Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Virus/Malware Virus /Rootkits Thread, Work In Progress

views
     
fenzodahl512
post Mar 3 2009, 08:19 AM


Group Icon
Elite
1,089 posts

Joined: Jun 2008
Hello.. Sality is a polymorphic virus that infects Win32 PE executable files, or in other words, infects each .exe and .scr files..

If your computer has Sality on it, I recommend you to go to any Malware Removal forum for further assistance.. The list can be found in website below..

http://www.uniteagainstmalware.com/schools.php

http://asap.maddoktor2.com/

To be honest, the most efficient way to combat Sality is just to do a full-reformat to your computer.. If you choose to reformat the computer, please don't forget to backup all of your data first.. Do NOT include any .exe and .scr files.. Meaning that do not include any screensaver, installer, applications in your backup.. You risk infecting other computers as well..
fenzodahl512
post Aug 26 2009, 08:18 PM


Group Icon
Elite
1,089 posts

Joined: Jun 2008
QUOTE(Chyan @ Aug 26 2009, 06:10 PM)
OMG.

I've been infected with reader_s.exe file.
It kept blowing up nasty files like .tmp [number].EXE
also because of this servises.exe

Reboot then hang after the startup sound  vmad.gif

*using malwarebytes and super.

I read somewhere that reader_s.exe is damn bad one.  rclxub.gif
*
Most probably Virut.. If you're not sure, just upload and scan it at either VirSCAN.org or VirusTotal

If there's detect it as either Virut/Virtob, then its Virut.. Look at below link for Virut..

http://forum.lowyat.net/index.php?showtopi...post&p=23701573
fenzodahl512
post Mar 31 2010, 10:55 PM


Group Icon
Elite
1,089 posts

Joined: Jun 2008
QUOTE(armadasaxon @ Mar 31 2010, 04:09 PM)
My whole company infected by this worm w2.downadup.b..I used the symantec tool also unable to clean.Install the ms08-67 patches also cannot.How to get rid of the worm?..My antivirus is symantec...also used the kaspersky kido removal tool and bitdefender one oso cannot..How ah?
I am really out of ideas and my boss is soo damm pissed off.
*
That particular worm will infected any computer that connected to your office network..

My recommendation to follow the "kidokiller" instruction from Kaspersky below.. Read from the "For corporate users (to remove the Net-Worm.Win32.Kido via Administration Kit)" part...

http://support.kaspersky.com/faq/?qid=208279973

If above is not working, my second recommendation is to install "kidokiller" in ALL computer in the office >> stay until after office hour >> disconnect ALL computer from network (just plug out the network cable or turn off the "switch" and "router") >> run "kidokiller" as per instructed in the link I give above..
fenzodahl512
post Nov 27 2010, 12:05 AM


Group Icon
Elite
1,089 posts

Joined: Jun 2008
QUOTE(k59 @ Nov 25 2010, 05:02 PM)
E:\rasipamse\idumigodine.exe

this file can't be open after scanning with free avira .
is it a thread for my thumbdrive.
icon for t thumbdrive also not as usual.

try to find the file but cant find.
pls help?
*
Go to Windows XP computer and then remove the rasipamse folder via IceSword

 

Change to:
| Lo-Fi Version
0.0267sec    0.71    7 queries    GZIP Disabled
Time is now: 12th December 2025 - 06:02 PM