Link to home
Start Free TrialLog in
Avatar of rhender9
rhender9

asked on

Malware virus lich.sys removal

Does anyone know how I can manually remove the lich.sys malware from Windows XP PC?  I have Symantec Antivirus loaded, and it finds the virus, but doesn't remove it.
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Does Symantec gives you the location of the virus? e.g., C:\lich.sys

Use MalwareBytes or even better Combofix and show us the Combofix log.
Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
I'd say use Combofix as the driver/service is already in its database.
ZZZdrv_lich
ZZZsvc_lich
ASKER CERTIFIED SOLUTION
Avatar of JeremySBrown
JeremySBrown
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial