Question:
2 Viruses on my daughters laptop, how do I remove them?
Nutty
2006-11-02 05:43:03 UTC
1. first is named 1.exe
2. second is A0036882.exe

AVG anti virus has detected them, but cant delete or heal.

What next?
Any help most welcome!
23 answers:
2006-11-02 17:36:10 UTC
Try some of these:



Spyware, Adware, Trojans, Malware, Dialers, Keyloggers, Popups:

http://www.download.com/Ad-Aware-SE-Personal-Edition/3003-8022_4-10399602.html?tag=tab_rev

http://www.ewido.net/en/download/

http://www.javacoolsoftware.com/spywareblaster.html

http://www.download.com/Bazooka-Adware-and-Spyware-Scanner/3000-8022-10247782.html

http://www.javacoolsoftware.com/sgdownload.html

http://www.safer-networking.org/

http://www.download.com/HijackThis/3000-8022_4-10379544.html

http://www.emsisoft.com/en/software/download/

Online Scanners:

http://www.webroot.com/consumer/products/spysweeper/freescan.html?

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

http://www.pandasoftware.com/products/activescan.htm

http://www.bitdefender.com/scan8/ie.html

http://www.windowsecurity.com/trojanscan/

http://www.kaspersky.com/virusscanner

http://www.spywareguide.com/onlinescan.php

http://housecall65.trendmicro.com/

Spyware, Adware, Trojans, Malware, Dialers, Keyloggers, Popups Lists:

http://www.softpedia.com/catList/104

http://www.download.com/Adware-Spyware-Removal/3150-8022_4-0.html?tag=dir

http://www.majorgeeks.com/downloads31.html

http://www.filehippo.com/software/antispyware/setarea

http://www.soft32.com/s/Windows/Security/AntiSpyware/3-9-0-0.html

Antivirus:

http://free.grisoft.com/doc/avg-anti-virus-free/lng/us/tpl/v5

http://www.avast.com/

http://www.free-av.com/

http://www.bitdefender.com/PRODUCT-14-en--BitDefender-8-Free-Edition.html

Antivirus Lists:

http://www.softpedia.com/catList/1

http://www.download.com/Antivirus/3150-2239_4-0.html?tag=dir

http://www.majorgeeks.com/downloads29.html

http://www.filehippo.com/software/antivirus/

http://www.soft32.com/s/Windows/Security/Antivirus/3-1-0-0.html

Firewall:

http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?dc=12bms&ctry=US&lang=en&lid=staticcomp_za

Firewall Lists:

http://www.softpedia.com/catList/97

http://www.download.com/Firewalls/3150-10435_4-0.html?tag=dir

http://www.majorgeeks.com/downloads34.html

http://www.filehippo.com/software/firewalls/

http://www.soft32.com/s/Windows/Security/Firewalls/3-5-0-0.html

IP Blocker:

http://prdownloads.sourceforge.net/peerguardian/pg2-050918-nt.exe?download

Browser:

http://www.mozilla.com/firefox/

Email, News, RSS:

http://www.mozilla.com/thunderbird/

System Cleaner:

http://www.ccleaner.com/

System Cleaning List:

http://www.softpedia.com/catList/98

http://www.majorgeeks.com/downloads12.html

http://www.filehippo.com/software/cleaning/

System Info:

http://www.softpedia.com/catList/92

http://www.majorgeeks.com/downloads9.html

http://www.soft32.com/s/Windows/System_Utilities/System_Tools/3-50-0-0.html
2006-11-02 05:55:39 UTC
I found that AVG Anti Virus does have a problem with removing some type of viruses the two you have on your PC sound to me to be Trajan viruses they can be very difficult to get rid of unless you have a very good anti virus system I have found that Norton seems to be one of the best as it has a good data base for this type of virus and will either delete it repair the file or quarantine the virus
Virus
2006-11-02 05:45:03 UTC
1. First of all go to the task manager.

2. Now check the checkbox to show all the process running in the list.

3. Now if any of two process is there, end the process.

4. Now go to search and find the file with the exact name.

5. If found, delete it immdiately.

6. If not deleted, use some wipe tool like in Norton Doctor.



Note : Check the computer services running & entries in the startup.



goto run command => type msconfig => fine the services running



if u r still unable to delete the file after finding it, boot the system in any other OS (eg. Linux or some other version of Windows) and delete those files.
Fran T
2006-11-02 05:51:25 UTC
If you already have an antivirus software on your PC then run it and follow the instructions if not try this. Go online and type in Avast and get the free anti virus software download. You can have it for 2 months before you have to register and then to register they just require your name address and email no charges and it works ok for me. Then just run it. It will detect any viruses and then quarntine them. Its updated daily and works fine.
2006-11-02 05:53:57 UTC
Mcaffee and Norton Suck . Go Get This



http://tinyurl.com/h94d4



It will save u money too and its an all in one - Anti Virus /Adware remover/ Spyware Remover /Internet security suite and It'll speed up Ur Daughters Pc's performance too.
Hotrod Hoender
2006-11-02 06:04:52 UTC
Go in Safe Mode, search for thm and delete them. Also turn off your System Restore Under > Right Click My Computer > Proterties > System Restoe.



ThisShouldWork



Heinrich



IT Tech
Tyler
2006-11-02 06:43:12 UTC
Try some other virus removal tools, there's a good list of free ones

here for you.http://www.basicspywaretips.com/spywareremovaltool.html
cmoo92
2006-11-02 05:51:12 UTC
If AVG truly can't remove/heal them (which I highly doubt), I'm sure it's at least giving you the name of the virus such as "M32/Something"



Take the virus name and Google search it. You should quickly find removal instructions.
jo
2006-11-02 09:42:22 UTC
on my PC there is a program called Norton Anti Virus buy that it will let you delete them
Lizzie
2006-11-02 05:46:36 UTC
First look up the virus names on the symantec website for norton anti-virus if its serious then turn off system restore and reboot with your windows recovery disk, remember to save any files you want to keep.
♥gigi♥
2006-11-02 05:50:11 UTC
i have used AVG for years and have never been let down by it until recently and it missed 2



after asking on here for help i was given another free anti virus link and it found the 2 immediatley and made them safe.



give it a try



http://www.avast.com/eng/download-avast-home.html
fluffy bunny
2006-11-02 05:46:06 UTC
If AVG anti Virus has located them it will automatically put them in the virus vault and from there you can safely delete them.. I have used that programme for 3 years and i sware by it....
tr2thhrt
2006-11-02 06:41:57 UTC
I looked these up and this is the links i found for removing Good Luck
Gary Crant
2006-11-03 04:23:51 UTC
Try www.neuber.com Use their free trial. You will probably se them listed. It tells you of what threat they are and gives you the option of what to do with them. Good Luck
species8472
2006-11-03 17:15:20 UTC
start pc in safe mode by pressing f8 during startup and scan using antivirus while in safe mode. or goto this sitefor free online virus scan its the best there is



http://uk.trendmicro-europe.com/housecall/v6.5/
bsmith13421
2006-11-02 05:48:10 UTC
no antivirus will remove everything but avg is the best at finding them you needto start in safe mode and hunt them down this site has directions on how to do it http://bartman1.blogspot.com/
2006-11-02 09:54:36 UTC
AVG is totally worthless. It is JUNK. I recommend active virus shield. It is way better and it is free.
tlc
2006-11-02 05:56:06 UTC
down load windows defender from microsoft.com. It is free and it removes all of that crap.
c0mplicated_s0ul
2006-11-02 05:53:16 UTC
go to this web site with the laptop and run the scan..

http://housecall.trendmicro.com/
mikhail_luh
2006-11-02 05:47:33 UTC
1st thing... update your anti virus...

if that don't work....

back up files you trust... and need... then format!

if you are unable to do the above 2

call you your friendly IT guy.

ir just format
jointy
2006-11-02 05:45:14 UTC
try another antivirus like NOD32 or search the files and delete them yourself
Reston
2006-11-02 06:24:00 UTC
First off, download ATF Cleaner and delete all temporary files where malware can hide. Make sure you set your Windows Explorer to show all hidden system files before you run ATF.



Update your antivirus. If you do not have one, download and install AVG or Avast!. They are free.



Also install and update:

1. Ad-Aware SE

2. Spybot Search and Destroy

3. Windows Defender (free from Microsoft)

4. Microsoft Malware Remover (free also)

5. SpywareBlaster

6. Ewido

7. Google Toolbar

8. McAfee SiteAdvisor

9. Firewall like Comodo Personal Firewall or Sygate Personal Firewall

10. CWShredder - there are 2 versions. Make sure you install both the last Merijn version and the latest version from TrendMicro.

11. About:Buster

12. HijackThis

13. WinsockXPFix - to be used only when no matter what you do you still can't connect to the Internet.

14. Opera browser - use this instead of IE (Internet Explorer) unless you are updating Windows or doing online banking or visiting sites that refuses to render correctly in Opera.

15. SmithFraudFix

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

Platforms supported: WinXP, Win2K



This tool removes Desktop Hijack malware:

Smitfraud

Win32.puper

AVGold

Security iGuard

Spyware Vanisher

quicknavigate.com

updateSearches.com

startsearches.net

Virtual Maid

SpySheriff

PSGuard

SpyAxe

WinHound

AlphaCleaner

AdwarePunisher

SpywareQuake



For info on how to use this utility and how to install it, go to the link above.



I would not suggest turning off System Restore while you're in the process of cleaning your system. Sometimes while getting rid of malware something unexpected can go wrong that you need to use one of those restore points. And if you turn System Restore off you have no restore points to go back to. Don't worry about viruses/malware in System Restore if there any. They can not harm your system because they are NOT ACTIVE while in a Restore Point. They will only become active if and when you use that particular infected restore point. The best time to clean the viruses in your restore points is when your system is running problem-free and no risk of messing up. All you have to do is turn the System Restore off, reboot, and viruses in there will be gone.



Download sites

Use these URLs to download the latest version (the file contains both English and French versions):

http://siri.urz.free.fr/Fix/SmitfraudFix.zip

http://siri.geekstogo.com/SmitfraudFix.php



Mirrors: Alternate official download locations for Smitfraudfix.zip

http://siri.geekstogo.com/SmitfraudFix.zip

Zebulon.fr



Extract the content (a folder named SmitfraudFix) to your Desktop.

Next, reboot your computer in Safe Mode by rebooting the computer, & repeatedly tapping the F8 key as the PC starts. Choose "Safe Mode" from the options listed.

Once in Safe Mode, open the SmitfraudFix folder again & doubleclick "smitfraudfix.cmd".



Select option 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt



Select option 2 - Clean by typing 2 and press "Enter" to delete infected files.



You will be prompted : "Registry cleaning - Do you want to clean the registry?"

Answer "Yes" by typing Y and press Enter in order to remove the Desktop background & clean registry keys associated with the infection.



The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press Enter.



The tool may need to restart your PC to finish the cleaning process; if it doesn't, reboot it in Normal Mode.



Screenshots

http://siri.urz.free.fr/Fix/ScreenShot.php





Update all the above programs RIGHT AFTER YOU INSTALL THEM.



All the above are FREEWARE. All of them are easily Googleble.



Reboot to Safe Mode and run your antivirus, #1-4, 6, 10 (both versions) & 11.



Reboot in Normal Mode. Run HijackThis (or HJT for short). DO NOT REPAIR OR FIX anything that it will list in its scan log. Just copy the whole log.



Register for free at MCH Forums:

http://mycomputerheadaches.tz4.com



After you register, post your HJT scan log at the above site, specifically at the System Security Forum. Precede your posting with a detailed description of your problem. And use a descriptive subject line. For example:

WinXP: Yahoo Messenger infection



Be patient. OJ, our resident HJT expert, has a life outside of his cyberlife. So just wait until he responds. Do read all the postings at the Announcements Forum to follow what you need to do as an MCH member.



I strongly recommend that you back up the registry before making any changes to your Registry. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions on how to make a backup of the Windows registry:

How to back up Windows Registry

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/199762382617?OpenDocument&src=sec_doc_nam



Note: If the Registry Editor does not open, the worm has made changes to the registry that prevent it from running. To fix this, download and run the Tool to reset shell\open\command registry keys, which also fixes this problem:

http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99



Kill2Me

Current version: 1.11

Freeware

Platform supported: All Windows

http://www.spywareinfo.com/~merijn/downloads.html



A removal tool specifically for the Look2Me (L2M) varieties of adware parasite. This tool removes versions 115, 116, 117 118, 120, 121 and 122 (the most recent ones) on all Windows versions. Kill2Me comes as an EXE file that require no installation, although it needs some Visual Basic 6 libraries which should already be present in all modern Windows machines. Running Kill2Me is extremely straightforward and will not be covered in detail here; just make sure you're running its latest version, since it is constantly updated, & make sure that all of your Windows Explorer & IE windows are closed when you run it, or else it may not be able to fix everything that needs fixing.



Look2me can be difficult to remove, but they do offer their own removal tool located here.



Download links

http://www.majorgeeks.com/download4166.html

http://download.bleepingcomputer.com/Merijn/kill2me.zip



KL-Detector

Current version: v1.3

http://www.dewasoft.com/privacy/kldetector.htm

Freeware

Platform supported: For Win2000 and WinXP. Win95/98 & Me are not supported.



This is a unique program that is able to detect keylogging activity on your computer. It is designed to be able to detect ALL keyloggers. Use KL-Detector to find out whether your activity is being recorded without your knowledge.



Some quick facts about KL-Detector



It should work under Windows NT 3.51 SP3, Windows 2000, and Windows XP.

No installation is necessary.

It cannot detect hardware keylogger. Well, no software can.

It cannot remove the keylogger automatically. You have to do it by yourself.

It reports the log file. If there is a log file, there should be a keylogger.

It might be called anti-keylogger, but I don't like that name. It detects keylogger, hence the name is KL-Detector.

It was written by a hobbyist programmer. So when I say it's free, it's really free



How does KL-Detector work?



It works by scanning your local hard disk for any log file created during the monitoring process. Most keyloggers will eventually save the recorded data into a location in the hard disk. KL-Detector will inform you of such log file. This way, the program can detect all keyloggers, both known and unknown. Use KL-Detector to detect keylogger in public computer before you enter your password, credit card info, etc.



I have found a log file. What should I do?



Sometimes KL-Detector will give a false positive; that is, when a normal file is perceived as a log file. So please ensure that the reported file is a log file. If it is, that means a keylogger is installed on your system. Check the startup items and eliminate suspicious program. XP users: press Ctrl-Alt-Del and review all processes. Of course, adequate computer knowledge is required to remove the keylogger from your system...



You have the latest qoologic infection.



The bad thing about this infection is that we have to get all the files in one shot, ohterwise it respawns immediately.



1) Download http://www.bleepingcomputer.com/files/winpfind.php



Extract WinPFind.zip to your c:\ folder.



Reboot your computer into Safe Mode by tapping the F8 key just before Windows starts to load.



Then open c:\WinPFind and double-click on WinPFind.exe. When the program is open, click on the Start Scan button to scart scanning your computer. Be patient as this scan may take a while. When it is done, it will show a log and tell you the scan is completed. Reboot your computer back to normal mode and and post the contents of c:\WinPFind\WinPFind.txt as a reply to this topic.



2) Please download FindQool by LonnyRJones:

http://downloads.subratam.org/Lon/FindQool.zip



* Extract the files and place the FindQool folder in root. Usually C:\

* Open the folder and run Qlocate.bat.

* Post the contents of the txt.log which will open.



3) Download F-Secure Blacklight (blbeta.exe) to your C:\ drive.

- Open a command window. (Start>Run and type: cmd)

- Copy paste or type the following in the command window:



C:\blbeta.exe /expert



- Accept the user agreement.

- Click Scan.

After the scan finishes, click on Next, then Exit.





Our sister Yahoogroup is:

MCH Yahoogroup

http://mch.tz4.com
big_chris_fool
2006-11-02 06:11:27 UTC
if u want to remove these to viruses that avg will not eliminate.....go here...download this......http://www.ewido.net/en/

now...b4 u scan...make sure u update ewido...then do this

go to start..run..type in msconfig.....press ok...new window...press start up..select disable all.press apply..press ok

go to start..run..type in prefetch in new window in top left corner..select edit..select all..press delete.......yes..delete all...

go to start..all programs..system tools..disc clean up..select c drive..after it has finished analyzing..check all the boxes..press ok..when it has finished cleaning..it will disappear...

now go to start..control panel...folder options.....view...u will see a option that says "show all hidden files and folders"..check that..press apply..press ok.....

ok....now we need to go into safe mode....turn off ur computer.....as soon as u turn it back on...u have to press f8 repeatedly until u see a screen that shows u several different options.....u need to enter the option " safe mode" use the arrow keys on keyboard to scrool to it..then press enter...after u afew moments..u will see log on as.....admin or user....select user....after that u will see ur desktop......now open ewido antispyware..( please update this b4 going into safe mode)..click scan my computer....select full or complete system scan.....then press next..it might take ahour or so..after it has finished..remove what ever it finds...now close ewido....

go to start.run..type in...%temp%...press ok..new window..go to edit.select all..press delete..tes..delete all....

go to start..control panel...folder options.....view...click reset to default..press apply..press ok...

now restart your computer...u will see a pop up from system configuration...put a check mark in the little box..press ok


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...