Home  
  Microsoft  
  Cisco  
  CompTIA  
  CWNP  
  InfoSecurity  
  Forums  
  Blogs  
  Topsites  
  Watch free videos online  
     
  Subnet Calculator  
  Online Degrees  
  Exam Vouchers  
  Free Magazines  
     

  Watch free videos online  
   

 

Register Practice Exams TechNotes Members List Search Today's Posts Mark Forums Read
Go Back   TechExams.net IT Certification Forums > General > Off-Topic
Reply
 
Thread Tools
Senior Member
 
ladiesman217's Avatar
 
Join Date: Oct 2007
Location: Philippines
Posts: 407

Certifications: CSNT,MCP 270
ladiesman217 is on a distinguished road
Old 12-27-2007, 04:26 AM   #1 (permalink)
Default help eliminate killer.exe

anyone here know an easy way how to kill this virus. its included on the startup. i cant run any utilities to eliminate this one since it kills all open programs.



__________________
No Sacrifice, No Victory.

ladiesman217 is offline   Reply With Quote

Login/register to remove this advertisement.
Senior Member
 
Join Date: Mar 2007
Posts: 12,182

dynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to behold
Old 12-27-2007, 04:38 AM   #2 (permalink)

You can try booting off the installation cd and loading the recovery console to delete the file. Maybe you could run some type of removal tool off a floppy or something too.

dynamik is offline   Reply With Quote
SWM
Senior Member
 
SWM's Avatar
 
Join Date: May 2006
Location: Australia
Posts: 288

Certifications: MCSE 2003, MCITP 2008, MCTS Vista, MCTS SBS2008, Blackberry Certified Server Specialist
SWM is on a distinguished road
Old 12-27-2007, 06:10 AM   #3 (permalink)

try booting from a Bartpe CD and then delete any killer.exe files on the hard disk



__________________
Isn't Bill such a Great Guy!!!!

SWM is offline   Reply With Quote
Senior Member
 
ladiesman217's Avatar
 
Join Date: Oct 2007
Location: Philippines
Posts: 407

Certifications: CSNT,MCP 270
ladiesman217 is on a distinguished road
Old 12-27-2007, 06:32 AM   #4 (permalink)

Quote:
Originally Posted by SWM
try booting from a Bartpe CD and then delete any killer.exe files on the hard disk
i was suppose to do that but problem is the laptop im fixing cant read burned cds...it can only read genuine cd's... i dont know why...

dynamik i'll try your suggestion but if i fail i'll just format to kill the killer....



__________________
No Sacrifice, No Victory.

ladiesman217 is offline   Reply With Quote
Self-Described Huguenot
 
blargoe's Avatar
 
Join Date: Nov 2005
Location: NC
Posts: 2,672

Certifications: MCSE (Messaging and Security 2000 & 2003); MCTS:E2K7; VCP; Security+; A+; EMCISA; CCNA (expired).
blargoe is a glorious beacon of lightblargoe is a glorious beacon of lightblargoe is a glorious beacon of lightblargoe is a glorious beacon of lightblargoe is a glorious beacon of lightblargoe is a glorious beacon of light
Old 12-27-2007, 11:00 AM   #5 (permalink)

Usually, my policy is to format an infected system anyway. But I really like a pristine system.

If you can't open any programs, you have no option than to try booting into another environment like Ultimate Boot CD, Bart PE, etc. and trying to clean the system. UBCD has a virus scanner included with it so maybe you should start there.



__________________
IT guy since 12/00

Next on my list to conquer: MCITP:EM; VCP4... then taking a break.

blargoe is offline   Reply With Quote
MIPS processor please
 
Mishra's Avatar
 
Join Date: Feb 2007
Location: Louisville, KY
Posts: 2,108

Certifications: MCSE 2003, MCTS: Vista Configure, VCP4, Associates in Computer Network Systems
Mishra is a jewel in the roughMishra is a jewel in the roughMishra is a jewel in the rough
Send a message via AIM to Mishra
Old 12-27-2007, 11:05 AM   #6 (permalink)

www.bootdisk.com

floppy?

Mishra is offline   Reply With Quote
Senior Member
 
ladiesman217's Avatar
 
Join Date: Oct 2007
Location: Philippines
Posts: 407

Certifications: CSNT,MCP 270
ladiesman217 is on a distinguished road
Old 12-28-2007, 06:50 AM   #7 (permalink)

thnks for all who replied!

i got another dvd now that supports reading burned cd's. now i can boot using bartpe....just want to ask how can i delete hidden virus files like krag.exe.

im wondering if its possible to perform manual deletion since the virus made a lot directories under the Windows folder.

if you know a free virus removal pls inform me.

pccillin is totally useless! it cant even detect krag.exe



__________________
No Sacrifice, No Victory.

ladiesman217 is offline   Reply With Quote
Grumpy old bugger
Forum Admin
 
RussS's Avatar
 
Join Date: Sep 2002
Location: Hamilton - New Zealand
Posts: 2,116

RussS is a jewel in the roughRussS is a jewel in the roughRussS is a jewel in the rough
Old 12-28-2007, 08:41 AM   #8 (permalink)

If you have UBCD for Win you can run several of the AV tools such as Stinger or the Avast tool to remove infections. You will also find that using one of the explorers such as Free Commander you can see invisible files.

**note** - remember to delete the page file



__________________
www.supercross.com
FIM website of the year 2007

RussS is offline   Reply With Quote
New Member
Registered Member
 
royal's Avatar
 
Join Date: Jul 2006
Location: Chicago, IL
Posts: 3,376

Certifications: A+, Network+, MCSE:M 2003, MCITP: Enterprise Messaging Administrator, MCTS: OCS (Conf/Voice)/Hyper-V, Exchange MVP, B.S.
royal is a jewel in the roughroyal is a jewel in the roughroyal is a jewel in the roughroyal is a jewel in the rough
Old 12-28-2007, 10:14 PM   #9 (permalink)

Seriously, if you have a virus, format. There are so many virus' that replicate and infect other stuff that antivirus programs don't detect. Especially if you do any type of online banking, etc..

If you don't want to format, run a program called HiJackthis so we can check out your run on startup registry keys and programs that are running in task manager.

As others said, you can just boot from some type of boot disk to delete the file. If you don't format, I highly suggest you use a bunch of antivirus scanners and try to ensure your system is virus free.

But again, I recommend to format, especially if the system is connected to a corporate network!



__________________
“For success, attitude is equally as important as ability.” - Harry F. Banks

royal is offline   Reply With Quote
Senior Member
 
Join Date: Sep 2006
Location: San Francisco Bay Area
Posts: 1,407

Certifications: A+, Net+, Sec+, CCNA:Sec/Voice, MCITP:SA & MCSE
Daniel333 will become famous soon enough
Send a message via AIM to Daniel333
Old 12-28-2007, 11:03 PM   #10 (permalink)

ladiesman217,

Malware removal is tedious. If it's going to take you more than an hour, it's best to reformat. BUT if you are doing it as an exercise in learning then here is my recommendation.

1) Snag McAfee command line scanner and trend command line scanner. Both free from their sites. Place them on the c: of the target computer.
2) Boot to BART-PE
3) delete all the temp folder on the computer
4) Run the Mcafee then the trend.
5) Find the exact path of the file you were having trouble with and delete it from the command line if it's still there. I also search through the C: root and C:\Windows\System32 folder for errant files as well.
6) Reboot to safe mode with networking, see if it comes back.
6a - if it does) pull the HDD out of the laptop and install it into an enclosure scan it from another computer running Panda, McAfee, Norton, Trend, Spysweeper, Ad-aware, spybot, Spyware Doctor and Avast.
6b) If it doesn't, install and update Avast, Ad-aware, Spybot and SpySweeper scan...
7) use hijackthis to remove anything funny.
uninstall the apps above
9) Boot to regular mode, run Registry Mechanic
10) Run/update the workstations regular protection (Anti virus, antispyware and firewall), chances are what ever they were using was not updated or a poor choice for that user. I personally find Norton to be a system hog and too complicated for most users, so it does more harm than good. Something simple like Spy sweeper normally works best.
11) Apply all Windows updates and switch them to Firefox.

That assumes you have 4 hours to blow.



__________________
-Daniel
Taking a break from certs for now. I need "direction"

Daniel333 is offline   Reply With Quote
Senior Member
 
binarysoul's Avatar
 
Join Date: Jul 2006
Location: Canada
Posts: 820

Certifications: Bachelor of Business (MIS), DIT (Networking). Certification(s): Superman. Working towards CEO.
binarysoul will become famous soon enoughbinarysoul will become famous soon enough
Old 12-29-2007, 12:39 AM   #11 (permalink)

Format and reinstall the OS.

If no backup exists, it's a lesson learned.

Of course there's a solutin, but r u willing to spend 10 hours?




__________________
Blaming tfosorciM

binarysoul is offline   Reply With Quote
Senior Member
 
Kasor's Avatar
 
Join Date: Jul 2003
Location: Statue of Liberty
Posts: 826

Certifications: x^n
Kasor has a spectacular aura aboutKasor has a spectacular aura aboutKasor has a spectacular aura about
Old 12-29-2007, 10:12 PM   #12 (permalink)

I agree with everybody, sometime it is better off to just reformat the HD. Unless you are engineer that like to break into the machine code and the circuit.

Tell the user that you will hold them accountable to bring the virus to the laptop. Now you need to reformat the HD to get it work. Of course unless they are senior management that must need the file back. Then you take the HD to the recovery specialist.



__________________
Kill All Suffer T "o" ReBorn

Kasor is offline   Reply With Quote
Bookmarks
Go Back TechExams.net IT Certification Forums > General > Off-Topic
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT. The time now is 06:58 AM.

 
 
Featured Sponsors

TrainSignal - “Hands On” computer training for IT professionals. Network+ Training, MCSE, Cisco & more! Visit Train Signal’s free training site to get loads of Free Computer Training, videos, articles and practice exams.

Preplogic - Sign up now to get Unlimited Access to PrepLogic's entire video training library. Enjoy open access to Microsoft Server 2008, CCNA, CISSP®, PMP and many more. Get Unlimited Access

 

Powered by vBulletin® Version 3.8
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
TechExams.net © 2002 - 2010