Virus Found: Cant delete it.

Status
Not open for further replies.

Anindya

In the zone
I use Avast Antivirus with lastest updates. A virus with this name has been found -"INF:Autorun-F [Trj]" in c: and subsequently infected all the drives.

i have tried all the knows methods to remove it, but without any result.
1) Scanned drives, av deleted it. But again the virus came back.
2)Scheduled boot time scan, av deleted it. But again the virus came back.
3)Opened command prompt, deleted it from there. But again the virus came back.
4)Rebooted in Safe Mode but couldnt find the virus and it was found there also by the av.
5) Rebooted in Safe Mode with CMD but didnt get it as i have already deleted it. But it was present, as the av detected it.

The main problem is "Show hidden files" option is not getting activated, so that i can delete it.
Screenshot -

[URL=*img172.imageshack.us/my.php?image=virusoy2.jpg][IMG]*img172.imageshack.us/img172/9875/virusoy2.th.jpg[/URL][/IMG]

Now plz tell me what to do with it? Thanks
 

Batistabomb

Deadman Walking
schedule a bootscan for avast this is a small autorun worm, then you will identify yourselves all those malicious things, so you can delete them by handy simply by means of keys 1 to 9
 

anandk

Distinguished Member
Disable system Restore. Use Disk Cleaner to clear old Restore Points. Run CCleaner. Then try all above again.
 
OP
Anindya

Anindya

In the zone
Batistabomb said:
schedule a bootscan for avast this is a small autorun worm, then you will identify yourselves all those malicious things, so you can delete them by handy simply by means of keys 1 to 9

I think u missed that point no 3 in my post!:p

Thanks Anand will try as u suggested.
 
OP
Anindya

Anindya

In the zone
Thanks guys for replies. I use a dial-up connection so need to think twice before downloading.

@Anandk the process mentioned by u did not work.
I scheduled a boottime scan again and nothing was found there. But in desktop it started detecting again. This is really a strange problem.
Plz suggest me what to do next
 

arun77574

Broken In
I use KAV 6 and it detects the same Autorun.inf virus whenever i plug in my frnds pendrive., he does not have a net connection and thats a different story. "KAV6" will defeniately remove it 100%. Why KAV6?... Because its size is only 19.5mb, its very light and does not consume much of your system resources.

I can give you the same version which i'm using with key if you want.
its ver 6.0.1.411
 
Last edited:

johnjjx

Ambassador of Buzz
use dis
*en.sergiwa.com/modules/mydownloads/singlefile.php?cid=2&lid=1
only 70kb.:D
i hope dis will help it removes all restrictions tht virus removes:D ;)
like taskmanager, regedit, n ofcourse folderoptions.:p
 
Well I think its not the autorun.inf which is the main culprit...the file is being executed by an .exe file from inside the system32..do 1 thing,as I think it 2 be an avpo.exe..go into the cmd,then trace into sys32,type dir /a avpo*.*..if U find any file related 2 it then change its attribute & delete...the get into ur drive(in cmd)& del that autorun stuff..let me know if it works or not
 

src2206

In the zone
Download HijackThis version 1.9.1 (you should get it in Filehippo. Then let it scan your PC and save a log file. Post that log in forums dedicated to analyze HJT logs, like Techsupportforum.com, Safernetworkingforum or Majorgeeks. Deleting anything using HJT is not really the best of the ideas andthe online HJT log checker is also not conclusive.
 

praka123

left this forum longback
if u know the location where the virus while is kept,boot from a linux livecd and remove it!
 
OP
Anindya

Anindya

In the zone
Thanks for all ur help. The problem is solved. I got KAV from Arun and it could detect it after update.
 
Status
Not open for further replies.
Top Bottom