How Do I Remove The Harry Potter Virus?

by Lee on November 29, 2009

in Antivirus

Are you infected by the Harry Potter virus?

If so, you need the cure -

1. Make a master file in My Documents database.mdb
2. Create a file autorun.inf in every drive, flash disk, and folders
3. Making file Thumb.db (hati2 without the letter s) in each folder
4. Making file Microsoft.lnk and New Harry Potter and …. Lnk in each folder
5. Making copies of each folder with the extension. Lnk
6. In task manager there are services wscript.exe

Tips for eradication of the Harry Potter virus -

1. Turn off System Restore .. (kilk right on my computer)
2. Turn off the virus wsrcipt.exe (C: \ WINDOWS \ System32 \ wscript.exe)
Can use Process Explorer or misc. tool in HijackThis ..
3. Delete virus files in the My Documents database.mdb ..
4. Remove duplicate files virus ..
Use the search facility in Windows ..
In the “More advanced options”, make sure the option “Search system folders” and “Search hidden files and folders “selected both ..
Search a file named autorun.inf size 8 KB
Search files with the name Thumb.db size 8 KB
Search files with the extensions. Lnk.lnk size 1 KB
Delete all files found ..
5. Remove Autorun registry created by using HijackThis virus ..Look at the HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Run: associated with the file database.mdb

I hope that helps!

Share this post: Tweet It | Facebook It | Stumble It | Digg It | Delicious It

Related Posts

  • Harry Potter And The Half-Blood Malware
  • Harry Potter And The Catholic Church
  • Is Koobface Coming Back For More?
  • Harry Potter Star Emma Watson Dies In Car Crash?
  • How Can I Avoid Malware That Targets The Latest Blockbuster Movies?
  • Koobface Virus Migrates From Facebook To Twitter
  • Johnny Depp Killed By Malware. Savvy?
  • Can You Download Your Way Out Of The Conficker Nightmare?
  • How Do I Remove Conficker After It Disables My Antivirus?
  • Move Over Conficker, Koobface Is Here
  • Leave a Comment

    { 1 trackback }

    Previous post:

    Next post: