Windows 7 Forums


Reply
Thread Tools

Tons of viruses won't go away.

 
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      11-22-2009
I've got a few annoying trojans that have been putting my CPU usage at 100% and popping up with some dialogs every once and a while. It's really, really annoying. I've scanned with Malware Bytes and AVG and while they both claimed to have removed the viruses, I notice no differences. The processes that seem to be the culprits are "svchost.exe", which I know about, so help me with that one and "temp.exe", which the description in task manager is "Recycler". I've gone to my friends but their solutions have had no resolution. HALP!
Attached Thumbnails
Tons of viruses won't go away.-.net-framework.png   Tons of viruses won't go away.-temp.png  
 
Reply With Quote
 
 
 
 
draceena draceena is offline
That Crazy Amazon Chick!
draceena's Avatar
Join Date: Jan 2009
Location: New Brunswick
Posts: 772
Thanked: 154
Send a message via MSN to draceena Send a message via Yahoo to draceena draceena's Twitter Pag
 
      11-22-2009
Are you runing the 32 bot or 64 bit W7? From what I've read, there are some difficulties in removing viruses from 64 bit systems.

Beyond that, have you tried an online virus scanners (like Kaspersky Online Scanner) or another Malware program like A-Squared?

You might like to try Hijack-This to solve your problem. I know that most forums that help cure virus problems will have you download and run the program and just grabbing the text file it creates and posting the output. Unfortunately, I'm not very versed on going through the Hijack-This logs but others may.
 
Reply With Quote
 
 
 
 
Cookieman Cookieman is offline
Established Member
Cookieman's Avatar
Join Date: Sep 2009
Location: UK
Posts: 133
Thanked: 27
 
      11-22-2009
This thread may be more appropiate in the Security section

Is this a x86 or x64 machine?

As draceena has already mentioned, most tools do not yet run on x64 systems due to the way they run and protect the files. For instance running HJT on x64 will not enumerate the system sevices and show them as all missing when they are not!

If this is a x86 machine then most tools will run on windows 7 but there will be very limited support from the authors of dedicated special tools needed for the removal process as testing is still ongoing in this department .

I would try running DDS by sUBs which will create two logs and give us a basic run down of your machine, this tool is non evasive and will not remove any malware, it is for evaluation purposes.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.


Post both logs back in your next reply

I would also advise a rootkit scan by the use of GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.


    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop and copy and paste this in your next reply


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
 
Reply With Quote
 
clifford_cooley clifford_cooley is offline
Established Member
Join Date: Mar 2009
Posts: 4,758
Thanked: 987
 
      11-22-2009
Quote:
Originally Posted by Cookieman View Post
This thread may be more appropiate in the Security section
It's moved now
 
Reply With Quote
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      11-23-2009
Hey, I'm on 64-bit. 5GB RAM wouldn't be wasted on 32-bit in my eyes. Attached are the logs from DDS, but GMER refused to launch without an error message.

The "DDS" log is too big to upload here, so it's right here on RapidShare.

Thanks guys!
 
Reply With Quote
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      11-23-2009
Alright, so my friend suggested booting into Windows XP, which is 32-bit and doing another Malwarebytes scan and then maybe it will remove them. So greetings from XP Professional and it's already found 139 infections! I've got my fingers crossed.
 
Reply With Quote
 
clifford_cooley clifford_cooley is offline
Established Member
Join Date: Mar 2009
Posts: 4,758
Thanked: 987
 
      11-23-2009
Quote:
Originally Posted by BetaMan View Post
Alright, so my friend suggested booting into Windows XP, which is 32-bit and doing another Malwarebytes scan and then maybe it will remove them. So greetings from XP Professional and it's already found 139 infections! I've got my fingers crossed.
Figured you would have given up XP by now.

I'll cross my fingers too
 
Reply With Quote
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      11-23-2009
Yeah, I know. I keep telling myself to get rid of it but after this... Nah!
 
Reply With Quote
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      11-23-2009
Haha, wow, XP uses an older version of AVG and it's detecting more viruses without scanning than my x64, updated version did. That's just... Dandy!
 
Reply With Quote
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      11-23-2009
Oh hey, are these actually viruses or are they vital system files?
Attached Thumbnails
Tons of viruses won't go away.-hi.png  
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Fixing tons of broken shortcuts when drive letter changes lakecityransom General Discussion 10 02-22-2012 02:08 AM
[SOLVED] Viruses through Firefox? catilley1092 Security 23 08-05-2010 06:56 AM


All times are GMT +1. The time now is 09:29 AM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.