Common Registry Changes by Virus Attack
User Rating: / 3
PoorBest 
Written by Anshul Saxena   







images.jpgAlmost all computer users today, have heard or faced a computer virus while using the Internet. Although they may seem to do deadly things to your machine, most computer virus are actually simple programs which change setting of the operating system(mostly windows). This article provides the 'registry changes' which can correct certain common effects of a virus such as disable task manager, shutdown button etc.

Recently my computer was effected with a virus called the 'Maa Virus'. This "Maa Virus" blocked my Task Manager, shutdown option, log off option, run option and various other things. While this may sound very deadly, and certainly renders your computer handicapped, it is just simple editing of the Windows registry which causes these effects. Most computer virus are programs which when run modify the Windows registry to disable these features.  

 

So what do u to counter these changes. Well you change the Registry settings back. To learn how to edit registry refer to http://www.mabaloo.com/Tips-N-Tricks/37-How-to-edit-registry-in-Windows.html#37

Given below are some of the most common registries which are edited by a virus and how can revert the changes.


DISABLE_TASK_MGR

Key: Software\Microsoft\Windows\CurrentVersion\Policies\System

Set Value of "DisableTaskMgr" to 1


SHUTDOWN_BUTTON 

Key: Software\Microsoft\WindowsNT\CurrentVersion\Winlogon

Set Value of "ShutdownWithoutLogon" to 1  


DISABLE_CD_ROM 

Key: Software\Microsoft\WindowsNT\CurrentVersion\Winlogon    

Set Value of "allocatecdroms " to 1


DISABLE_FLOPPY 

Key: Software\Microsoft\WindowsNT\CurrentVersion\Winlogon       

Set Value of "allocatefloppies" to 1 


DISABLE_USB 

Key: System\CurrentControlSet\Services\USBSTOR       

Set Value of "Start" to 4


DISABLE_CD_AUTORUN 

Key: System\CurrentControlSet\Services\Cdrom

Set Value of "AutoRun" to 1

 

If anyone of you is troubled with similar issues, then appropriate changes in the registry by setting the above key values to their default values would restore your previous comfiguration of registry without much efforts.

For further help or any kind of queries please use the Mabaloo Forum.

*Readers please note that the article has been written for the sole purpose of protecting oneself from these simple viruses. The writer or the website is not responsible for any misuse of this information.







 

Quote this article on your site

  Be first to comment this article

Only registered users can write comments.
Please login or register.


Powered by AkoComment Tweaked Special Edition v.1.4.6
AkoComment © Copyright 2004 by Arthur Konze - www.mamboportal.com. All right reserved

 
< Prev




Privacy Notice | Advertising Info | Feedback | Contact Us | Partners

The information and views presented above are by the author. Mabaloo.com does not take any gurantee of accuracy.
The views expressed above are that of the author and in no way related to mabaloo.com
Highlite It
© 2007 @ mabaloo.com.