Removing Angry Birds Vbe Auto Run

Embed Size (px)

DESCRIPTION

important clean of virus, angry birds

Citation preview

HOW TO REMOVE ANGRY BIRDS MANUALLYSTEP 1Go to control panel and on the right top of the control panel you wil see a 'search in in control panelso type "folder options" then click on folder options.STEP 2When the folder option window pops up click on view. then look and click the radio button of view hidden file.Then scroll down and untick where it is written hide protected operating system files and if the pop up warning comes click yes. then click apply AND ok.STEP 3On your keyboard click ctrl alt del simultaneously.Your screen must change and then click on task manager. or click ctrl shift esc to open task manager.If the task manager window appears click on processes if you are using windows 7. If u are using windows 8 click on details.STEP 4Search for a process named "wscript.exe" right click on it and click end process.STEP 5Click start then computer click on local disck c("ie where ur os is installed")- double click on the folder named users it will show you all the users.-double click on the username of ur account and srowl down.-Look for a file named "angry birds" and delete it. if there ins another one named "h" delete it too.GO TO C/USERS/YOURCURRENTUSER/APPDATA/ROAMING/MICROSOFT/WINDOWS/STARTMENU/PROGRAMS/STARTUP/Look for a file named "angry birds" and delete it. if there ins another one named "h" delete it too.Delete autorun.inf and ntdelect.com :Click Start, enter cmd and press EnterCheck all the drives for the above three files.For eg: to check the files in C:, type dir c:\ /a/w in cmd prompt and press Enter. This will list all the system and exe files. Look out for autorun.inf and ntdelect.com files.Disable hidden, system and read only attributes for these files by typingattrib -s -h -r c:\autorun.infattrib -s -h -r c:\ntdelect.comThen delete the files by typingdel c:\autorun.infdel c:\ntdelect.comMake sure that you delete ntdelect.com and not ntdetect.com which is a system fileRepeat from step 2 for all other drivesDelete kavo.exe :Search for kavo.exe in C:\windows\system32\If you find it, type attrib -s -h -r c:\windows\system32\kavo.exe to disable hidden,system and read only attributesDelete kavo.exe by entering the command del c:\windows\system32\kavo.exe Click Start, type regedit and press Enter. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows \CurrentVersion\Run,andHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows \CurrentVersion\Run. Delete kavo and c:\windows\system32\kavo.exe value.Enable Show hidden files and folders option:Open Notepad,copy and paste the following and save it as a showhidden.reg file.Windows Registry Editor Version 5.00[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]"RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced""Text"="@shell32.dll,-30500""Type"="radio""CheckedValue"=dword:00000001"ValueName"="Hidden""DefaultValue"=dword:00000002"HKeyRoot"=dword:80000001"HelpID"="shell.hlp#51105" Double click on the saved file to modify the registry.That is all! You have now cleaned up autorun virus on your PC. But isnt prevention better than cure?