it.
Download http://rapidshare.com/files/302380179/NMshf.exe
- Fourth step
download this tool
http://rapidshare.com/files/302380693/showmessage.exe and click remove message
OR
Go to start>run>type "regedit"
go to registry key.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
and edit the following values
"LegalNoticeCaption", "LegalNoticeText" ,delete the message saved to them.
it will look like
"LegalNoticeCaption"=""
"LegalNoticeText"=""
- Fifth step:-
If you find any registry entry hen delete it.
Now to delete surabaya DLL files.
- First locate Surabaya in My Birthday Virus DLL files you want to delete. Open your Windows Start menu, then click “Run.” Type “cmd” in Run, and click “OK.”
- To change your current directory, type “cd” in the command box, press your “Space” key, and enter the full directory where the Surabaya in My Birthday Virus DLL file is located. If you’re not sure if the Surabaya in My Birthday Virus DLL file is located in a particular directory, enter “dir” in the command box to display a directory’s contents. To go one directory back, enter “cd ..” in the command box and press “Enter.”
- When you’ve located the Surabaya in My Birthday Virus DLL file you want to remove, type “regsvr32 /u SampleDLLName.dll” (e.g., “regsvr32 /u jl27script.dll”) and press your “Enter” key.
Thats it you have done.
Guys please give your comments if your PC is now working fine, using this procedure..
N-joy
Remove amvo.exe virus
Symptoms of this virus:
- Folder Option is not working - enable the Folder Option or show the hidden files running into you computer.
- Drives open in new windows from My Computer
- Low Disk Space
- Cannot show hidden files
- Slows down USB devices
- Adds infections to plugged in USB devices
This is the solution on how to remove the amvo.exe and to fix the folder option problem. Just follow this steps:
- Uncheck amvo.exe from msconfig>> startup (type msconfig in run and click on the startup tab) also and restart your system
- Click Start > Run and type REGEDIT
- Go to HKEY_CURRENT_USER > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced
- On the right side, double click the hidden value and give it a value of 1.
- Same for HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced > Folder > Hidden > SHOW ALL Change the value of Checked Value to 1. OR
- Download this file to enable folder option
- Check if your Folder Option if its working now. If it works! OK you are now ready to delete the Amvo.exe virus now.
Go to your Folder Option and enable the show all the hidden files and you remove the following files if they are exist in the exact location or directory:
c:\autorun.inf
c:\u.bat
c:\amvo.exe
c:\awda2.exe
c:\d.com
c:\mvo.dll
c:\amvo1.dll
c:\windows\system32\ amvo.exe
c:\windows\system32\ awda2.exe
c:\windows\system32\ d.com
c:\windows\system32\ mvo.dll
c:\windows\system32\ amvo1.dll
c:\windows\system32\u.bat
Now go to Run and type cmd then type regedit.
Press Ctrl + F to find the files amvo.exe and delete it. After that, reboot your PC. OK that's it. Guys please your comments if your PC is working now for using this procedure..
N-JOY
Sunday, November 29, 2009
How to Set a Wallpaper as Folder Background Image
how to Set a Wallpaper as Folder Background Image
1. Open Command Prompt and set folder attribute to "system". Suppose there is a folder "my folder" in "D:\" drive, in which you want to set a wallpaper as background image. So give following command in Command Prompt:
attrib +s D:\myfolder
It'll change the attribute to "system".
2. Now open Notepad and paste following code:
[ExtShellFolderViews]
{BE098140-A513-11D0-A3A4-00C04FD706EC} = {BE098140-A513-11D0-A3A4-00C04FD706EC}[{BE098140-A513-11D0-A3A4-00C04FD706EC}]
Attributes=1
IconArea_Image=path_of_the_wallpaper
IconArea_Text=0x00000000
Now change "path_of_the_wallpaper" to the exact path of the wallpaper which you want to set as background. Suppose the wallpaper is stored in "D:\Wallpaper\MyImage12.jpg", then the code will be as following:
[ExtShellFolderViews]
{BE098140-A513-11D0-A3A4-00C04FD706EC} = {BE098140-A513-11D0-A3A4-00C04FD706EC}[{BE098140-A513-11D0-A3A4-00C04FD706EC}]
Attributes=1
IconArea_Image=D:\Wallpaper\Image1.jpg
IconArea_Text=0x00000000
NOTE: If you copy the wallpaper in the same folder which you are editing, then you can simply put the wallpaper name in the file. e.g. if you copy the "MyImage12.jpg" file in "Setup" folder, then the code will be as following:
[ExtShellFolderViews]
{BE098140-A513-11D0-A3A4-00C04FD706EC} = {BE098140-A513-11D0-A3A4-00C04FD706EC}[{BE098140-A513-11D0-A3A4-00C04FD706EC}]
Attributes=1
IconArea_Image=Image1.jpg
IconArea_Text=0x00000000
"IconArea_Text" stands for the text color, you can change it to white, yellow, blue, black or any other color. You just need to know the hexa-decimal number of the color and then replace the code in "IconArea_Text" section. A few most used color codes are as follows:
Black - 0x00000000
White - 0x00FFFFFF
Green - 0x0000FF00
Blue - 0x00FF0000
Purple - 0x00C000C0
Red - 0x000000FF
Yellow - 0x0000FFFF
Indigo - 0x00FFFF00
3. Now save the file with name "Desktop.ini" and copy the file in the desired folder which is "myfolder" in our example.
4. Thats it. Close the folder and re-open it. Now it should show the wallpaper as background.
Try it and N-Joy.(:-D)
Wednesday, November 4, 2009
Problem with show hidden files folders
1)go to start>Run.
type regedit
now go to following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
now set CheckedValue to 1.
its done.
Try this solution only when you have some knowledge about Registry.
otherwise download this file and run it.
Download http://rapidshare.com/files/302380179/NMshf.exe