We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Virus on Computer

Options
135678

Comments

  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ill have a look when i get round to me mums house tongiht and see if i can have a look for that albertross :)

    another thing ive just thought of as well is that i tried to uninstall AVG before i installed bitdefender and it would let me uninstall it either, it kept closing the uninstall down as well...
    Savings Total so far for 2023: £8,062.58
  • pchelpman
    pchelpman Posts: 1,275 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Excellent advice here, James, but, if nothing else works, you can try your original idea of some free online scanners ....

    Superantispyware >
    http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE

    AVG AntiSpyware > http://www.ewido.net/en/

    TrojanHunter > http://www.misec.net/

    These will all allow full program downloads and will disinfect the computer of anything they find. Yes, the programs may not work fully after the trial period but make maximum use of them now if you can.

    If the infected computer has trouble downloading HijackThis I suggest you do the following ...

    > Download HJT to a working computer ...

    > rename the file from HJT.exe to scanner.exe ...

    > transfer the scanner.exe file to the suspect machine via floppy, CD, pen drive or whatever ...

    > run HJT and "scan & save a log file".

    Copy the logfile report and post it here for more advice.


    PCH
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    will do PCH ive just done the stinger virus checker and that has come up with showing nothing so will give all the others a go and see what i can find :)
    Savings Total so far for 2023: £8,062.58
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    PCH

    just tried to go on to the superantispyware site but its closing the window down :( im going to try and run 8bit defender again and see if i can post the results from it :)
    Savings Total so far for 2023: £8,062.58
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ok just run the f-secure one that was on the free scanner pages and its just detected and cleared trojan-spy.win32.small.gv but it skipped over 6 files so ill assume these are viruses :rolleyes:

    Ive tried the links that PCH has given but everysingle one opens and then closes down again :(

    just off to run bit defender and will post the results once its done :)
    Savings Total so far for 2023: £8,062.58
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    here are the files it missed out in its scan :

    C:\HIBERFIL.SYS
    C:\PAGEFILE.SYS
    C:\WINDOWS\SYSTEM32\SYSDRV0.EXE
    C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
    C:\DOCUMENTS AND SETTINGS\COMPAQ_OWNER\WN0008.EXE
    C:\DOCUMENTS AND SETTINGS\COMPAQ_OWNER\LOCAL SETTINGS\TEMP\US0008.EXE
    Savings Total so far for 2023: £8,062.58
  • albertross_2
    albertross_2 Posts: 8,932 Forumite
    Ever get the feeling you are wasting your time? :rolleyes:
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    thanks albertross will give that a go :)
    Savings Total so far for 2023: £8,062.58
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    hi guys heres the report that has just come off fromt he bitdefender virus sca :


    //
    //
    // Product: BitDefender 8 Standard
    // Version: 8.0
    //
    // Created on: 21/06/2007 22:15:23
    //
    //

    Statistics
    Scan path : C:\
    D:\
    Folders : 6499
    Files : 260239
    Archives : 16784
    Packed files : 9605
    Identified viruses : 1
    Infected files : 2
    Warnings : 0
    Suspect files : 0
    Disinfected files : 0
    Deleted files : 0
    Copied files : 0
    Moved files : 0
    Renamed files : 0
    I/O errors : 29
    Scan time : 00:59:35
    Scan speed (files/sec) : 72
    Virus definitions : 524653
    Scan plugins : 14
    Archive plugins : 38
    Unpack plugins : 6
    Mail plugins : 6
    System plugins : 1
    Scan options
    Detection
    [X] Scan boot sectors
    [X] Scan archives
    [X] Scan packed files
    [X] Scan email
    File mask
    [ ] Programs
    [X] All files
    [ ] User defined extensions:
    [ ] Exclude extensions: ;
    Action
    Infected objects
    [ ] Ignore
    [X] Disinfect
    [ ] Delete
    [ ] Copy to quarantine
    [ ] Move to quarantine
    [ ] Rename
    [ ] Prompt user
    Second action
    [ ] Ignore
    [ ] Delete
    [ ] Copy to quarantine
    [X] Move to quarantine
    [ ] Rename
    [ ] Prompt user
    Scan options
    [X] Enable warnings
    [X] Enable heuristics
    [ ] Show all files in log
    [X] Report file: vscan.log
    [ ] Append to existing report
    Summary:
    C:\WINDOWS\system32\erhecwjrbgbv.dll Infected Backdoor.Delf.HBI
    C:\WINDOWS\system32\erhecwjrbgbv.dll Disinfection failed
    C:\WINDOWS\system32\erhecwjrbgbv.dll Move failed
    C:\WINDOWS\system32\prmgkujwhutt.dll Infected Backdoor.Delf.HBI
    C:\WINDOWS\system32\prmgkujwhutt.dll Disinfection failed
    C:\WINDOWS\system32\prmgkujwhutt.dll Move failed



    Seems like after running smitrem it has cleared up 2 of the virus's but im left with one more to sort out :rolleyes:

    any ideas how to progress from here??


    All help appreciated


    James :)
    Savings Total so far for 2023: £8,062.58
  • pchelpman
    pchelpman Posts: 1,275 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Yes James it does seem as if there is still work to do.

    I thought you may not be able to run those scanners I mentioned in view of the difficulties you reported earlier.

    I think the time has come for us to see a HJT log now.

    Please post one.


    PCH
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 598.9K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.