core.sys & core.dsk insidious pop-up warning

Posted by mortal 
core.sys & core.dsk insidious pop-up warning
Date: May 14, 2007 11:48AM
Posted by: mortal
Ok guys, there's a pop-up browser virus, fairly new and it hit my machine on Saturday. It opens an ie window and attempts to access uvcplfeed.com with your ip addy, and the site you are currently on. Every time you view a page in Mozilla or whatever browser you are using it opens the new browser window. Both files are resident in c:/windows/system32/drivers. You cannot delete them, I tried gipo delete on boot util and it failed. You must use safe mode to delete them, then access your registry start/run/regedit and find the h-key local machine services entry and delete the core folder. I was unable to access safe mode, der, trying to use f8 with a wireless keyboard and I don't have a spare so I set msconfig boot.ini to run in safe mode which now gives me safe-mode in the four corners of the screen but nothing else and the HD light locked on. So I have removed my c-drive, I have yet to insert a spare drive and install windows on it, then replace the original c as a secondary, access it as drive d and remove the files, edit the boot.ini file then swap them back, so currently my machine is in bits. I will also add the url to my hosts file to block any incoming from the address. So if you get this problem it's a drama to get rid of it, hijack-this cannot see it, adaware cannot see it, in fact none of my anti-virus or trojan software can see it as a virus. It will drive you nuts :-S


[www.mediafire.com] Some say you should click it, you know you want to. :-) [www.gp4central.com] <----GP4 Central
Bugger. Sorry to hear that mortal. *checks system*



Everyone knows that million-to-one chances happen 9 times out of 10; indeed, it's a common requirement in fairy tales. If the human didn't have to overcome huge odds, what would be the point? Terry Pratchett - The Science Of Discworld

GPGSL S5 Race driver for IED.

Re: core.sys & core.dsk insidious pop-up warning
Date: May 14, 2007 12:22PM
Posted by: Morbid
If you cannot delete files, then try this. It will delete them while you reboot, and it works 99% of the time...

[www.softforall.com]

... all you need to do then, is to remove this registry entries before you reboot, and you should be cured.



It's only after we've lost everything, that we are free to do anything.
Re: core.sys & core.dsk insidious pop-up warning
Date: May 14, 2007 05:16PM
Posted by: gav
You might like to try Unlocker too, where you just right-click on a file and let Unlocker... unlock it. Chances are it won't work in this instance, and Morbid's solution will be more successful, but it's nice time to mention it anyway. One of those tiny little programs which should be on every system.
Re: core.sys & core.dsk insidious pop-up warning
Date: May 14, 2007 05:26PM
Posted by: chet
Oh, that helped me Gav, thanks :D

I get a few things I cant delete. thats a nice little tool!






"Trulli was slowing down like he wanted to have a picnic" LOL
Sorry, only registered users may post in this forum.

Click here to login

Maintainer: mortal, stephan | Design: stephan, Lo2k | Moderatoren: mortal, TomMK, Noog, stephan | Downloads: Lo2k | Supported by: Atlassian Experts Berlin | Forum Rules | Policy