Computing.Net > Forums > Windows XP > unfixable virus!!!!

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

unfixable virus!!!!

Reply to Message Icon

Name: yodadude1
Date: April 16, 2005 at 12:02:37 Pacific
OS: xp pro sp1
CPU/Ram: 2.2gz 256mb
Comment:

Ok. My Av (Updated wednesday) has found a trojan virus that cannot be healed, nor can it be deleted, and it can't be moved to the quarentine vault!. So how am I supposed to get rid of it, if a fully updated Av can't do it?



Sponsored Link
Ads by Google

Response Number 1
Name: salihsabri
Date: April 16, 2005 at 12:13:50 Pacific
Reply:

sometimes virus programs have a tough time deleting files that are "in use" by windows. Try booting into windows safe mode (press f8 after your computer posts, but before windows starts up) and delete the file from safe mode. It's possible that windows is accessing the folder or file in regular mode and that starting in safe mode might free it up for deletion.


0

Response Number 2
Name: yodadude1
Date: April 16, 2005 at 12:17:27 Pacific
Reply:

Ok. going to do it right now. will post results in about 5-10 mins.
Thank you :o)


0

Response Number 3
Name: cyanide42
Date: April 16, 2005 at 12:19:40 Pacific
Reply:

I agree with Salihsabri above ^^. Often times the AV software can't fix/delete/quarantine a file if Windows is concurrently trying to use it. Starting in Safe Mode forces Windows to release its hold on most file usages. Just continually tap F8 as your computer is starting, and you'll be given a Startup menu. Select the "Safe Mode." option (NOT the "Safe mode with Networking" and NOT the "Safe Mode with Cmd Prompt Only.")

Once your system has started up in Safe Mode, run the AV software again (Don't try to update your AV in Safe Mode, it won't work. Just run the AV scan.) Then see if your AV software can fix/delete/quarantine the file.


0

Response Number 4
Name: yodadude1
Date: April 16, 2005 at 12:52:55 Pacific
Reply:

Well, scanned the infected directory, and it came up all clear.

Restarted pc, and it's back!!
Also I'm garanteed a pop up from my a/v saying a virus has come through, even now i've been here 5 mins, and I've healed or deleted 4-5 trojans. There are no peer to peer progs on this pc, I am not downloading anything. The only connection on the net is this site... ( I know it isn't from this site, because any site from i/e does this).

I'm fed up now of scan after scan. I'm spending more time scanning than surfing now.
I'll give any suggestions a go, and I am in debt with your help guys, but I'm considering a format job.

It's been nearly a year without a total re-install, so I guess that ain't too bad.



0

Response Number 5
Name: OtheHill
Date: April 16, 2005 at 12:55:13 Pacific
Reply:

Download and run AdawareSE and Spybot Search & Destroy 1.3.


0

Related Posts

See More



Response Number 6
Name: yodadude1
Date: April 16, 2005 at 13:00:21 Pacific
Reply:

I have them OtheHill, installed, checked n everything. I also have spyware nuker, cwshredder, and spysubtract. I have too many anti this and anti that now, my pc is getting sluggish, and I've upgraded to 1/2 gig ram now too!

It sucks that to surf the net, that I have to have this amount of protection. It used to be fun going on the net, but it's fast becoming a constant fight to be safe nowadays.



0

Response Number 7
Name: per
Date: April 16, 2005 at 13:03:52 Pacific
Reply:

Did you turn off system restore before the scan? Don't forget to turn it back on.


0

Response Number 8
Name: yodadude1
Date: April 16, 2005 at 13:06:10 Pacific
Reply:

lol yeah. i did it as soon as the trouble started about a week n half ago. I daren't turn it on yet.


0

Response Number 9
Name: yodadude1
Date: April 16, 2005 at 13:15:06 Pacific
Reply:

Just for a laugh guys (and gals), My 8 yr old son saw the window pop up stating the virus was here, and it took me 2 days to convince him that a virus couldn't jump out the computer and get him LMAO!!!!!



0

Response Number 10
Name: S.T.A.R.
Date: April 16, 2005 at 13:22:13 Pacific
Reply:

yodadude1,

"trojan", "virus", or some of each? What's the name these nasties? In your first/initial question you said, "...trojan virus that cannot be healed, nor can it be deleted, and it can't be moved to the quarentine vault" What/where is this "infected directory"?

"Also I'm garanteed a pop up from my a/v saying a virus has come through, even now i've been here 5 mins, and I've healed or deleted 4-5 trojans."

Again, what is it saying, thanks. Also, which "a/v" are you using? It "come through", explain that one. What type of fire wall are you using?


0

Response Number 11
Name: yodadude1
Date: April 16, 2005 at 13:39:22 Pacific
Reply:

My a/v is AVG, and I'm using Tiny personal firewall. AVG says it's a "trojan dropper", they keep appearing in the temp folder of local docs and settings.

The one that won't go is a bitmap file in the windows directory called "zapotv.bmp" (which is also unseeable when i look).

the windows/system32 folder also keeps getting infected every 5 or ten mins.

AVG has a folder that quarentines the virus for me so I can fix it later if i want to.

Again, thanks for all this help.


0

Response Number 12
Name: yodadude1
Date: April 16, 2005 at 13:41:59 Pacific
Reply:

My a/v is AVG, and I'm using Tiny personal firewall. AVG says it's a "trojan dropper", they keep appearing in the temp folder of local docs and settings.

The one that won't go is a bitmap file in the windows directory called "zapotv.bmp" (which is also unseeable when i look).

the windows/system32 folder also keeps getting infected every 5 or ten mins.

AVG has a folder that quarentines the virus for me so I can fix it later if i want to.

I've just deleted another....... C:DOCUME~1\Shelly\LOCALS~1\Temp\INTLRECO.exe.

Again, thanks for all this help.



0

Response Number 13
Name: yodadude1
Date: April 16, 2005 at 14:14:26 Pacific
Reply:

the trend micro website has instructions on how to remove the virus, and is telling me all the regestry keys i must delete, but none of the keys are present in the regestry.

I have found that this particular virus brings pop ups to my screen, so I'm thinking of letting it get on with it.
It doesn't seem like it's going to do damage, and I'm tired of trying to lose it because it isn't making my surfing fun at all.
I don't think a re-install will stop it either, it'll just come back.

Oooh if only I could get my hands on these spotty gits who write this rubbish.


0

Response Number 14
Name: Tufenuf
Date: April 16, 2005 at 15:17:55 Pacific
Reply:

yodadude1, Is the link below of any help or is it the one you tried?

ADW_ABET.ACC Removal Instructions

Here's another link to check out.

DrTemp Removal

Tufenuf


0

Response Number 15
Name: S.T.A.R.
Date: April 16, 2005 at 15:32:51 Pacific
Reply:

yodadude1,

The one you tell about in the temp folder, is spyware/adware.

You say you have ad-aware & spybot s&d "installed". Just checking, are they updated. Also, any new/unsure things in Add/Remove Programs.

"the trend micro website has instructions on how to remove the virus"

And the name, that they/you/AVG give this virus is what ______? << Fill in the blank, please.

Have you tried, sorry if I missed it, an online scan for virus/trojan at any sites?


0

Response Number 16
Name: Derek
Date: April 16, 2005 at 19:06:11 Pacific
Reply:

I appreciate that you are well peeved off with scanners but you could try throwing this freebie Trojan finder/fixer at it:

A2FREE - JUST DOWN PAGE

Derek.W


0

Response Number 17
Name: yodadude1
Date: April 17, 2005 at 01:30:30 Pacific
Reply:

Tufenuf, yeah that's the 1 I tried. The reg keys they specify don't exist there, and the programs they say that install this virus, I did not install any of these programs "abetterinternet" is the name of the spyware.
S.T.A.R...INTLRECO.exe is the name of the virus itself, AVG says it's a Trojan dropper.
I'll give derek's link a go (got nothing else to lose).
Post after another scan...........(my poor H/D lol)



0

Response Number 18
Name: yodadude1
Date: April 17, 2005 at 07:21:53 Pacific
Reply:

A2 can't connect to their server to update.
Keeps telling me to check my connection (which is clearly all correct).
I'm giving up as a lost cause guys. Many thanks for all your help, but it looks like this virus is staying until I reformat, and I have spent a whole year getting my windows exactly the way I like it, so I need a while to jot everything down before I do it.
1 - 0 To the lowlifes grrrrrrr.

Thanks again people.


0

Response Number 19
Name: Tufenuf
Date: April 17, 2005 at 07:55:58 Pacific
Reply:

yodadude1, Before you go the reformat route you may want to try the Free on-line Panda Acive Scan. It's been said to be one of the best on-line scans and detects & removes many trojans. Here's the link.

Panda Active Scan

Tufenuf


0

Response Number 20
Name: yodadude1
Date: April 17, 2005 at 11:47:52 Pacific
Reply:

Will do tufenuf ta. I'll give it a last resort, then close this post as a virus wins. I've informed Trend micro of everything I tried, and all the programs I used, plus anything they might want to know.
I'll see if they get in touch.

I can't express enough the gratitude for the help I've recieved here. It's the reason I come here first.
The most professional help isn't the helplines, or companies that charge for their services... It's the fanatics who live and breathe their hobbies who know best. And they are right here on computing.net!

Yoda


0

Response Number 21
Name: Derek
Date: April 17, 2005 at 13:19:06 Pacific
Reply:

Sorry to hear that A2FREE wouldn't run because it is a good Trojan scanner. It runs on mine just fine, but that's computers for you I guess.

Derek.W


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: unfixable virus!!!!

Trojan Virus problems www.computing.net/answers/windows-xp/trojan-virus-problems/143804.html

virus perhaps keeping IE from loadi www.computing.net/answers/windows-xp/virus-perhaps-keeping-ie-from-loadi/91975.html

I may have a virus called Isass www.computing.net/answers/windows-xp/i-may-have-a-virus-called-isass/129166.html