VIRUS HELP URGENT

dilrasan

Well-known member
  • Oct 30, 2007
    42,714
    1
    4,792
    113
    40
    හත් ඉලව්වෙ!
    deffa said:
    doestn work.. trid dat in safe mode also.. dint work... dats da only pob i haf


    if u have one account...then Make a new Account...(Administrater)
    then Delete ur existing Account...:D
    it'll solve the problem..:yes:;)

    just an Idea...may be it'll nto work..:D

    But...Don't Forget to Have a Copy of ur Documents....;):
    (copy them into D: or E:...U know those Stuff right?:D)
     

    airbus342

    Member
    Aug 6, 2008
    1,137
    1
    0
    40
    Gampaha
    Mama hithanne oka hide wela thiyenne kaspersky guard eka athule..sirawatamai kiyanne.eka parak mama office eke weda karaddi eke important file ekak nathi wela thibba......mama boka wela hama thanama search kala...eth naha.passe mama kasper eka open karala nikamata option walata giya..ethakota eka opt ekaka a file eka thibba...passe mama file eka resend kala thibba thanata...but machan mama path eka danne naha.....kanawata weda kale...boru neme...sirawatamai kiyanne
     

    dilrasan

    Well-known member
  • Oct 30, 2007
    42,714
    1
    4,792
    113
    40
    හත් ඉලව්වෙ!
    airbus342 said:
    Mama hithanne oka hide wela thiyenne kaspersky guard eka athule..sirawatamai kiyanne.eka parak mama office eke weda karaddi eke important file ekak nathi wela thibba......mama boka wela hama thanama search kala...eth naha.passe mama kasper eka open karala nikamata option walata giya..ethakota eka opt ekaka a file eka thibba...passe mama file eka resend kala thibba thanata...but machan mama path eka danne naha.....kanawata weda kale...boru neme...sirawatamai kiyanne


    Quarantine Option eke wenna oni:D
     
    dilrasan said:
    if u have one account...then Make a new Account...(Administrater)
    then Delete ur existing Account...:D
    it'll solve the problem..:yes:;)

    just an Idea...may be it'll nto work..:D

    But...Don't Forget to Have a Copy of ur Documents....;):
    (copy them into D: or E:...U know those Stuff right?:D)

    wel i did try dat b4. but da hidden partition thin is still der.. dat isnt goin..
    and i googled this virus name can t fing any thing... on this

    wat happns. is from the RRT it cancels the hidden drive. .but as soon as it happns there is a nothr script whic runs and turns it bak to hidden i asume..
     

    dilrasan

    Well-known member
  • Oct 30, 2007
    42,714
    1
    4,792
    113
    40
    හත් ඉලව්වෙ!
    deffa said:
    wel i did try dat b4. but da hidden partition thin is still der.. dat isnt goin..
    and i googled this virus name can t fing any thing... on this

    wat happns. is from the RRT it cancels the hidden drive. .but as soon as it happns there is a nothr script whic runs and turns it bak to hidden i asume..


    Well then.....let me see...mmmm...:rolleyes:

    Did u try this...:D

    well if u have the Mother Board CD..there will be a Virus Guard in it wich has A Build in Registry Key(most Probably Norton)

    Uninstall the Virus Guard U have now and Install that one and Scan..:DViruses may be identified By it..:Dthen u can Do the rest...;);):

    if i were u...i may have tried this method also;):D
     
    dilrasan said:
    Well then.....let me see...mmmm...:rolleyes:

    Did u try this...:D

    well if u have the Mother Board CD..there will be a Virus Guard in it wich has A Build in Registry Key(most Probably Norton)

    Uninstall the Virus Guard U have now and Install that one and Scan..:DViruses may be identified By it..:Dthen u can Do the rest...;);):

    if i were u...i may have tried this method also;):D

    machna wats running is a prog which changes the reg key of dat.. when its change.,.. im doin sum research..

    and hav u heard of da solo virus
     

    Halloween

    Member
    Nov 2, 2007
    601
    2
    0
    deffa said:
    my cpomputer got infecteed wit the followiin virus

    riskware Worm.P2P.generic ƒOEÑIX.EXE

    this virus blocks

    floder options
    task manager
    registry editor
    and HIDEs the c drive

    can some one help me please.. urgent guys

    Remove your hard drive and put it in another computer which is running from another hard drive. (Its better if there is Kaspersky installed in it.) Then scan the whole hard drive. I'm sure Kaspersky will fix it.:yes:
     

    Malinga

    Well-known member
  • Jul 20, 2006
    61,301
    1,013
    113
    deffa said:
    dat virus doenst allow the user to work on sundays.. it was made by a sri lankan..hehe

    oyaage prashane dan hari da? mokak da velaa thiyenne? C: partition eka penanne nathi eka da?


    http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

    http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

    oya deka daala logs file denna oya deke. eeta passe balamu run vena virus eka mokak da kiyala.

    Norton Partition Magic vage ekak daala partition eka hidden velaa nadda kiyala balannath puluvan onnum oyaata.
     
    Last edited:
    machan i forund da worm form the command prompt

    the locations are

    c:/recycler`/ƒOEÑIX.EXE
    c:/autorun.inf

    c:/windows/system32/ƒOEÑIX.EXE


    d:/recycler`/ƒOEÑIX.EXE
    d:/autorun.inf

    so on on each drive.... i managed to delet the autorun.inf form cpommand prompt..

    but when i try to do it for ƒOEÑIX.EXE cant do
     

    dilrasan

    Well-known member
  • Oct 30, 2007
    42,714
    1
    4,792
    113
    40
    හත් ඉලව්වෙ!
    deffa said:
    machan i forund da worm form the command prompt

    the locations are

    c:/recycler`/ƒOEÑIX.EXE
    c:/autorun.inf

    c:/windows/system32/ƒOEÑIX.EXE


    d:/recycler`/ƒOEÑIX.EXE
    d:/autorun.inf

    so on on each drive.... i managed to delet the autorun.inf form cpommand prompt..

    but when i try to do it for ƒOEÑIX.EXE cant do


    Did u try Removing System Restore Points And Temparary Files...:D

    coz it's in Recycler right?:confused:(it means the Virus)
     
    C:\>attrib -h -r -s autorun.inf

    C:\>del autorun.inf


    :\WINDOWS\system32>dir/ah
    Volume in drive C has no label.
    Volume Serial Number is 9C69-A46F

    Directory of C:\WINDOWS\system32

    10/06/2008 10:03 PM 749 cdplayer.exe.manifest
    10/23/2008 08:04 AM 56 ezsidmv.dat
    10/06/2008 10:03 PM 488 logonui.exe.manifest
    12/24/2006 01:14 AM 158,208 msconfig.exe
    10/06/2008 10:03 PM 749 ncpa.cpl.manifest
    10/06/2008 10:03 PM 749 nwc.cpl.manifest
    10/06/2008 10:03 PM 749 sapi.cpl.manifest
    10/06/2008 10:03 PM 488 WindowsLogon.manifest
    10/06/2008 10:03 PM 749 wuaucpl.cpl.manifest
    11/20/2008 05:40 PM 65,536 ƒOEÑIX.exe
    10 File(s) 228,521 bytes
    0 Dir(s) 0 bytes free

    C:\WINDOWS\system32>del ƒOEÑIX.exe
    Could Not Find C:\WINDOWS\system32\ƒOEÑIX.exe

    dats da log of da files
     

    Malinga

    Well-known member
  • Jul 20, 2006
    61,301
    1,013
    113
    deffa said:
    machan i forund da worm form the command prompt

    the locations are

    c:/recycler`/ƒOEÑIX.EXE
    c:/autorun.inf

    c:/windows/system32/ƒOEÑIX.EXE


    d:/recycler`/ƒOEÑIX.EXE
    d:/autorun.inf

    so on on each drive.... i managed to delet the autorun.inf form cpommand prompt..

    but when i try to do it for ƒOEÑIX.EXE cant do


    http://killbox.net/

    ooken delete karanna. habai vadee thiyenne registry keys makanne nathuva delete kalaata ooka aaith ai da kiyana ekai.
     

    Malinga

    Well-known member
  • Jul 20, 2006
    61,301
    1,013
    113
    deffa said:
    machan kant kill it.. file not found kiyanawa.. but dos wala baluwama pennanawa

    e file not found kiyanne eeka hidden ekak venna athi. oyaa ara dunna Autoruns kiyana software eken e file hadena registry key eka makala danna. eeta passe run venne nae e file eka. ethakota oyaata ara RRT eka daala hidden files aapahu ganna puluvan.

    ehema naththum oyaa dena nama varadi athi. eeka penvanne nathi name kotasak athi thava.