I caught a virus earlier today using the same name as WINLOGON.EXE. There are three files contained in this file I scanned using Avast and Superantispyware and both reported positive infection. Superantispyware confirms them as 1 Hijacker and 2 malware, Problem is they won't let me remove these files they just tell me "unable to remove selected items".I tried running as Administrator but I get the same results. After this I tried using HitmanPro but that never found anything.
Does anyone have anyway to delete these files? I'm running Vista 32 bit.
Your help would be appreciated.
I also uploaded the file to virus total and it came back with around 7 positives.
-
perrin_aybara Notebook Consultant
-
Which engines in VirusTotal detected it as malware?
-
perrin_aybara Notebook Consultant
An edit to my previous post: It was Spybot and avast that foound these NOT Superantispyware!
Arjunned I can't recall what engines detected them from Virustotal. So I ran Spybot again to locate the file locations and I managed to delete two of these. Problem is, Spybot asked me to do a restart and it would scan on start up- so I did and when the scan result came upo with the one remaining hijacker I cant find the file location for that to upload to virus total again.
Scanned on start-up this morning and never found a thing. Not sure why that is. Is it they were all from the same virus and by deleting 2 have somehow managed to kill the third?
Is that possible? -
Maybe ... or the third one managed to hide itself somehow.
In any event, what I usually did in these situations was to simply make sure my definitions were up to date, then restart the system in safe mode, re-scan the system from there and delete the infections.
Spybot is not so good these days apparently.
Malwarebytes seems to be the best in terms of free solutions.
I would suggest you download, install and update Malwarebytes.
Make sure Avast is fully updated as well.
Restart the system in safe-mode and re-scan from there with both (I think a quick scan, or a full scan will suffice).
Run a quick scan using both programs on the system first, and if it comes out clean, then repeat the procedure with a full scan.
Spybot was unable to remove the infection in standard windows mode because system files were not accessible.
In safe-mode, that's not the problem and infections are far easier to remove.
But Malwarebytes is more effective. -
perrin_aybara Notebook Consultant
Thanks, I will give this a go. I've never had any major virus to deal with so i'm a bit of a novice in this department.
I will post back results.
Cheers. -
@perrin_aybara
What sort of backup method do you use for your system? -
Try malwarebyte.
http://www.malwarebytes.org/mbam.php -
I think microsoft security essential is very good free one as well. You can also install a trial version of free software like hitman pro, norton for 30 days.
-
Avast 5 is apparently comparable to MSE in most aspects apart from 2 of them.
First, Avast 5 is more optimized and therefore uses less resources (though MSE is already quite light, so it really won't be noticed running in the background either).
MSE is much better in removing infections from the system when compared to Avast which had issues in doing so with some of them (as did a lot of paid programs).
I personally stick with MSE, though Avast is perfectly fine.
Having Malwarebytes though as a backup software (just in case) would be a smart thing to do.
Aside from that, common sense and nothing else is really needed -
perrin_aybara Notebook Consultant
I downloaded and ran malwarebytes, and it found three forms of malware and a trojan-dropper.
As for Spybot, I think I will still keep this as this programme found the infections firstly.
cheers for the help people. -
Malwarebytes is actually better than Spybot.
You can easily remove Spybot and simply keep Malwarebytes.
Oh and, were you able to completely remove the infections finally? -
perrin_aybara Notebook Consultant
Yip, all gone. It did find 4 infections where I new of only three, so yes it was a success.
Cheers.
Need help deleting malware and (virus?)
Discussion in 'Security and Anti-Virus Software' started by perrin_aybara, Feb 13, 2010.