Showing posts with label Computer virus. Show all posts
Showing posts with label Computer virus. Show all posts

Friday, October 3, 2008

NTDetec1 virus removal

Another name for Ntdetec1.exe is W32.Ceted. W32.Ceted is a worm that copies itself to all shared and removable drives.

Most Common Symptoms Of Ntdetec1.exe Virus are:
  1. Task Manager doesn’t open or it is blocked.
  2. Regedit or registry editing has been disabled.
  3. Folder Options are not visible under File Menu --Tools
  4. Creates a hidden folder C:\ntdetec1

Analysis:

NTdetec1.exe executes itself with the following name list process.

  • \ntdetec1\ntdetec1.exe
  • \ntdetec1\cmrss.exe
  • \ntdetec1\run.exe
  • \ntdetec1\shell32.exe

Removal Procedure For Ntdetec1.exe:

  1. Open Start >> Run and type cmd and press enter.
  2. Type the following commands :
    taskkill /im cmrss.exe
    taskkill /im ntdetec1.exe
    taskkill /im shell32.exe
    attrib ntdetec1 -s -h /s /d
  3. Locate the folder ntdetec1 in your operating system root directory and delete it permanently.
  4. Type regedit in run window and press enter. This will open registry editor. Locate the key as shown below and delete it.
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\ Run\"winlogon" = "C:\ntdetec1\run.exe"

Monday, August 4, 2008

W32.USB Worm

It spreads through Pen,USB,Thump disk thats why the name.

It shows messages like

"I DNT HATE MOZILLA BUT USE IE OR ELSE..."

"USE INTERNET EXPLORER U DOPE"

"Orkut is banned you fool, The administrators didnt write this program guess who did?? MUHAHAHA!!"

Use the following procedure for removal.

1. Go to the processes tab in task bar using Ctrl+Alt+Delete

2. Look for svchost.exe under the image name with username as current logged user.

3. Kill those files using delete key or right click and chose 'End Process'. It will give you a warning, Press Yes.

4. Do not kill svchost.exe with system, local service or network service.

5. Now open My Computer

6. In C Drive locate C:\heap41a and delete, it's hidden folder.

7. Now go to Start --> Run and type Regedit

8 Go to the menu Edit --> Find

9. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"

10. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes

11. Now close the registry editor.

Now the virus is gone. But be sure to delete the autorun.inf file and any folder whose name ends with .exe in the pen drive.


Subscribe free via email

Enter your email address:

Delivered by FeedBurner

...