1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | page 10

Run the registry editor regedit and search for the name of the deleted processes. Look at the startup section at the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, note and remove any suspected items, or simply rename the Run section to something else (Run1, for example). Again wait for a few minutes, if the entries reappear, or the Run section is recreated, your computer is definitely infected with scumware. The scumware needs this section in the registry, so it can start up again after the next reboot. Delete the Run entry, and do a cold shutdown. Turn power off and do not initiate the shutdown sequence, since Windows will send a shutdown message to all processes, including the scumware. If the scumware process receives the shutdown message, it will definitely reinstall itself (and you will be caught with your pants down on the next reboot).
Notice the location of the scumware (usually c:\windows\system or c:\windows\system32). Create a copy of notepad.exe and rename it to the same name of the scumware. If notepad is launched, your computer definitely has scumware. You can then notice when and how it is launched. One small advantage of renaming the scumware to notepad.exe is other portions of the scumware will fail to communicate properly with their hosts.

Continue to do a registry scan for the suspected name of the scumware. Use the Find… option (Ctrl F) for all keys, values, and data. Repeat this step with F3 if you find more than one keys having the name of the scumware. The scumware may be hidden in one of the COM interfaces in the registry, and also as a hidden file on your local hard drive, so you will need to set the folder’s setting to show all hidden and system files.

Install a personal or application firewall as soon as possible. You should note that most hardware or server-based firewall provides port protection only. The scumware can still communicate to the outside world through the firewall from your compromised computer. A personal or application firewall would help prevent further unauthorized local network access and communications, as well as unauthorized file modifications (most likely your Internet browser). Here is a freeware copy for personal, non-commercial use of the old and effective (approximately 8 MBs).

Back up major applications from \Program Files. You can quickly verify if the installed program is self contained in its own directory, or it may store additional program and registration information in the registry, by running it from a different location (after copying). In many cases, the program may just ask for the registration key, and performs normally. Unfortunately, most Adobe and Microsoft software will need to be reinstalled to function properly.

Reinstall the OS using the upgrade option only, so critical system files are restored and you do not lose your current account and desktop settings.

WARNING
The information presented on the following pages illustrates how to
backup compliant Video-DVDs to DVD±RW / DVD±R media.
The software tools and information presented on these pages
work with unencrypted DVD files only and are not made
to create illegal copies of copyrighted DVD material.

Please record responsibly.
Before copying anything onto a recordable media including
CD-R, CD-RW, DVD+R, DVD+RW, DVD-R or DVD-RW
please be sure that you are excersizing your fair use rights
under the copyright law of your country
and not violating any local copyright laws.

DISCLAIMER
The software from this web site is designed to assist you
in reproducing only the material in which you own the copyright or
for which you have obtained permission to copy from the copyright owner.
Unless you own the copyright or
hold permission to copy from the copyright owner,
you may be violating copyright law and may be subject to
payment of damages and other remedies.

If you are uncertain about your rights in a court of law,
you should contact your legal counsel before proceeding to download
or use the software products and/or information from this web site.
You assume full responsibility for the legal and
responsible use of the information and software downloaded or
acquired by any delivery method via this web site and its affiliates.

It is against the law in many countries to reproduce copyrighted material.
Some countries' laws only allow you to make a limited number of
backup copies of any software or media
for personal and archival purposes.
By browsing this site you also acknowledge that you are
the sole "Owner" of all copyrighted material that might be reproduced.
In no way this site and its affiliates are held responsible
for any violation or potential violations of
copyright infringement that you may perform.


1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | page 10