Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Spyware / AdWare » Virus In Pc Cant Delete It!!!

Spyware / AdWare - Virus In Pc Cant Delete It!!! posted in the Security & Safety forums; It is a week that my BitDefender antivirus keeps on occasionaly (usually when i am not working with the pc but its left on) pops up a screen saying virus ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-08-2006
Ali2005's Avatar
Silver Member
 
Join Date: Aug 2005
Posts: 134
Ali2005 - See this Members User comments on their Profile page
Default Virus In Pc Cant Delete It!!!

It is a week that my BitDefender antivirus keeps on occasionaly (usually when i am not working with the pc but its left on) pops up a screen saying virus alert found in c>program files>red storm entertainment> ravenshield>r-r6rstr.exe which I remember was a cheat .exe for raven shield game (which i uninstalled long time ago) that anabled you to have all weapons and guns in the game. it says suspect with: BehavesLike:Win32.RemoteInjector

and virus blocked and pc not infected but it is anoying to see pop up screen every now and then and to know there is something harmful in your pc.

how do I remove this??? I tried unlocker, CClean, nothing worked.


  #2  
Old 02-08-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Give it a go with killbox:

download KillBox by Option^Explicit from HERE.

Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\Program Files\red storm entertainment\ravenshield\r-r6rstr.exe

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)


And if it doesn't work then post a hijackthis log to see if showes there.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 02-09-2006
Ali2005's Avatar
Silver Member
 
Join Date: Aug 2005
Posts: 134
Ali2005 - See this Members User comments on their Profile page
Default

killbox didnt work...didnt reboot by itself (a error came saying pending file rename operations data has been removed by external process! so rebooted manually and file was still there so i posted a hijackthis log:
Attached Files
File Type: txt hjt.txt (6.1 KB, 1 views)



Last edited by joe5; 02-09-2006 at 06:22 PM.
  #4  
Old 02-09-2006
zugolg's Avatar
Silver Member
 
Join Date: Sep 2005
Posts: 119
zugolg - See this Members User comments on their Profile page
Send a message via AIM to zugolg
Default

would running Anti-Virus software/ cclean in safemode delete the virus?


  #5  
Old 02-09-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

It doesn't seem to running , or showing up in an hjt log.

But these can be fixed:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing




This one resets OEM installation settings at bootup. Not required unless youre new to PCs:

O4 - HKLM\..\Run: [OemReset] %systemroot%\OPTIONS\OEMRESET.EXE /AUDIT
Where did you get that file from? And indeed have you also tried to delete it in safemode?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 03:16 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top