Author Topic: Become an antivirus.  (Read 3259 times)

0 Members and 1 Guest are viewing this topic.

Offline iAmLuFFy

  • Long
  • ****
  • Posts: 231
  • Karma: +11/-6
  • i aM MoDiFiEr nOt A cReAtOr
    • View Profile
Become an antivirus.
« on: December 03, 2011, 01:43:34 PM »
Hello friends,
Well i am in a mood to wirte somthing about detecting a virus and to delete it without antivirus.
 
Well its not anything new, may be you guys already know all these, and if so MOD can remove this topic.
 
I am gonna tell you about basic virus come through external drive or some virus already executed in your system.
 
Sometimes its really annoying when you want to scan your pen drive and your antivirus tell you 3 hours left or one day left. so you can apply some basic tricks first then scan with your antivirus.
 
First of all always disable autorun, you can do it from group policy option or from registry or some hady registry files are there to do it with ease ( "Kulverstukas" have posted it before.)
 
or if you don't want to do so then you can hold shift on your keybord while you are connecting your external drive to your system. By holding shift your external drive will not be automatically executed.
 
Now second most important thing to remeber is to remove tick from
 "hide extension of file" in folder option" means you should always know that what is the extension of file that you are accessing.
 
then select check box "show hidden files" and remove tick mark from "hide system files". now a days most of the virus have attribute of hidden and system, so you better check that option
 
in XP (tools-->folder option-->view)
in newer (organize-->folder option-->view)
 
thus you will be able to see hidden files.
and if system files are getting annoying for you then just do it when you connect your drive, otherwise undo it.
 
This will help you if virus is not executed in your system. if your system is already affected then may be that option won't work, i mean it will be reset everytime automatically. (we will talk about it later)
 
First we will see when your system is still safe.
 
  • so if your pen drive is affected then probably there is a autorun.inf file with hidden and system attribute. try to delete it normaly if its get deleted then it will be easy, and if not then go to its properties and uncheck hidden and read only,
  • then open it in notpad and remove everything and save it, or just delete file. if still not working or error occured that access denied or read only file.
(note: don't yell if you know all this.. just skip ahed, because you are not the only one here :) )
 
  • then close file and start CMD
  • now go to your drive (suppose its m then)
  • c:\user\xxx> m:
  • m:\>
now change  the attribute of autorun.inf file by typing
 
  • m:\>attrib -h -s -r "autorun.inf" (h for hidden, s for system and, r for read only)
  • m:\>del "autorun.inf"
or just open your drive and delete it. it will get deleted (in 99% case).
 
  • now delete all the suspicious file in drive like folder with .exe extention or any suspicious file like 67kb or 128kb or 2kb... any file which you found suspicious can be deleted after you delete autorun.inf file.
Many points are missing, i am not getting it now,so if question arise then just ask it :)
 
Now what you can do if your system is Alreay Effected.
 
Well there is many thing you can do to make it good from worst.
 
So there are many kind of effection, like
 
  • cmd                  (not able to start)
  • task manager     (not able to start
  • folder option      (get reset everytime)
  • registry             (not able to start)
  • msconfig            (not able to start)
  • antivirus            (not detecting virus--> probably out of date or installed after virus system affected, or virus is not in antivirus database entry or virus         activity is diffrent then antivirus activity rule)
Now what to do to make those work..
 
So here are some steps that you can try
 
1) start system in safe mode. (work in most cases)
 
2) if safe mode isn't working then try to use safe mode with cmd prompt.
 
3) create a new user and check in that new user account if cmd can be open or not.
 
4) always keep some software (like tune up) from which you can check date of any   
    service created
 
use one of them and start cmd any how, if its not working then tell me situation ill help you.
 
now, after you are able to start them.
   
  • first start task manager and end all suspicious services.
  • then end explorer.exe also
  • now from new task start msconfig.
  • now in msconfig go to service tab and uncheck any suspicious or unwanted service.you can guess by manufacture or by thinking that did you have installed something releted to that service or not.
  • now go to startup tab.check for service which look unknown or cross check with tune up ( on which date service is created) or any service that you can say its virus.
  • now check location of that service from where it is started, you can find location  within startup tab under COMMAND.. it will show you the path of the file
  • now again open cmd..
  • go to that location..
  • change attribute of the file..( as i shown above)
  • then DELETE it :)
do it for every file that look like virus to you. Be care full, you will need some experiance, because if you delete some important file then it can cause problem in releted application.
 
 
Lets talk about diffrent problem
 
some times a problem arise, that you can't open anything. everything get opened in media player or notpad or office, or something else.
 
even in safe mode you can't open any exe file.
 
what will you do then?
 
don't worry, mostly this type of virus only attack specific user. you can repair this by creating a new user. control panel and user account won't work in this case.
 
  • just go to manage (my computer--> right click--> manage)
  • now local use and group--> user--> right click in blanck space and select create user
  • put user in administrator group.
  • now logoff and login to new user.
  • WOW its repaired :) :)
THAT's all right now.. if i remember missing things then ill update here, and if you get any point or question then just ask here ;D 
 
 
 
 
« Last Edit: December 03, 2011, 01:44:41 PM by iAmLuFFy »
iAmLuFFy

PublicEnemy

  • Guest
Re: Become an antivirus.
« Reply #1 on: December 03, 2011, 03:39:17 PM »
Who doesn't dream of growing up to be an antivirus?

Offline xzid

  • VIP
  • Long[]
  • *
  • Posts: 304
  • Karma: +37/-4
    • View Profile
Re: Become an antivirus.
« Reply #2 on: December 04, 2011, 11:11:02 AM »
Who doesn't dream of growing up to be an antivirus?
ME, i'm pissed off enough that I ended up a "programmer".

> quotes imply I don't give a shit, "programming" is "hobby".
> prefer chem, math & circuits.
< I R fucking "nerd"

life sucks ass... need woman, secks been about 8 months... HALP!!! PLZ FUCKIN HALP ME!!!!!!!!!!!!!!!!!!!!!

I dying, maybe... idk, my biology very weak(biology is uninteresting[electrons seem irrelevant]). w/e life suks AZZ.

STRIPPER/HOOKER next time I'm drunk enough for courage.

 >:( >:( >:( >:( >:( >:( >:( >:( >:( >:( 8) >:( >:( >:( >:( >:(

Offline PH03N1X

  • NOP
  • Posts: 15
  • Karma: +0/-0
  • Gender: Male
  • Security is just an illusion.
    • View Profile
Re: Become an antivirus.
« Reply #3 on: December 04, 2011, 04:06:03 PM »
life sucks ass... need woman, secks been about 8 months... HALP!!! PLZ FUCKIN HALP ME!!!!!!!!!!!!!!!!!!!!!

I dying, maybe... idk, my biology very weak(biology is uninteresting[electrons seem irrelevant]). w/e life suks AZZ.


Your need for intercourse seems to have seriously affected your ability to use correct spelling and grammar. I'd see a doctor :/

Online gh0st

  • 0x1337
  • *****
  • Posts: 454
  • Karma: +13/-6
  • hacker ;)
    • View Profile
Re: Become an antivirus.
« Reply #4 on: December 05, 2011, 01:53:31 AM »
I used to grow up an be an antivirus but then I took an arrow to the knee...

"Nothing is true... everything is permitted."

Offline noob

  • Int
  • **
  • Posts: 122
  • Karma: +12/-0
    • View Profile
Re: Become an antivirus.
« Reply #5 on: December 05, 2011, 02:36:13 AM »
Tricks for Windows XP,this would be very usefull  5-10 years in back :P

Online Kulverstukas

  • Administrator
  • 0x13338
  • *
  • Posts: 1928
  • Karma: +113/-10
  • Gender: Male
  • Delphi coder (and proud)
    • View Profile
    • My blog
Re: Become an antivirus.
« Reply #6 on: December 05, 2011, 07:24:21 AM »
Tricks for Windows XP,this would be very usefull  5-10 years in back :P
WinXP is still being used, noob.

Offline iAmLuFFy

  • Long
  • ****
  • Posts: 231
  • Karma: +11/-6
  • i aM MoDiFiEr nOt A cReAtOr
    • View Profile
Re: Become an antivirus.
« Reply #7 on: December 05, 2011, 10:34:10 AM »
Tricks for Windows XP,this would be very usefull  5-10 years in back :P

Are you kidding..
all these steps are for xp,2003,vista,7,some on 2008, and might work on win8  also..
 
Do you even use Windows or not!
iAmLuFFy

Offline noob

  • Int
  • **
  • Posts: 122
  • Karma: +12/-0
    • View Profile
Re: Become an antivirus.
« Reply #8 on: December 05, 2011, 04:53:26 PM »

Are you kidding..
all these steps are for xp,2003,vista,7,some on 2008, and might work on win8  also..
 
Realy?
Autorun is disabled on ,Vista,2008,Windows 7,and they had UAC,so you cant compare them with XP.All this shit you write is mostly for XP /
« Last Edit: December 05, 2011, 04:56:48 PM by noob »

Offline iAmLuFFy

  • Long
  • ****
  • Posts: 231
  • Karma: +11/-6
  • i aM MoDiFiEr nOt A cReAtOr
    • View Profile
Re: Become an antivirus.
« Reply #9 on: December 05, 2011, 08:03:16 PM »
Realy?
Autorun is disabled on ,Vista,2008,Windows 7,and they had UAC,so you cant compare them with XP.All this shit you write is mostly for XP /
Well i am using windows 7. and i wrote all this for windows 7.
now read everything one by one and try it on windows 7.
 
Then compare it with xp. then tell me diffrence.
 
And yeah i am not comparing feature of their various version. so please don't start counting them like you did now about UAC. :P
iAmLuFFy

Offline noob

  • Int
  • **
  • Posts: 122
  • Karma: +12/-0
    • View Profile
Re: Become an antivirus.
« Reply #10 on: December 05, 2011, 09:20:57 PM »
Dude AutoRun for USB drive is disabed by default in Windows 7 so first half of your tutorial is outdated,its not going to happen ,no need to prevent it

Offline Tsar

  • Int
  • **
  • Posts: 133
  • Karma: +10/-0
  • turing-recognizable
    • View Profile
Re: Become an antivirus.
« Reply #11 on: December 05, 2011, 09:25:58 PM »
This isn't really becoming an antivirius, it's just common sense and troubleshooting.

This isn't helpful for most viruses.

Offline iAmLuFFy

  • Long
  • ****
  • Posts: 231
  • Karma: +11/-6
  • i aM MoDiFiEr nOt A cReAtOr
    • View Profile
Re: Become an antivirus.
« Reply #12 on: December 05, 2011, 09:49:20 PM »
Quote
I am gonna tell you about basic virus come through external drive or some virus already executed in your system.


yes, thats what i said. but belive me its very helpful sometimes.
 
« Last Edit: December 05, 2011, 09:50:04 PM by iAmLuFFy »
iAmLuFFy

Offline Rafy

  • Int
  • **
  • Posts: 108
  • Karma: +3/-0
    • View Profile
Re: Become an antivirus.
« Reply #13 on: December 06, 2011, 02:41:55 PM »
If you get infected by autorun virus it is helpful indeed but not for most viruses.This is the method we used in the
tech shop I used to work like 4 years ago when win7 was still in the RC2 version.OT: momma,momma, when I grow
up I wanna be an antivirus! Mom: :facepalm: 
XD just for laughs!
If it moves shoot it,if it runs... hack it!

Offline neusbeer

  • Short
  • ***
  • Posts: 217
  • Karma: +18/-8
  • Gender: Male
  • Beer makes you stronger XD
    • View Profile
    • http://www.facebook.nl/hackneus
Re: Become an antivirus.
« Reply #14 on: December 11, 2011, 03:35:13 PM »
HijjackThis maybe a good idea ? :-)
Most virusses don't show up in the processlist.


a while ago a kiddo called me (son of my local pub owner) and
was 'hacked' he said. No virusscanner or whatever.
I login in with teamviewer and took a look.
he was lucky, just a RAT (installed by a fake-game-cheat)
the guy who had owned the RAT was hijjacking his email, game accounts etc.
He was even talking to him through one of his own email accounts through msn.
(that was dum) .. opened cmd.. netstat
got the ip of that duwd.
told that kiddo to disconnect from the internet, and by phone I helped him
remove the RAT/virus. (took 1 hour, because it's a kiddo who doesn't now anything about windows) found 2 injected dll files. removed them after starting in safe-mode.
Got his game account back through the game administrators there (Kuddo's for that game! normaly you're f$cked)..


done!..

So I virusscanner..  :o




Was it done?  no, ofcourse not..  got a ip to hunt down..
after a hour scanning, networking, found out who that guy was,
got all his links (blogs, facebook (even his brother's fb), google account, computer id,)  It turned out to be a hacker from a argentina hackersgroup.
noob.. big time.. Mailed him, got strange response about him being Turkish and
that I traced a botnet of him..  sjahh right..
(This is still actual.. because I still need to own this bastard..)
Fun! hack the hacker.. :P
--Neusbeer

 



Intern0t SoldierX py1337 SecurityOverride programisiai
Want to be here? Contact Ande or Satan911 on the forum or at IRC.