If you run the OnDemand Scanner regularly it can be used to disinfect but some viruses, such as Mimail.C@mm, cannot be disinfected in Windows. This is caused by the fact that the virus infects files that Windows uses while running. Thus F-Prot Antivirus cannot access the files to disinfect and it is necessary to disinfect using the DOS scanner (for Windows 95/98/ME) or the Command-line scanner (for Windows NT/2000/XP).
Please note that both the DOS scanner and the Command-line scanner are included in F-Prot Antivirus for Windows
DOS Scanner:
For Windows 95/98/ME:
To boot into DOS press START \ SHUT DOWN \ RESTART IN MS-DOS MODE.
Windows ME users need to use a Windows startup disk.
In DOS mode at the command prompt type:
cd \ [ENTER]
cd progra~1 [ENTER]
cd fsi [ENTER]
cd f-prot [ENTER]
f-prot.exe [ENTER]
We are assuming here that F-Prot Antivirus was installed in the default location. Set the scanner to "Automatic disinfection".
Command-line Scanner:
For Windows 2000/XP:
Click on START \ SHUT DOWN \ RESTART. As the computer is booting up press the F8 key and from the menu select:
"Safe mode with Command prompt"
At the command prompt type:
cd \ [ENTER]
cd "program files" [ENTER]
cd fsi [ENTER]
cd f-prot [ENTER]
fpcmd c: /disinf /auto /list [ENTER]
NB! Please note that the scanning must be done for each drive individually.
When the scanning is done and the system is clean, then restart the computer.
For Windows NT 4.0:
Restart the computer in SVGA mode (Safe Mode)
1. Click "Start" / "Run" / type "cmd" [ENTER]
2. Command prompt window appears.
3. Press "Ctrl-Alt-Del" once and click on "Processes".
4. In "Processes" find "Explorer.exe" and select "End process". The Desktop will disappear and only the background/wallpaper
and the command prompt window will be visible.
5. In the command prompt window type the following:
cd \ [ENTER]
cd "program files" [ENTER]
cd fsi [ENTER]
cd f-prot [ENTER]
fpcmd c: /disinf /auto /list [ENTER]
NB! Please note that the scanning must be done for each drive individually.
When the scanning is done and the system is clean, then restart the computer.
After F-Prot has completed scanning and removed the worm, reboot the computer and go into windows.
Remove this registry key from the registry.
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NetWatch32"="C:\\WINDOWS\\netwatch.exe"
|