Randelissimo
Joined: 06 Sep 2006 |
Posts: 0 |
|
|
 |
Posted: Wed Sep 06, 2006 6:56 am |
|
 |
 |
 |
 |
It's been identified by ClamWin but not moved to quaranteen. When I browse to the stated location, I cannot see it, even with hidden files displayed on.
Scan started: Mon Sep 04 17:01:55 2006
File excluded 'C:\Documents and Settings\Administrator\Application Data\DOBE~1\svchost.exe'
C:\Documents and Settings\Administrator\Application Data\DOBE~1\svchost.exe: Trojan.PurityScan.BJ FOUND
-- summary --
Known viruses: 67591
Engine version: 0.88.4
Scanned directories: 456
Scanned files: 1195
Infected files: 1
Not moved: 1
Data scanned: 988.97 MB
Time: 339.016 sec (5 m 39 s)
- Any ideas please?
Thanks in advance.
Rand.
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Wed Sep 06, 2006 7:03 am |
|
 |
 |
 |
 |
go to start-run, then type cmd.exe and open the command prompt.
In the command prompt type:
cd C:\Documents and Settings\Administrator\Application Data\DOBE~1\
then DIR
it should list all files
|
|
Randelissimo
Joined: 06 Sep 2006 |
Posts: 0 |
|
|
 |
Posted: Wed Sep 06, 2006 8:10 am |
|
 |
 |
 |
 |
alch wrote: |
go to start-run, then type cmd.exe and open the command prompt.
In the command prompt type:
cd C:\Documents and Settings\Administrator\Application Data\DOBE~1\
then DIR
it should list all files |
Thank you, how then, would I go about deleting?
|
|
sherpya
Joined: 22 Mar 2006 |
Posts: 0 |
Location: Italy |
|
 |
Posted: Wed Sep 06, 2006 8:14 am |
|
 |
 |
 |
 |
the virus is in execution, windows prevents to remove the file, open task manager,
all processes named svchost.exe, winlogon.exe csrss.exe smss.exe lsass.exe and services.exe
that belongs to user and not system are always virus, you may need to use
process explorer from https://www.sysinternals.com/ https://www.sysinternals.com/ to kill them
since win task manager is dumb and it will refuse to kill process by looking at their name
I also suggest to try autoruns utility (same site), check "hide microsoft entries" in the options,
then do a scan, you will have a lot of stuff, most are ok, but some will looks as suspicious.
it also has a context menu to search google for each entry, so you can find more info about each entry.
Don't remove entries until you are sure that is a virus or something like
|
|