Recognizing and getting rid from Viruses…

pjayampathi

Well-known member
  • Jan 20, 2008
    6,253
    39
    48
    Oyage PC eka haraha godak data transfer karanawanam ekata virus enna hekiyava vediei…den godakma virus enne Internet ekenuth Flash Driver (Pen drives) walinuth thamai..Pen drives walin ena virus autoplay nowana nisa PC ekata enna kalin ain karanna puluwan..hebei meka karanna oyage system eke Hidden Files on karala thiyennaoni..

    Pen eka gehuwahama eke drive icon ekata Double click wath Right click wath karala open karanna epa.

    windows explorer waladee drive eke path eka Gahanna..

    ethanin pen eka open karagena pen eke thiyana Autorun.inf file eka open karanna.
    eke line ekak thiyanawa

    OPEN=filename.exe

    ethana filename wenuwata namak ethi..eenama thiyana file eka pen eken search karala Delete karanna (meka godak velaawata penennama thiyanawa)..

    eetapasse Autorun.inf ekath delete karanna.


    Pen eka open unahama explorer wala View gihilla Thumbnails vighiyata pennana denna..
    Ethakota folder icon walin thiyana application andurganna puluwan.

    Oyaata huru nethi Folder ekak thiyanawaanam eke Properties balanna.
    Ethana Type of File yatathe Application kiyala thiyanawanam eka virus ekak.

    Ehema nethnam Folder ekakata Double click karath open wennethnam ekath godak velaawata virus ekak..


    Den me kiyanne virus eka PC ekata aawoth mokadha karanne kiyala.

    Hadissiyewath Drive ekata double click karala eth drive eka open une nethnam, eekiyanne eke Autorun ekak samaga virus ekak thiyanawa..
    Eka denatama oyage PC ekata evilla ewarai..

    Task Manager yanna..
    bohovita ekath disable vela ethi. ehemanam mage article ekak thiyanawa Tips and Tricks wala After a Virus attack kiyala.eke thiwyana Task manager Enable karana code ekak eka use karala enable karaganna.

    Task manager eke process walata gihin balanna nuhuru service thiyanawada kiyala..

    Thiyanawa nam ewa stop karanna..windows run wenna onima service menna mewa vitharai.

    Svchost.exe (me service 4 vithara thiyanawa)
    Lsass.exe
    Service.exe
    Winlogon.exe
    Csrss.exe
    System.exe
    Explorer.exe
    System Idle Process.exe

    Hebei aluth virus wala service eka methane pennana ekak ne..ehema unoth
    Tune-Up Utilities wala thiyana Tune-UP Process Manager wage software ekaka use karanna.

    suspicious service okkoma close karahata passe Registry Editor ekata yanna.

    Eke menna me keys walata yanne.
    ewa ethule ( visheshayenma deveni key eke ) yam exe file ekak run venna key ekak thiyanawanam ee exe file eke path eka ( samahara vita godak ethi ) eath ewain seka ewa balaganna..( data kiyana tab eka yatathe )


    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

    athule values okkoma makanna...

    Eetapasse Registry Editor eka close karala aaith open karanna.

    Ara kiyapu key walata gihilla balanna ..
    Ewaye aaith values hedilanam thaama virus eka run venawa…

    ehema nethnam eelanga step ekata yenna puluwan.(virus eka stop vela nethnam issarahata kiyana kisima vedak karanna be..)
    kohomata wathma virus eke service eka stop venne nethnam Safe mode walin gihilla try karanna..

    eelangata virus eka system eken makanna oni

    virus ekak aawahama hidden files hide karana nisa ewa pennana ekak ne..ehema unoth

    Click Start > Run type regedit and hit enter

    menna me key ekata yanna

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced

    eke value ekak thiyanawa Hidden kiyala eka dbl click karala 1 type karala OK karanna.a.


    eelangata me key ekata yanna..

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN

    eke value ekak thiyanawa CheckedValue kiyala eka dbl click karala 2 type karala OK karanna.
    ekata yatin value ekak thiyanawa DefaultValue kiyala eka dbl click karala 2 type karala OK karanna.



    den me key ekata yanna..

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL

    eke value ekak thiyanawa CheckedValue kiyala eka dbl click karala 1 type karala OK karanna.
    ekata yatin value ekak thiyanawa DefaultValue kiyala eka dbl click karala 2 type karala OK karanna.



    den Hidden files pennanawa..eelangata ara registry ekedee dekapu exe file eke path ekata yanna( me path eka godak welaawata system32 walai eththe. )...eeke ara nama thiyana file eka hoyala DELETE karanna..
    virus eka run venne nethnam file eka nikamma mekila yai...

    den virus eka PC eken ain venna oni..
    eelangata honda virus guard ekakin PC eka full scan karanna..samahara vita virus eke backup thiyenna puluwan. ( example: exe killer virus)

    ------------------------------------------------------------------------------------------------
    me mama kiwwe normal virus ekak ain karana heti..Advanced virus ekak ain karanna meeta wadaa amaarui.
    ehema unoth mata pvt message ekak ewanna..samahara vita udauuwak karanna ouluwan vei..
    hema virus ekakma mehema ain karanna be. hebei me krama udau wenna puluwan..

    Virus ekak enna kalin..

    Windows Install karala mukuth software ekak install nokara Restore Point eka thiyaaganna..virus ekak evilla kisima kramayakata ain karanna beriunoth
    ee point ekata Restore Karanna puluan.

    Aluth honda Virus Guard Ekak thiyaaganna..( meka Internet ha System security kiyana dekenma venna oni )

    Flash Drives use karanakota ewaye thiyana Folders gena, Hidden files gena selakilimath venna..( virus enna puluwan exe vighiyata vitharak newei )



    :yes::yes::yes::yes::yes::yes::nerd::nerd::nerd::nerd::dull::dull::dull::no::no::no::frown::frown::lol::lol::growl::growl::shocked:
     

    Madushann

    Member
    Feb 22, 2008
    53
    0
    0
    Recovering Locked Things Form Registry

    Goto START>RUN type regedit and press enter

    To Unlock Task Manager
    Goto HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
    Change the DWORD value :- DisableTaskMgr to 0 (or delete the value)

    To Unlock Folder Options
    Goto
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    Change the DWORD value :- NoFolderOptions to 0 (or delete the value)

    To Unlock Display Properties
    GotoHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
    Change the DWORD Value :- NoDispCPL to 0 (or delete the value)

    That all i remember @ the moment. I'll try to post some other this when I remember

    ALL REGISTRY EDITS 100% WORKING ON XP AND ALSO IN VISTA