JS

Saturday, June 14, 2008

How to Manually Remove Viruses From Your System



Note: This solution will work only against those Viruses which does not infect Windows own Exe files e.g like explorer.exe

Virus Symptoms

You may have seen some unexpected things that should not happen. Some of the symptoms of viruses are:

Disables Task Manager

Disables Registry Editor

Disables Command Prompt

Sometime you have no application open but CPU usage goes over 50%

My Computer Drives not opening by Double Click

Automatic Shutdown

Computer Slows down

Hidden Files will not be showing

Folder Options will be disappear

Manual Removal

If you have tried all the solutions listed on our site and still could not disinfect your system then try to manually remove the virus using the instructions below. There are four steps
Caution: While the manual
process is going on do not open any My Computer drive through My
Computer

1. Process Termination

In order to complete the
instructions below. You need to have Process Explorer and Autoruns.
Download them separately

Powerexes.exe

Close and exit all programs (even from tray) except Internet Explorer
or your internet browser.

Run process explorer by typing procexp in the start menu

Run and do as illustrated.


1111.jpg

After collapsing
1212.jpg
procexp.exe is Process Explorer’s own process
All the system process are collapsed in the system tree, so if you see a process like winlogon.exe in explorer tree then it is surely a virus
If you do see any suspicious process, Processes can be sought for their suspiciousness at http://www.processlibrary.com/
Right click on it if the process is found and then properties. In the path: field copy the path and Open Run Dialogue and paste the path there
Now terminate the suspicious task in process explorer
If the same process starts again then suspend the process by right clicking on it and click suspend on the menu. Remove the name of the application from path now listing only folder.

e.g If you have copied C:\WINDOWS\system32\mspaint.exe then remove mspaint.exe and you will see C:\WINDOWS\system32\ this in the Run Dialogue.
How to Manually Remove Viruses From Your System

2. File Deletion

The second step is deleting files. Download 7-ZIP which will show you all hidden files and go through the root path of every drive

screenshot010.jpg

Delete .exe and autorun.inf like

ravmon.exe, smss.exe,Funny UST Scandal.exe

But do not delete these files as these are system files

autoexec.bat, boot.ini, bootmgr,config.sys, io.sys, msdos.sys, ntdetect.com, pagefile.sys,ntldr, hiberfil.sys

3. Removal of startup entries

Now you have successfully terminated virus process the next thing is to remove those virus files which run upon system start.
Open Autoruns by typing autoruns in the Run Dialogue. Wait while refreshing completes.

In the Options –> Hide Microsoft Entries. And click Refresh button on the interface OR Close the program and start again

autoruns.jpg

After scanning completes select Logontab and uncheck all the entries be sure do not unselect any Microsoft Entry.Restart system for the changes to take effect.

4. Restoring Windows Default settings

Use Smart Anti-Virus to restore some settings
Smart Anti-Virus

Now scanning your system for an fully functional Anti-Virus will be the last suggestion as my own Anti-Virus can only catch almost 10 viruses

Troubleshooting

Incase of any problem. you did a wrong move. Open Autoruns, in the Options –> Unselect Hide Microsoft Entries. And click Refresh button on the interface OR and select all entries .Close the program and start your system again.

No comments:

Post a Comment