calyssab
asked on
System.exe Trojan
Windows 7 x64 computer with symantec anti virus found a trojan in system.exe. I have tried removing it, restoring to an earlier date. I am having no luck getting rid of it! please help
ASKER
I find this scary, wouldnt the computer stop working all together without those?
You could try using SuperAntiSpyware (free).
Thats the trick - these are not actually system files, just similiar names. The files to delete are system.exe and explore.exe. Windows does not have a system.exe and the interface is explorer.exe. The virus tries to hide itself by using scary names.
You could also try restoring your system to a previous point using System Restore.
ASKER
I tried the system restore :( it did not work.
Did you try (system restore) from safe mode command prompt: rstrui.exe ?
ASKER
No, it wouldnt let me get to safe mode when i restarted.
Sorry (first for missing the fact that you already tried system restore). :-(
If SAS and the other suggested method does not solve the problem, although it's painful, you may consider a reinstall.
Before you do that however, you may try:
(1) MBAM
(2) TDSSKiller
(3) Combofix.
If SAS and the other suggested method does not solve the problem, although it's painful, you may consider a reinstall.
Before you do that however, you may try:
(1) MBAM
(2) TDSSKiller
(3) Combofix.
You really need to get into Safe mode to clear this out. Turn the computer off and then turn it back on and immediately when you see anything on the screen, start tapping the F8 key on your keyboard. Keep tapping and eventually you will be brought to the advanced options menu. Select Safe Mode with Networking and press enter. Once you get into Safe mode, you should be able to remove this Malwarebytes Anti-Malware.
ASKER CERTIFIED SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER
the other comments did not fix the problem, i spent time on google and found the solution
http://www.ehow.com/how_6762878_remove-system_exe-virus.html