Solved

how to remove virus permantely without formating system

Posted on 2009-05-10
10
589 Views
Last Modified: 2013-11-22
Dear Expert,

I have a single desktop pc which has been effected by virus on c:\windows\system32 folder the name of the virus is svcghost.exe. I have installed original antivirus that is sophos anti virus but it cant remove that virus when it quatrains.  I dont want to format that system because i have some important software which i cant collect anywhere. So please suggest me some solution on it.

Ajit

0
Comment
Question by:AJITPADHY
  • 3
  • 3
  • 3
  • +1
10 Comments
 
LVL 8

Expert Comment

by:skywalker39
ID: 24348777
Hi AJITPADHY,

A couple of things to try, try scanning and removing again in Safe Mode. Another method you can try is taking out the hard drive and placing it into another computer as slave and scanning it that way, if you do take your hard drive out and place it into another computer, your best bet would be to backup and important data you want to save.
0
 

Author Comment

by:AJITPADHY
ID: 24348849
hi skywalker,

i have already removed through safe mode but it shows an error message file cant be access  it is in write protected mode. i rename and try to delete  but same result. I want to delete it permantely without formatting system.

Ajit

0
 
LVL 8

Expert Comment

by:skywalker39
ID: 24348861
Have you tried using Unlocker? Here's the link: http://ccollomb.free.fr/unlocker/
0
 

Author Comment

by:AJITPADHY
ID: 24348895
hi skywalker,

ok. let me try first from this software and also observer the behavior of the system. is there any other way to remove this virus.

Ajit
0
 
LVL 8

Expert Comment

by:skywalker39
ID: 24348934
Unless you know where in your system, which directory these viruses are located, not really. The last resort would be to format. Some viruses are a pain to remove, most times when removing them from your system, the removal process takes out part of your registry as well.
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 23

Expert Comment

by:phototropic
ID: 24349793
I suggest you try running Combofix. Download and tutorial here:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Download to your desktop, disable your av and then run the program. Please post the scan log here using the "attach code snippet" check box below.

0
 
LVL 4

Expert Comment

by:althakar
ID: 24352621
0
 
LVL 4

Expert Comment

by:althakar
ID: 24352630
0
 
LVL 4

Accepted Solution

by:
althakar earned 500 total points
ID: 24352642
you can also have this software to remove

UnHackMe - easy removal Rootkits/Adware/Spyware.
http://www.unhackme.com

RegRun Security Suite - removal and protection. http://www.regrun.com

RegRun Reanimator - free removal tool. www.greatis.com/reanimator 
0
 

Author Comment

by:AJITPADHY
ID: 24726360
thanks
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows Defender Pop Up Message 8 47
Dropbox,Google Drive cloud system protection 2 73
remove chinese softwares 22 110
Av for Windows mobile 3 83
As more computers now shipped with 64-bit version of Windows, more users are now using this Operating System.  So it's important to be aware how some 32-bit diagnostic tool works on these systems, so we know what to expect when analyzing the logs an…
The purpose of this Article is to provide information for a newly released variant of malware – with the assumption that many EE Members will have need of the information. According to “Computerworld”, well over one million web sites have been co…
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now