Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless xbox
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Unknown Virus on system files (New)

Reply  
Thread Tools
Iva's Avatar
Iva Iva is offline
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2009
Experience: Student Technician
17-Nov-2009, 10:26 AM #1
Unknown Virus on system files
(Going to post/edit in burst so that i don't loose a load again)

I downloaded a file on friday that I suspect to have been a virus.

Since then my Explorer.exe file has been playing havok with the rest of my system.

It would crash and freeze my computer when I entered certain directories via Explorer, then show in TaskManager that there were two versons of the program

I used MG config to disable two startup items. one called b.exe and another that had no name.
I also disabled Rundll32.exe because its command line looked strange and i was told that it wasn't NEEDED.

that allowed me to enter the files but my computer continued to freeze at random times.

using Procexp (Process explorer) I found that the C:\WINDOWS\Explorer.exe was unable to be verified so i took the Explorer.exe from a computer that i knew was uninfected and put it into a read-only folder called SAFE.

With this explorer.exe running I went to delete C:\WINDOWS\Explorer.exe but after i did so, Winlogon.exe flared in CPU usage (at 13-15%).

I did the same for that file but it is still playing up so i have given up trying it on my own but don't want to download any more files without an expert telling me what to do.

Last edited by Iva; 17-Nov-2009 at 01:13 PM..
Iva's Avatar
Iva Iva is offline
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2009
Experience: Student Technician
19-Nov-2009, 06:20 AM #2
I would post a Hijackthis log but every time I Install it, it runs once and crashes.

After it crashes it stops working and i have to reinstall it to try something different
Iva's Avatar
Iva Iva is offline
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2009
Experience: Student Technician
20-Nov-2009, 07:16 AM #3
Also Found a file called Winver.exe

This file comes up as a WORM when searched in google but again, deleting it causes it to be replaced by the same file

Please can someone help, I use this laptop for all my work and this Virus is making it difficult
Iva's Avatar
Iva Iva is offline
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2009
Experience: Student Technician
23-Nov-2009, 08:03 AM #4
sorry for bumping but this has been going on for over a week and no one has replied so I am getting a little stressed trying to sort it.

If anyone knows anything then I would be most grateful.
Reply

Tags
unknown, virus, windows xp

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 09:54 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.