Staredit Network > Forums > Technology & Computers > Topic: A (new) challenge
A (new) challenge
Mar 19 2009, 9:32 pm
By: Conspiracy  

Mar 19 2009, 9:32 pm Conspiracy Post #1



I have a virut (yes, virut.) called reader_s.exe. One of the most annoying things I have confronted in my life. And I was wondering if anyone knew a way to remove it without reformatting. Here is what I have tried:

- MSConfiged it. It re-enables it self.
- Used a program created by Prevx CSI (If you google reader_s.exe, its the first link) to isolate all of the corrupted files, I manually deleted them all and the reader_s.exe file came back.
- When reader_s.exe executes, AVG Free 2008 detects it, and I prompt it to delete the file, but reader_s.exe comes back.
- I have tried system recovery. It doesn't work.

Things I cannot do:
- Log in (used to be able to), because reader_s logs me out.
- Execute a program when I am NOT in safe mode, reader_s stops the process.
- Install programs. I am in safe mode.
- (Prefered) Reformat.

Can anyone come up with a way to root out this virut?

Post has been edited 1 time(s), last time on Mar 23 2009, 9:48 pm by Conspiracy.



None.

Mar 19 2009, 9:37 pm O)FaRTy1billion[MM] Post #2

👻 👾 👽 💪

Can you remove it in safe mode?

Also:
http://forums.majorgeeks.com/showthread.php?t=35407



TinyMap2 - Latest in map compression! ( 7/09/14 - New build! )
EUD Action Enabler - Lightweight EUD/EPD support! (ChaosLauncher/MPQDraft support!)
EUDDB - topic - Help out by adding your EUDs! Or Submit reference files in the References tab!
MapSketch - New image->map generator!
EUDTrig - topic - Quickly and easily convert offsets to EUDs! (extended players supported)
SC2 Map Texture Mask Importer/Exporter - Edit texture placement in an image editor!
\:farty\: This page has been viewed [img]http://farty1billion.dyndns.org/Clicky.php?img.gif[/img] times!

Mar 19 2009, 9:38 pm Conspiracy Post #3



Quote from O)FaRTy1billion[MM]
Can you remove it in safe mode?

Yes, but when I log in, it comes back.

And if I use Msconfig, it re-enables itself. I have never seen anything like this.



None.

Mar 19 2009, 9:38 pm Falkoner Post #4



Download and set up the Ultimate Boot CD on another computer, and then boot off of it on the broken computer instead of the main OS, that way the virus never runs, and then clean it up using the temporary OS.

Also, I would disconnect my internet if I were you before getting onto the normal operating system again, that way it doesn't just go out and redownload itself.



None.

Mar 19 2009, 9:43 pm O)FaRTy1billion[MM] Post #5

👻 👾 👽 💪

Online thing says it adds itself to the registry to run or something... You could play in there.





TinyMap2 - Latest in map compression! ( 7/09/14 - New build! )
EUD Action Enabler - Lightweight EUD/EPD support! (ChaosLauncher/MPQDraft support!)
EUDDB - topic - Help out by adding your EUDs! Or Submit reference files in the References tab!
MapSketch - New image->map generator!
EUDTrig - topic - Quickly and easily convert offsets to EUDs! (extended players supported)
SC2 Map Texture Mask Importer/Exporter - Edit texture placement in an image editor!
\:farty\: This page has been viewed [img]http://farty1billion.dyndns.org/Clicky.php?img.gif[/img] times!

Mar 19 2009, 9:45 pm Conspiracy Post #6



Quote from Falkoner
Download and set up the Ultimate Boot CD on another computer, and then boot off of it on the broken computer instead of the main OS, that way the virus never runs, and then clean it up using the temporary OS.

Also, I would disconnect my internet if I were you before getting onto the normal operating system again, that way it doesn't just go out and redownload itself.

Thanks falky, but I sadly don't know where my windows disk is. :/

Quote from O)FaRTy1billion[MM]
Online thing says it adds itself to the registry to run or something... You could play in there.


I have eliminated that, I even changed the string data, but when I did, it just decided to re-add it.



None.

Mar 19 2009, 9:47 pm Falkoner Post #7



Quote
Thanks falky, but I sadly don't know where my windows disk is. :/

You can torrent one, that's what I did, it doesn't need a CD Key.



None.

Mar 19 2009, 9:49 pm O)FaRTy1billion[MM] Post #8

👻 👾 👽 💪

Have you done anything with this yet?



TinyMap2 - Latest in map compression! ( 7/09/14 - New build! )
EUD Action Enabler - Lightweight EUD/EPD support! (ChaosLauncher/MPQDraft support!)
EUDDB - topic - Help out by adding your EUDs! Or Submit reference files in the References tab!
MapSketch - New image->map generator!
EUDTrig - topic - Quickly and easily convert offsets to EUDs! (extended players supported)
SC2 Map Texture Mask Importer/Exporter - Edit texture placement in an image editor!
\:farty\: This page has been viewed [img]http://farty1billion.dyndns.org/Clicky.php?img.gif[/img] times!

Mar 19 2009, 9:49 pm Conspiracy Post #9



Quote from Falkoner
Quote
Thanks falky, but I sadly don't know where my windows disk is. :/

You can torrent one, that's what I did, it doesn't need a CD Key.

What do you mean torrent? Isn't that a program? Sadly I don't have any type of torrent, and I can't install it. I maybe able to install it to my flash drive though...

Have you done anything with this yet?[/quote]

Yes, I am trying this.



None.

Mar 19 2009, 9:51 pm Biophysicist Post #10



You don't need to torrent it on the virus'd computer.



None.

Mar 19 2009, 9:53 pm Falkoner Post #11



Quote
What do you mean torrent? Isn't that a program? Sadly I don't have any type of torrent, and I can't install it. I maybe able to install it to my flash drive though...

Yeah, I would recommend µTorrent as a torrent program, then just google Windows XP CD torrent and you should be able to download an ISO of it with that, and since UBCD uses an ISO, it's perfect.



None.

Mar 20 2009, 3:00 am Lt.Church Post #12



if you cant install anything to torrent use bitlet, its a java based inbrowser torrent client.



None.

Mar 21 2009, 5:10 am Kellimus Post #13



When you're in safe-mode and you go into the registry and delete everything associated with the virus, it shouldn't come back.. That must mean that you missed a file somewhere.

I've gotten nasty malware/virus's before and used a program that showed where each file was in the registry (don't remember the name of the program), went into safe mode and deleted all the files that were on the list and BAM!

They were gone.

So, good luck in your venture.. Better lay off the porn ;-P



None.

Mar 21 2009, 2:35 pm Riney Post #14

Thigh high affectionado

Quote from Kellimus
When you're in safe-mode and you go into the registry and delete everything associated with the virus, it shouldn't come back.. That must mean that you missed a file somewhere.

I've gotten nasty malware/virus's before and used a program that showed where each file was in the registry (don't remember the name of the program), went into safe mode and deleted all the files that were on the list and BAM!

They were gone.

So, good luck in your venture.. Better lay off the porn ;-P

Or stay on 4chan and cnet for downloads and media ;o

Honestly if you can see a process in your task manager that DOESNT belong, lets say one called scvshost (Theres an extra s in it somewhere), using a more advanced task manager to locate the file is a great start. Also making sure its not an IE toolbar that ISNT is another step to deleting some more pesky ones. Go into IE, Under tools (IE 7) look for manage addons, then enable disable addons. Anything in there that looks fake, disable immediatly.



.riney on Discord.
Riney on Steam (Steam)
@RineyCat on Twitter

Sure I didn't pop off on SCBW like I wanted to, but I won VRChat. Map maker for life.

Mar 21 2009, 4:54 pm Moose Post #15

We live in a society.

Did you use the Malware Removal Guide from the pinned Computer Care thread? ;)




Mar 21 2009, 5:50 pm Sand Wraith Post #16

she/her

You can also try getting Hijackthis. It has a few nifty features such as "delete on bootup". Or something along the lines of that. Try it in safe mode.




Mar 21 2009, 11:06 pm Falkoner Post #17



Quote
When you're in safe-mode and you go into the registry and delete everything associated with the virus, it shouldn't come back.. That must mean that you missed a file somewhere.

Lots of spyware have good protection such as randomized names to stop you from easily removing them by simply deleting stuff.

Have you managed to try anything else mentioned by anyone?



None.

Mar 22 2009, 6:23 am Zero Ame Post #18



This sounds alot like a virut i just got rid of called sixth meow.exe

it kepot itself runing, if i toke it off startup using msconfig it came back, all it did was make IExplorer run. I found the it, then deleted the folder it was in, hasnt come back yet



None.

Mar 22 2009, 9:10 am Kellimus Post #19



Quote from Falkoner
Quote
When you're in safe-mode and you go into the registry and delete everything associated with the virus, it shouldn't come back.. That must mean that you missed a file somewhere.

Lots of spyware have good protection such as randomized names to stop you from easily removing them by simply deleting stuff.

Have you managed to try anything else mentioned by anyone?

If you would have read my post, you would see that wasn't a problem.



None.

Mar 22 2009, 2:44 pm Falkoner Post #20



Uh, it still is a problem, seeing as you couldn't provide the program mentioned.



None.

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[12:30 am]
ClansAreForGays -- When you join a pub lobby because you see 7/8 players, but then realize host is bating you with computers. :flamer: :flamer:
[11:48 pm]
O)FaRTy1billion[MM] -- :wob:
[2024-10-30. : 6:24 pm]
Ultraviolet -- :wob:
[2024-10-29. : 4:33 pm]
Vrael -- :wob:
[2024-10-29. : 1:32 pm]
Zoan -- :wob:
[2024-10-28. : 5:21 pm]
Ultraviolet -- :wob:
[2024-10-27. : 4:34 pm]
jjf28 -- :wob:
[2024-10-27. : 9:01 am]
Zycorax -- :wob:
[2024-10-27. : 3:31 am]
RIVE -- :wob:
[2024-10-26. : 7:12 pm]
Ultraviolet -- :wob:
Please log in to shout.


Members Online: Roy