Wednesday, November 24, 2010

How to Remove the W32 Harakit Virus

The W32 Harakit virus, also known simply as Harakit, spreads through online chat applications, such as AOL Instant Messenger. Once W32 Harakit has infected your computer, it begins to search your computer for personal information, such as your credit card numbers. To make matters worse, the W32 Harakit virus enters your system registry and deletes your security programs. Consequently, the W32 Harakit virus must be removed manually.



Instructions


End Processes


  • Press "Ctrl" + "Alt" + "Delete" to open the Task Manager.


  • Click on the "Processes" tab of the Task Manager.


  • 3 Click on "Show Processes From All Users."

  • 4 Kill the following processes. To kill a process, right-click on the process and select "End Process":

    "csrcs.exe"
    "cftm.exe"
    "cftmen.exe"


  • 5 Close the Task Manager.


  • Delete Registry Values

  • 1 Click on the "Start" menu, type "regedit" into the "Search Programs and Files" box and press "Enter." The Registry Editor opens.

  • 2 Delete the following registry values from the left pane of the Registry Editor. To delete a registry value, right-click on the registry value and select "Delete." Note that deleting the wrong registry value can cause serious system-wide problems.

    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"cftm" = C:\WINDOWS\system32\cftm.exe"


    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"csrcs" = C:\WINDOWS\system32\csrcs.exe"


    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"cftm" = C:\WINDOWS\system32\cftm.exe"


    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\cftm = C:\WINDOWS\system32\cftm.exe"


    "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden = 0"


    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell = Explorer.exe csrcs.exe"


    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM"


    "HKEY_LOCAL_MACHINE\SOFTWARE\ESET\Nod"


  • 3 Close the Registry Editor.


  • Delete Files

  • 1 Click on the "Start" menu and click on the "Search Programs and Files" box.

  • 2 Search for and delete the following files from your computer. To delete a file, right-click on the file and select "Delete":

    "System\\csrcs.exe"
    "System\\autorun.inf"
    "SystemDrive\\khq"
    "SystemDrive\\khr"
    "System\\cftm.exe"
    "System\\cftmen.exe"


  • 3 Restart your computer.

  • How to set the HonorAutorunSetting registry key manually

    Windows Server 2003 and Windows XP

    1. Click Start, and then click Run.
    2. In the Open box, type regedit, and then click OK.
    3. Locate and then click the following registry subkey:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\
    4. Right-click in the right side pane, point to New, and then click DWORD Value.
    5. Type HonorAutorunSetting, and then press ENTER.
    6. In the Value data box, type 1, click Hexadecimal if it is not already selected, and then click OK.
    7. Exit Registry Editor.
    8. Restart the system for the new settings to take effect.

    How To Delete Registry Enteries?

    1. What is the Registry?

    Windows Registry is a collection of records of all system settings, hardware settings and software settings. It is a part of Windows operating systems such as Windows XP, Windows Vista, Windows 9x, Windows CE, Windows NT, Windows 2000 and Windows Millennium.
    The Registry is essential for Windows to function normally. Every change made to a machine reflects on the Registry, but every change made on the Registry influences computer’s work as well.

    2. Why is it important to delete malicious registry entries?

    Computer’s performance can be affected badly with a single deleted or modified registry entry. It is the reason why the most majority of malwares make some changes on the Windows Registry.
    Malwares usually employ Registry to run malicious files every time a computer boots and to change homepage of web browsers. The Registry may also be used for other malicious purposes. You have to delete malicious registry entries or to restore the default ones; otherwise the malware won’t leave your computer. Even if you delete all the malicious files, the settings saved on the Registry may restore the malware or interrupt normal use of a PC.
    Security tools usually take care of malicious registry entries. However, new computer parasites appear every day and there is no universal software that could detect and delete all the threats.

    3. Things to consider BEFORE removing registry entries.

    Every modification made on the Windows Registry influences how a computer functions; this is why the Registry should be handled with caution. Removing malicious registry entries and modifying values of regular entries is a risky and complicated task. Modifying the Registry should be avoided unless there is a serious reason.
    If a wrong entry is removed or useful setting is changed, the computer might crash and the software installed on board might be corrupted. Set a System Restore point in advance of modifying the registry in order to avoid data loss. Use anti-spyware and anti-virus programs before changing Windows registry manually; this way saves your time and efforts.

    4. How to delete registry entries?

    a) Open Registry Editor.
    Click the “Start” button and choose the “Run” option. Type “regedit” in the “Open” field and click the “OK” button.
    b) Navigate to find the needed registry key and value.
    Registry Editor is divided into two panels. The left panel is dedicated to navigation and the right one is for displaying values of selected keys.
    c) Select the value to modify it.
    Select the value you want to edit, click the right mouse button on it and choose the “Modify” option. You can also reach the “Modify” option by clicking “Edit” on the top menu. You can modify the value by double-clicking it.

    Enter the new value
    d) Find the value using the steps above and delete it.
    Select the value you want to edit, click the right mouse button on it and choose the “Delete” option.Warning! Make sure you delete malicious entries!
    e) You may need to add a new value or a new key to the Windows registry.
    Click “Edit” option on the top menu, choose option “New” and then choose a type for your entry.
    f) You may need to export certain key or value from the registry.
    Choose an object, click the right mouse button on it and choose the “Export” option from the menu.

    Type a name for the exported file and save the file as a *.reg file.
    g) You can import missing or new values and keys.
    Click on the “File” option on the top menu, choose the “Import” option and then select a file to import it to the Registry.
    h) Close the Registry Editor and reboot a computer for changes to take an effect.

    Thursday, November 4, 2010

    Disaat Aku Mencintaimu

    Mengapa kau pergi, Mengapa kau pergi
    Di saat aku mulai mencintaimu,
    berharap engkau jadi kekasih hatiku,
    Malah kau pergi jauh dari hidupku,

    Menyendiri lagi, Menyendiri lagi,
    Di saat kau tinggalkan diriku pergi,
    Tak pernah ada yang menhiasi hariku,
    Di saat aku terbangun dari tidurku,

    Aku inginkan diri mu, datang dan temui aku,
    Kan ku katakan padamu, aku sangat mencintai dirimu.