rhender9
asked on
Malware virus lich.sys removal
Does anyone know how I can manually remove the lich.sys malware from Windows XP PC? I have Symantec Antivirus loaded, and it finds the virus, but doesn't remove it.
I'd say use Combofix as the driver/service is already in its database.
ZZZdrv_lich
ZZZsvc_lich
ZZZdrv_lich
ZZZsvc_lich
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Use MalwareBytes or even better Combofix and show us the Combofix log.
Please download ComboFix by sUBs:
http://download.bleepingco
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix