Thread: Ntldr+viruses
View Single Post
  #8  
Old 06-30-2006, 01:24 PM
vee_ess's Avatar
vee_ess vee_ess is offline
Super Moderator
 
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
Send a message via ICQ to vee_ess Send a message via AIM to vee_ess Send a message via MSN to vee_ess Send a message via Yahoo to vee_ess
Default

You can prove that the virus is functioning as it's author intended by checking that the following files are in place:

%System%\taskgmr.exe
%SystemDrive%\funny_pic.scr
%SystemDrive%\my_photo2005.scr
%SystemDrive%\see_this!!.scr

%System% and %SystemDrive% are variables that will coincide C:\Windows\System32 and C:\, unless you or the installer set them differently.

If you can verify those are in place, you can argue that the worm is functioning as the author intended. This would prove that the virus has had no impact on the boot sector or the NT Loading files.
Reply With Quote