Lately ,the users computer / Notebook / Laptop, especially those using Windows XP shortcut Inkdipusingkan virus by the presence of virus / malware which constantly make a duplicate folder or new folder microsoft, applications, music and more. Worse yet ... foder-folders can not be diDEL or if terDEL, if you click on a folder ..., then the folders appear again.
Tutorial below hopefully can help overcome the problems that her computer got a virus / malware shortcut folder ... lnk harry potter, microsoft, new folders and so on.
According to the hypothesis of how the virus / malware is as follows:
* Virus / malware this will put the files database.mdb, Thumb.db, Autorun.inf, shortcut folder harry potter .... Lnk, folder shortcut microsoft, new folders and shortcuts pd my document folder.
* Virus / Malware This will activate the file wscript.exe and Thumb.db file located in system32 folder, the folder window to run the file database.mdb on my document.
* Shortcut folders'd be associated with the file Thumb.db.
* If you open the shortcut folders before it will activate the wscript.exe file and folder shortcuts Thumb.db files that exist on your computer, Thumb.db file and the file autorun.inf in all drives C. If your computer is infected with the virus / malware is the entire C drive on your computer will have duplicate an existing shortcut folder on your computer, Thumb.db file and the file autorun.inf. It will also scan drives A, CD ROM, flash and your network as a medium for distributing viruses / malware. and will create a duplicate
There are 2 ways to mengDEL virus:
1. By using the updated antivirus.
Antivirus which can recognize the virus (I only had 3 antivirus), namely: 1. AVG: detected as VBS Worm. AVG will mengDEL all shortcut duplicate folders and files was the primary virus. 2. Norton Antivirus 2009: detected as VBS Runauto. Norton will mengDEL Thumb.db files in all drives C. You can mengDEL Autorun.inf file and folder shortcuts all the duplicates manually. 3. Avira Antivir Premium: DR/Agent.JP.4 detect it as malware. Antivir will mengDEL Thumb.db files on all drives C. You can mengDEL Autorun.inf file and folder shortcuts all the duplicates manually.
2. With the manual method.
1. Turn off System Restore.
2. Turn off the virus using tools CProcess wscript.exe / CurrProcess (you can DownLoad via google). Run CProcess, search the name wscript.exe process tab then right click and click the kill selected procesess.
3. Open windows explorer, click tools menu option, folder option, view, click show hidden files and folders, click / DEL, check the Hide extensions for known file types and Hide protected operating system files.Klik OK.
4. Go to your documents. DEL database.mdb file.
5. Click the Search button. Click All Files and Folders. in the All or part of the file name type: Thumb.db, pd click the Look in my computer. DEL all the files which have been found. Repeat the steps above and DEL all the files which are found again.
6. Click the Search button. Click All Files and Folders. pd the All or part of the file name type: Autorun.inf, pd click the Look in my computer. DEL all the files which have been found. Repeat the steps above and DEL all the files which are found again.
7. In step 6 is actually a virus is gone or no longer active but there was still some duplicate shortcut folder dbwt by virus / malware earlier.
8. If you want to remove it also, you have to be careful at all between the shortcuts that dbuat by the virus with the default Windows shortcut. The hallmark of the shortcut folders created by a virus that is when we pointed to that folder will display a link from the shortcut that is in the direction windows/system32. That's who we should DEL shortcut.
9. How to locate a folder shortcut is: Click the Search button. Click All Files and Folders. pd the All or part of the file name type: *. lnk, pd click the Look in my computer. You should choose based on the characteristics of a shortcut folder created by the above virus.
10. FOR can mengDEL registry created by the virus using HijackThis tool. (Can Download via google). Click Scan system only and looking at the HKCU \ ... \ ... database.mdb, HKLM \ ... \ .... who associated with windowsxp cd (I forget the name of its length, as well as to who is sometimes there are sometimes not), also HKCU \ ... \ .... disableregedit = 1. click the button fixed.
11. Now restart your computer. Actually, if we do not mengDEL registry before (step 10) is not a problem, but at the time of restarting windows dialog box will appear 2 distinguished the first point that we find a file database.mdb DEL earlier, the latter asked for the windows xp cd. click Ok aja has no problem. Then we'll probably regedit disabled by the virus. It is also not problematic if you do not often brain-tweaking the windows registry. Method To counteract the virus came back.
This virus works if you click the new folder shortcut harry potter, microsoft. After we click the shortcut folder then he will find a file which is located in the folder wsript.exe windows system32 folder. wscritp.exe active with the virus will start spreading. So the key for active virus is pd file wscript.exe. For that we have to turn off the road merename_nya wscript.exe.
The way is:
1. Open windows explorer, click tools menu option, folder option, view, click show hidden files and folders, click / DEL and check the Hide extensions for known file types and Hide protected operating system files.Klik OK.
2. Open the folder C: \ Windows \ system32 \ dllcache. Folder is a collection of backup files from the files in the System32 folder. Find the file wsript.exe then right-click rename for example a wscriptx.exe. Then BKA C: \ Windows \ system32, locate the file wsript.exe then right-click rename such a wscriptx.exe too.
may be useful for you all ^ _ ^
NB: use the latest smadav also, artav or artav installer / artav latest portable & esetNOD32 Norman malware cleaner is the latest and updated.
Noteworthy is: Use antivirus must alternately / should not be installed simultaneously, (Install after scans on Uninstall)