Tech ARP Forums

Go Back   Tech ARP Forums > Hardware Discussion > General Hardware
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

General Hardware For other hardware related discussions, this is the place!

Reply
 
LinkBack Thread Tools
Old 29th Jan 2008, 04:21 PM   #1 (permalink)
Hyperactive
 
NeoSquall's Avatar
 
Join Date: 11 May 2003
Location: Sabah, Malaysia
Posts: 2,537
Reputation: 14
NeoSquall is on a distinguished road
Rep Power: 9
Default Virus or worm?

a few of this warning signs came up unto my comp.. all link to these 3 program?

kavo.exe
p3r1ud.exe
zz.exe

I've ran two anti virus.. kapersky and avast.. nothing seems to get rid of the warning signs.. they dont detect any virus or worms or trojan tho.. just its kinda annoying when u start the comp you get the warning sayying that it will terminate the program because of some part of the memory cant be found.. anyone knows how to completely remove this?

then again.. I cannot view my hidden folders.. each time I choose the option to view my hidden folers.. it automatically goes back to "Do not show hidden files and folder"..

help...
__________________
LALALA WEEEE....
NeoSquall is offline   Reply With Quote
SPONSOR
Old 29th Jan 2008, 05:25 PM   #2 (permalink)
Official Mascot Creator
 
Falcone's Avatar
 
Join Date: 18 Dec 2002
Location: Shanghai, See En
Posts: 3,371
Reputation: 1878
Falcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant futureFalcone has a brilliant future
Rep Power: 29
Default

Get Hijackthis and remove the startup from your registry.
__________________
I'm a noob, my photos sucks, but if you can live with that...
http://www.pumpkinproject.com/


Flickr
Falcone is online now   Reply With Quote
Old 29th Jan 2008, 07:34 PM   #3 (permalink)
Hyperactive
 
NeoSquall's Avatar
 
Join Date: 11 May 2003
Location: Sabah, Malaysia
Posts: 2,537
Reputation: 14
NeoSquall is on a distinguished road
Rep Power: 9
Default

the program p3r1ud.exe still exist in my slave HDD.. I think its from a dos file called 3g08.bat.. but my anti virus cant seem to detect it.. do I have any other choice other than reformatting my slave HDD??

I still cant view hidden files tho ..

btw.. the hijackthis works! thx a lot falcone! really appreaciate it..
__________________
LALALA WEEEE....
NeoSquall is offline   Reply With Quote
Old 29th Jan 2008, 07:50 PM   #4 (permalink)
Little Kiki
 
Trinity's Avatar
 
Join Date: 5 Jan 2003
Location: Ohio,usa
Posts: 7,249
Reputation: 6033
Trinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond reputeTrinity has a reputation beyond repute
Rep Power: 75
Default

Try turning system restore off, Then reboot to safe-mode and then find and delete it or run virus scanner from there. Then reboot and then turn system restore back on. I had to do it this way to get rid of something a few weeks ago.
__________________
(\__/)
(-. - )
(> < )
Trinity is offline   Reply With Quote
Old 29th Jan 2008, 08:24 PM   #5 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 33,137
Reputation: 3730
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 78
Default

Quote:
Originally Posted by NeoSquall View Post
the program p3r1ud.exe still exist in my slave HDD.. I think its from a dos file called 3g08.bat.. but my anti virus cant seem to detect it.. do I have any other choice other than reformatting my slave HDD??

I still cant view hidden files tho ..

btw.. the hijackthis works! thx a lot falcone! really appreaciate it..
Did you try seaching through the registry for p3r1ud.exe?
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 29th Jan 2008, 08:48 PM   #6 (permalink)
Pickin' Da Gitfiddle
 
Mac Daddy's Avatar
 
Join Date: 19 Nov 2007
Location: Canada
Posts: 2,052
Reputation: 802
Mac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to beholdMac Daddy is a splendid one to behold
Rep Power: 13
Default

Also try this it removes things other programs don't as well

The home of Spybot-S&D!
Mac Daddy is offline   Reply With Quote
Old 29th Jan 2008, 10:44 PM   #7 (permalink)
"Little" Devil
 
PsYkHoTiK's Avatar
 
Join Date: 8 Apr 2004
Location: On the "throne"
Posts: 14,746
Reputation: 4681
PsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond repute
Rep Power: 66
Default

Spybot S&D is one of my fav apps. Though it rarely gets much use...

__________________
Intel SLBEJ @ 4GHz : 3x2GB OCZ Platinum DDR3 1600 : Asus P6X58 Premium : WD RE3 250GB x2 RAID 0 : 3ware 9650SE-2LP : XFX Radeon 5850 : XFi Platinum : Silverstone OP650 : Silverstone TJ-07 : Swiftech Apogee XT : MCP655 : Thermochill PA120.3 w Scythe Ultra Kaze
CPU-Z: SLBEJ : SLAPL : SLA9U : FX-55 : DDR 600 : VX
www.techarp.com
PsYkHoTiK is offline   Reply With Quote
Old 29th Jan 2008, 10:54 PM   #8 (permalink)
Hyperactive
 
The_YongGrand's Avatar
 
Join Date: 12 Feb 2005
Location: Somewhere in 甲洞...
Posts: 2,877
Reputation: 1187
The_YongGrand has much to be proud ofThe_YongGrand has much to be proud ofThe_YongGrand has much to be proud ofThe_YongGrand has much to be proud ofThe_YongGrand has much to be proud ofThe_YongGrand has much to be proud ofThe_YongGrand has much to be proud ofThe_YongGrand has much to be proud ofThe_YongGrand has much to be proud of
Rep Power: 19
Default

Quote:
Originally Posted by NeoSquall View Post
a few of this warning signs came up unto my comp.. all link to these 3 program?

kavo.exe
p3r1ud.exe
zz.exe

I've ran two anti virus.. kapersky and avast.. nothing seems to get rid of the warning signs.. they dont detect any virus or worms or trojan tho.. just its kinda annoying when u start the comp you get the warning sayying that it will terminate the program because of some part of the memory cant be found.. anyone knows how to completely remove this?

then again.. I cannot view my hidden folders.. each time I choose the option to view my hidden folers.. it automatically goes back to "Do not show hidden files and folder"..

help...
try searching for these program names in Google - sometimes they might give you a lot of clue if found.
__________________
Intel Core 2 Duo E7200, 2GB DDR2-667 RAM, Gigabyte 945GCMX-S2, Sapphire ATi Radeon HD4850 512MB DDR3

Intel Pentium Dual Core E2140, 2GB DDR2-667 RAM, Asus P5B-E Plus, nVidia Geforce 7950GT 512MB DDR3

The_YongGrand is offline   Reply With Quote
Old 30th Jan 2008, 07:58 AM   #9 (permalink)
Administrator
 
Chai's Avatar
 
Join Date: 6 Oct 2002
Location: Maranello
Posts: 28,124
Reputation: 4649
Chai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond repute
Rep Power: 82
Default

Most of the time, virus scanner cannot detect them.
__________________
Chai (Contributor & Forum Admin)
http://www.techarp.com/
Chai is offline   Reply With Quote
Old 30th Jan 2008, 09:15 AM   #10 (permalink)
Super Active
 
lee_what2004's Avatar
 
Join Date: 28 Dec 2007
Location: Melaka
Posts: 1,352
Reputation: 1149
lee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud of
Rep Power: 15
Default

First, post the hijackthis log here first.

For the hidden file, run the program UnLock Them All!.exe from folder fixing hidden, if you see any checklist, please unchecklist it, then press Ubah, Yes, Yes, then press Keluar.

For the deleting virus file, use kill you.exe from The killer machine folder, go to virus removal, then press browse, go to the virus file is, if it is unseen due to it is hidden, then just type it address, most probably D:\p3r1ud.exe
Then just press scan and wait. it will scan all your hdd and delete the same file with that one, so use it wisely (you will not want to delete one of your system file )
after that, then do it one more time for the 3g08.bat
Then post another hijackthis log.

and for the last, if still have any problem, just state it here.

[code]http://files.myopera.com/horlicksfamily/files/The_Killer_Machine.rar[/code]
__________________
Once a wise-man said :
Chapter 1: Don't ever compare if you want to stay constant.....
Chapter 2: Whatever you have done in the internet, you will never get away from it...
Chapter 3:To be continued after I thought another one
lee_what2004 is online now   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +8. The time now is 08:49 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2009 Tech ARP. All rights reserved.