Infection by test.exe, how to delete a file [FIXED]

Problems? Post here...
User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

dude, re-read this thread so we don't waste time. Process Explorer is in the downloads section here, use the search feature.

DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
Insection
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 132
Joined: 22 Jul 2008, 16:00
15
Contact:

Post by Insection »

Ok i fixed, thanks to everyone for your help.

I found out it was somehow hooked to explorer.exe

So in cmd i did

cd desktop
tskill explorer
del test.exe
start explorer

_____

Again thanks to everyone for their help

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

awesome.
Process explorer would be good for finding out what is running, try the right click menu>properties>Threads>Stack on any running process.

Image


So example I can see what all is used by the process/application:
ntkrnlpa.exe!KiDeliverApc+0xb3
ntdll.dll!KiFastSystemCallRet
MFC71.DLL!Ordinal1106+0x18

Image

Get used to using the process explorer, it is more surgical than taskman.
Watch your computer startup, put the processexplorer.exe in your startup folder.

DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
Insection
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 132
Joined: 22 Jul 2008, 16:00
15
Contact:

Post by Insection »

thanks for the clarification DNR

Post Reply