"Jee Aaya Nu"

Welcome!!
That's what I said in Punjabi.

Sunday, August 24, 2008

A little Technical- "Antivirus XP 2008"

Last week my laptop got infected by the Anti-Spyware program "ANTIVIRUS XP 2008".

It is a anti-spyware program, which creates a shortcut on the right corner of your taskbar tray.
It will pop-up for running the scan at various times on the system, and will show you number of infected files, even though you dont have them.
It will make changes to the registry files, it even disturbed my desktop and screensaver settings, and deleted some of my desktop pics.

I tried out couple of scans using the McAfee antispyware, but still the pop-up was adamant to go. It will from time to time pop-up asking "your computer has virus, would you like to clean it up, or run infected".
If you open the IE browser, it will advise you not to open the site, because Google thinks the site is bad.

1) I tried out the Google "SpyWare Doctor" and the "Norton Security scan", the tool is good in figuring out the files infected, going to the registry files level. However since it is free, it does not delete it.
One way is to get the file paths after the scan, and manually delete them from the location, and restart the machine.
But for me this did not help much, I still used to get the pop-ups.

2) One another thing I noticed, in the task manager, there was a process "2.tmp" that runs when the pop-up used to appear. So whenever I killed that process, the pop-up used to disappear.

The file used to be located inside C:\WINDOWS\Prefetch folder.

3) Now the worst was still to come.
After one of the scans- I deleted unknowingly some registry file, which was related to the machine start-up process.
Damn, my machine started showing a blue screen error message.

Machine will start, but it shuts down. Googled it, and found that you may start the machine with other options-
a) like last known good configueration
b) starting in safe mode
and then you can either restore the machine after taking a back-up of your personal data, or figure out the registry file deleted and try to get to copy it from somewhere.

Bur for me neither of the above worked. So I had to re-install the OS completely. This was the best bet that i had taken, since now my machine is healthy as ever.
the advantage that I had was, that my drive having all my personal data, songs, movies was safe.
This is a nice guide to help you with the re-install process-
http://windowsxphome.windowsreinstall.com/installxpcdoldhdd/indexfullpage.htm

Njoi!!

No comments: