Question:
Potential computer virus/trojan?
meathookcook
2007-06-22 15:25:59 UTC
I just started a virus scan by McAfee and as it was running 6 little windows popped up each one stating that each .exe file was not a valid Win32 application. When McAfee finished it had no mention of any of these executable files on its summary. When I try to navigate to the file on my C drive I cannot find it based on the file path.

For example
C:\DOCUME~1\All\LOCALS~1\Temp\wr-1-2000219.exe

If they aren't valid exe programs I want to remove them. How can I find them? I tried using Search. Nothing. Did McAfee remove them automatically?
Nine answers:
anonymous
2007-06-22 15:29:35 UTC
I would bet McAfee did. Try doing another scan and see what comes up.
Butt
2007-06-22 15:38:47 UTC
I just ran Advanced Windows Care v2.I clicked on a programe to open and then the end of the writing(syng or something)I got

the big shock when i saw what was not.It also told me Win 32 was not valid and had been put there by a trojan.A lot has.It does give you sites if you press the writing syng? to help.But i'm

going to leave it until tomorrow.But download it(free)It may help

you.Good luck.
Darkkrystel
2007-06-22 15:29:01 UTC
Sound more like spyware popping up telling you something is not valid trying to get you to click on it to go to their website to download programs to fix an issue that you don't have. I'd get Spybot Search and Destroy and AdAware and run both those programs to fix your issue. I only say this because I recently fixed an issue on my sisters computer that was doing the same thing and hers was spywayre and not a virus. Though spyware can be sometimes as harmfull as viruses.
anonymous
2007-06-22 15:30:26 UTC
You can manually delete them from the windows search if you know the name of them. Just search your local hard drives for them and delete anything with that name. Sometimes, windows like normal will screw up and say certain programs are not valid. For instance when i installed F.E.A.R. , something corrupted and It said it was not valid. I reinstalled and i didn't get the message again. Best of luck to you.
vashisast
2016-09-28 11:51:39 UTC
Trojans are recent in my places alongside with merely vacationing a internet site. place your laptop in secure mode then run a test, then delete infections, then place laptop into general mode and run yet another test to verify the Trojan is long previous.
anonymous
2007-06-22 16:41:36 UTC
VIRUS REMOVAL PROCESS:



do this OFFLINE



trash likes to hide in your restore system,so every time you clean up your computer and you use system restore,it restores the trash along with everything else !

turn off system restore:

XP:

start--all programs--accessories--system tools--system restore

check the off box



Vista:



right click computer icon

select properties

select system protection

uncheck os ( c: ) ( system )



delete history:



XP & Vista:



internet explorer--tools--internet options--general:

click delete history--temp files & cookies

set days to keep history to 0



alerter & messenger services:

stop messenger spam !!



XP only:

all programs--administrative tools--services

all services are in alphabetical order,right click both alerter & messenger services--select properties--from drop down menu,select disable



Active X:

XP ONLY

internet explorer--tools--internet options--security--advanced

uncheck download unsigned--unsafe--autoprompt



CLEAN UP:

Disk clean:

XP:

start--all programs--accessories--system tools--disk clean up

open disk clean up--select disk drive ( c )--select drive ( c )--check all boxes with files--ok--delete



repeat process for disk defrag



Vista:



control panel,performance information and tools

click disk clean up

select drive ( c )

click ok

check all options showing files to be deleted

click ok

click delete files

repeat process for disk defrag but select advanced tools to get there



do weekly



Prefetch folder:



XP:

start,my computer,disk drive ( c ),windows,prefetch

click view

select "select all"

press delete key on keyboard



Vista:



same thing except my computer is now plain ole computer



Security:



block spyware cookies:

XP:

either from your desktop shortcut or all programs or start page [ lol,MS is all about redundency ]

internet explorer--tools--internet options--privacy--advanced--override

check allow 1st party cookies,block 3rd party [ spyware ] cookies



Vista:



same way as XP



manage your cookies [ with screenshots ]

http://managecookies.diaryland.com



ActiveX:



XP ONLY



internet explorer,tools,internet options,security tab,advanced tab

uncheck download unsigned, not safe & automatic prompt



now return to system restore and select create a new restore point,name the point [ new ? ] and you're set to go



go online and:



download/install/update & run spybot spyware remover,avast anti-virus,regseeker,avg anti-rootkit,rootkit revealer,firefox 2.0.0.4 web browser from



MENU

Acessibility Help,ANTI-ROOTKIT,ANTI-VIRUS,ANTI-SPYWARE,Browser FIREFOX 3.0a5pre

Buddy Browser,a child safe wweb browser for children,CLEAN UP,DESKTOP HELPERS

FIREFOX EXTENSIONS INSTALLED,FIREWALL,Multi Media Files,REGISTRY CLEANERS

SECURITY,Link Checkers,Ect



http://browseraddons.friendpages.com



clear google and i.e."s addressbars:



XP AND VISTA:



internet explorer,tools,internet options,content tab,autocomplete,settings



uncheck forms and web addresses



download these 2 firefox security extensions:

coolirus preview emails and web links

dr web check links for threats BEFORE you open them

http://mozilla.friendpages.com



Manage Start Up Programs:



Vista:



control panel--performance information & tools

manage start up programs

click program

click remove



XP:



windows key + letter R

enter--msconfig

select startup tab

uncheck the program to stop starting with windows

when the "you have customized" dialog box comes up later,check don't show again or it will haunt you !



registereduser1946@gmail.com
Tracy L
2007-06-22 16:23:18 UTC
Were all of them in the same Temp directory?

C:\DOCUME~1\All\LOCALS~1\Temp\...



If so just go to that directory in My Computer and delete everything in it. Temp is only for temporary files so it is safe to clear it. I think you can even clear it with "Disk Cleanup" if you want.



Then rescan and see it they still show.
Benji P
2007-06-22 15:29:25 UTC
run a full service

scan to get rid of viruses and junk files





http://onecare.live.com/site/en-US/default.htm
anonymous
2007-06-22 15:47:49 UTC
Try a online antivirus scanner and a online anti-adware/malware/spyware scanner in safe mode with network to clean up your computer BEFORE you download anything.



Turn of system restore before you boot up in safe mode with network to clear your system restore points for viruses, spyware, adware etc.



To get in safe mode tap F8 when booting you computer.

Choose "Safe mode with network".

Go to Start – Run - type iexplore http://www.bitdefender.com/scan8/ie.html Enter(ok).

Do a full system scan. If something is found, delete it, reboot and do the same again in safe mode with network.

When that scan does not find anything you reboot again in safe mode with network.

Go to Start – Run – type iexplore http://www.ewido.net/en/ Enter(ok).

Do a full scan. If you find something, delete it, reboot and do the same again in safe mode with network.



**NOTE: Do NOT do anything else with your computer when scanning. This because you can start virus/adware/spyware/malware manually.



When no one of these scanners are showing anything you can reboot back to normal mode.

Turn on system restore.

------------------

You need to get one antivirus program, one firewall and some spyware/adware/malware removers if you don't have it.

I use Norton Internet Security on my desktop running XP Home SP2 with Firefox.

On my laptop i have Ubuntu 7.04. No security needed in Linux, but i have antivirus and firewall.



Here are some free programs.

BitDefender Anti-Virus Free.

http://www.bitdefender.com/PRODUCT-14-en--BitDefender-8-Free-Edition.html

Avast Anti-Virus Free.

http://www.avast.com/eng/avast_4_home.html

AVG Anti-Virus Free.

http://free.grisoft.com/doc/2/lng/us/tpl/v5

Avast Virus Cleaner - free virus removal tool.

http://www.avast.com/eng/avast-virus-cleaner.html



Firewall Protection.

ZoneAlarm Firewall Free.

http://www.zonealarm.com/store/content/catalog/products/sku_list_za.jsp?dc=34std&ctry=&lang=nb&lid=trial_zaFamily

Easy-to-use firewall blocks hackers and other unknown threats.

* Systematically identifies hackers and blocks access attempts.

Automatically makes your computer invisible to anyone on the Internet.

Use ZoneAlarm if you normally use Windows Firewall.

Disable Windows Firewall after downloading ZoneAlarm if it's not done automatically.



Ad-Aware 2007 Free.

http://www.lavasoftusa.com/products/ad_aware_free.php

Ad-Aware 2007 Free remains the most popular anti-spyware product for computer users around the world, with nearly one million downloads every week. Our free anti-spyware version provides you with advanced protection against spyware that secretly attaches and takes control of your computer, resulting in aggressive advertising pop-ups, sluggish computer activity, even identity theft through stolen bank details, passwords, and credit card account numbers. If you want real-time scanning capabilities, consider upgrading to Ad-Aware 2007 Plus for real-time protection against spyware, all the time.



SUPERAntiSpyware Free.

http://www.superantispyware.com/



AVG Anti-spyware Free.

http://free.grisoft.com/doc/20/lng/us/tpl/v5



Spybot-S&D Free.

http://www.safer-networking.org/en/mirrors/index.html

Spybot - Search & Destroy detects and removes spyware, a relatively new kind of threat not yet covered by common anti-virus applications. spyware silently tracks your surfing behaviour to create a marketing profile for you that is transmitted without your knowledge to the compilers and sold to advertising companies. If you see new toolbars in your Internet Explorer that you haven't intentionally installed, if your browser crashes inexplicably, or if your home page has been "hijacked" (or changed without your knowledge), your computer is most probably infected with spyware. Even if you don't see the symptoms, your computer may be infected, because more and more spyware is emerging. Spybot-S&D is free, so there's no harm giving it a try to see if something has invaded your computer.



AVG Anti-Rootkit Free.

http://free.grisoft.com/doc/39798/lng/us/tpl/v5

AVG Anti-Rootkit is a powerful tool with state-of-the-art technology for detection and removal of rootkits. rootkits are used to hide the presence of a malicious object like Trojans or keyloggers on your computer. If a threat uses rootkit technology to hide itself it is very hard to find the malware on your PC. AVG Anti-Rootkit gives you the power to find and delete the rootkit and to uncover the threat the rootkit is hiding.



CCleaner free.

CCleaner is a freeware system optimization and privacy tool. It removes unused files from your system - allowing Windows to run faster and freeing up valuable hard disk space. It also cleans traces of your online activities such as your Internet history. But the best part is that it's fast and contains NO spyware or adware.

http://www.ccleaner.com/



ClearAllHistory - clears browser history, cache, cookies, clipboard and remove other computer activity tracks.

http://www.clearallhistory.com/delete-passwords.html



**NOTE: Only have one antivirus program and one firewall installed on your computer.

Anti-adware/malware/spyware are ok to have more of.



Also scan with online scanners sometimes.

http://security.symantec.com/sscv6/home.asp?langid=ie&venid=sym&plfid=00&pkj=VOONYHGBYNCJEIMXQKC&bhcp=1

http://www.bitdefender.com/scan8/ie.html

http://www.ewido.net/en/onlinescan/

http://www.kaspersky.com/virusscanner

http://support.f-secure.com/enu/home/ols.shtml



Also run Windows Updata http://windowsupdate.microsoft.com/



Hope this was helpful.

Good luck.

JTB - Security adviser from Norway.


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...