Wednesday, July 9, 2008

disabling worms

hello
ip information
Note:-This Note is only for educational purpose. It will work with type of worm generated in a drive through New Folder.exe.

I often listen from people that worm are irritating them. Here is my first attempt to solve those problems.

First of all you all need to know that what is actually a worm,what it does and what can be done using these worms.
what is a worm:-
A self-replicating computer program. It uses a network to send copies of itself to other systems
and it may do so without any user intervention.
What it does:-
As told above it is a self-replicating program it copies it self to all the folder of infected drive.
Generally name of the worm depends upon the folder inside which it copies it self. For example if the folder name is Gaurav then the name of worm will be like Gaurav.exe. Generally it uses folder icon to make you neglect them all but when you will see those in detailed that will show that theses are not a folder but an application.
what can be done using these worms:-
As i told that it copies itself to every folder of that drive it consumes the same amount of space also in the system .It spreads so fast and according to number of folder it consumes space.If the infected drive is your windows drive it attains lot of space there consequently slowing your computer. Now so for sure a smart hacker can easily send any Trojan to your computer to track your system and can command your system easily from some remote computer.


so after reading all these you can image what can it does and how fast and how much it can infect you.


some times even after scanning the infected drive or whole computer you didn't get rid of all these worms. Do following thing to enable a secured scanning.

Normally all worms and most viruises doesn't works in Dos Mode and in safe mode.
Acctually in safe mode window intall only its owb files that are neccessary to boot windows. so even those viruses who installs itself on startup doesn't start untill other applications force them to start. so in those mode one can get easy acces over registries and other infected applications.
follow these steps to disable the worm.
  • First try to find the file New Folder.exe in the infected drive.
  • It can be hide as a normal file or as a system file so for finding them click on toolshow hidden file and folder
  • Now search the file File New Folder.exe in the infected drive.
  • now Open that file using Notepad.
  • For this open notepad
  • Now select all text and press del.
  • save this.(ctrl+s).
  • If it prompt that the file is read only then go to the file open it property. uncheck the option read only then save again.
  • Now this New Folder.exe is disabled. Now it is not going to spread worms. Now you can scan your infected drive for sure scan.
All the Best.