Friday, May 16, 2008

Remove the Amvo.exe !!

First of all you we must know what is the amvo.exe is? what the symptoms when we have amvo.exe in our PC and how to remove it manually without using any software. Ok here we go!

What is Amvo.exe?

* Amvo.exe is Trojan/Backdoor

Symptoms

* Folder Option is not working - you cannot enable the Folder Option or show the hidden files running into you computer.
* Hidden file problem
* Always open new windows in all drives
* Error occur of the memory reference (Low Disk Space)

How to solve this?

This is the solution on how to remove the amvo.exe and to fix the folder option problem. Just follow this steps:

1. Uncheck amvo.exe from msconfig>> startup (type msconfig in run and click on the startup tab) also and restart your system

1. Click Start > Run and type REGEDIT

2. Go to HKEY_CURRENT_USER > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced

3. On the right side, double click the hidden value and give it a value of 1.

4. Same for HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced > Folder > Hidden > SHOW ALL Change the value of Checked Value to 1.

5. Check if your Folder Option if its working now. If it works! OK you are now ready to delete the Amvo.exe virus now.

Go to your Folder Option and enable the show all the hidden files and you remove the following files if they are exist in the exact location or directory:

c:\autorun.inf
c:\u.bat
c:\amvo.exe
c:\awda2.exe
c:\d.com
c:\mvo.dll
c:\amvo1.dll
c:\windows\system32\ amvo.exe
c:\windows\system32\ awda2.exe
c:\windows\system32\ d.com
c:\windows\system32\ mvo.dll
c:\windows\system32\ amvo1.dll
c:\windows\system32\u.bat


Lastly go to Run and type cmd then type regedit, press Ctrl + F to find the files amvo.exe and delete it. After that, reboot your PC.


Love happen's once and the rest is just life!!!!

How to remove Funny UST Scandal avi.Exe Virus Manually !!

1. Firstly you need to end process running by the virus

killer.exe ,b.lsass.exe ,c.smss.exe

Note: close all those processes that have the same icon of Funny UST Sandal.avi.exe

2. Open Start >> Run and type cmd (without quotes) and press enter.
3. Above command will open up command prompt, type cd\ (without quotes)
4. Type attrib -h -s smss.exe (without quotes)
5. Type attrib -h -s autorun.inf (without quotes)
6. Repeat step 4 and 5 for all the drives through command prompt (on the root folder)

7. Now open all your drives one by one by typing C: ,D: and so on in the address bar at the top, delete smss.exe,autorun.inf,Funny UST Scandal.avi.exe

8. Open command prompt again by following step 2.
9. Type cd c:\windows (without quotes)
10. Type attrib -h -s smss.exe (without quotes)and press enter. Type delete smss.exe and press enter also type delete lsass.exe and press enter.
11. Now Open Start >> Run and type regedit and press enter.
12. Locate these paths one by one in the registry.

* HKLM\Software\Microsoft\WindowNT\CurrentVersion\Wi nlogon\shell
* HKCU\Software\Microsoft\windows\Currentversion\Run \Runonce

At these paths, locate the keys which have values as (killer.exe) and (c:\windows\smss.exe). Delete these registry keys.



Love happen's once and the rest is just life!!!!

How to Remove Disk Knight Virus !!

1. Temporarily Disable USB Drive to auto run (Windows XP):

a. Open Windows Explorer or press the Windows + “e” key.
b. Right-click the drive of the USB Drive. Then select Properties. Drive Properties will appear.
c. Select the AutoPlay tab.
d. Choose Select an Action to Perform
e. At the bottom of the selection, click Take no Action, then click Apply.
f. Click OK to exit Drive Properties.

2. Show Hidden Files

a. Open Windows Explorer
b. Go to Tools > Options
c. On View tab, mark Checked the “Show Hidden Files and Folders and “Hide Protected Operating System Files” Unchecked.

3. Delete the files manually
a. Go the USB Drive and delete autorun.inf
b. Go to C: Drive and delete autorun.inf
c. Go to C:\Windows and delete Disk Knight.exe

4. Modify Windows Registry
a. Go to Start > Run then type regedit
b. On Registry Editor, go to Edit > Find and type “knight”
c. Delete all entries it found.

5. Connect to Internet and update your AntiVirus

6. Reboot your computer in Safe Mode
a. During Boot Up process Press F8 continuously until selection appears
b. Use Arrow Up Down to select Safe Mode on the selections menu.
c. Hit Enter to proceed.

7. Scan your computer with an updated Antivirus and delete all infections it founds.

Note: You may enable auto run of the USB Drive by reversing the process in Step 1.


Love happen's once and the rest is just life!!!!

HOW TO Remove NTDETEC1.exe !!

If you’re using the Operating System called Windows, chances are that you might have already come across the ntdetec1.exe virus. Or you will, sooner or later.

Its official name is W32.Ceted and it is a worm that copies itself to all shared and removable drives and spreads when the user double clicks on it to open it. If a system is infected, it creates a folder called ntdetec1 in your System Drive which is NOT visible via Explorer or Command prompt.

Related files:
\ntdetec1\ntdetec1.exe
\ntdetec1\cmrss.exe
\ntdetec1\run.exe
\ntdetec1\shell32.exe
\ntdetec1\drivelist.txt
\ntdetec1\child\autorun.inf
\ntdetec1\child\ntdetec1.exe

Symptoms:
1. Task Manager closes as soon as it launches.
2. RegEdit may be inaccesible
3. Folder Options may be inaccessible

When I scanned using some anti-virus software, Nod32, Symantec AV Corporate, McAfee and AVG failed to detect the files, even in Safe Mode.

To remove it, run the following commands at the command prompt:

taskkill /im cmrss.exe
taskkill /im ntdetec1.exe
taskkill /im shell32.exe

Now, make sure you are in the root drive of your system. For example, if your Windows in installed in C:, make sure your prompt shows C:\>
Now, run the command..

attrib ntdetec1 -s -h -r /s /d
(s->system,h->hidden,r->read only)

This will make the folder visible in explorer. Now you can Shift+Delete the folder from explorer.

Also, you might need to delete the following registry key (if it is present)

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\policies\Explorer\ Run\"winlogon" = "C:\ntdetec1\run.exe"

Congratulations, this will remove all known traces of the above worm.
And remember, next time you use someone’s PD, before you access it, goto your command prompt and delete the autorun.inf file if any.


Love happen's once and the rest is just life!!!!

Worst Computer Viruses Of All Time!!

1. Brain, 1986
It all started here: Brain was the first "real" virus ever discovered, back in 1986. Brain didn't really hurt your PC, but it launched the malware industry with a bang and gave bad ideas to over 100,000 virus creators for the next 2 decades.

2. Michelangelo, 1991
The worst MS-DOS virus ever, Michelangelo attacked the boot sector of your hard drive and any floppy drive inserted into the computer, which caused the virus to spread rapidly. After spreading quietly for months, the virus "activated" on March 6, and promptly started destroying data on tens of thousands of computers.

3. Melissa, 1999
Technically a worm, Melissa (named after a stripper) collapsed entire email systems by causing computers to send mountains of messages to each other. The author of the virus was eventually caught and sentenced to 20 months in prison.

4. ILOVEYOU, 2000
This was notable for being one of the first viruses to trick users into opening a file, which in this case claimed to be a love letter sent to the recipient. In reality, the file was a VBS ****** that sent mountains of junk mail and deleted thousands of files. The results were terribly devastating- one estimate holds that 10 percent of all computers were affected, to a cost of $5.5 billion. It remains perhaps the worst worm of all time.

5. Code Red, 2001
An early "blended threat" attack, Code Red targeted Web servers instead of user machines, defacing websites and later launching denial-of-service attacks on a host of IP addresses, including those of the White House.

6. Nimda, 2001
Built on Code Red's attack system of finding multiple avenues into machines (email, websites, network connections, and others), Nimda infected both Web servers and user machines. It found paths into computers so effectively that, 22 minutes after it was released, it became the Internet's most widespread virus at the time.

7. Klez, 2001
An email virus, Klez pioneered spoofing the "From" field in email messages it sent, making it impossible to tell if Bill Gates did or did not really send you that information about getting free money.

8. Slammer, 2003
Another fast spreader, this worm infected about 75,000 systems in just 10 minutes, slowing the Internet to a crawl (much like Code Red) and shutting down thousands of websites.

9. MyDoom, 2004
Notable as the fastest-spreading email virus of all time, MyDoom infected computers so they would, in turn, send even more junk mail. In a strange twist, MyDoom was also used to attack the website of SCO Group, a very unpopular company that was suing other companies over its code being used in Linux distributions.

10.Storm, 2007
The worst recent virus, Storm spread via email spam with a fake attachment and ultimately infected up to 10 million computers, causing them to join its zombie botnet.. ........



Love happen's once and the rest is just life!!!!

Working Proxies for Orkut !!

HTTPS Proxy List these are more secure

* https://www.fancysportscar.com/
* https://www.goldpuddle.com/
* https://www.tirephone.com/
* https://www.tirephone.com/
* https://www.jellyshell.com/
* https://www.smokeflower.com/
* https://www.spiceflame.com/
* https://www.headcross.com/
* https://www.fancysportscar.com/
* https://www.goldpuddle.com/
* https://www.smokeflower.com/
* https://www.frogtunnel.com/
* https://www.turtlejar.com/
* https://www.jokebottle.com
* https://www.hairchip.com
* https://spacepiano.com
* https://cakebird.com/
* https://iceknock.com/
* https://junkblender.com/
* https://cheeseglobe.com
* https://kitebroth.com
* https://www.technotapes.com/

HTTP Proxy List less secure
* http://www.blackdile.com/
* www.jumboproxy.net
* www.orkuch.com
* www.orkutpass.com
* www.orkut.pk
* http://pmoder.info/
* http://smex.in/
* http://bowsnap.com/
* http://pagemod.com/
* http://backfox.com
* http://atunnel.com
* http://calculatepie.com
* http://bravebadger.com
* http://kproxy.com
* http://www.stupidcensorship.com
* http://www.vmathpie.com
* http://www.ipfaker.com
* http://www.orkutproxy.in/
* http://62.193.235.46
* http://www.ipfaker.com
* http://www.backfox.com
* http://www.newbackdoor.com
* http://www.proxut.com


Or you can try these also

*OrkutWeb.info
*OrkutLive.info
*EasyOrkut.info
*OrkutProxy.in
*Proxy4orkut.com
*Proxut.com


Love happen's once and the rest is just life!!!!

Launch System Restore from a command prompt !!

Launch System Restore from a command prompt - Win XP

If your Windows XP system begins acting strange, a typical fix is to use System Restore to remove any system changes made since the last time you created a Restore Point. However, what if the problem is so bad that you can't start Windows XP normally, or even start the system in Safe Mode?

The good news is you can run System Restore from a command prompt. Here's how:

1. Restart your computer and press [F8] during the initial startup.
2. When you see the Windows Advanced Options Menu, select the Safe Mode with a Command Prompt option.
3. Select the Windows XP operating system.
4. Log on to your computer with an administrator account or with an account that has administrator credentials.
5. Type the following command at a command prompt:
C:\windows\system32\restore\rstrui.exe

When you see the System Restore window, the graphics may look odd, but you can still follow the onscreen instructions to restore your computer to an earlier state.

Note: This tip applies to both Windows XP Home and Windows XP Professional.


Love happen's once and the rest is just life!!!!
>