Different Users run several applications in their computers,
Specially Windows have large range of applications,
Some of these applications require to run at startup for users convenience.
As windows applications are automatically configured for users ease, it can sometimes becomes threat to users, as virus makers can easily detect the running up service in a computer and attack it.
Some applications are designed such that they remove the files in uninstall but their impact still remain in registry or other files.
Most of my clients computer have been found infected with viruses and worms that start at startup.
Just by caring a bit from user, you can easily maintain the problems you face in your comptuer.
If you feel you are running some disorders, most probably it is because of virus (malfunctioning application) running at startup.
How to control Malfunctioning applications ?
One great idea is to check the process list, with respect to workload, you can also choose additional options to see what application is it originated from,
see www.neuber.com and load Security Task manager, you can get a better version of trial version software.
Once you know the running processes, you can easily know which application is abnormally running in your computer.
Some viruses and torjans are found running from several locations.
First you need to know that you are running application with authority of creating files in %System% or %windows% location.
IF you are doing it, you might have these applications created files in these locations, Mark out these files are most frequently hidden.
These appplication target their killer applications as antiviruses and taskmanager, command and some important tools.
They can run from autorun.inf file that they create in the secure locations.
%windows%, %System% and %root%
read the autorun.inf file in these location and delete these applications, if you are not sure and feel they are usable files delete autorun.inf file.
The next Location is registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
There should just be --> explorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Be sure, The most required application like antivirus is enough in one of these space.
Or analyze if something else is running that is malfunctioning
Most abnormal applications found just look like windows essential files but just a spelling or more changed check these out
Good luck,
If you have more
write to meromarqu@gmail.com
Tuesday, December 25, 2007
Subscribe to:
Posts (Atom)