Previously, let us know the characteristics of viruses.
- virus always make start-up files
- virus has a file-parent and child
- virus is usually fused with the file system
- virus have a strange file name / almost similar to the file system
- The child virus will become the parent virus if at exekusi
How the virus
- active virus by using the start-up files
- after activation in the disable utility for maintenance
- Off to the virus can not be deleted
Trick:
1. Disable the startup files of the virus
-Look at the "run -> msconfig -> startup" there kira2 suspicious ga
-Characteristics
a. strange filename
b. located in the path c: \ windows, c: \ windows \ system32, or
c: \ users \ username \ ... (Win7), c: \ documents and settings \ username ...
(xp)
If there, Delete
2. Disable startup registry virus
Open run -> regedit
- Open the path "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run"
Note the path-virus before it was deleted
- Delete if there is a suspicious character as earlier aj
Also open the path "HKCU \ software \ microsoft \ windows \ CurrentVersion \ Run"
Also remove a suspicious-
Try refresh if-then reappear
-Try deleting again
-If still not go away run next steps
3. Also look for suspicious files in the startup folder on the Start menu
(Remember the virus can be in the form of hidden)
4. Turn off the virus in the Task Manager
-Filename can be seen in the registry that had been deleted
-If you can not use cmd
-Type "tasklist" to the list of process
-Type "tskill namaproses" to turn off process
5. Search for virus files
- Use search, explorer, same cmd
- If you already know where he can simply use explorer or cmd
6. Delete virus files
- Agan can use explorer or cmd to remove
- Type "del filename / f / q" for the file is not hidden
- Type "del filename / f / q / a: h" for hidden files
7. Make sure the file the virus does not reappear
Explorer-in virus entry was then refresh path
- If still appear
a. there is the possibility of viruses child / parent who is still active
b. virus fused with the active file system
- If still showing the way
Cmd-prepare on the path to the virus and then type in "md namavirus.extensinya"
Prepare a longer-cmd / explorer in the path virus
-Delete virus files and then quickly enter cmd with
command "md" was then immediately press enter
-It will display the folder with the name of the virus
-Contents of the folder with the data
So that the virus can not delete the folder)
8. Now check your computer by way of restarting
Effect-if there is a virus but the virus did not appear to be deleted
means less fortunate or virus very cool
1,2,3-check step