Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
{TUT} How to find out if you are infected and clean your PC!
#1
Hello SF,

Welcome to my Tutorial on how to find out if you are infected. This ways are Basic. If you are infected, I guarantee you to 80% that you will clean your System using this Tutorial. There are 2 ways, Be lazy and reformat your whole PC or be a Smart Guy and get it working without reformating. I will Show you the Smart Way Smile .

Index of the Tutorial:

Checking the startup
Checking the Registry
Checking the file

Well Let's start with the First step

Checking the StartUp

1. Step - Go to "Start"
2. Step - Select/find "Run"
3. Step - Type "msconfig" 
4. Step - A window will come up. Go to the Tab "Startup".
5. Step - Now you have the List of all apps starting with Windows Smile. Almost every RAT/Stealer/Keylogger/bot etc. Startsup with the System, we can find it here. Search for some file like "Stub.exe" or "server.exe". This are the Most used names. Uncheck them, click on Save, Close And reboot PC. You have successfully preventes the malware(s) to startup with the System. 

Checking the Registry

The Registry is a datebase, where Most Applications save their Configuration. Of course Malware too. Malware often uses the Registry to startup, and Save the options. 

1. Step - Go to Start>Run>regedit.exe
2. Step - Search in HKCU the "Software" Folder. There will Be a List with the programs. If you are infected, there should Be sth like Server or Stub or SpyNet some crap like that. If there is, delete this entry (Right Click>Delete Entry)

Checking the File

If you are Not sure, if a file is clean or not, don't Open it yet without analyzing. First Look at the Details of the program. Look at the Assembly. Of its something Random like fhjedj792&3 then its mostly a infected file encrypted with a Crypter. If its a File you downloaded from YouTube, or from a Site which Assembly is e.g: Hijack This is Most likely infected too because Crypters fool Antivirusses with a Fake Assembly. You also can Scan the file on many online Scanning Services like:

http://www.NoVirusThanks.Org
http://www.virustotal.com (Not recommended)
http://www.jotti.org

And many more...

Also you can use a Great tool named "Sandboxie" (http://www.sanboxie.com).

Enjoy it and good luck cleaning your PC! And note: This is not the advanced method. It is the basic one.

~ViRuzz 
Returning to SF / HF. Long story Tongue
Reply
#2
I wouldn't recommend computer newbies to mess around MS Config or the Registry. Smile

Other than that, thank you for sharing.
Reply
#3
Ye, S7N is correct. It's somthing you shouldn't mess around with when you're new. For the advanced computer guys/girls however this is really nice.
Reply
#4
Very nice Infection removal Tutorial, This will defiantly help a lot of people.
Reply
#5
Nice share
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  I am Infected Give some good suggestions heartylover 11 3,975 03-12-2015, 03:19 AM
Last Post: TobyCordova
  Infected - Can't Start System Restore srcstcbstrd 2 1,524 08-17-2014, 11:39 PM
Last Post: Autopost
  [Think You're Infected?! LOOK HERE] Infested Cleaner [White Hat Heper] Infested Terran 11 4,600 02-08-2012, 08:39 PM
Last Post: AceInfinity
  [TUT] How to Manually Remove a Virus [TUT] Codad Law 76 29,632 12-06-2011, 07:11 PM
Last Post: Ⓓⓐⓝ
  Help. Infected with Adware.Toolbar.Dealio Resistance 3 3,509 11-27-2011, 11:47 AM
Last Post: Resistance

Forum Jump:


Users browsing this thread: 3 Guest(s)