Cool Smileys & Winks
Showing posts with label Virus And Spyware. Show all posts
Showing posts with label Virus And Spyware. Show all posts

How to remove frmwrk32.exe

0 comments

Symptoms:
  • Can not change background wallpaper from display properties
  • Task manager disable
How to remove:
  1. Download this applicationn. Click here.
  2. End this image name:
  • frmwrk32.exe
  • ntdll64.exe
  • Fvupir.dll
   3. Delete this file:
  • "c:\windows\system32\frmwrk32.exe"
  • "c:\WINDOWS\Fvupir.dll"
  • "C:\WINDOWS\agifiqem.dll"
  • "c:\docume~1\user\locals~1\temp\ntdll64.dll"
  • "c:\docume~1\user\locals~1\temp\mousehook.dll"
  • "c:\windows\system32\ntdll64.exe"
   4. Download here to enable change wallpaper in your desktop properties.

       or
  1. Start > Run > gpedit.msc
  2. Under User configuration > Click [Administrative Templates\Control Panel\Display\]
  3. There will be a value named "Prevent changing wallpaper" > Set it to "Not Configured"
       or
  1. Run "Regedit".
  2. Navigate to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Windows\CurrentVersion   \policies
  3. If you see a folder (key) "ActiveDesktop" select it. If not, make a new key and label it "ActiveDesktop".
  4. If you see "NoChangingWallPaper", double-click the DWORD value and set it to "0". Otherwise, you need to create a new DWORD value of "NoChangingWallPaper"    and set it to "0".
  5. Try changing your wallpaper. If this fix doesn't solve the problem, you may also need to make the above registry changes at location: HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Policies.



What is frmwrk32.exe

1 comments

This is cloaked malware and malware downloader.

Also use the following names:
  • 64439744.EXE
  • 71698828.DAT
  • VRTA.TMP
  • TOP[n].TXT
  • 6.TMP
  • 8.TMP
  • 93511318.DAT
  • 92837428.BAD
  • 11244301.EXE
  • LOADER[n].EXE
  • WJQS.EXE
  • A.EXE
  • SVCHOST.EXE
  • FRMWRK32/A.EXE
  • FRMWRK32/A0051148.EXE
  • FRMWRK32/U-STORE[n].GIF
  • FRMWRK32/FRMWRK32.EXE
  • RDL4.TMP
  • 45049727.EXE
  • 22690229.EXE
  • 303350.EXE
  • 06696265.EXE
  • 78935166.EXE
  • LOADER.EXE
File activity:
  • Deletes c:\windows\system32\frmwrk32.exe
  • Copies filec:\windows\system32\frmwrk32.exe to c:\windows\system32\frmwrk32.exe
  • Creates c:\windows\system32\ntdll64.exe
  • Creates c:\windows\system32\win32hlp.cnf
  • Creates c:\windows\system32\warning.gif
  • Creates c:\windows\system32\ahtn.htm
  • Creates c:\docume~1\user\locals~1\temp\cscript.exe
  • Creates c:\windows\cscript.exe
  • Deletes c:\docume~1\user\locals~1\temp\ntdll64.dll
  • Creates c:\docume~1\user\locals~1\temp\ntdll64.dll
  • Deletes c:\docume~1\user\locals~1\temp\mousehook.dll
  • Creates c:\docume~1\user\locals~1\temp\mousehook.dll
  • Moves c:\windows\system32\userinit.exe to c:\windows\system32\init32.exe
  • Copies filec:\windows\system32\ntdll64.exe to c:\windows\system32\userinit.exe
  • Copies filec:\windows\system32\ntdll64.exe to c:\windows\system32\dllcache\userinit.exe
  • Deletes c:\windows\system32\ntdll64.ex
Registry Activity:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System DisableTaskMgr value:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NoSetActiveDesktop value:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop NoChangingWallpaper value:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NoActiveDesktopChanges value:
  • HKEY_CURRENT_USER\Software 2a422c91-6984-47e4-94be-04c4fad5f8d8 value:
  • HKEY_CURRENT_USER\Software 1099ce4a-ff51-4a8d-ab3c-c74b9c06e46f [REG_DWORD, value: 0000009F]
  • HKEY_CURRENT_USER\Software\Microsoft WinId {564F3BEB-5C60-48E6-A249-2EF6CE6B0C31}


How to remove ntdll64.dll

0 comments



Possible name:

  • AntiSpyware 2008
  • Antivirus XP 2009
Symptoms:
  • Wallpaper change into "Warning!"
  • Can not change desktop wallpaper
  • Can not open Task Manager.
How to remove this trojan:
  1. Uninstall this files located in "C:\ Program Files\Antispyware 2008\Antispyware-2008.exe"
  2. Go to "My Computer" or "Computer". Access your "C:\windows\system32" folder.
  3. Find this file named "ntdll64.dll".
  4. Delete this files.
The name of the trojan may be different. It is Usually named "Antispyware" or "Antivirus".

How to detect you have invisible virus

0 comments

Do you see this icon in your pen drive or flash drive?



Instead of this?


What actually this mean? If you haven't changed an icon for you removable disk, that mean you removable disk have a invisible virus.

Usually, this virus is known as ISE32.exe. Even though your antivirus detect and delete the virus but the virus still intact to your registry.

To remove:
Please refer to this link,click here.


Protect your computer from USB pen-drives virus

4 comments

ninja!
Virus Conficker (aka Downup, Downadup and Kido) disables many system services like computer Automatic Update, reset System Restore Point and etc. One of the main causes of virus infection is careless open of pen drives (USB sticks). Because of its auto run feature, virus can easily get in to your system. Ninja designed to protect computers from virus infection through USB pen disks.

Feature:
LAN Chat box

system_tray

Available:
  • Windows XP
  • Windows Vista.
Download here.

Anti-Virus for Windows 7 Beta

2 comments


http://www.cartoonstock.com/newscartoons/cartoonists/rma/lowres/rman3882l.jpg
image courtesy:CartoonStock

Windows 7 Beta is not immune to computer virus . So here some list of anti-virus that currently can be used for Windows 7.

http://www.storageworldconference.com/Speaker%20logos/symantec-logo-300dpi.jpg

Norton 360 3.0 beta works on Windows 7 Beta.



Kaspersky Internet Security 2009.



AVG Internet Security and AVG Anti-Virus works with Windows 7.



NOD32 works in Windows 7 Beta.



Avast Home (Free) and ESET Smart Security works well.



Bitdefender works well.



McAfee VirusScan Enterprise + AntiSpyware Enterprise 8.7.0i is working without any problems.



Avira AntiVir Personal and Avira Premium Security Suite Version 9 works fine.

http://www.spyzone.com/media/ccp0/prodsm/computer-firewall.jpg

Subelt VIPER working.

How to remove ISE32.EXE

1 comments

ISE32.exe usually hides on C:\RECYCLER\. It also create a folder name 'RECYCLER' and 'autorun.inf'
on your thumb drive or external drive.

ISE32.exe can also use the following names:
  • SUSPEITOS/WINDOSS.EXE
  • EXE32.EXE
  • IRZ[n].EXE
  • WINDOSS.EXE
  • 40378584.DAT
  • 92239921.DAT
  • 23419202.DAT
  • KK2[n].EXE
  • FOLDER.EXE
  • 10220403.EXE
  • K85DFDRFSDGT[n].EXE
  • SS1[n].EXE
  • B143GT[n].EXE
  • BOT[n].EXE
  • 64970665.EXE
  • SWDF.EXE
  • SYSTI.EXE
  • SYESTE.EXE
  • SYSTR.EXE
  • SYSTQ.EXE
  • SYSTZ.EXE
  • JHKJKJ.EXE
  • SYRSF.EXE
  • SYSF.EXE
  • SYWQT.EXE
  • DYDE.EXE
  • AVVAQ.EXE
  • IS2[n].EXE
  • 95741567.EXE
  • JUF34.EXE
  • WINDLL.EXE
  • IRC[n].EXE
How to detect you have this virus?
  1. Insert a flash disk, thumb drive or etc.
  2. If it has a folder name 'RECYCLER' and 'autorun.inf'
  3. Try delete the folder name 'RECYCLER' and 'autorun.inf'

How to remove:
1. Remove all your thumb drive, pen drive or etc from your computer.
2. Open 'Folder Option'. Choose show 'show hidden files and folders' and untick 'Hide
protected operating system files (Recommended)
'.


3. Delete this file:
C:\RECYCLER
C:\autoexec.bat
C:\c.exe


4. Open 'Registry Editor' and don't close this yet because we need this later.



5. Open 'Search' or press 'F3' on your keyboard to search files and folder.



6. Search this keyword 'ise32.exe'.
7. Delete the files that come from 'Prefetch'. Usually that have extension '.pf'. Warning!
8. Open 'Task Manager', find 'Explorer.exe' under the image name. Right click the image
name and choose 'End Process'. Don't close this yet.



9. Back to 'Registry Editor', press 'Ctrl + F' and search for 'ise32.exe'(without the '').



10. Delete all registry that have same name as 'ise32.exe' (without the'').Warning!
11. After that, go back to 'Task Manager'. Hover your mouse to 'File' and navigate to 'New
Task (Run...)
'. Click 'OK'.




12. A 'Create New Task' windows will pop up. Type 'explorer.exe' and click 'OK'.



Warning!
DELETE file that have the 'ise32.exe' keyword and have '.pf' extension.
DONT delete registry like 'unwise32.exe'.
Delete the wrong file and registry may cause your computer unstable.

Technorati Tags: , , , ,

What is Resycled\boot.com

0 comments

Symptom:

When you try to open drives, a message is shown "C:\resycled\boot.com is not valid Win32 application"

How to remove resycled\boot.com:

1. Show you hidden files and folder. Click here, how to show hidden files and folders.
2. Search and delete 'autorun.inf' in all you drives.
  
Technorati Tags: , , , , , , ,

C:\resycled\ntldr.com

7 comments

C:\resycled\ntldr.com is a word that creates autorun.inf files on all drives when the removable drive is inserted into a computer.

Symptoms:
Cannot open all you drive using double click

How to remove ntldr.com?

First, enter the Windows using safe mode.

Kill process in the task manager:
ntldr.com

Delete Files and Folders:
C:\resycled\ntldr.com
D:\resycled\ntldr.com
E:\resycled\ntldr.com
C:\autorun.inf
D:\autorun.inf
E:\autorun.inf
%Programs%\aquaplay\Uninstall.lnk
%ProgramFiles%\aquaplay\Uninstall.exe
%Windir%\Temp\tmp6.tmp

Note: Open your drive using your mouse. Right click your drive and choose open. Then find the files.



Remove Registry Values(Click here for how to open Registry Editor):
ntldr.com,
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems,
HKEY_CLASSES_ROOT\videoplay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aquaplay
HKEY_CURRENT_USER\Software\aquaplay
Note: Press 'Ctrl+F' and search all the files.

Or just download this tools, click here. To use this tools, please enter the Windows using safe mode also.

Warning: If you delete the wrong files, it will make your computer unstable and can not be open. Your Windows also can be open and showing error such as 'Ntldr is missing'.
Technorati Tags: , , , , <

Windows 7 beta affected by viruses

0 comments

The virus works by creating a malicious autorun.inf file and loading it onto a USB peripheral. When a user access the USB by the auto play menu or double click the USB, they are actually installing malicious software on their computer.

Currently Windows Vista and Windows 7 beta is vulnerable to this virus.

Technorati Tags: , ,

How to remove MS32DLL.dll.vbs and Hacked by Godzilla virus

0 comments

This post will be step-by-step guide to remove MS32DLL.dll virus.

Step-by-Step guide:

1. Press 'Ctrl + Alt + Delete' together to open up 'Windows Task Manager'.
2. Click the 'Process' tab and find the process on the 'Image Name' column called 'wscript.exe'.


3. Press 'Delete' key after selecting the process.
4. After that go to 'Folder Option'. Select 'View' tab, check 'Show hidden files and folders' and press 'OK'.

5. Search for 'MS32DLL.dll.vbs' in your computer. Usually the virus files can be found in 'C:\Windows'. When you found the files, delete the files from your computer.

Note: Dont double click your C drive. Open your C drive by using right click. Then delete 'autorun.inf'.
6. Open 'Start Menu' by pressing Windows logo key.


7. Go to 'Run' , and type 'regedit' (without '') and press 'Enter'. Click here for more detail.
8. Navigate to the following path:
HKEY_LOCAL_MACHINE\ Software\ Microsoft\Windows\Current Version \Run
If you see any key for 'MS32DLL.dll', delete the key.
9. Next, navigate to the following path:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
If you see Window Title with value 'Hacked By Godzilla' virus,delete the entry
10. Exit the 'Registry Editor' and Restart your computer.

Technorati Tags: , , , , , , , ,

How to show hidden files and folders

0 comments

This tutorial is useful when you want to search for virus file.

Step-by-Step guide:


1.

For Windows XP:

Open 'My Computer', go to 'Tools'.

For Windows Vista:

Open 'Computer', go to 'Tools'.



2. Select 'Folder Options'.



3. When the 'Folder Options' windows is show, select the 'View' tab.



4. On the 'Advance settings' section, locate and choose 'Show hidden files and folders'. Untick also this option 'Hide extensions for known file types' and 'Hide protected operating system files (Recommended)'. Finally click 'OK'.



Note: If you still can not see hidden files and folder, click here to download software for enable show hidden files and folder.


Technorati Tags: , , , , ,

Juzt-Reboot Your Recovery Solution

0 comments


Juzt-Reboot® is a new generation of recovery solution that can be for PC and notebook. Later, I will tell you what is the SECRET for this product. Juzt-Reboot® can configured to operate in computing environment for academic, business or home purposes.


  1. System files or data is destroyed
  2. Virus or spyware attacks,
  3. Deletion, formatting, overwrites, modification system files
  4. Improper shutdowns or software corruption


Juzt-Reboot® will fix your system instantly, at the touch of a button or set to automatic on reboot. No other additional system/data recovery operations are required. BUT, if you DONT BACKUP the problem as the restore point for Juzt-Reboot®.


Juzt-Reboot® support many operating system including Linux and Windows Vista. Juzt-Reboot® come with Hardware and Software version. What make Juzt-Reboot® worth to buy? Isn't it same with Deep Freeze? Juzt-Reboot® has a feature like:
  • Clone your hard drive
  • Boot from certain drive only
  • Hardware and Software version


I will not tell you the secret because if everyone know then this company will out of bussiness. Juzt-Reboot® recording changes made to the HDD and applications, thus it only requires a small amount of HDD space to operate. This space totally hidden. Any idea where it is?

Technorati Tags: , , ,

 

Copyright © 2009 - Things About Computer - Modified by: by $uWari