Monday, 26 March 2012

How to Manually Remove a Computer Virus

If you’ve been on the Internet for more than a minute or two, you should know that good anti-virus software is worth its weight in gold. This is doubly true if you find yourself on a broadband or wireless connection, which makes you even more vulnerable to hackers and other online baddies. Once in a while, however, even the best anti virus software needs a helping hand and you may find yourself in a situation where you have to manually remove a computer virus yourself. While this process sounds a bit intimidating, there are quite a few reliable websites out there that can help break down this process into easy-to-execute steps.

You do need to be careful, however, with any process that requires you to edit your Windows Registry. Your registry is like the brain stem of your computer. One wrong move and your computer can be rendered no more useful than a paperweight.

The first thing you need to figure out is if you have virus protection software installed on your computer. If you do, run a scan to find the virus that is causing all the trouble. If you have a decent virus protection program, it will either remove the virus for you automatically, or give you explicit instructions on what you need to do to remove it yourself. In most cases, the steps are as follows, although you may have to try more drastic measures to get rid of a computer virus.

You’ll need to create a back up of everything on your computer before you go about deleting things, especially if you are required to change your registry. Make sure all work files, family photographs and other essential items have been saved to disk. You also want to create a backup of your registry, just in case. Once you know the name of the virus, your protection software should give you step by step instructions on how to delete it, including deleting the virus itself, any sub directories that it has spawned as well as any changes in the Windows Registry that are required. Make sure you go very slowly when changing your registry as many of the long strings of information look very much the same. Editing your registry is often a crucial part of learning how to get rid of a computer virus from your computer, so if you need help, don’t be afraid to ask.

If you have found yourself with no virus protection, but you are pretty sure you have a virus, there are websites that will scan your computer for you. One of the best is located at although there are many others that work just as well. Once you know the name of your virus, you are going to have to perform a Google search to find the manual removal instructions. It is very important that you only trust respected virus removal websites since many of these sites that may come up in a search will only ask you to install programs that will actually make the problems you are having much, much worse. Yahoo has an excellent online directory of viruses and so does Norton, one of the largest and best known virus removal programs. These sites will help you remove a computer virus from your computer in minutes.

Since every virus requires different action for removal, it is difficult to give blanket instructions for removal, but here is a basic step-by-step process which may lead you in the right direction.

The following steps involve viewing and optionally editing the Windows registry. Before you do this, you should make a backup of the Windows Registry, so that you can restore it in case you inadvertently delete something that causes your computer to behave unexpectedly. You can backup the registry, by going into Regedit (described in step 1 below), select 'My computer', click File->Export, then type a file name, then click save. You can also export various branches (sections) of the registry by selecting the particular root folder of the section you would like to export. This generally makes more sense when you are only editing a specific area (as in the steps below). So for this example you might want to simply export the 'Run' section (described in step 2).

1. Click Start->Run->type regedit->hit enter

2. Browse to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Here is where certain files are run when you start your computer. Many viruses place their files here.

3. Each item in this area represents a file, which can be seen in the data column, the actual file will end in '.exe'. For each file, you can do a search on Google to determine what it is. If you find that it is a virus, you should be able to safely delete the item registry so that it is no longer listed in the registry. You should also delete the actual '.exe' file from the file system by browsing to it in Windows Explorer, selecting it, hitting the delete key, and confirm by clicking Yes.

4. Repeat the process above but this time look in:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

There are a few things you always want to do before deleting files from your computer like performing a complete back up of all of your files, which you should be doing on a regular basis, anyway, and remembering to back up your registry just in case you need it again later. Knowing how to remove a computer virus by hand is vitally important to owning a healthy and lasting computer.

No comments:

Post a Comment