Un-deleteable Virus

Discussion in 'Computer Games and General Discussion' started by [M]artin, Jun 25, 2009.

Jun 25, 2009

Un-deleteable Virus by [M]artin at 1:46 PM (1,846 Views / 0 Likes) 23 replies

  1. [M]artin
    OP

    Member [M]artin .

    Joined:
    Nov 7, 2006
    Messages:
    3,658
    Country:
    United States
    Hey gang, I've run into a big problem. This morning I booted up my PC and ESET greeted me with this:

    [​IMG]
    So, both "Quarantine" and "Remove" are ticked in the Advanced Options underneath. "Submit File for Analysis" is grayed out, though.

    So I hit "Remove" and then this pops up:
    [​IMG]

    I hit "Retry" and eventually get stuck with this:
    [​IMG]
    I have no choice but to click "Cancel" at this point.

    The Threat Box has popped up a number of times already and I always get stuck with the same messages.

    Whatever the threat is, it's been messing with my internet, causing pages to load a bit sluggish and even cutting it out for a few minutes at a time (about 1 or 2).

    Any suggestions on what I should do about this? [​IMG]
     


  2. moodswinger

    Member moodswinger GBAtemp Regular

    Joined:
    Sep 6, 2008
    Messages:
    237
    Country:
    Philippines
    Not sure if you should delete it or not, but you can try gmer.
     
  3. david432111

    Member david432111 GBAtemp Advanced Fan

    Joined:
    Jul 17, 2008
    Messages:
    859
    Location:
    Denmark
    Country:
    Denmark
  4. zidane_genome

    Member zidane_genome My sword has a +2 bleeding... wanna test it out?

    Joined:
    May 21, 2006
    Messages:
    2,320
    Country:
    United States
    Yea, pretty sure if you delete winlogon.exe your gonna have to reinstall Windows (2000 by the looks of it!)

    Kill it in your task manager, then you can try...
     
  5. [M]artin
    OP

    Member [M]artin .

    Joined:
    Nov 7, 2006
    Messages:
    3,658
    Country:
    United States
    Thanks a bunch, I'll be trying this out shortly.

    lilsypha suggested that I run Autoruns to find to file, and while the program was seeking it out, a new threat popped up note the comment and how it points to the new program I was using to seek it out):
    [​IMG]
    lilsypha suggests that the virus is attaching itself to every .exe I try to run. A number of people in IRC also suggest that a full format is the way to go, but I only want to do so as a last resort.

    Shit. Think it was from a (working) IPS patcher from a link posted here. Not 100% sure, though.

    EDIT: And another Threat message just popped up telling me that the Threat has returned back to winlogin.exe... [​IMG]
     
  6. Golfman560

    Member Golfman560 TheRapist.com

    Joined:
    Dec 29, 2008
    Messages:
    1,099
    Location:
    Living with seals
    Country:
    Antarctica
    It poped up because ESET checks files as programs use them, so if you were in eplorer.exe and went into the system32 folder I would bet quite a few virus alerts would pop up. The comment would then say it was found when running the application explorer.exe.
     
  7. Law

    Member Law rip ninjacat that zarcon made me

    Joined:
    Aug 14, 2007
    Messages:
    4,132
    Location:
    ‭jerkland
    Country:
    United Kingdom
    I had something similar recently, I had to reformat two of my drives (backed up most of the stuff I wanted to keep that weren't exes on a different drive).
     
  8. xcalibur

    Member xcalibur Gbatemp's Chocolate Bear

    Joined:
    Jun 2, 2007
    Messages:
    3,166
    Location:
    Sacred Heart
    Country:
    United Kingdom
    Hijackthis, Malware antibytes, Ad-Aware, Spybot S&D etc etc.
    If all else fails, run in safe mode and delete them manually.
     
  9. OSW

    Former Staff OSW Wii King

    Joined:
    Oct 30, 2006
    Messages:
    4,796
    Country:
    Australia
    My PC is stuffed up on numerous levels... I believe part of it is from when i tried to install a cracked antivirus program...

    I'm going to backup everything and start from scratch since I haven't been able to remove these viruses after numerous attempts.
     
  10. outgum

    Member outgum Pokemanz Master

    Joined:
    Sep 22, 2009
    Messages:
    1,993
    Location:
    Hamilton, New Zealand
    Country:
    New Zealand
    Do a system restore, back about a week maybe...
    Its a chance, and if it works, better than doing a Full Format.
    You cant delete it because its a system32 File
    You could try boot command prompt and go chkdsk

    Might help
     
  11. blitzer320

    Member blitzer320 GBAtemp Fan

    Joined:
    Sep 29, 2008
    Messages:
    370
    Location:
    NYC
    Country:
    United States
    no load in linux or safe mode and copy the winlogon.exe from your i386 folder on linux live cd this is straight forward but on safe mode you have to kill the winlogon process first winlogon is the program that runs when you first load windows and it asks you for your password so yeah you need it to load windows
     
  12. cobleman

    Member cobleman GBAtemp Maniac

    Joined:
    Jun 23, 2009
    Messages:
    1,449
    Location:
    Australia
    Country:
    Australia
    System restore wont help if its a WORM it will attach its self to your restore point and infect it as well.
    Save what you can to a seperate drive, format and reinstall windows get antivirus on rite away then connect your other drive backup and scan before you open it. You could spend upto 20 hours trying to remove it only to find its infected everything you have opened!
     
  13. funem

    Member funem Retro Powered..

    Joined:
    Nov 4, 2006
    Messages:
    1,160
    Location:
    out of nowhere....
    Country:
    United Kingdom
    Get a fresh copy of the file from another PC with the same level of OS as yours, boot into recovery console, rename infected file, copy over the replacement one, reboot PC... If there is a problem go back to recovery console and put the old infected file back until you have another fix to try...
     
  14. Elritha

    Member Elritha GBAtemp Addict

    Joined:
    Jan 24, 2006
    Messages:
    2,037
    Country:
    Canada
    You'll probably need to remove the infection manually. Combofix and HijackThis should be run to find out more, they should create a log file each. I'd advise going to a forum that specialises in virus removal with both logs from those programs. Combofixer requires you to disable your antivirus temporarily to run also.
     
  15. raulpica

    Supervisor raulpica With your drill, thrust to the sky!

    Joined:
    Oct 23, 2007
    Messages:
    10,663
    Location:
    _____________ PowerLevel: 9001
    Country:
    Italy
    Why bump a thread from the 26th JUNE 2009?
     
  16. .Chris

    Member .Chris Pffft.

    Joined:
    Feb 20, 2009
    Messages:
    2,182
    Location:
    United States
    Country:
    United States
  17. Elritha

    Member Elritha GBAtemp Addict

    Joined:
    Jan 24, 2006
    Messages:
    2,037
    Country:
    Canada
    I didn't even notice the date... lol. [​IMG]
     
  18. funem

    Member funem Retro Powered..

    Joined:
    Nov 4, 2006
    Messages:
    1,160
    Location:
    out of nowhere....
    Country:
    United Kingdom
    Same....... [​IMG] just saw a reply and thought it was under discussion......
     
  19. .Chris

    Member .Chris Pffft.

    Joined:
    Feb 20, 2009
    Messages:
    2,182
    Location:
    United States
    Country:
    United States
    WHOA. its from June 26 2009?? Same here funem...
     
  20. jalaneme

    Member jalaneme Female Gamer

    Joined:
    Nov 27, 2006
    Messages:
    6,247
    Location:
    London
    Country:
    United Kingdom
    kaspersky, end of problem!
     

Share This Page