Viruses everywhere!

unnamedplayer

Member
Feb 1, 2006
44
0
0
Hi all,

I need some help cleaning up a friend's computer. I was originally there to help them with some CD recordings, but then this came up.

Basically they are running Avast antivirus and it has started picking up a whole bunch of infected files. I tried quarantining or deleting those infected, but some of the files that it is reporting look pretty serious (the one example that springs to mind is mmc.exe). I ran a thorough scan and it picked some up, but after that it reported finding a virus that was at the operating system level and suggested a boot time scan. I did the boot time scan and everything seemed to come up clean.

When I got back into Windows though, it found more infections. And the thing is when I try to read the name of the infection I can't make it out because the characters are not displaying right for some reason. Two of the names for example were something like f(then a little square looking character)bop and m(square looking character)bop. Another one was called µ.

I'm not really sure as to where to go from here. I ran a thorough scan a couple of more times and things seemed to come up clean, but after I restarted I got more infected files. I'm afraid a total format might be in store.

What do you guys think?
 

deathwalker

Golden Member
May 22, 2003
1,211
0
0
Make sure you try to run the Virus scan in Safe-mode...also..disable system restore prior running scan then re-enable after scan is done.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Here's what I'd do (other than strongly considering the reformat):

1) download F-Secure's BlackLight Beta, which is a rootkit detector.

2) download a free 30-day trial of Kaspersky Antivirus Personal 5: mech's link showing how to configure it for maximum detection. Kaspersky is way better than Avast.

3) also get set up to run this manual scanner: instructions



Now uninstall Avast (you don't want two antivirus packages installed), install Kaspersky, and follow the configuration instructions I gave in my link above. Don't get flustered and run a scan yet. First run F-Secure's BlackLight and use the Rename option on any rootkits it finds.

After using BlackLight Beta, now reboot the system into Safe Mode With Command Prompt and try the manual scanner I have in Step 3 above. Once it's done, its scanning window goes away.

After that scan is done, while you're still in Safe Mode With Command Prompt, use CTRL ALT DELETE to bring up Task Manager, and use the New Task button to start explorer.exe. The taskbar and Start button appear. Now use the Start > Programs menu to start up Kaspersky Antivirus and run an exhaustive scan with it as well.

Now reboot into normal Windows and see how it goes. If the computer has no firewall, or is not up-to-date on its patching, then take care of those issues too.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |