Page 1 of 2 12 LastLast
Results 1 to 15 of 16

Thread: Need help removing a virus!!!

  1. #1

    Join Date
    Jan 2010
    Location
    St.Helens
    Posts
    259
    Thanks
    55
    Thanked 5 Times in 4 Posts
    Rep Power
    1

    Default Need help removing a virus!!!

    dfg.exe to be exact.

    MSSE removes it then asks to restart. After restart it comes back.

    It claims to be a "data recovery" thing. It isnt, MSSE says its a Trojan.

    How do i get rid?

    Its my Dad's PC and my sister has been on it and royally ****ed it up.

    Oh and its only on one user account. Which is strange. Il try deleting the account.

    Thanks
    flyboyovyick
    AMD Llano A8-3870k 3Ghz|Cooler Master Hyper 612s|ASUS F1A55-M LE Motherboard
    Kingston HyperX Blu 8GB 1600MHz DDR3|Seagate Barracuda 2TB 7200RPM HDD
    Radeon HD 6550D OC'd @ 800Mhz|Windows 8 Pro 64bit|NZXT M59
    Packard Bell Viseo 23" FullHD LCD|LOGITECH G15 \m/ and a MX518 mouse.

  2. #2
    Moderator Snakedoc's Avatar
    Join Date
    Jan 2010
    Location
    Omnipresent
    Posts
    14,772
    Thanks
    1,472
    Thanked 2,433 Times in 1,542 Posts
    Rep Power
    6

    Default

    Try Ccleaner, Mbam and Superantispyware. Then delete all restore points and reboot.

    Two months and no smoking. Zero Carbon monoxide.

  3. The Following 2 Users Say Thank You to Snakedoc For This Useful Post:


  4. #3
    Moderator Spaceboy's Avatar
    Join Date
    Aug 2010
    Location
    Leicester
    Posts
    14,763
    Thanks
    3,234
    Thanked 3,117 Times in 2,316 Posts
    Rep Power
    8

    Default

    What snake said
    malwarebytes is where I'd start
    Quote Originally Posted by nft99 View Post
    They dont let me in the shop
    If you open your mind too much, your brain will fall out
    ---------------------------------------------------------------
    Fractal R3, Core i5 3570k, z77x-d3h, 8gb exceleram, GTX460

  5. #4
    The Original Bammster Bammy's Avatar
    Join Date
    Nov 2007
    Location
    192.168.0.4
    Posts
    2,092
    Thanks
    520
    Thanked 659 Times in 418 Posts
    Rep Power
    2
    Last edited by Bammy; 4 years ago at around teatime.

  6. #5

    Join Date
    Jan 2010
    Location
    St.Helens
    Posts
    259
    Thanks
    55
    Thanked 5 Times in 4 Posts
    Rep Power
    1

    Default

    Deleted the user account.

    Just ran CCleaner,

    Running Malwarebytes now.

    Then il run superantispyware


    Thanks alot guys!
    flyboyovyick
    AMD Llano A8-3870k 3Ghz|Cooler Master Hyper 612s|ASUS F1A55-M LE Motherboard
    Kingston HyperX Blu 8GB 1600MHz DDR3|Seagate Barracuda 2TB 7200RPM HDD
    Radeon HD 6550D OC'd @ 800Mhz|Windows 8 Pro 64bit|NZXT M59
    Packard Bell Viseo 23" FullHD LCD|LOGITECH G15 \m/ and a MX518 mouse.

  7. #6
    Moderator Spaceboy's Avatar
    Join Date
    Aug 2010
    Location
    Leicester
    Posts
    14,763
    Thanks
    3,234
    Thanked 3,117 Times in 2,316 Posts
    Rep Power
    8

    Default

    As snake said, don't forget to delete the restore points, viruses hide there sometimes.
    Quote Originally Posted by nft99 View Post
    They dont let me in the shop
    If you open your mind too much, your brain will fall out
    ---------------------------------------------------------------
    Fractal R3, Core i5 3570k, z77x-d3h, 8gb exceleram, GTX460

  8. #7
    Fish Fingers
    Join Date
    Mar 2011
    Posts
    182
    Thanks
    76
    Thanked 32 Times in 23 Posts
    Rep Power
    1

    Default

    Malwarebytes!

  9. #8

    Join Date
    Jan 2010
    Location
    St.Helens
    Posts
    259
    Thanks
    55
    Thanked 5 Times in 4 Posts
    Rep Power
    1

    Default

    Ye ive just deleted the restore points.

    EDIT: Malwarebytes has just found something 10 minutes in!

    Thanks
    flyboyovyick
    AMD Llano A8-3870k 3Ghz|Cooler Master Hyper 612s|ASUS F1A55-M LE Motherboard
    Kingston HyperX Blu 8GB 1600MHz DDR3|Seagate Barracuda 2TB 7200RPM HDD
    Radeon HD 6550D OC'd @ 800Mhz|Windows 8 Pro 64bit|NZXT M59
    Packard Bell Viseo 23" FullHD LCD|LOGITECH G15 \m/ and a MX518 mouse.

  10. #9
    Moderator Snakedoc's Avatar
    Join Date
    Jan 2010
    Location
    Omnipresent
    Posts
    14,772
    Thanks
    1,472
    Thanked 2,433 Times in 1,542 Posts
    Rep Power
    6

    Default

    When MBAM scan completes (It can take a couple of hours) make sure when removing infections, that all items are selected. MBAM tends not to select tracking cookies and such so right click on a infection and click "Select all".

    Two months and no smoking. Zero Carbon monoxide.

  11. #10

    Join Date
    Jan 2010
    Location
    St.Helens
    Posts
    259
    Thanks
    55
    Thanked 5 Times in 4 Posts
    Rep Power
    1

    Default

    Haha!

    The one result with Malwarebytes was RemoveWAT!

    All clean otherwise. Which is good i suppose...
    flyboyovyick
    AMD Llano A8-3870k 3Ghz|Cooler Master Hyper 612s|ASUS F1A55-M LE Motherboard
    Kingston HyperX Blu 8GB 1600MHz DDR3|Seagate Barracuda 2TB 7200RPM HDD
    Radeon HD 6550D OC'd @ 800Mhz|Windows 8 Pro 64bit|NZXT M59
    Packard Bell Viseo 23" FullHD LCD|LOGITECH G15 \m/ and a MX518 mouse.

  12. #11
    Moderator Snakedoc's Avatar
    Join Date
    Jan 2010
    Location
    Omnipresent
    Posts
    14,772
    Thanks
    1,472
    Thanked 2,433 Times in 1,542 Posts
    Rep Power
    6

    Default

    Oh dear, I hope your Windows is genuine.

    Two months and no smoking. Zero Carbon monoxide.

  13. #12

    Join Date
    Oct 2011
    Location
    Manchester
    Posts
    32
    Thanks
    1
    Thanked 0 Times in 0 Posts
    Rep Power
    1

    Default

    I would format the Drive...

  14. #13
    I Oc'd my beard in 2012 © Tainted's Avatar
    Join Date
    Dec 2009
    Location
    Belfast
    Posts
    2,793
    Thanks
    593
    Thanked 555 Times in 324 Posts
    Rep Power
    2

    Default

    Quote Originally Posted by flyboyovyick View Post
    Haha!

    The one result with Malwarebytes was RemoveWAT!

    All clean otherwise. Which is good i suppose...
    Naughty, naughty!

    Those who believe in telekinetics, raise my hand.

  15. #14

    Join Date
    Oct 2010
    Posts
    307
    Thanks
    4
    Thanked 38 Times in 31 Posts
    Rep Power
    1

    Default

    normally i would just use Spybot , but most antiviruses cant check you RESTORE folder so first thing i do is make sure system restore is disabled or any viruses you get rid of can be reinstalled (i think)

  16. #15
    ɹoʇɐɹǝpoɯ Aaron's Avatar
    Join Date
    May 2006
    Posts
    22,718
    Thanks
    492
    Thanked 1,897 Times in 1,300 Posts
    Rep Power
    14

    Default

    I think its more that it appears the user is potentially stealing the software and using a pirated/non registered version.

    Not a good idea to post that you have that file on your computer. And definitely not on the forum of a Microsoft Partner who may be obliged to report the IP to MS. But it is a great way of ringing the forum alarm bells and making sure you're watched very closely!


Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •