PPRuNe Forums

Go Back   PPRuNe Forums > Supplementary Forums > Computer/Internet Issues & Troubleshooting
Forgotten your Username/Password?
Register FAQ Calendar Advertise Mark Forums Read

Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. We will also try and help with troubleshooting any technical problems you may have with the forums.


Closed Thread
 
Thread Tools Display Modes
Old 8th November 2004, 13:06   #1 (permalink)
 
Join Date: Nov 2001
Location: UK
Posts: 106
virus advice please

well after seven years i finally get a virus (trojan) on my pc, but i'm having a big problem eradicating it! My anti viral software successfully cleans all the infected files except one which cannot be accessed as it is constantly "in use by windows" it cannot be deleted for the same reason. I've researched the virus in trend micros online virus encyclopaedia and followed their instructions referring to deleting it in the registry, but the files they say should be deleted are not there, or are under a different name. I hope i don't need to get the HD cleaned down and everything reinstalled. Any help/suggestions/ideas appreciated.
Private jet is offline  
Old 8th November 2004, 13:10   #2 (permalink)

Spicy Meatball
 
Join Date: Jan 2004
Location: Liverpool UK
Age: 27
Posts: 1,113
Whats the spec of your machine? I will assume Windows.

Try rebooting your PC and loading it in safe mode (do this by pressing F8 when it boots up near the start). Then run the antivirus program. Doing this may stop the virus from running when you load up.

Secondly, when in Windows, press Ctrl+Alt+Del and have a look at the list of things running to see if anything suspicious is in there.

Failing this, and bearing in mind that you have tried the removal advice from the relevant website, a fresh install of Windows is a better solution.

Regards

Maz
mazzy1026 is offline  
Old 8th November 2004, 16:32   #3 (permalink)
 
Join Date: Mar 2004
Location: UK
Posts: 213
is it hiding in system restore?
if so you will have to turn sytem restore off reboot then turn it on again but remember to set a new restore point
maxell is offline  
Old 8th November 2004, 19:27   #4 (permalink)
The Oracle
 
Join Date: Aug 2001
Location: Naples, Florida U.S.A.
Posts: 3,006
Private jet,

Knowing which Malware was on your computer would help for getting a removal tool too.

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 8th November 2004, 20:09   #5 (permalink)
 
Join Date: Jan 2004
Location: Bracknell UK
Posts: 360
Hi PJ,

Please download 'Hijack This!' from here, unzip, and place it in it’s own folder, (not in the temp folder, or on the desktop) doubleclick HijackThis.exe, and hit "Scan". When the scan is finished, click "Save Log", and copy and paste it in a reply.

This will give us a rundown of what’s going on in your PC. One of us here will be glad to analyse it for you. Don’t fix anything yourself yet, as a lot of the stuff on that list will be harmless or required.

Cheers

Liam
E-Liam is offline  
Old 9th November 2004, 07:28   #6 (permalink)
Chief Tardis Technician
 
Join Date: Jan 2001
Location: Western Australia S31.715 E115.737
Age: 57
Posts: 318
reboot your computer in safe mode, and then run your AV prog, the trojan wont have loaded so will be able to be removed. Also shut down System restore (this will clear out anything saved in the restore area,) then restart it again. you should be better now.
Avtrician is offline  
Old 9th November 2004, 15:07   #7 (permalink)
 
Join Date: Feb 2002
Location: UK
Posts: 414
It can't be deleted 'cos windoze is using it!!

Press control/alt/delete at the same time then select processes in the task manager. Find the name that cannot be deleted, click it and then click 'end process'. You should then be able to delete the file with your virus program.
mono is offline  
Old 12th November 2004, 02:28   #8 (permalink)
 
Join Date: May 2001
Location: UK
Posts: 55
Question How can I be 100% sure a virus has been fixed?!

Hello everyone

Last night I had a similar situation where 2 viruses decided to very kindly make their home on my computer. One was a Trojan Horse and the other was Bloodhound.Exploit.6.

Both files were detected by my up to date Norton Anti-Virus, however the log file states that access to both files was denied and therefore the repair failed. Since then I performed a scan with both NAV and Trand HouseCall-both found no viruses. I have also ran HijackThis and there was one dodgy looking entry, so I fixed that. I have also deleted my Temporary Internet Files folder because this is where the Trojan Horse was located.

I still have that niggling feeling though that there is something still lurking in the background. Surely Norton Internet Security should have prevented those things in the first place? My security settings seemed to have changed though since installing Windows XP SP2.

Is there anything else I can do to double check my system?! Also any ideas on how to further increase the security on my PC would be greatly appreciated!
JustAnotherVictim is offline  
Old 12th November 2004, 15:56   #9 (permalink)
The Oracle
 
Join Date: Aug 2001
Location: Naples, Florida U.S.A.
Posts: 3,006
JustAnotherVictim,

From the log file in NAV, you could get the names and locations of the Malware Files. Then, in Windows Explorer (make sure you have Explorer set to show Hidden and System Files) look to see if the files are still on your computer.

One other program that you could use along with a fully updated NAV and HouseCall is:

McAfee AVERT Stinger

Between the three, you should have a good idea if there is Malware on your computer.

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 12th November 2004, 19:32   #10 (permalink)
 
Join Date: Jan 2004
Location: Bracknell UK
Posts: 360
Hi JustAnotherVictim,

Can you reboot (in case you normally leave the machine on) and then post up the HJT log (disable smilies before posting). I'll have a look through it for you. If you can remember the name of the file you deleted, it would help. It may of course show up again anyway.

Cheers

Liam
E-Liam is offline  
Old 16th November 2004, 10:08   #11 (permalink)
 
Join Date: Nov 2001
Location: UK
Posts: 106
Thanks for all your suggestions.

Tried the "safe mode" thing, but on start up with CTRL or F8 held i end up in BIOS setup menu and not Windows startup menu and it says nothing about safe mode in any of the options! I'm not a computer guru so any simple language would be much appreciated! this is driving me nuts
Private jet is offline  
Old 16th November 2004, 21:28   #12 (permalink)

I'd rather be floating

 
Join Date: Nov 2000
Location: Cambridge, England
Posts: 1,812
Depending on which version of Windows you're running, it is sometimes possible to rename an "in use" file that you can't delete. So the process is:

(1) rename the file to something completely different
(2) reboot
(3) delete the renamed file.

(Of course, if you do this to a file which is a legitimate and essential part of Windows then your computer won't reboot.)
Gertrude the Wombat is offline  
Closed Thread
 


Thread Tools
Display Modes


Posting Rules
vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


All times are GMT +1. The time now is 16:15.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
© 1996-2010 The Professional Pilots Rumour Network

As these are anonymous forums the origins of the contributions may be opposite to what may be apparent. In fact the press may use it, or the unscrupulous, or sciolists*, to elicit certain reactions.

*"sciolist"... Noun, archaic. "a person who pretends to be knowledgeable and well informed".