Web Hosting Talk







View Full Version : Virus detected, but unable to clean...


Rebel
12-01-2003, 11:29 PM
I use AVG free edition because well...I'm cheap, and I feel it does a pretty decent job with basic virus prevention. However just recently I started to get these popup virus detection messages from AVG which asked me to run the virus scan to remove it.

http://www.clangrounds.com/virus.jpg

I've run the full scan several times, and even went to TrendMicro's online scan for a second source to see if there was a difference which there is not. I also used SpyBot to remove some spyware, but it wasn't anything from the usual net browsing ad cookie trackers.

Yet with all this checking I am still getting these popup virus detection messages. All of the programs I used above are up to date. If you're a fellow tech that can help me with this situation with some advice I would greatly appreciate it. Thank you. :)

John[H4Y]
12-02-2003, 12:04 AM
The reason it can't "clean" it is because it is resident in memory, which means you are fully infected, and it is probably spreading. You can try hitting control+alt+delete and killing the running processes that are obviously the virus, then deleting the files themsevles manually, but it probably won't do much good since the virus can easily have attached itself to any executeable file, including Windows system files. Plus, you will probably have to edit the registry to remove any references to the virus starting when Windows starts, plus who knows what else.
OR, you can search google for the virus and you will no doubt find instructions on how to remove the virus easily.

Rebel
12-02-2003, 12:14 AM
Sounds like fun...

Well after checking the AVG test results log I discovered a virus was detected at 1am this morning when the scan ran automatically, and showed as 11 files being infected. However it said it cleaned them all. The worm was called wlogf.exe if that rings any bells... How do I tell which processes to kill, and which not to kill? Trial and error? :/

Chicken
12-02-2003, 12:55 AM
I found a couple mentions on the web about it, pertaining to running an exe in Kazaa (were you doing anything recently with/in Kazaa?)

Incognito
12-02-2003, 01:00 AM
For some of these, McAffee and other Anti-Virus people have developed some specific removal software. Example: http://us.mcafee.com/virusInfo/default.asp?id=vrt

bear
12-02-2003, 10:00 AM
The path it seems to be finding that virus is is the system restore folder. It's protected there, and your AV can't have access to remove it. I believe you need to disable system restore temporarily and reboot. You can then re-enable restore.

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039