Page 1 of 4 123 ... LastLast
Results 1 to 10 of 32
  1. #1
    Newbie
    Overall activity: 0%

    Join Date
    Jan 2008
    Location
    India
    Posts
    33
    Liked
    0 times
    Points
    4,344

    Angry Infected by some Virus

    I installed a fresh copy of XP after my previous installation got unstable. After installing the copy when I started deleting the folders installed in the previous os many of them refused to get deleted and the message said that "can't delete since the directory is not empty" eg Drivers folder in System32. After that I renamed the folder Windows and again tried to delete but again the same message. The same happened when I tried to delete VB 6.0. So I left it. Now my antivirus is regularly displaying msgs like
    "Object Name c:\MicrosoftVB6.0\VB98\TSQL\vbsdicli.exe
    Virus Name W32.Almanahe.B!inf
    Action taken The file was repaired"
    and
    "D:\program Files\Common Files\Teleca Shared\CapabilityManager.exe
    Virus Name W32.Almanahe.B!inf
    Action taken The file was repaired"
    while for
    "Object Name D:\Program Files\Messenger\msmsgs.exe"
    The file is in accessible so can't be repaired

    What should I do???

  2. #2
    Experienced User
    Overall activity: 0%

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,785
    Liked
    3 times
    Points
    14,465
    http://www.raymond.cc/blog/archives/2008/01/23/how-to-clean-and-remove-jambanmu-alman-or-almanahe-virus/

    And manually remove startup entries and fix reg setting in registry using HJT.
    Happy To Help

  3. #3
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    I'd suggest you to reformat your computer and reinstall Windows as this virus is too destructive. The virus will inject itself into every EXE files and even if the antivirus is able to "clean" it, the file would be corrupted.

    Make sure your USB flash drive (pen drive) is clean from ahmanahe virus too because that is where it spreads.

  4. #4
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645

    I thought this one is now curable via AV scan but as u said sir { "The virus will inject itself into every EXE files and even if the antivirus is able to "clean" it, the file would be corrupted. " } That's horrible -


    %Windir%\killer.exe


    W32/Almanahe.a is a polymorphic parasitic worm that infects Win32 executable files (*.exe) that can also download and execute additional malware.


    Last edited by Ceyfer √; 10-08-2008 at 05:06 PM.

  5. #5
    Experienced User
    Overall activity: 0%

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,785
    Liked
    3 times
    Points
    14,465
    Indeed - very scary one. There several variants too. Some articles or analysis say the damage level as "Medium". Is there any virus still more destructive ?
    I need to get my hands on some samples of this.

  6. #6
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Several variants exist /and its case to case basis - If u do have a good AV protection u could definitely wiped this nasty bug out from ur flash drive / storage device but once ur system got infected ( severely ) hmm, u need to solve via the article written by sir Raymond above "link" or just reformat it...

  7. #7
    Newbie
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Malaysia
    Posts
    48
    Liked
    0 times
    Points
    4,101
    Try to using 'Trojan Remover'. Simply download here : http://www.simplysup.com/
    It is 30 days trial but you can use it to remove your virus/trojan.
    I use this software and doesn't have any problem.

    I hope this will help you.

  8. #8
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    Ahmanahe is a very destructive virus, NOT a trojan and I am sure that Trojan Remover can't clean it. Even if it can, I believe it won't be able to cure those executable files that has been injected by the virus.

    Prash, I will try to get a copy of that virus and let you see its power.

  9. #9
    Experienced User
    Overall activity: 0%

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,785
    Liked
    3 times
    Points
    14,465
    Err.. if you do get it, please make a password protected archive. I might accidentally extract it. I don't have the habit of making data backups.

  10. #10
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    Will do. But I will only be going to my client's place next Wednesday so we have to wait until then.

 

 
Page 1 of 4 123 ... LastLast

Similar Threads

  1. Infected with Virus named "ViP Al Ain"
    By smiley in forum Spyware/Viruses
    Replies: 14
    Last Post: 09-07-2010, 11:03 PM
  2. What type of file extension cannot be infected by any virus
    By jitendra.web in forum General Forum
    Replies: 12
    Last Post: 01-19-2009, 03:26 PM
  3. Virus Infected Installer
    By ginzon in forum Spyware/Viruses
    Replies: 6
    Last Post: 11-29-2008, 11:15 AM
  4. Is my comp infected with a virus???
    By k9 in forum General Forum
    Replies: 2
    Last Post: 04-19-2008, 08:55 AM
  5. Is my mobile Virus Infected...??
    By Shaggiee in forum Mobile Phone
    Replies: 8
    Last Post: 03-01-2007, 11:50 PM
All times are GMT +8. The time now is 10:07 AM.