Noob Killer - Useful Virus Removal Tool


Download Free Noob Killer
Noob Killer by Leerz  is a simple tool to designed easily remove common worms and viruses, it has many useful tools that would help users and administrators get back control and clean their personal computers. I personally use this removal tool on my computer to repair/remove most viruses and worms. Easy to use, fast and lightweight.

You will need the VB6 Runtime Environment as this program was written using Visual Basic program, if not you will receive this error when trying to open the program:

Error :
NOOB.KILLER.leerz.exe - Unable to Locate Component
This application has failed to start because MSVBVM60.DLL was not found. Re-installing the application may fix this problem.



Noob Killer by Leerz most recent version is able to pick up and remove the following annoying viruses:

* VBS Worm\Solow
* Baguio Strawberry Worm
* Yahoo! Worm (Sohanad) || Some Variants
* Krag.exe (I´m Not The Only One)
* Destrukto | explorar.vbs
* jay.exe | jaymykawen9
* w32dranyam | marcmaynard.exe
* Funny UST Scandal(Avi).exe
* SilentSoftech.exe | anti-taga lipa are
* Disk Knight
* Thank You!! Password WinZip123 | password_viewer.exe bar311.exe
* iloveher.exe | say no to drugs!!!
* display monitor.exe | new folder variant
* ImgKulot and variants, jamesgo, bungoton and the like [*.bat, *.reg, *.vbs collection]
* kxvx | kavo, amvo, kevo
* transmit.exe setup.exe | black pegasus
* .. and still counting!



List of registry hotfixes that restores settings on the registry that has been modified by viruses causing severe errors and usability impairment.

* Folder Options
* Task Manager
* Regedit
* Control panel
* Task Bar Right Click
* IE Title Bar Caption
* Show all hidden files
* and Turning on\off of autorun on CD Drives, and Flashdrives respectively.

The latest build currently has the following tools:
* Run replacement similar to MS Windows run
* Run Items shows run items on startup with delete and backup functions.
* Simple Process Explorer, able to close down Processes hidden on the standard Task manager.
* Delete File on Restart  similar to Unlocker, Hijackthis, MoveOnBoot programs.
* Create Copies of Windows Native TroubleShooting Tools such as
* Msconfig, CMD, regedit, taskmanager



The Handy Live update feature allows users to update their Noob Killer with just a few mouse clicks within the Program itself.

Currently, the production is trying to make the Noob Killer Compatible with new and old systems, keeping the Program, small, portable and non bloated for efficiency and importantly Speed.

The Noob Killer is under testing on Windows Vista, working for support to get things running properly, it has been tested under WINE on Linux and is able to run smoothly without too much quirks.

How to use Noob Killer by Leerz:
1. There are several files at the noob killer folder. You need to run NOOB.KILLER.leerz.exe
2. Update the program if you are not sure that you are using the latest one. Select X at the toolbar and select Live Update Now!
3. After updating, click 8-X Kill All and it will scan for all possible virus infection it can get rid off. Remember that it will restart your computer after that so you need to save all your work prior to running Noob Killer by Leerz.

Remove these Virus Manually :

Removing Taga Lipa Are & Hacked By Godzilla Manually by Leerz: 

[*] Quick Steps [ OverView ]
-> Plug all infected medias
-> Close all Wscript.exe instances from the Task manager
-> Set Files and Folders Settings to
> "Show Hidden Files and Folders"
> (uncheck/untick) "Hide File Extensions for Known File Types"
-> Delete 
>"FS6519.dll.vbs" or 
>"MS32DLL.dll.vbs" or 
>"maskrider2001.vbs" 
> "XXXXWORMNAMEDLL.VBS" 
^ Common mask name Format
>"autorun.inf"
> from [each] drive root and "root\Windows\" folders
-> Delete
> "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FS6519"
> "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ms32dll"
> "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\maskrider"
> "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\XXXXWORMNAME" 
^ Taken From XXXXWORMNAMEDLL.VBS / It's Common Mask name Format
> from the Registry
-> Delete or change to blank\nothing
> "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title"
> from the Registry
-> Restart and Done!


[*] Steps [ Details ]
-> Plug "ALL" infected medias such as your :
- USB/Flashdrive/disk
- mp3, mp4, Cellphones
- anything that is recognized as 'Removable Media'
- Mass Storage Devices and 
- anything that can be accessed and Written localy

-> Open Task Manager 'ctrl + alt + del' 
- Make sure you're in the Process list[WinNT Processes]

-> End & close all instances of "Wscript.exe" from the Process list

-> Open Folder Options, click on the 'Views' tab
> Enable 'Show hidden files and folders' and
> Uncheck ' Hide protected operating system files'
-Control Panel >> Folder Options or
-Windows Explorer >> Tools >> Folder options

-> Delete "FS6519.dll.vbs" or "MS32DLL.dll.vbs" or "maskrider2001.vbs" and autorun.inf
> from [each] drive root and "root\Windows\" folders
> check all Drives, C:\, D:\, E:\

-> Delete the "FS6519" with the value "C:\WINDOWS\FS6519.dll.vbs" from
> "HKLM\software\Microsoft\Windows\CurrentVersion\Run\" 

OR

-> Delete the "ms32dll" with the value "C:\WINDOWS\ms32dll.dll.vbs" from
> "HKLM\software\Microsoft\Windows\CurrentVersion\Run\" 

OR

-> Delete the "maskrider" with the value "C:\WINDOWS\maskrider2001.vbs" from
> "HKLM\software\Microsoft\Windows\CurrentVersion\Run\"

-> Delete the "Window Title" subkey
> with the value 
"TAGA LIPA ARE!" 
"HACKED BY GODZILLA!" 
"Taga Esti - Mabuhay Marunduque!!! " 

from

> "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"
> or leave it blank

-> Restart Computer and Done!

Click the followings links below to Download Noob Killer 
Photobucket

Download Now















Search Terms : How, How to, remove, Noob Killer, tool, Removal Tool, Worms, Virus, clean, Registry, Folder, Regedit, control panel, Hidden, Auto Run, MSCONFIG, cmd, Program, kill, Scan, Infect, hack, task manager, Hacked, Godzilla, infected, vbs, autorun.inf, USB, Flashdrive, disk, Mabuhay Marunduque, TAGA LIPA ARE, HACKED BY GODZILLA


Category: Download
Software

How to Remove 81u3f4nt45y Virus



How to Remove 81u3f4nt45y - 24.01.2007 - SURABAYA Virus

81u3f4nt45y - 24.01.2007 - Surabaya It's a virus that often comes up at your booting, just exactly before the Windows Welcome Screen.

It shows this message: " Surabaya in my birthday
Don’t kill me, I’m just send message from your computer………………. '’ is a W32.Drower W32/Drowor.worm.


> First you must Disable System Restore point.

I will explain how to disable system restore :

STEP  1:  

> Click Start button.
Then Right-click the My Computer and then click Properties.
> Click the System Restore tab.
Check the box "Turn off System Restore" or "Turn off System Restore on all drives" as shown in this picture below.
> Click Apply.
When turning off System Restore, the existing restore points will be deleted. Click Yes.
> Click OK button.
When you have finished, restart the computer and follow the instructions in the next section to turn on System Restore.


STEP  2:

Disable "Adobe Online.com" and "Adobe Update.com"
How to Disable "Adobe Online.com" and "Adobe Update.com" :
Press Ctrl + Shift + Esc (Windows Task Manager)
Go to "Processes" tab and find “Adobe Online.com" and "Adobe Update.com"
If the file still available on "Processes", try "End Process Tree"


STEP 3:

After that open registry editor click Edit > Find > in the Find bar type Surabaya and click OK.
The location of any file that belong to Surabaya will be displayed for you. Delete any of them by right-clicking on the file on the dropdown menu and delete it.


STEP 4:

Repair Registry
How to Repair :
Open the Notepad
Copy and paste this code into your text editor and save with name "repair.inf" (Note : Select "All Files" not Text Documents)


Source Code

*******************************************************************************************************

[Version]
Signature="$Chicago$"

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, UncheckedValue,0x00010001,0
HKLM, SOFTWARE\Classes\scrfile,,,"Screen Saver"

[del]
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, LegalNoticeCaptio
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, LegalNoticeText
HKLM, SOFTWARE\Classes\scrfile, InfoTip
HKLM, SOFTWARE\Classes\scrfile, NeverShowExt
HKLM, SOFTWARE\Classes\scrfile, TileInfo
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

*******************************************************************************************************

Right Click the file and then choose "Install"


STEP 5:

Delete the Virus
How to Delete the Virus :
First open Windows Explorer or press (Ctrl + E)
Go to C:\Document and Settings\%username%\Start Menu\Programs\Startup\
Delete Adobe Online.com and Adobe Update.com
Delete folder with size +/- 40Kb, "autorun.inf", "Thumbs.com", and "Thumbs.db" within all drive


STEP 6:

Show Hidden Files
How to Show Hidden Files :
Open Command Prompt
Type:  attrib -s -h /s /d and press enter ( Note : Do it on all drives )
For Example:    C:\attrib -s -h /s /d
                        D:\attrib -s -h /s /d


>> Restart your computer before the changes that you make affect.


Note:
This virus generally reaches to your computer through any USB drive (Pen drive or Hard disc). Whenever you plug your USB drive into any other PC, infected with this virus, the virus will infect this drive and will infect the next computer, in which the drive is plugged in next time. So it’s always advisable not to open the drives directly (USB Pen drive or Hard disk does not open with double click). Instead always right click on the drive and select open option. If at all you see the first option as “autorun”, after you right click on the USB drive, this means that the drive is infected; it means that it is infected with some virus or it was infected with some virus but the autorun.inf is still in the directory of your USB device.

That's all.

Search Terms : How to, Remove SURABAYA-81u3f4nt45y-24-01-2007 Virus, Surabaya (81u3f4nt45y - 24.01.2007, booting virus, Removal 81u3f4nt45y Virus, message "81u3f4nt45y, virus 81u3f4nt45y, Virus surabaya 81u3f4nt45y, W32/VBWorm, Virus BlueFantasy 81u3f4nt45y, Fix "81u3f4nt45y-24-01-2007 surabaya virus", Worm/VB.bdy, W32/Drowor.worm,  [REMOVED]k1m0" Worm, W32.Drower, Surabaya in my birthday


CAUTION! : These tips and tricks are advanced, we can not guarantee that you will be able to solve your problem that result from using tips and tricks incorrectly and is used at your own risk.
Category: Tips & Tricks
Operating System : Windows

Recommended Articles

100 GB Free Backup

 
Contact Form