help with a virus

August 7th, 2016

i have a running process – notepad 32 bit – that looks like a virus , of course i’m not running notepad .
when i checked the file location i found it in c:\programdata\324234.TMP
there is also an entry in the windows registry . problem is every time i try to delete the file it creates itself again , ending the process and it starts it self again , same for the registry .
norton , super anti spyware and windows defender couldn’t detect it as a virus , i also tried other scanning tools but none of them detected as a virus / maleware /……
how do i get rid of it ?

Answer #1
You could bring in the big guns and give Combofix a go..
http://www.bleepingcomputer.com/download/combofix/
Answer #2
reboot into safe mode and run ClamWin Portable
http://portableapps.com/apps/security/clamwin_portable
Answer #3
it creates itself again simply because there’s an entry either in the registry, or startup folder that runs when windows starts up!. you have to search those 2 areas for entries that should not be there. boot into safe mode when doing this.
Answer #4
will check all these options and get to you back .
thx in advance .
kasperskey did the job . thx for all .

 

| Sitemap |