Buying A New Car

There are many things that you must consider when buying a new car. Most will have to do with the car itself such as what model to buy- the options you want to add- and the price of the car. However there is one thing that it always pays to check out first- and that is- who are you buying the car from.

CAR INSURANCE FOR LADY DRIVERS

Car insurance companies prefer lady drivers to their gentlemen counterparts because they are considered as much less risky drivers.It is not that the accident rates of ladies are low. They face as many accidents as males do

AUTO LOAN NEW CAR

Is it time to get a new car? Do you want to purchase a new car to replace your current worn down vehicle? If yes is your answer- then you might want to think about your purchase and getting a loan for your new investment

CAR INSURANCE

America has become a culture of cars-SUV's- minivans and sports coupes. With all this traveling in and out- back and forth around the maze that is the United States infrastructure

NEW CAR LEASING TIPS

If you do have an accident with the outside or the inside of the car - you may have to pay for the cost. You will also only be allowed to put on so many miles in your lease period. This is hard for many people that do drive a lot

Showing posts with label Virus Nadia Saphira. Show all posts
Showing posts with label Virus Nadia Saphira. Show all posts

Wednesday, June 3, 2009

8 Steps To Clean Virus Nadia Saphira

Here are eight steps to clean the virus' Nadia Saphira 'alias' W32/VBTroj.AOQB' on the computer:

1. We recommend you disconnect the computer from the network will be cleaned
2. Turn off 'System Restore' for the virus cleaning process (for Windows XP / Vista).
3. Turn off the virus active in memory. Use tools for task managers, such as CProcess (you can download on the site Nirsoft)

4. Make a kill process, in some file that the virus is active are:
  • C:\Documents and Settings\All User\Start Menu\Programs\Startup\lan.exe
  • C:\WINDOWS\system32\misconfig.exe
  • C:\WINDOWS\taskmgr.exe
5.Delete registry string that has been created by the virus. To facilitate the registry can use the script below.

[Version]
Signature="$Chicago$"
Provider=Vaksincom Oyee
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKCR, batfile\shell\open\command,,,"""%1"" %*"
HKCR, comfile\shell\open\command,,,"""%1"" %*"
HKCR, exefile\shell\open\command,,,"""%1"" %*"
HKCR, piffile\shell\open\command,,,"""%1"" %*"
HKCR, lnkfile\shell\open\command,,,"""%1"" %*"
HKCR, scrfile\shell\open\command,,,"""%1"" %*"
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,
HKLM, SOFTWARE\Classes\exefile\DefaultIcon,,,""%1""
HKLM, SOFTWARE\Classes\exefile,,,"Application"
HKLM, SOFTWARE\Classes\exefile,infotip,0, "prop:FileDescription;Company;FileVersion;Create;Size"
HKLM, SOFTWARE\Classes\exefile,TileInfo,0, "prop:FileDescription;Company;FileVersion"
HKCU, Software\Microsoft\Command Processor, AutoRun,0,
HKLM, SOFTWARE\Microsoft\Command Processor, AutoRun,0,
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue, 0x00010001,1
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, DefaultValue, 0x00010001,2
[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, nofind
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer, nofind
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sessmgr.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SPYXX.exe

* Use the notepad, then save with the name "repair.inf * *" (use the Save As Type option to be All Files so that the error does not occur).
* Run repair.inf with a right click, then select install.
* We create a file on the computer that repair.inf clean, so that the virus is not active.

6. Remove the file that the virus has characteristics as follows:

* Icon application / folder
* Ext. exe
* Size 69 & kb 17 kb
* Note:
* We show the hidden files in order to simplify the search process in the virus file.
* To facilitate the search process should use the "Search Windows" with the filter file **. exe **. * & * have this size 69 KB & 17 KB.
* Delete the file that the virus usually have the same modified date.

7. Unhide the hidden folders on the drive or flash. Use the command 'attrib' in the command prompt.

* Click 'Start'
* Click the 'Run'
* Type in 'CMD' and press the Enter key
* Move the cursor position to drive Flash Disk
* * Then type the command attrib-s-h-r / s / d *, then press the enter

8. For optimal cleaning and prevent re-infection, you should use the anti-ter-virus update and recognize this well.