Monday, February 27, 2012

:: DirectX.exe :: captured And Quarantined!!

:: DirectX .exe capured! ::

file Size: 1.94 MB

file Icon:

Most of the netizens are unaware of a new virus , named DirectX .exe which is infecting the system files of Windows 7. It takes the CPU usage into 100% which makes the system 'hang' and unstable.



The most astonishing fact is that most of the famous Antiviruses like Norton, Avast, Nod 32, Quick heal has failed to detect this virus !!



How To Find If Your System Is Attacked?!!"

The answer is right here..

(1)    Press Alt + Ctrl + Del keys to launch the Task manager.


(2)    Select the Processes tab. Taskmanager displays a number of running system processes in your system.


(3)     If you see any process named DirectX .exe and the 'Description' as 'whome' ... itz sure that your system is attacked.. !:(


Where you can find him?!



The folders in which you can find this virus' executable file are:

(*)    The Startup folder in your Start menu.
Path: C:\users\(your_username)\Appdata\Roaming\Microsoft\Windows\Start menu\Programs\Startup\


(*)    C:\Users\(your_username)\AppData\local\temp\
you can access this also by typing %temp% in Run dialog box...




#Blind Solution !


Press F8 button before your system boots and select Safe mode. then, after booting, goto the above mentioned folders and Shift + Del the DirectX .exe file in them :D .



@And the Game isnt Over ;( !


Evenif you delete those infected files, the problems that it has caused to your explorer.exe in C:\Windows\ may persists..

Note that explorer.exe usual size is 2,616,320 bytes.. Even a single byte change from that indicates your system is infected.. So, you have to replace this file using a Windows Repair Disk. or, Google for an alternative explorer.exe download.

I will be providing a copy soon.. check this blog again after some days.. { me got board exams ;) }


@@@only for debuggers$$$


im uploading a copy of this virus (7zipped) for debugging purposes..
click here for the download.. use it wisely .. Please mail me at donajmal@gmail.com for the password :) .