Go Back   Technibble Forums > Site Stuff > Repair Tool of the Week Suggestions

  Technibble Sponsor

Reply
 
Thread Tools Display Modes
  #11  
Old 01-12-2010, 01:08 AM
tekgeek's Avatar
tekgeek tekgeek is offline
 
Join Date: Mar 2009
Location: Nashua, IA
Posts: 40
tekgeek is an unknown quantity at this point
Default

this is funny I was dealing with this exact problem with a customer
and was on the phone with the client and connected remotely from
crossloop

I was looking for a way to get process explorer installed and was checking
this site for the location (remotely) and here directly and found this
thread....

well I was a bit busy trying to fix the clients issue to read this thread
I just left it open to read it later.... after lots of fussing with the computer
and getting it working again I hung up with her and read this article
giving me a better way to do what I just spent a slow connected few
hours doing
Reply With Quote
  #12  
Old 01-12-2010, 08:50 AM
Methical's Avatar
Methical Methical is offline
Super Moderator
 
Join Date: Feb 2009
Location: Christchurch, New Zealand
Posts: 2,483
Methical will become famous soon enough
Default

Cheers mate, Nice find. Adding to Ketarin

Is there a homepage for this product for further reading ? I know its creating by an MVP from BleepingComputer.com. I did a google for some info on it, found some on a few blogs, but thought that there might be an official homepage buried in BleepingComputer somewhere.
__________________
Would a homeless guy understand a knock-knock joke?
Reply With Quote
  #13  
Old 01-12-2010, 09:22 AM
steve51 steve51 is offline
 
Join Date: Dec 2009
Location: Calderdale. England UK.
Posts: 100
steve51 is an unknown quantity at this point
Default

Many thanks for yet another very useful tool, I am seeing more and more of these fake av's/rogue spyware so anything that speeds up the removal is a big help.
__________________
Steve's pc repairs.
Mobile Pc repair, covering the calderdale area.
Reply With Quote
  #14  
Old 01-13-2010, 04:31 PM
kdyer's Avatar
kdyer kdyer is offline
 
Join Date: Jul 2009
Location: Tigard, OR
Posts: 351
kdyer is an unknown quantity at this point
Smile

Quote:
Originally Posted by Methical View Post
Cheers mate, Nice find. Adding to Ketarin

Is there a homepage for this product for further reading ? I know its creating by an MVP from BleepingComputer.com. I did a google for some info on it, found some on a few blogs, but thought that there might be an official homepage buried in BleepingComputer somewhere.
Methical,

Have a gander at: http://www.gmer.net/ as this goes in to more detail on what the rkill app does.

HTH,

Kent
Reply With Quote
  #15  
Old 01-13-2010, 05:52 PM
arrow_runner's Avatar
arrow_runner arrow_runner is offline
 
Join Date: Nov 2008
Location: Cincinnati, OH
Posts: 920
arrow_runner is an unknown quantity at this point
Send a message via AIM to arrow_runner Send a message via MSN to arrow_runner Send a message via Yahoo to arrow_runner
Default

In regards to Antivirus Live: Has anyone seen where it will rename an exe and then put an infected placeholder file there instead?

For example, the infection I saw yesterday had about 8 files like the following


realplay .exe (383k) - renamed, original file
realplay.exe (40k) - placeholder, malicious file

cmd. exe (93k) - renamed, original file
cmd.exe (40k) - placeholder, malicious file

You might want to check for that with your infections. This one seemed to be renaming an executable you ran. Luckily the computer was off after 3 minutes of first sign of infection.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:02 PM.


Powered by vBulletin®
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Technibble.com is based out of MELBOURNE, AUSTRALIA.