Ethan Δημοσ. 30 Ιανουαρίου 2006 Δημοσ. 30 Ιανουαρίου 2006 Exw vrei afto to process na trexei ston ypologisti mou gyrw stis 30 fores taftoxrona. Sthn anazitisi to arxeio vrethike na einai sto windows->system32, apote esvisa to kleidi HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\wininfo apo ti registry kai ekana reboot se safe mode opote kai esvisa kai to wmram.exe apo to pc. Sto epomeno restart o wmram.exe einai pali sta processes enw den yparxei pouthena san arxeio ston ypologisti kai kontevw na palavwsw!!! to thema einai oti oute norton to pianei,oute kaspersky oute antispyware. Sto internet den yparxoun polles plirofories,yparxei malista kai ena site pou to parousiazei san process tis microsoft.yparxei se 30 peripou antitypa sthn process list kai trwei to kathena 3,5mb mnimis kai to pc sernetai.please help an xerei kapoios kati parapanw.
accipio Δημοσ. 30 Ιανουαρίου 2006 Δημοσ. 30 Ιανουαρίου 2006 http://tvilda.tigbis.lt/dokuwiki/doku.php?id=how_to_remove_virus_that_shows_in_process_table_as_wmram.exe_en Στο παραπάνω λινκ λέει αυτά: How to remove virus that shows in process table as wmram.exe I just saw in my windows xp process table row with filename wmram.exe itʼs a virus, I donʼt know what it does, but it sucks, you canʼt just delete wmram.exe, because itʼs created again and again after itʼs removed, so you need KillBox, select c:\windows\system32\wmram.exe and select Replace on reboot and check Use dummy, then press button with red cross, donʼt reboot computer yet, because there is another file to remove using the same way, this file is c:\windows\system32\winifo.dll do the same, and this time you can restart windows. Two files will be replaced by dummy file after reboot. Now you can remove run entry of wmram.exe in registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\wininfo and delete dummy files c:\windows\system32\wmram.exe, c:\windows\system32\winifo.dll I hope this helped, because I didnʼt found any information about this virus on the internet, and no one of antiviruses mark it as virus. I submitted it to antivirus companies, but they doesnʼt responde. Itʼs program created with Visual Basic and compressed with UPX compression tool. Το αρχείο στο οποίο παραπέμπει: http://i-loveyou.info/files/tools/KillBox.exe
Ethan Δημοσ. 30 Ιανουαρίου 2006 Μέλος Δημοσ. 30 Ιανουαρίου 2006 nai,afto exw dokimasei.Alla to thema einai oti meta to reboot opou esvisa ta dummy files kai to registry entry,o wmram.exe yparxei akoma sta processes enw den yparxei poythena san arxeio. epipleon vrika to exis:To worm afto yparxei sto programma Change Harddisk Volume 1.0 tis PVOSoftware pou diakinei elefthera i Softpedia....opote mallon tin patisa. Gia pliroforisi kai twn ypoloipwn xristwn,opoios thelei na allaxei to volumeid se skliro kalitera na xrisimopoihsei to VolumeID 2.0 apo ti Sysinternals
vagpap Δημοσ. 30 Ιανουαρίου 2006 Δημοσ. 30 Ιανουαρίου 2006 Χρησιμοποίησε το HijackThis και σβήσε τυχόν εγγραφές που αναφέρονται στο συγκεκριμένο.
Προτεινόμενες αναρτήσεις
Αρχειοθετημένο
Αυτό το θέμα έχει αρχειοθετηθεί και είναι κλειστό για περαιτέρω απαντήσεις.