Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.
Mebroot (uninstall.exe) isn't getting deleted
Name: MasterT Date: April 29, 2009 at 04:55:58 Pacific OS: Windows XP SP3 CPU/Ram: 2GB Subcategory: Viruses
Comment:
Norton found Trojan.Mebroot, on C:\Users\All Users\Start Menu\Programs\Startup\uninstall.exe
Every time I quick scan it finds it again, even after the scan is finished and the files are deleted, the files are re-created....
On hijackthis I saw , "O4 - Global Startup: uninstall.exe" I "fixed" it, but every time I re-scan its there again. I tried all on safe mode as well.
Name: james88 Date: April 29, 2009 at 20:46:59 Pacific
Reply:
Mebroot is updated now and it is considered the most stealthiest rootkit ever, its appearing as sinowal or even torpig or tropig. try this manual removal guide to remove mebroot http://darfuns.com/trojan-removal/m...
0
Response Number 3
Name: MasterT Date: April 30, 2009 at 00:16:55 Pacific
Reply:
I ran ESET - nothing found I already got Malwarebytes, I'll run and tell if anything found. EDIT: Nothing found
james88: I didn't found anything they said on the guide.. no notepad, nor on process explorer... only the C:\Users\All Users\Start Menu\Programs\Startup\uninstall.exe ... and sometimes blue screens for no reason..
0
Response Number 4
Name: hunter9x Date: May 1, 2009 at 01:38:03 Pacific
Reply:
i had this problem, except it didn't use unistall.exe, but managed to attach itself to a sys 32 file, it is difficult to remove
in the end i formatted 3 hard-drives at a loss of 750GB of data
so good luck
Computers make very fast, very accurate mistakes.
0
Response Number 5
Name: james88 Date: June 3, 2009 at 22:04:12 Pacific
Reply:
Man, you are already told to do manaul removal. i hope you can get rid of this virus by doing manual removal steps. Good Luck
Summary: I have the same problem too: - Norton messagge: Virus Alert: "Documets and Settings\All users\sysconf.exe" --> quarantine - Another one will produced after some times - Alert is produced only if I'm i...
Summary: It all began with the Trojan Downloader -2388 A.K.A JS_Wonka and Trojan.Downloader.JS.Small.dn. Iv'e tried to get rid of it but just can't, mainly because the only thing that traces it is ClamWin. I'v...
Summary: Hi, I'm infected with winupgro.exe and can't get rid of it. I delete the file from the application data/drivers folder, but it comes back every time I restart the computer. I've tried several tools ...