PDA

View Full Version : Virii Removal/Detection.


Valmar
2003-03-12, 11:01 PM
Ive been informed by a few people that have gotten Virii on there computer from links that were posted on Zelaron. Now i know this isnt anything new to some of you but i figure this will help alot of people get rid of them annoying Virii.

First off you need a good virus scanner, i reccomend AVG 6.9. If your not able to find a copy of this program get it at the website in my Sig, it contains a serial number to cancel the 30 day trial.

Next, when you suspect you are infected, run AVG and if it runs then great but sometimes due to the newer virii that have AV/FW killers in them it will be shut off. There is a simple way to fix this problem. Disconnect from the internet the second you think your infected. Check to see if your V-scanner will run, if not your definatly infected. Then in order for you to be able to run your V-scanner locate the main directory which its held in. For AVG 6.0 it will be in C:\Program Files\Grisoft\AVG6 after opening this folder locate the file AVGw and rename it to something random (anything works) this is to cancel out the AV/FW killer that is embedded into the trojan or virus itself, because it goes by name so renaming the V-scanner makes it stealthed to the AV/FW killer. Then run your scanner, it should then be able to pick up the virii, follow the instruction to get rid of the virii. If it says that it cant be romoved due to it being in use then AVG wont be able to delete this trojan. You will then have to get a copy of Panda Anti-Virus Platinum. Rename the MAIN scanner to something random as to bypass the AV/FW kill then run the scanner. Follow the instruction and it will tell you to restart the computer and the virus will be neautrilized.

Hope this helps, ill sticky this for a while.

Mr.Lee
2003-03-17, 04:26 AM
Btw do you know HEX? From what ive heard if you hex a program you can "see" if it contains a virus or not. How do you check it? What offsets etc...

Seliggy
2003-03-17, 11:36 AM
mmmm

Valmar
2003-03-18, 12:41 PM
Yes, Mr. Lee i know HEX. Its not as easy as you might think, do you know anything at all about it?

Mr.Lee
2003-03-19, 02:14 AM
Yes.

Anime-Otaku
2003-04-18, 07:27 PM
question *off topic sort of* but could u say take some hex from err.. lets say a trade hack (only thing that came to mind dont flame) u took it and then redid it totally (total over haul ) and remade its writting. actually what im getting at is would it work on closed? or would it stil be detected by blizz server protection stuff and kick it ?

Valmar
2003-04-18, 07:52 PM
Well, if you redid it you would have to have another method to use the "tradehack" as the first took the trade buffer and exploited it. You would have to have a completly different method to use it or else it would be the same thing... So the answer...no.

uncapped
2003-04-19, 07:47 AM
EDIT~ Staff can handle all that.

!King_Amazon!
2003-04-19, 09:05 AM
Let's freak out about it.

uncapped
2003-04-20, 03:50 AM
Bastards...

Valmar
2003-04-20, 06:59 AM
To much spam, closed.

Mr.Lee
2003-05-22, 03:19 AM
Unstuck. Not really DII.