Windows 7 Forums


Reply
Thread Tools

Tons of viruses won't go away.

 
 
Cookieman Cookieman is offline
Established Member
Cookieman's Avatar
Join Date: Sep 2009
Location: UK
Posts: 133
Thanked: 27
 
      11-26-2009
If no luck with the kaspersky site then try Panda...

To perform an online scan with Panda ActiveScan
  • Click on Scan Your PC Now
  • A "pop up" window will appear, or a new tab will open.
  • Click on Register
  • Choose the option you like most, but we recommend the Free Registration.
  • Click on Register
  • Enter your e-mail address, and create a password.
  • Select "I do not want to receive any type of information". (unless you want to receive such information)
  • Click on Send
  • Confirm registration, and continue by entering your user name and password, then click on Enter
  • Select Full Scan, then Click on Scan Now
  • Wait for the components to be loaded and installed. Don't close this window or go to another page while it is downloading. You can continue using the Internet by opening another window in your browser.
  • If it finds any malware it can disinfect, the Disinfect button will be enabled. Click on Disinfect
  • Please ignore the offer to buy the program. Click on Export To
  • Export the log and save it to your desktop.
  • Please post the contents of that log to your reply.

* Turn off the real time scanner of any existing antivirus program while performing the online scan.

Avast users note:

Please do continue with the online scan at Panda if you receive an alert. It is a false positive from Avast because Panda Antivirus does not encrypt its virus database.
 
Reply With Quote
 
 
 
 
draceena draceena is offline
That Crazy Amazon Chick!
draceena's Avatar
Join Date: Jan 2009
Location: New Brunswick
Posts: 772
Thanked: 154
Send a message via MSN to draceena Send a message via Yahoo to draceena draceena's Twitter Pag
 
      11-28-2009
I agree on the reinstall at this point....sounds like something crazy is going on and nothing short of a nuke-n-pave will really fix it.

Heck I get paranoid and thinking of reinstall if my anti-virus even just pops to say it blocked something and my system is perfectly fine...lol
 
Reply With Quote
 
 
 
 
Veedaz Veedaz is offline
~
Veedaz's Avatar
Join Date: Sep 2009
Location: England
Posts: 1,988
Thanked: 332
 
      11-28-2009
Quote:
nuke-n-pave
I know Boot and Nuke (DBAN) would sort it, if you need to get a HDD clean/wiped this is the tool, i have used it many times

Link > http://www.dban.org/
 
Reply With Quote
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      12-16-2009
Nee... A few weeks ago, I vowed to myself that I would not reinstall, then isolated myself on Ubuntu for three weeks. Or more, I don't know. But now I'm back and I need to fix this. I'm trying panda right now. Wish me luck.
 
Reply With Quote
 
BetaMan BetaMan is offline
Official G33k
BetaMan's Avatar
Join Date: Jan 2009
Location: Portland, Oregon, USA
Posts: 463
Thanked: 26
Send a message via AIM to BetaMan Send a message via MSN to BetaMan
 
      12-16-2009
Oh, wow. I haven't told you guys that I actually found the problem, and now I need help. I've got something called the "temp.exe" virus. The process cannot be ended because the PID is dynamic, so when Task Manager tries to end it, the PID has changed. Anyway, I'm sure this is the problem, this "temp.exe". The description is "recycler" and I've seen a few folders named that around my system. HALP!
 
Reply With Quote
 
kitesurfa kitesurfa is offline
Member
Join Date: Dec 2009
Posts: 46
Thanked: 8
 
      12-16-2009
not come across the virus but things to try and kill it.

Search registry and find the key that runs it when your PC is first swiched on and delete it.
next delete the running file with software like http://lockhunter.com/ or FileASSASSIN.
If above doesn't work use Explorer or My Computer to find the location of 'temp.exe' then Reboot and F8 and boot to C:> prompt then CD to the required directory and delete manually before Rebooting to windows to test.

Other tip...
Use a Firewall to stop files like this connecting to the web, which should show what the software is and the location it is on your PC. (ZoneAlarms is good for this)
 
Reply With Quote
 
clifford_cooley clifford_cooley is offline
Established Member
Join Date: Mar 2009
Posts: 4,758
Thanked: 987
 
      12-16-2009
Can you boot to Ubuntu and remove the file from outside Windows 7 bootup. If it is not on the computer to load then it won't be a problem.

I know I would have options to remove it manually with Hiren's BootCD using NTFS4DOS.
 
Reply With Quote
 
kitesurfa kitesurfa is offline
Member
Join Date: Dec 2009
Posts: 46
Thanked: 8
 
 
Reply With Quote
 
clifford_cooley clifford_cooley is offline
Established Member
Join Date: Mar 2009
Posts: 4,758
Thanked: 987
 
      12-17-2009
Thanks kitesurfa

I've downloaded it myself
 
Reply With Quote
 
Veedaz Veedaz is offline
~
Veedaz's Avatar
Join Date: Sep 2009
Location: England
Posts: 1,988
Thanked: 332
 
      12-17-2009
File Assassin from Malwarebytes is a great tool (and a powerful one) as it can
Quote:
use advanced programming techniques to unload modules, close remote handles, and terminate processes to remove the particular locked file
File Assassin > http://www.malwarebytes.org/fileassassin.php
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Fixing tons of broken shortcuts when drive letter changes lakecityransom General Discussion 10 02-22-2012 02:08 AM
[SOLVED] Viruses through Firefox? catilley1092 Security 23 08-05-2010 06:56 AM


All times are GMT +1. The time now is 12:59 AM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.