CariDotMy

 Forgot password?
 Register

ADVERTISEMENT

12Next
Return to list New
View: 5509|Reply: 30

Virus Degil

[Copy link]
Post time 6-8-2008 12:53 AM | Show all posts |Read mode
aku x dapat nak del virus dlm pendrive aku...

virus tu document.exe

aku da try format tp x leh... file tu protect...

so how?
Reply

Use magic Report


ADVERTISEMENT


Post time 6-8-2008 01:07 AM | Show all posts

Reply #1 Rempit_25's post

guna unlocker kat fileforum.com
Reply

Use magic Report

Post time 6-8-2008 01:09 AM | Show all posts
Document.exe - Dangerous
--------------------------------------------------------------------------------

document.exe

Document.exe is a mass-mailing worm W32.Shima-A.

Document.exe tries to terminate antiviral programs installed on a user computer.

Document.exe monitors user Internet activity and private information.

It sends stolen data to a hacker site.

Related files:
%Windows%\Document.zip
C:\Document.exe
Reply

Use magic Report

Post time 6-8-2008 01:12 AM | Show all posts
kao pakai le anti virus.....mesti boleh..tapi kao kena boot dlm safe mode..
Reply

Use magic Report

 Author| Post time 6-8-2008 01:29 AM | Show all posts
Originally posted by razhar at 6-8-2008 01:07 AM
guna unlocker kat fileforum.com


aku da guna...tp still x leh nak del...

antivirus pun x dapat nak buang....

cam ne nie
Reply

Use magic Report

Post time 6-8-2008 02:16 AM | Show all posts
kalau dah degil sangat.. cucuk je pendrive tu kat pc yg ada os linux.... remove all partion + boot .. lepas tu create new partion..abis cerita
Reply

Use magic Report

Follow Us
Post time 6-8-2008 02:19 AM | Show all posts
ko dah try scan ngan mane2 spyware applications?
Reply

Use magic Report

Post time 6-8-2008 08:03 AM | Show all posts
kalo takleh format, guna aje hdd wipe atau kill disk.
cari kat sini : www.hddguru.com
Reply

Use magic Report


ADVERTISEMENT


Post time 6-8-2008 11:33 AM | Show all posts
Originally posted by Rempit_25 at 6-8-2008 12:53 AM
aku x dapat nak del virus dlm pendrive aku...

virus tu document.exe

aku da try format tp x leh... file tu protect...

so how?

Mula2 kat Folder options, setkan supaya show all hidden system files.

Masuk thumbdrive tu and tengok ada tak autorun.inf. Kalau ada, delete tu dulu. Takyah tutup explorer window tu.

Then kat task manager, kill semua DOCUMENT.EXE yg ada.

Masuk semula ke thumbdrive and delete DOCUMENT.EXE tu.

Buat search kat PC... cari autorun.inf... delete SEMUA.

Kemudian scan semula in Safe Mode PC tu... harap2 explorer.exe and calc.exe ko pun tak infected ngan virus tu.
Reply

Use magic Report

Post time 7-8-2008 12:52 AM | Show all posts
Originally posted by 0001 at 6-8-2008 11:33

Mula2 kat Folder options, setkan supaya show all hidden system files.

Masuk thumbdrive tu and tengok ada tak autorun.inf. Kalau ada, delete tu dulu. Takyah tutup explorer window tu.

Then  ...


wa rasa dia punya calc.exe tu musti dah dijangkiti......calc.exe ni adalah default yg akan dijangkiti..
Reply

Use magic Report

Post time 7-8-2008 12:56 AM | Show all posts
Originally posted by Rempit_25 at 6-8-2008 01:29


aku da guna...tp still x leh nak del...

antivirus pun x dapat nak buang....

cam ne nie


lu tahu ke cam na nak boot ke safe mode nih?..kalu boot dlm safe mode,kemungkinan virus tu hidup adalah kosong kerana semasa safe mode,hanya basic operating system je yg wujud...khas untuk troubleshooting...dlm safe mode,scan le guna anti virus dan anti spyware....mesti boleh punya la bai......standard anti virus boleh bunuh...
Reply

Use magic Report

Post time 7-8-2008 09:17 AM | Show all posts
emm sepatutnya unlocker dah bereskan dah perkara ni.. atau pun dia bagi pilihan nak delete masa reboot atau tidak..
Reply

Use magic Report

Post time 7-8-2008 10:22 AM | Show all posts

Reply #12 kmkd's post

betol.....virus ni boleh dibunuh oleh AV ...small matter je.. ..agak2 bai tu ada tak AV?
Reply

Use magic Report

Post time 7-8-2008 10:26 AM | Show all posts
bai yg kena jangkit tu..sila baca article nih ye.. -

"It's a overwriting virus, programmed in Visual Basic 6.
It will add itself in the registry as

H K E Y _ L O C A L _ M A C H I N E \ S O F T W A R E \ M I C R O S O F T \ W I N D O W S \ C U R R E N T V E R S I O N \ R U N \ E x p l o r e r

---> terminate running processes and remove this value.

It will OVERWRITE calculator programs from windows !
Don't start calc - or you will get infected again.

It copies itself in the windows folder as calc.exe, config_.com (file is hidden!), mscalc.exe and WINDOWS.exe. All files having a filesize of 40960 bytes.

ATTENTION: it also overwrites OTHER EXEFILES! Means if you start a infected executable it will "strip" the virus code out of this file and will start it uninfected, BUT WILL INFECTED IN THE SAME TIME ANOTHER EXECUTABLE!"
Reply

Use magic Report

Post time 7-8-2008 10:32 AM | Show all posts

W32.Lovgate.Y@mm

W32.Lovgate.Y@mm ni sebahagian dari komponen document.exe...so bai try guna W32.HLLW.Lovgate Removal Tool kat http://www.symantec.com/content/ ... _writeups/FixLG.com
Reply

Use magic Report

Post time 7-8-2008 10:33 AM | Show all posts
tapi musti dibuat dlm komputer bai berada dlm SAFE MODE...
Reply

Use magic Report


ADVERTISEMENT


Post time 7-8-2008 10:54 AM | Show all posts

pilihan untuk bai...

1. Dr.Web CureIt! 4.44- http://www.freedrweb.com/cureit

2. McAfee AVERT Stinger 3.9.9- http://download.nai.com/products/mcafee-avert/stng399.exe

3. Norman Malware Cleaner 2008.05.13- http://fileforum.betanews.com/se ... Malware_Cleaner.exe

Scanning MUSTI dlm SAFE MODE...
Reply

Use magic Report

Post time 7-8-2008 10:58 AM | Show all posts
Reply

Use magic Report

Post time 7-8-2008 11:00 AM | Show all posts
selepas sudah..bai masuk regedit (run-regedit)..bai cari HKEY_LOCAL_MACHINE entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Explorer
<Windows folder>\config_.com

bai delete -<Windows folder>\config_.com
Reply

Use magic Report

Post time 7-8-2008 11:06 AM | Show all posts
bai musti2 guna unlocker untuk bunuh document.exe..bai kena pilih option unlock,sebelum itew bai kena highlight file tu..selepas pilih unlock...exit then bai guna unlocker semula untuk pilih option KILL../DELETE...
Reply

Use magic Report

12Next
Return to list New
You have to log in before you can reply Login | Register

Points Rules

 

ADVERTISEMENT



 

ADVERTISEMENT


 


ADVERTISEMENT
Follow Us

ADVERTISEMENT


Mobile|Archiver|Mobile*default|About Us|CariDotMy

28-11-2024 07:10 AM GMT+8 , Processed in 0.065483 second(s), 32 queries , Gzip On, Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

Quick Reply To Top Return to the list