SV650.org - SV650 & Gladius 650 Forum

SV650.org - SV650 & Gladius 650 Forum (http://forums.sv650.org/index.php)
-   Idle Banter (http://forums.sv650.org/forumdisplay.php?f=116)
-   -   I have a virus (http://forums.sv650.org/showthread.php?t=100003)

Stig 10-11-07 08:29 AM

I have a virus
 
My computer antivirus software has found one.

Virus Found!rnVirus name: Backdoor.NuclearrnFile: C:\WINDOWS\WINDOWS\scvhost.sysrnLocation: C:\WINDOWS\WINDOWSrnComputer: MAINPCrnUser: Simon HudsonrnAction taken: Clean failed : Quarantine failed :

I looked it up and found this.

Quote:

Backdoor.Nuclear is a back door Trojan that gives an attacker full control over the compromised computer. It is created and configured using a builder program.
It also said this about getting rid of it.

Quote:

  1. Disable System Restore (Windows Me/XP).
  2. Update the virus definitions.
  3. Run a full system scan and delete all the files detected.
  4. Delete any values added to the registry.

I've done this but I still can't delete that file when it is found in the scan.

Can anyone help?

What is this 'builder program'.

the_lone_wolf 10-11-07 08:45 AM

Re: I have a virus
 
have you started in safe mode and tried it then?

or try using unlocker to stop the process that's using the file and not allowing you to erase it:

http://ccollomb.free.fr/unlocker/

MeridiaNx 10-11-07 09:34 AM

Re: I have a virus
 
Now I can't quite remember how to do this, it's been a long while since I had to. But I know that you can make certain antivirus checks run on boot, before windows is loaded. In other words, it can catch the process before it manages to hide itself.

If I remember rightly there are often specific little tools that will do this for certain viruses. So if you google the one you have found you may find a pre-boot scanner to do it for you. Might be a program to be installed, I think I remember mine as being a small couple of files that I had to add to a boot floppy and run.

That's the general gist of it at least. Sorry I haven't been more specific, I'll head off and do some checking for you cos I know how annoying it is when it won't let you delete the virus!

MeridiaNx 10-11-07 09:43 AM

Re: I have a virus
 
Seems all references to the virus lead back to Symantec and their page for removal tips. So next stage would be to run a safe mode check to see if that will do it and then follow the full instructions on the registry if necessary.

Link here for expanded instructions if you haven't already got them.

Stig 10-11-07 10:00 AM

Re: I have a virus
 
Thank you guys. I have just come back from a safe mode start and my antivirus software managed to delete the file. :thumleft:


All times are GMT. The time now is 05:32 PM.

Powered by vBulletin® - Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.