Solved

how to remove IDP.Program.D1B0A5C0 virus

Posted on 2014-11-12
6
505 Views
Last Modified: 2014-11-16
This looks to be a bad virus (IDP.Program.D1B0A5C0) on a W7 laptop.  I haven't been able to find any good "easy" way to remove it.  Most tools do not do a good job of completely removing it.  Any thoughts?
0
Comment
Question by:tonyadam
6 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40438682
format c:

The only safe way to end up with a stable fully functional computer system after a virus infection of this type is to format your drive and start again.
Removal of the actual infection is one thing but the correcting of the problems that they cause that are deep rooted in the OS, registry, corrupt data etc are another.
If this is a business computer then consider the cost in your time and your users time in spending days trying to A) Remove the virus and B) correct all the problems afterwards.
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 40438791
This one is a bear to remove.. Manual removal is the only way
follow this guide http://virusremovalguideline.blogspot.ca/2014/06/idpprogramd1b0a5c0-affection-what-is-it.html
0
 
LVL 70

Expert Comment

by:garycase
ID: 40440381
First, the BEST way to remove this is to simply revert your system to an image taken prior to infection.    But of course if you don't have an image, that's not an alternative.

Second, it CAN be removed automatically, but the only time I've done that, I did it by removing the drive from the infected system; attaching it to another system; and then running a full scan on the drive with Malwarebytes, which found the virus and wanted to "quarantine" the associated files -- I changed that to "delete"; then rebooted and ran another full scan against the drive to confirm it was clean ... then reinstalled it in the original system and all was well.

Doing it like this ensures that there are no active processes from the malware that are monitoring and interfering with removal efforts ... something that's often the case with very persistent "bad boys" :-)
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 37

Expert Comment

by:Neil Russell
ID: 40440692
The Wrong way to remove a virus is to mount it in another system.  The likes of MalwareBytes are spefically designed to and will function best when used as designed. In a full windows boot, not safe mode and not in as a slave disk.
0
 
LVL 70

Accepted Solution

by:
garycase earned 500 total points
ID: 40441614
Actually, Malwarebytes, MSE, Norton, McAfee, etc. work just fine scanning a slave disk -- it's no different than scanning a 2nd, 3rd, 4th, etc. disk in your system.    And it completely eliminates any possibility that the infection can inhibit the scanner, which is often the case when a system is infected.

There are MANY infections you can eliminate by scanning in a different system that will NOT be removed if you try to run the scanner in the infected system.
0
 

Author Closing Comment

by:tonyadam
ID: 40446334
I elected to remove the drive from the system, attach it to a clean system and run Malwarebytes and a virus program against the drive with the virus. Malwarebytes found 4 additional issues and those were removed.  I reinstalled the drive natively into the laptop, ran Malwarebytes again as well as AVG and all seems well.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now