Anti-virus experts have intercepted the first computer virus targeting 64-bit Windows workstations. Read more
Financial institutions in eight countries have been hit by a Word 97 macro virus that threatens to destroy data when triggered in mid December First detected last month, the "Thursday" virus was reported by several anti-virus companies. Read more
Brador, the new virus targeting the Pocket PC platform, is not as widespread as media reports would have you believe. Read more
A virus masquerading as a year 2000 countdown program is created an online e-mail hazard. Read more
We tightened the budget on this month’s enthusiast-level system while loosening our belt for the low-cost gamer box by a similar percentage. Today we gauge the effect of these changes on performance and value and compare to last month's machines. Read more
On this, the second day of our System Builder Marathon, Don turns down the price tag of his mid-range build looking for a sweet spot just above the $1,000 marker. Let's see what sort of hardware he found for it! Read more
This month's System Builder Marathon is all about your feedback to us. We've revamped our entry-level and mid-range PCs with new price points. Let's kick things off with what we think is the best value at a $625 price point! Read more
Where were we in 2008 and where are we heading in 2009? In his State of the Personal Computer address, Alan Dang shares his insights as a user of three different platforms--Mac, Windows, and Linux. Read more
Tom's Hardware UK and Ireland Forums »
Applications
»
Security, Utilities, Anti-Malware »
A big-ass virus!
| Bottom | |
|---|---|
| Author |
Thread : A big-ass virus!
|
|
"Verba non acta"
Profile: stranger
More Information
|
Hi!
|
|
Related Product
|
|
Not today maybe tomorrow
Profile: Honorary Poster
More Information
|
let me guess, heatwave virus program keeps popping up. You need a injection tool to remove the runtime codes. I've removed this but to explain the process is just too friggen hard. The kernel is infected and several files that are running in memory and every time you do something to try to remove it the virus changes its name so you really never know which file to remove.
Message edited by gomerpile on 06-21-2008 at 02:02:33 PM --------------- WAITING FOR THE NEXT MOMENT TO STRIKE |
|
Profile: enthusiast
More Information
|
use windows task maneger and exmaine for new services that weren't runnign ealier. if you find which belongs to viruses etc. stop them.
|
|
Not today maybe tomorrow
Profile: Honorary Poster
More Information
|
no this virus does not show up in task manager, after the virus is removed the payload does show up but you cannot delete it or stop the service, the only way is with an injection tool to remove the lines of codes from kernel32. then you are able to remove the files. Message edited by gomerpile on 06-29-2008 at 07:50:25 AM --------------- WAITING FOR THE NEXT MOMENT TO STRIKE |
|
Profile: enthusiast
More Information
|
so what's and injection tool ?? is it different from a virus guard or is it something like a patch ?? |
|
Not today maybe tomorrow
Profile: Honorary Poster
More Information
|
sqlmap is an automatic blind SQL injection tool capable to enumerate entire remote database, perform an active database fingerprint and much more. The aim of this project is to implement a fully functional database mapper tool which takes advantages of web application security flaws.
Message edited by gomerpile on 06-30-2008 at 10:36:26 AM --------------- WAITING FOR THE NEXT MOMENT TO STRIKE |
|
Profile: enthusiast
More Information
|
try this in this order:
|
|
www.portfolio.j-henderson.co.uk
Profile: Honorary Poster
More Information
|
and run them in safe mode (press f8 when booting up the pc) |
|
Profile: journeyman
More Information
|
try this.
Message edited by donald7777 on 08-20-2008 at 05:53:29 AM |
|
Profile: stranger
More Information
|
It sounds like the virus, whatever it is, has latched on to the kernel and is going to be a little trickier to remove than simply booting in to safe mode and removing a known executable. If its running in the memory and changing its name to evade detection, you're going to have to isolate it carefully.
--------------- http://www.pcfixreview.com |
|
Profile: stranger
More Information
|
THAT IS A VERY TRICKY VIRUS INDEED.I SUGGEST YOU USE THE SMITFRAUD REMOVAL TOOL.DISABLE YOUR AV BEFORE DOWNLOADING CAUSE C=SOME DETECT IT A A VIRUS(WHICH IT IS NOT) FORM:
|
Tom's Hardware UK and Ireland Forums »
Applications
»
Security, Utilities, Anti-Malware »
A big-ass virus!
