Antivirus Guide & User Reviews.

dashing.sujay

Moving
Staff member
No impression of virus, but many of the windows files are missing. That shows that the virus has done a substantial damage to your OS. Run this command- sfc /scannow
 

utkarsh73

Journeyman
Great to see you can conclude anything from that scrambled text. And what type of scan is this?(I have begun the scan).
 

utkarsh73

Journeyman
No impression of virus, but many of the windows files are missing. That shows that the virus has done a substantial damage to your OS. Run this command- sfc /scannow
But what about those .exe and .pif files which I see only in winRAR or Linux MInt and not in windows explorer and Avast tries to delete it???
 

Neuron

Electronic.
But what about those .exe and .pif files which I see only in winRAR or Linux MInt and not in windows explorer and Avast tries to delete it???

Corrupted registry.Try this,create a new user account with admin privileges.Log into this new account.Now goto folder options and enable the display of hidden as well protected system files.
 

topgear

Super Moderator
Staff member
@ utkarsh73 - use avg,avast, avira or KS free bootable cd to scan your entire hdd - this will clean any virus you still might have ;-)
 

utkarsh73

Journeyman
^Do they still exist? :eek: And Avast not able to delete it?

Yes. As I said, only when I open it in winRAR, avast detects and deletes it.

@ utkarsh73 - use avg,avast, avira or KS free bootable cd to scan your entire hdd - this will clean any virus you still might have ;-)
Ok. Now I m going to boot with Kaspersky Rescue Disk 10 provided with this month's DVD. But do you think it will work because avast deletes those files and they return again after some time??
 

dashing.sujay

Moving
Staff member
Yes. As I said, only when I open it in winRAR, avast detects and deletes it.

Did you do full system scan? (I guess obviously yes). But as you mentioned that the virus is returning even after deletion by Avast, seems like you gotta try another AV.

Ok. Now I m going to boot with Kaspersky Rescue Disk 10 provided with this month's DVD. But do you think it will work because avast deletes those files and they return again after some time??

I had already suggested you Kaspersky rescue disk in your last thread. Go ahead.
 

utkarsh73

Journeyman
Kaspersky Rescue Disk took its own time and scanned the entire hard disk in a little over 3 hours. Removed and disinfected a lot of infections. Lets hope it solves the problem.

Did you do full system scan? (I guess obviously yes). But as you mentioned that the virus is returning even after deletion by Avast, seems like you gotta try another AV.
Other AVs don't even detect those files, forget about deleting them. I tried Quickheal, Norton, AVG, kaspersky.
 

Neuron

Electronic.
Corrupted registry.Try this,create a new user account with admin privileges.Log into this new account.Now goto folder options and enable the display of hidden as well protected system files.

@utkarsh:So,did you try this?It doesn't seem like there is a virus in your system.
 

topgear

Super Moderator
Staff member
Kaspersky Rescue Disk took its own time and scanned the entire hard disk in a little over 3 hours. Removed and disinfected a lot of infections. Lets hope it solves the problem.

So at last KS rescue Dics has cleaned your system pretty well - now if the OS boots fine repair the OS using sfc /scannow like dashing.sujay has suggested or lese re-install the OS ( using repair method ) - so that any infected OS file that was deleted by the AV can function properly - re-install HW drives or any other apps if you need to.


Other AVs don't even detect those files, forget about deleting them. I tried Quickheal, Norton, AVG, kaspersky.

if your OS and lots of others files are infected with some virus then Av apps just can't clean them from within windows OS ( this includes safe mode/ command lie only etc. ) - only way is to boot from a latest AV rescue CD and scan the whole HDD - after this just install any good AV product you like and update it regularly - I've used Avira Rescue disc like this before and learned this lesson ;-)
 

utkarsh73

Journeyman
Guys, problem is still there........:-(
This time I have taken some snapshots but how to paste a picture in the middle of post and not as thumbnail??
 

dashing.sujay

Moving
Staff member
Post them by using
 

utkarsh73

Journeyman
this is task manager along with the error window. click on any option and message appears again and this time you have click 3 times to make the message disappear.
*img16.imageshack.us/img16/4517/taskmanager1.jpg
*img196.imageshack.us/img196/6669/taskmanager3.jpg
*img849.imageshack.us/img849/2391/taskmanager2i.jpg
*img140.imageshack.us/img140/7505/avastreport.jpg
*img864.imageshack.us/img864/5738/taskmanagert.jpg
 

dashing.sujay

Moving
Staff member
I have a feeling IDMAN is the culprit.

Try a online AV scan- HouseCall - Free Online Virus Scan - Trend Micro USA

Not at all.

@Utkarsh - Its happening because the virus has linked itself with the respective .exe's (IDman, IeMonitor,etc). Now, when you turn your PC, infected .exe's are ought to start, but as they're launched, Avast's real time protection traps the virus (attached along with .exe's) and quarrantines it. But windows has to start the ".exe" which was sheduled in startup. But since the process has been suspended by Avast, windows is giving this error. IDK how your system is still infected with viruses after boot scan. My personal suggestion - give a last try by using ESET smart security. I'm using it now from 2 years, not a single virus infection.
 

coderunknown

Retired Forum Mod
if you are using an illegal version of IDM, remove it. instead try DAP. even though it displays some banner, its the next best choice for you.

also do a boot time scan using avast. and also try avira A/V without the shields (deselect during installation). Avira have lot better detection rate than Avast when it comes to cleaning these trojan horses & spywares. i personally use this trick once every few month.
 

MyGeekTips

script-kiddie geek
My favorite virus here sality. :mrgreen:

I've been infected by this virus 3 times in last few years but never able been to disinfect it. I had KAV in 2007 it failed to disinfect it :-x then in 2009 I had norton it wasn't able to disinfect it. :-x & in 2011 I was infected with it to remove this virus I ran Quickheal Boot Scan 3 times still it wasn't able to disinfect it. :shock:

This virus is a polymorphic file infector. It keeps on injecting it codes in every executable file in the pc. It keeps on continuing the never ending process. :p
As it is a polymorphic virus it re-generates everytime it is deleted. :-x :-x

I would only advise doing a reinstall of windows in this situation. If you still wishes to give a last try to clean it try using these:

1. Download Win32/Sality Remover 1.2.0.616 Free - A useful tool for deleting the Win32/Sality virus from your computer - Softpedia

2. How to disinfect my computer from Virus.Win32.Sality?

Another way to disinfect is to remove the payload code in last line of every infected file. :p

I may analyze your system if you provide these logs:

1. HJT Log

2. MBAM Log

3. OTL Log

4. GMER Log
 
Top Bottom