The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Need help deleting malware and (virus?)

    Discussion in 'Security and Anti-Virus Software' started by perrin_aybara, Feb 13, 2010.

  1. perrin_aybara

    perrin_aybara Notebook Consultant

    Reputations:
    183
    Messages:
    185
    Likes Received:
    3
    Trophy Points:
    31
    I caught a virus earlier today using the same name as WINLOGON.EXE. There are three files contained in this file I scanned using Avast and Superantispyware and both reported positive infection. Superantispyware confirms them as 1 Hijacker and 2 malware, Problem is they won't let me remove these files they just tell me "unable to remove selected items".I tried running as Administrator but I get the same results. After this I tried using HitmanPro but that never found anything.
    Does anyone have anyway to delete these files? I'm running Vista 32 bit.
    Your help would be appreciated.

    I also uploaded the file to virus total and it came back with around 7 positives.
     
  2. arjunned

    arjunned Notebook Deity

    Reputations:
    288
    Messages:
    766
    Likes Received:
    0
    Trophy Points:
    30
    Which engines in VirusTotal detected it as malware?
     
  3. perrin_aybara

    perrin_aybara Notebook Consultant

    Reputations:
    183
    Messages:
    185
    Likes Received:
    3
    Trophy Points:
    31
    An edit to my previous post: It was Spybot and avast that foound these NOT Superantispyware!
    Arjunned I can't recall what engines detected them from Virustotal. So I ran Spybot again to locate the file locations and I managed to delete two of these. Problem is, Spybot asked me to do a restart and it would scan on start up- so I did and when the scan result came upo with the one remaining hijacker I cant find the file location for that to upload to virus total again.

    Scanned on start-up this morning and never found a thing. Not sure why that is. Is it they were all from the same virus and by deleting 2 have somehow managed to kill the third?
    Is that possible?
     
  4. Deks

    Deks Notebook Prophet

    Reputations:
    1,272
    Messages:
    5,201
    Likes Received:
    2,073
    Trophy Points:
    331
    Maybe ... or the third one managed to hide itself somehow.

    In any event, what I usually did in these situations was to simply make sure my definitions were up to date, then restart the system in safe mode, re-scan the system from there and delete the infections.

    Spybot is not so good these days apparently.
    Malwarebytes seems to be the best in terms of free solutions.

    I would suggest you download, install and update Malwarebytes.
    Make sure Avast is fully updated as well.
    Restart the system in safe-mode and re-scan from there with both (I think a quick scan, or a full scan will suffice).
    Run a quick scan using both programs on the system first, and if it comes out clean, then repeat the procedure with a full scan.

    Spybot was unable to remove the infection in standard windows mode because system files were not accessible.
    In safe-mode, that's not the problem and infections are far easier to remove.
    But Malwarebytes is more effective.
     
  5. perrin_aybara

    perrin_aybara Notebook Consultant

    Reputations:
    183
    Messages:
    185
    Likes Received:
    3
    Trophy Points:
    31
    Thanks, I will give this a go. I've never had any major virus to deal with so i'm a bit of a novice in this department.
    I will post back results.
    Cheers.
     
  6. LaptopNut

    LaptopNut Notebook Virtuoso

    Reputations:
    1,610
    Messages:
    3,745
    Likes Received:
    92
    Trophy Points:
    116
    @perrin_aybara

    What sort of backup method do you use for your system?
     
  7. clogui

    clogui Notebook Consultant

    Reputations:
    14
    Messages:
    137
    Likes Received:
    0
    Trophy Points:
    30
  8. yejun

    yejun Notebook Deity

    Reputations:
    50
    Messages:
    1,158
    Likes Received:
    0
    Trophy Points:
    55
    I think microsoft security essential is very good free one as well. You can also install a trial version of free software like hitman pro, norton for 30 days.
     
  9. Deks

    Deks Notebook Prophet

    Reputations:
    1,272
    Messages:
    5,201
    Likes Received:
    2,073
    Trophy Points:
    331
    Avast 5 is apparently comparable to MSE in most aspects apart from 2 of them.
    First, Avast 5 is more optimized and therefore uses less resources (though MSE is already quite light, so it really won't be noticed running in the background either).

    MSE is much better in removing infections from the system when compared to Avast which had issues in doing so with some of them (as did a lot of paid programs).

    I personally stick with MSE, though Avast is perfectly fine.

    Having Malwarebytes though as a backup software (just in case) would be a smart thing to do.
    Aside from that, common sense and nothing else is really needed
     
  10. perrin_aybara

    perrin_aybara Notebook Consultant

    Reputations:
    183
    Messages:
    185
    Likes Received:
    3
    Trophy Points:
    31
    I downloaded and ran malwarebytes, and it found three forms of malware and a trojan-dropper.
    As for Spybot, I think I will still keep this as this programme found the infections firstly.

    cheers for the help people.
     
  11. Deks

    Deks Notebook Prophet

    Reputations:
    1,272
    Messages:
    5,201
    Likes Received:
    2,073
    Trophy Points:
    331
    Malwarebytes is actually better than Spybot.
    You can easily remove Spybot and simply keep Malwarebytes.

    Oh and, were you able to completely remove the infections finally?
     
  12. perrin_aybara

    perrin_aybara Notebook Consultant

    Reputations:
    183
    Messages:
    185
    Likes Received:
    3
    Trophy Points:
    31
    Yip, all gone. It did find 4 infections where I new of only three, so yes it was a success.
    Cheers.