Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I have irradicated Protoride.B virus six times in the last week. AVG virus checker finds it and heals it but it keeps coming back. I don't open any threatening email. Where can it be coming from? I use AOL instant messanger. My ISP is ameritech dialup. Help! Thanks in advance.
Dan

Scan with you anti virus and write down everything it find's (or you can print off a report).
Remember to back up your registry before you mess with it (name it "with_virus");And after you verify everything is working properly back it up again and remove the virus infected version of backup and of course keep the clean one!
Terminating the Malware Program
This procedure terminates the running malware process from memory. You will need the name(s) of the file(s) detected earlier.
Open Windows Task Manager.
On Windows 95/98/ME systems, press CTRL+ALT+DELETEIn the list of running programs, locate the malware file or files detected earlier.
Select the malware process, then press either the End Task or the End Process button, depending on the version of Windows on your system.
To check if the malware process has been terminated, close Task Manager, and then open it again.Close Task Manager.
*NOTE: On systems running Windows 9x/ME, Task Manager may not show certain processes. You may use a third party process viewer to terminate the malware process. Otherwise, continue with the next procedure, noting additional instructions.Removing Autostart Entries from the Registry
Removing autostart entries from registry prevents the malware from executing during startup. This is also an effective way to terminate its process. In this procedure, you will need the name/s of the file/s detected earlier.
Open Registry Editor. Click Start>Run, type Regedit then hit Enter.
In the left panel, double click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run
In the right panel, locate and delete the entry or entries whose data value is the malware path and file name of the file/s detected earlier.
Close Registry Editor.NOTE: If you were not able to terminate the malware process from memory as described in the previous procedure, restart your system.
Addressing Registry Shell SpawningRegistry shell spawning executes the malware whenever a user opens files with EXE extensions. The following procedures should restore the registry to its original settings.
Click Start>Run.
In the Open input box, type:
command /c copy %WinDir%\regedit.exe regedit.com | regedit.comPress Enter.
In the left panel, double-click the following:HKEY_CLASSES_ROOT>exefile>shell>open>command
In the right panel, locate the registry entry:
DefaultCheck whether its value is the path and filename of the malware file.
If the value is the malware file, right-click Default and select Modify to change its value.
In the Value data input box, delete the existing value and type the default value:
"%1"%*Close Registry Editor.

Hi
No listing anywhere. Is there any unusual activity?
beansoup
"Error: Keyboard not attached."
"Press F1 to continue."

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |