Jump to content

Malwarebytes

FYSTEMROOT exposed

- - - - -

6 replies to this topic

#1
Aspirina

    New Member

  • Members
  • Pip
  • 13 posts
I post here because i couldn't find in the whole internet a solution for this malware and I was enable to disable it from registry but it would be better if some day some antimalware software is enable to remove it for me. Maybe this help can be useful for antimalware software developers and for anyone else who wants to remove this malware manually

You can find some info about the malware here in my answer to this topic: http://www.malwarebytes.org/forums/index.p...amp;#entry62920

#2
Aspirina

    New Member

  • Members
  • Pip
  • 13 posts
Upload failed. You are not permitted to upload this type of file

:D sorry guys I think I'm gonna post the malware somewhere else. Good luck finding the file =)

#3
Aspirina

    New Member

  • Members
  • Pip
  • 13 posts
successfully uploaded =) looking forward to find it soon in your database

#4
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Well I don't see where you uploaded it. Do you have a link?

Are you still infected, do you need help cleaning your system?
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#5
Aspirina

    New Member

  • Members
  • Pip
  • 13 posts

View PostAdvancedSetup, on Mar 9 2009, 06:37 AM, said:

Well I don't see where you uploaded it. Do you have a link?

I uploaded it at http://uploads.malwarebytes.org/ as "3d16ee25.sys.VIRUS" (it is renamed with .VIRUS because i need to know which of my files are infected) Anyway i'm uploading again.

Quote

"Upload failed. You are not permitted to upload this type of file"

So if you don't let me upload here, then don't ask me for that. Go to upload.malwares.org and check out there. I would share my virus file but i don't know if it is legal :D sharing viruses! I never tried.

View PostAdvancedSetup, on Mar 9 2009, 06:37 AM, said:

Are you still infected, do you need help cleaning your system?

mMmM I don't think so, I'm a pro :D. It took a while but i had to remove it by myself since I didn't find any help about this malware on the whole internet. I can remove virus and rootkits without using your antimalware programs, but I still wanted to "give you" "antimalware removers" or infected unexperienced people a "hint" on finding this one because ... I'm nice =).

The malware was written with the driver developement kit from microsoft as I could find and as I don't know much about driver programming I couldn't go on with my reverse engineering on this but I hope you can find the file in upload.malwarebytes or if you can't... I don't really have much time to try again and again so mail me or add me to messenger contacts as - minuevolive at hotmail dot com - I use it to work so I'm online a lot and then I can send you the so called file and maybe who knows help you finding more malware. I like to learn so even when I'm infected it is so fun! Thanks for your support anyway and please make the upload system more easy to find =) or enable the upload system of the forum that it wouldn't let me upload anything or tell me how to upload because I don't want to read a whole tutorial on how to do you a favor. I'm sure you understand.

Good luck!

#6
Aspirina

    New Member

  • Members
  • Pip
  • 13 posts
UploadNET™
Thank you! The file 3d16ee25.sys has been uploaded!


see. but the uploads.malwarebytes.org i found by trying different subdomains, I just guessed the "uploads" part, because i couldn't find the link in www.malwarebytes.org. Also I don't have the time to visit a whole site every time i'm looking for something. It should be on the home page at least the link for the uploads page, not the whole upload system, but a link. Please?

#7
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Okay - thank you for the feedback and information. Cheers.


Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us