Author Topic: Unable to delete viruses after scan  (Read 3670 times)

0 Members and 1 Guest are viewing this topic.

Offline twhite8611

  • Newbie
  • *
  • Posts: 6
Unable to delete viruses after scan
« on: November 23, 2014, 04:05:12 PM »
ran internet scan last night.  went to delete findings this morning and found a number of viruses found but unable to delete them because the "apply" button is greyed out on screen of scan results.

I have avast internet security 2015 on laptop with windows 7.

thanks

this

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Unable to delete viruses after scan
« Reply #1 on: November 23, 2014, 04:08:20 PM »
Hello twhite8611 and welcome to avast! web forum.

Could you tell us the path of detections? Screenshot will do. I'll need to see the full path of detecion files (aka: c:\windows\system32\file.exe or simular)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Unable to delete viruses after scan
« Reply #2 on: November 23, 2014, 08:13:58 PM »
as magna86 say ..... what files was detected, and what is the location ...full file path
what malware name does avast give the detected files?

you may attach a screenshot of detection result......

i suspect this is what you see  https://blog.avast.com/2014/02/28/how-do-i-handle-files-that-avast-cant-scan/


« Last Edit: November 23, 2014, 09:58:25 PM by Pondus »

Offline twhite8611

  • Newbie
  • *
  • Posts: 6
Re: Unable to delete viruses after scan
« Reply #3 on: November 25, 2014, 07:00:40 PM »
Thanks for the prompt response.

I have apparently deleted the files according to the scan report.  I have attached the file.  Anyone that has a comment about these viruses I would be interested in hearing what you have to say.

I am having a difficult time getting rid of syswow\dilhost.exe which is taking over my computer and driving up the CPU usage to 100%.  Any comments and suggestions on how to rid this virus would be greatly appreciated.

Thanks again.

Tim

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Unable to delete viruses after scan
« Reply #4 on: November 25, 2014, 08:55:05 PM »
Quote
Anyone that has a comment about these viruses I would be interested in hearing what you have to say.
JS:ScriptPE-inf comes from infected website .....


see instructions   https://forum.avast.com/index.php?topic=53253.0
attach Malwarebytes and Farbar Recovery Scan Tool logs





Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Unable to delete viruses after scan
« Reply #5 on: November 25, 2014, 09:14:33 PM »
Judging by the your username, I'm guessing that's an admin account.

Any file running on that user Account has Admin permissions. Which is bad, and not limited to games, chrome and typical day apps. That includes "viruses" and "malware".

I suggest you move your documents and that all to a LIMITED user account, and use that account for your usage, authenticating any known files (Like setup files or update files for browsers/trusted programs). The rest, say no too.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Unable to delete viruses after scan
« Reply #6 on: November 26, 2014, 04:43:36 PM »
Hello twhite8611, I will be working on your Malware issues. 

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper

avast! shows the files presented in default $Temp folder. avast! should not have problem with removing them though these files were mostly harmless.

Quote
I am having a difficult time getting rid of syswow\dilhost.exe which is taking over my computer and driving up the CPU usage to 100%.  Any comments and suggestions on how to rid this virus would be greatly appreciated.

I shall require FRST/GMER logs for comprehensive analysist. Then I can target the malware using advanced scripts.

There is no need for moving documents.


---     ---     ---     ---     ---




Please download Farbar Recovery Scan Tool () by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
.




Please download GMER, the AntiRootKit tool from the link below and save it to your Desktop:

Gmer download link
Note: file will be random named

Double-clicking to run GMER.
  • Wait for initial scan to finish - if there is any query, click No;
  • Click [ Scan ] button and wait until the full scan is complete;
  • Click [ Save ... ] button - save the report to the Desktop (named ARK );
Please attach here Gmer's (ARK.txt) logreports.
« Last Edit: November 26, 2014, 04:46:26 PM by magna86 »

Offline twhite8611

  • Newbie
  • *
  • Posts: 6
Re: Unable to delete viruses after scan
« Reply #7 on: November 27, 2014, 03:21:04 AM »
Judging by the your username, I'm guessing that's an admin account.

Any file running on that user Account has Admin permissions. Which is bad, and not limited to games, chrome and typical day apps. That includes "viruses" and "malware".

I suggest you move your documents and that all to a LIMITED user account, and use that account for your usage, authenticating any known files (Like setup files or update files for browsers/trusted programs). The rest, say no too.

I dont understand everything you said but I am working on it. 

A couple of years ago I changed my login to my computer to login as administrator every time.  I would like to change it back to what it was but dont know how to do it.  If you could point me to a web page with directions I would appreciate it.  I googled but was unable to find directions.

Thanks.

Tim