📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Virus removal not working-please help!!

u_r
u_r Posts: 115 Forumite
Hi all

Hope someone knowledgable in IT will be able to help out as I have very little clue as to what to do..

had a virus pop up yestrday night(looked like a fake security message).

in safe mode, dwnloaded , scanned and deleted virus(Ramnit)..
However, when back in normal mode the same messges pop up again..grrrrrrrrrrrr!! this means depsite the fact that Malware now says thre are no viruses, they still are present!

i have googled(in Smode) the solution and from what i gather I need to re format/re install the system!!! I am very reluctant to do that as I would not know if the changes being made are supposed to be made or are still part of the virus.

Is there no easier option??Will anyone be able to provide step by step instructions to helping me out??

I would greatly appreciat your efforts in this regard.

Thanking in anticipation.
PS- I have read the anti virus thread in ths section, but tooooo much info, dnt know where to start!!!!!!
u_r

Comments

  • goofy115
    goofy115 Posts: 20 Forumite
    First thing i would try is to give system restore a try.This simply sets the computer back to a date choosen by you and may rid you of the problem.If your operating system is windows seven click on the windows icon (bottom left of screen,enter 'system restore' in the search box,run the application (double left click 1st result) and follow the straightforward instructions.Obviously you need to select a date before the computer became infected.When you start the restore it can take about 10mins for the process to finish.Good luck.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    First thing we can do is check for further instances of ramnit, if it is further infected with ramnit then unfortunately you really are better off wiping the drive & reinstalling windows. Ramnit is a file infector and although you could possibly remove it you might not get it all, end up reinfected and have to start all over again - so any time taken removing it is time wasted. Files could also end up corrupted as a result of the disinfection process by an AV so would have to be repaired/replaced so reinstalling in the first instance makes sense.

    http://www.eset.co.uk/Antivirus-Utilities/Online-Scanner
    • Click on Scan now.
    • Select the option YES, I accept the Terms of Use then click on: START
    • When prompted allow the Add-On/Active X to install.
    • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
    • Now click on Advanced Settings and select the following:
      • Scan for potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth Technology
    • Now click on: START
    • The virus signature database will begin to download.
    • When completed the Online Scan will begin automatically.
    • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
    • Copy and paste that log here.
  • penrhyn
    penrhyn Posts: 15,215 Forumite
    Part of the Furniture Combo Breaker
    For what its worth Malwarebytes is not an antivirus programme.
    That gum you like is coming back in style.
  • Yoingco
    Yoingco Posts: 7 Forumite
    One thing worth noting here is that a virus can infect System Restore files and Recovery Files/Partitions - See here:

    brighthub dot com /computing/smb-security/articles/44731.aspx

    And due to what waddler_8 was saying about the infection and time consumed etc it may be best to do a clean install - Format the hard drive and then use an installation dvd where possible (preferably the one that came with the computer or the ones you were asked to burn by the manufacturer when you first bought the computer - when the computer was "clean"/new).

    Some tools worth a mention are:

    Spybot
    MalwareBytes
    SmitFraudFix (a little dated now but still worth a spin)
    RKill - Stops malware processes from running.

    If you are using Safe Mode to run such tools always download the latest versions/updates of those tools first using a clean computer of course and burn them onto a cd/dvd where possible to avoid any infection of those tools (files) later. And when running those tools in safe mode make sure your internet connection is switched off, otherwise a virus may just re-download its files again. You shouldn't need an internet connection if you have downloaded the latest versions/updates of those tools.

    Manually download malwarebytes updates:

    forums.malwarebytes.org /index.php?showtopic=11217
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.