How to identify and kill strange viruses when using YM

In the face of strange virus attacks, Yahoo Messenger (YM) community can identify and destroy viruses in two ways.

In the face of strange virus attacks, Yahoo Messenger (YM) community can identify and destroy viruses in two ways .

First, you can use anti-virus software like Kas, Microsoft Security Essentials and especially Malwarebytes' Anti-Malware 1.46 to be the most effective to kill Foto virus.

But before scanning your entire computer with the above antivirus programs, you should update the latest information about malware and make sure the software is copyrighted. After that, start scanning the entire system.

Second, you can use manual removal. Any kind of virus that enters the computer, no matter how mischievous it is, leaves a trace. Based on that, you can track it down by going to the system file to find it manually. This is a bit time-consuming but equally effective. You can combine in parallel with the antivirus software in use.

However, the YM user community needs to be very careful when deleting the following files correctly.

C: Windows mds.sys
C: Windows mdt.sys
C: Windows winbrd.jpg
C: Windows infocard.exe
C: Program Files infocard.exe
C: Program Files mds.sys
C: Program Files mdt.sys
C: Program tập tin winbrd.jpg
C: Users Public mds.sys
C: Users Public mdt.sys
C: Users Public infocard.exe
C: Users Public winbrd.jpg
C: Documents and Settings Administrator mds.sys
C: Documents and Settings Administrator mdt.sys
C: Documents and Settings Administrator infocard.exe
C: Documents and Settings Administrator winbrd.jpg
C: Documents and Settings mds.sys
C: Documents and Settings mdt.sys
C: Documents and Settings infocard.exe
C: Documents and Settings winbrd.jpg

 

User name.

Manually delete registry keys:

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] 'Firewall Administrating' = 'C: WINDOWSinfocard.exe'.

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] 'Firewall Administrating' = 'C: WINDOWSinfocard.exe'.

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentV ersionRun] 'Firewall Administrating' = 'C: WINDOWSinfocard.exe'.

[HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesS haredAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList] 'C: Documents and Settings DesktopIM56245.JPG-www.myspace.com.exe' = 'C: WINDOWSinfocard.ex e: *: Enabled: Firewall Administrating'.

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServic esSharedAccessParametersFirewallPolicyStandard ProfileAuthorizedApplicationsList] 'C: Documents and Settings DesktopIM56245.JPGwww.myspace. com.exe '=' C: WINDOWSinfocard.exe: *: Enabled: Firewall Administrating '.

[HKEY_USERSS-1-5-21-117609710-764733703-1957994488-1003SoftwareMicrosoftWindowsCurrentVersionRun] 'Firewall Administrating' = 'C: WINDOWSinfocard.exe'.


User name.

Finally, some security experts also recommend users to be more cautious when clicking on unknown links. Ideally, you should carefully review and continuously update the latest information for your antivirus software.

4 ★ | 1 Vote