Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

I have a virus,and it won't die.

  • 26-04-2001 9:00am
    #1
    Registered Users, Registered Users 2 Posts: 3,446 ✭✭✭


    Lo all.I have the Hybris virus,which was responsible for alot of Tribes2 related problems plus other stuff.Ok,the virus reared its ugly head last night.
    The scans I ran didn't find anything,but soon as I tried to run T2 post-scan i got the warning box.The bad news is that McAfee can't clean or delete the files,which appear to be randomly created or something! Its a different file each time.but always in C:\WINDOWS\SYSTEM.
    I can't find the infected files manually or by using search either.The file names frankly look made up.When I try to delete the file when prompted by McAfee it says it cannot,and to check write protection on the infected file or something like that.Can't clean em either,or can't move them to diff folder.Anyone have ideas on how to sort this? Or should I just format? Would a reinstall of windows do the trick?
    Thx smile.gif


Comments

  • Registered Users, Registered Users 2 Posts: 17,165 ✭✭✭✭astrofool


    try to find out the names of the file you're dealing with that time, have a look through the windows config (type msconfig into run) andcheck nothing is running that shouldn't be, probably another file that's run to change the name or make a new one.

    Close down into DOS mode, get a boot disk from a CLEAN machine to do this, go to c:\windows\system (cd\windows\system is command), and type del "filename" without quotes, this will delete the file as long as it's name is right, try del c:\windows\system\"filename" also if first doesn't work, then try booting up, if the virus is still there, than another file must be present that's creating it.

    A reformat may be certain, just make sure none of your backed up files are infected, if in doubt DELETE.

    I use Norton here and it's been able to deal with most Virus's I've met.


  • Registered Users, Registered Users 2 Posts: 11,397 ✭✭✭✭azezil


    look for an antivirus update first!

    but if that fails u may hav to format!

    "just because ur not paraniod, doesn't mean they're not after u!"


  • Closed Accounts Posts: 589 ✭✭✭Magwitch


    If the virus is duplicating search for all files created since bootup. If you already know the files what are their extension?


  • Registered Users, Registered Users 2 Posts: 3,446 ✭✭✭bugler


    I think i have it sorted now lads,thx for replies.everything seems to be in order smile.gif


  • Registered Users, Registered Users 2 Posts: 1,004 ✭✭✭Lord Khan


    I take it that is the "snow white" hybird virus ... check security link posted there for a fix.

    although what you are descripting doesn't sound too much like the win32.hybris virus


  • Advertisement
  • Closed Accounts Posts: 9,314 ✭✭✭Talliesin


    Is this on Win2000?
    Win2000 has a feature that prevents you overwriting or deleting files in the system directories to prevent accidental damage that is often caused when someone deletes the wrong thing (hehe, I accidentally deleted shell32.dll from one of the machines here and had fun getting it back on).
    http://arstechnica.com/tweak/win2k/others/disable_sfp-1.html has details on both why you normally wouldn't want to disable this, and how to disable it if you do want to.
    May help.

    Have you looked at what's triggering the virus? checked the various "run" and "run once" keys in the registry?


Advertisement