Cartoon Network

08 January 2014

Re: [DIY] help with computer please

 

I should also add that the Registry Hkey_CurrentUser is the user that logged on. If the infection entry is in another users Registry space, the infection entry won't show in CurrentUser for that login. There are other user registry locations in Hkey_Users but are a little hard to navigate as they are encoded and there is no easy way to figure what user they are for, some are system users, the structures are different there though. But the computer users sections have the same Software, Microsoft, Windows, CurrentVersion, Run structures. They can be searched for bad entries under anyone's login. When you log in, the correct structure from these user spaces is migrated to CurrentUser's space for valid log ins.
Steve

On 1/7/2014 7:50 PM, Steve Wilson wrote:
 

Virus are usually just startup programs, kill the startup entry and or remove the file to stop it from starting during a reboot.
This works for XP and Windows 7, not sure how Windows 8 works. Haven't much dealt with it yet. But I would think its very similar.
Look in Start, Programs, Accessories, System tools for System Information.
Run it and look in Software Environment, Startup Programs.
Most so called virus run as a program that start in various startup locations.
You may have to run Regedit to remove any unwanted startup entries. Open a command window or use the Run feature and enter Regedit.
Most startup entries are in the Registry in CurrentUser, Software, Micrsosoft, Windows, CurrentVersion, Run.
There are several locations like this, instead of CurrentUser, there is also Machine, with the same branches of sub entries. There is also DefaultUser but it usually isn't used unless CurrentUser is damaged.
If there are any startup entries like this System Info will show it.
Whenever I get a startup program that is entered by a rogue web page, this is one of the ways I find it and remove it.
Many startup programs hijack the Operating Systems response system. In this case you may have to reboot and force Safemode. Safemode doesn't start any startup programs and should allow you to run system programs to search and remove the bad program.
Pressing F8 on a reboot before the Windows logo comes up should initiate the boot menu to choose Safemode. If it doesn't, keep rebooting until you get the timing right and get the boot menu.
There are also several startup locations on the hard drive in the directory structures. These start up without Registry entries invoking them. Some of these locations can be protected so file removal can be tricky in some. Be fairly sure about what you are deleting. You can fairly well cripple your computers functionality by deleting something critical. But in most of these startup locations there isn't anything system critical. It is more likely to eliminate customized features. If there are hard drive startup entries, System info will show them and will show the location of  them.

to simply change the language:(Windows 7 and Vista)

  1. Open Regional and Language Options by clicking the Start button, clicking Control Panel, clicking Clock, Language, and Region, and then clicking Regional and Language Options.

  2. Click the Keyboards and Languages tab.

  3. Under Display language, choose a language from the list, and then click OK.

XP
1.
Open Regional and Language Options in Control Panel.
2.
 On the Languages tab, under Language used in menus and dialogs, click the language you want.

Most changes require a reboot.

Best of luck,
Steve



On 1/5/2014 4:54 PM, rjlt0407@yahoo.com wrote:
 

has anyone heard of darik's boot and nuke?   my son who had a viris on his computer had a friend look at it and when we got it back its all in portaguess  and we cant seem to get it back in english . welcome any advise




__._,_.___
Reply via web post Reply to sender Reply to group Start a New Topic Messages in this topic (10)
Recent Activity:
Please send decorating questions to Interior Motives List - to subscribe send an email to: Interior_Motives-subscribe@yahoogroups.com
.

__,_._,___

No comments:

Post a Comment