Your Ad Here

Recent Posts

Showing posts with label Virus and Virus Removal. Show all posts
Showing posts with label Virus and Virus Removal. Show all posts

A new version of Avira Antivirus is out

imageWhen I booted my pc two weeks ago, I had a pop near my system tray saying that there is a new version of Avira Antivirus. Downloaded that software and it was very much like the older version but probably changes were done under the hood. I used Avira (the Free version) for  more than 3 years now and I have no problem with it.

When installing the software, everything was nearly automated and all performed without a glitch. I now have the latest version of Avira running in my pc.

You can download Avira from here and you can configure the software by following the instructions here. A small note though, you can also configure the Extended threat categories from ConfigurationGeneral. You can use Select all or have the configuration modified to your liking. As of me, I don’t play games that much, so I used Select all. Also, when you configure the Actions for concerning files, you have the choice to do an Automatic or Manual action. For me, I used Automatic with Repair as the Primary action and Delete for the Secondary action. I also unchecked Copy file to quarantine before action cause what it did was place file that it detected as virus to the quarantine folder and had my drive space occupied by these files. But it is your choice though, just try to delete the quarantined files once in a while to free disk space.

Read more...

Modified BartPE Installer

Just want to make a quick post before I leave the house. For those who have been asking me to create a modified installer for PEBuilder, your wish is granted. Click on the RapidShare link below.

Take note, if updating McAfee virus definition file fails via HTTP and FTP download, please manually download the SuperDat file. I have included the instructions on how to manually download, and extract the downloaded files for use with BartPE CD.

Aside from this installer, you will also be needing an XP installation disk. For proprietary reasons, I can not help you with that, find the XP installation disk somewhere else, in Piratebay maybe. ;-)

DO NOT MODIFY the default installation directory (C:\Program Files\pebuilder3110a) or else you will have problems extracting the SuperDat file.

Once you have created the CD, you might want to take a look at this post as well.

BartPE Installer by Borge (Modified)

 

Read more...

Configure Avira Antivirus Personal Edition Classic

This is a short tip how to make Avira Antivirus work better - and by the word better I mean meaner to viruses and trojans. It worked for me, just try it out, it might also work for you.

Configuration Guide

  • You must have Avira Antivirus Personal Edition Classic, you can download the software for free from www.avira.com. Install the software and do the update. Make sure you have a full install. By the way, this software is free and it works good. But it lacks the network scanner capability - that is, it can not scan network folders for trojans and viruses, so careful when you browse network folders.
  • Once you are done with the installation process, you'll have an icon near your clock that looks like an umbrella, double click that icon to view the settings.

image

  • Click Configuration and you'll see this.

image

  • Check the Export mode box and select Scan. Choose these options. Files -> All Files; Additional Settings should be checked - all of it.; Scan process would be low and the Allow process stopping should be checked.
  • Setting for the Actions Concerning Files should be set Automatic and Copy file to quarantine before action should be checked. Choose repair as the Primary Action and delete as the Secondary Action. What the scanner will do first is backup the file in quarantine folder, try to disinfect it then deletes the file it can't be disinfected or repaired.

image

  • This time, click Archives. Check the following options: Scan archives, All archive types, Smart Extensions, Limit recursion depths. This way, even if you are downloading something say from p2p network or torrent that contains a trojan or a virus, then the scanner will see though it even if it has been zipped or rared.

image

  • Now, let's set the Heuristics options. Macrovirus heuristics should be checked. Win32 file heuristics should be set to High. Although this might take some system resources from your pc, but this will help you a lot when you try to make your pc "virus free" - but not "totally virus free", you might still get infected if you are not careful with what you open or click on the web.

image

  • Let's configure the Guard. What we have configured so far is the Scanner - the manual scanner that is. This time, let's configure the Guard, this is the thing that scans almost everything in the background. Now let's make the Guard meaner to viruses. Select Scan and you will have this window.

image

  • For the Scan mode, select Scan when reading and writing. For the Files option choose All files and for the Archives check Scan all archives and select everything below it. Now select Heuristics, you should have this window.

image

  • Same configuration with the Scanner, check Macrovirus heuristics, and use High for the heuristics and select Ok.

This works well if you have your virus definition file updated regularly and that you do a full system scan in the background regularly, I'd say twice a month is ok.

Read more...

Using BartPE CD to scan pc for viruses

This is a reply to the request of having a tutorial on how to scan pc using BartPE cd. The cd itself was created using PE Builder which can be downloaded from the net free of charge. This guide will not give instructions on how to create the PE CD itself but how to use the CD for virus scanning and removal. The guide on how to create a BartPE CD will be discussed probably by the next blog (hopefully if I still have the time). This guide assumes that you already have a copy of the CD. I will not upload the CD to a server for the reason that virus definitions and regularly update and probably by the time Google has crawled to this tutorial, the definitions included in the CD are already antiquated. I can only give copies to those who can and will see me at the campus, other than that, you can search again the web on how to create BartPE cd of your own and use this tutorial as a guide on how to use the CD. ;-)

REQUISITES:

  • A copy of BartPE cd I created
  • A CD rom drive for the PC you are about to scan for viruses
  • A lot of guts - :-)

THE GUIDE:

  1. Make sure that your first boot device in your pc is the CD rom or DVD rom drive. How to do this? Restart your pc, as the monitor displays a lot of sci-fi things on the screen press DEL on your keyboard, this will allow you to enter to your CMOS settings. Note: There are PC's that do not use the DEL key to enter CMOS, if this is the case, consult the User Manual for your PC's mother board. Hint: Try using F2 or F5 if DEL key is not taking you to CMOS settings. Inside your CMOS settings, look for Boot device or something that says about Boot devices or Boot Sequence. Make sure that the first boot device is the CD ROM or DVD ROM drive. Then press F10, then Save your changes on exit.
  2. Place the PE CD on your CD or DVD ROM drive and once prompted to Press any key to boot from CD, press space bar or any key on your keyboard. What will happen is that you will use the CD's OS (PE Environment) to run Windows. It will load as if you are running Windows in your machine. Wait until loading has been completed and you will have a screen similar that of Windows but the start button has been replaced with GO.
  3. So click GO - then Programs and click McAfee VirusScan GUI Wrapper.
  4. In What to scan option check the following: Scan all drives, Scan all local drives, Scan all files regardless of filename extension, Scan subdirectories, Scan inside archive files.
  5. For the Action option, select these: Clean viruses from infected items, Delete infected files, Remove all macros from infected MS Office files.
  6. Check everything and after that, click Scan. The virus scanner will automatically delete viruses, trojans and worms. After scanning is complete you can now close the scanner windows and from the Go menu, select Shutdown - then click Restart. As the PC restarts, remove the PE CD.

Hopefully, all viruses has been eliminated. If you have trojans and worms that starts with windows, you will probably get errors while your start windows, just click ok. This can be removed using Autoruns software. It is also free for download in the web.

I made this tutorial without clarifying most things, if you have questions, please post a comment.

Ihave uploaded a modified version of PEBuilder installer, so you can make your own BartPE CD. Click here.

Read more...

Remove SCVHOST.EXE from PC

At last, I have something new to share. This is after being infected by some sort of a malware (probably a Trojan or a worm - of which I don't know how to classify because I'm not an expert). Here is the scenario, I had a friend who has a problem of opening/accessing her USB drive. I tried to help her by placing the USB drive on my PC and viola, I was infected. The first thing I noticed was in some way, the malware sent a message to my friend who is online in Y! Messenger. Checking the system, I found out that my registry has been edited because I am unable to access my Task Manager, Registry Editor, Folder Options, and Command (DOS). After 5 hours of non-stop PC tinkering, I think I might have the solution.. So here it goes:

NOTE: Do not confuse SCVHOST.EXE with SVCHOST.EXE because SVCHOST.EXE is used by windows - it should be in running when you bootup your system.

Needed software and codes:

  • autoruns - a tiny software very useful to stop other software from starting up with windows
  • registrar lite - a registry editing tool good for searching registry entries

and my personal registry codes (technically not personal, I took it from somebody's work and added my touch)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableCMD /t REG_DWORD /d 0 /f
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_DWORD /d 0 /f

  • first code - enable Task Manager
  • second code - enable CMD in run
  • third code - enable REGEDIT in run
  • fourth code - enable folder option in Control Panel

 

Steps on how to remove SCVHOST.EXE

1. Download and install registrar lite. In the case of autoruns, it's actually in a zip file and you don't need to install it, just extract the files and from there you can run autoruns by double clicking on the application autoruns.exe.

2. You need to gain access to your task manager so that you can stop/end process scvhost.exe. Copy the first code and paste it in the run command option. To access the run command, press and hold windows key + R on your keyboard. Right click on your system tray and select Task Manager. Once Task Manager is open, look for SCVHOST.EXE and end that task. You can also copy and paste the other codes to enable registry editing, folder option, and command prompt.

3. Run autoruns and look for the following entries in the registry that calls for scvhost.exe in the Image Path column.

    Try here:

  • 1st: You'll find one just below Explorer.exe - uncheck the folder icon and delete.
  • 2nd: It's another folder icon that says Yahoo Messenger but it calls for scvhost.exe, also delete that one.
  • 3rd: In the scheduled task tab, double click on AiT.* and delete that task.

4. Run registrar lite and search for SCVHOST.EXE. Delete all entries in the registry that points to SCHVOST.EXE.

5. Fully search your PC and look for SCVHOST.EXE. Delete all files being shown in the results and you are done.

HOPE THIS HELPS.

Note: SCVHOST.EXE may take another name such as SSCVIIHOST.EXE. If this is the case, modify your searches to match the malware's new name. Do not open USB drives double-clicking its icon in my computer, I'd suggest to disable autoplay in most drives and use ExplorerXP than the built-in Windows explorer. As I was editing this blog, I changed my antivirus from Avira to NOD32, surprisingly, NOD32 recognized scvhost.exe as a worm - Win32/Hakaglan.D worm to be exact, while avira could not. Heads up to you guys using Avira as antivirus, even with the latest virus definition files (as of September 1, 2007), you can still be infected by this worm.

 
Read more...

Followers