RPC Virus Virus

Page 1 of 3 123 LastLast

  1. Posts : 22
    Windows 7 Ultimate x32
       #1

    PC Tools Firewall Plus--Help!


    In my pc's device manager under "network Adapters" i see "PC Tools Driver #6"...ok I remember I installed PC Tools Firewall Plus months ago..and It might have been installed then....it also has a tiny yellow exclamation mark over...useless stuff...so i decide to uninstall it..
    So, I click uninstall and the device manager page refreshes but OMG! it's still there
    I tried many times but that ugly thing is still there...
    Can anyone help?
      My Computer


  2. Posts : 22
    Windows 7 Ultimate x32
    Thread Starter
       #2

    RPC Virus Virus


    The action center keeps on saying "Remove the RPC Virus Virus"..
    Anyone knows how to remove it??
    I'm using MSE and Malwarebytes Anti Malware and both found nothing!
      My Computer


  3. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #3

    The RPC Virus (aka Remote Procedure Call Virus) is also known as MSBlast or the Blaster Virus, is a malicious worm that spreads by infecting vulnerable computers. If your computer has been infected, you may experience frequent system crashes or be completely unable to access any website. Remove the virus using an updated spyware removal tool immediately.
    What is RPC Virus – Fake Alert?

    RPC Virus is a fake alert message coming from a rogue security program that will mislead its victim from buying the licensed version of the software. The fake alert messages will be shown as:
    Remove the RPC Virus virus
    Windows has detected RPC Virus, a known computer virus on your computer. RPC Virus has caused your computer to stop working properly.
    Remove the RPC Virus virus from your computer
    This problem was caused by RPC Virus, a known computer virus.
    To prevent this problem from occurring again, install and run an up-to-date antivirus and antispyware program on your computer.
    RPC Virus or MSBlast Removal Instructions

    Suggest you run these tools, do a full system scan after following the removal instructions. If you cannot do this in regular mode, then run in safe mode:

    http://www.microsoft.com/security/pc...e-removal.aspx

    http://security.symantec.com/nbrt/npe.asp?lcid=1033
      My Computer


  4. Posts : 22
    Windows 7 Ultimate x32
    Thread Starter
       #4

    Actually neither the process nor the registry key was found in my PC...any gusses??
      My Computer


  5. Posts : 382
    Windows 7 Ultimate 64 bit
       #5

    Malwarebytes' Anti-Malware should pick that baddie up. Try updating MBAM then do a Full Scan. Post the resulting log here, please.
      My Computer


  6. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #6

    akshaybz said:
    Actually neither the process nor the registry key was found in my PC...any gusses??
    After you do the full malwarebytes scan as suggested by Carolyn, if nothing shows, run the Malicious software removal tool and then the Norton Power Eraser (full system scan)

    These RPC Virus files can be in the form of EXE, DLL, LSP, TOOLBAR, BROWSER HIJACK, and/or BROWSER PLUGIN. For example, RPC Virus might create a file like
    %PROGRAM_FILES%\RPC Virus\RPC Virus.exe. Locate and remove these files.
    You may wish to consider running the Malwarebytes & Malicious software removal tool while disconnected from the net.

    The Power Eraser will need a net connection to function properly
      My Computer


  7. Posts : 22
    Windows 7 Ultimate x32
    Thread Starter
       #7

    MBAM cleaned this:
    Code:
    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\TJHTHX1O7X (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    Also here is screenshot of my task manager which are suspicious:
      My Computer


  8. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #8

    Good, glad it's apparently sorted.

    Now it's a good idea to run a full system scan with MSE, Malwarebytes and the Malicious Software tool just to be sure it's out of the system & there are no leftovers. Run these scans disconnected from the net so that it can't "call for help".

    That's just to be sure it's gone, I know this can take a little bit, but why take chances on it coming back?
      My Computer


  9. Posts : 382
    Windows 7 Ultimate 64 bit
       #9

    Those are legit processes in the screenshot

    for example, see HERE
      My Computer


  10. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #10

    Yeah, don't delete anything that "looks suspicious", let the scanners decided that. If you remove the wrong thing, you could end up crippling your PC.

    After Mbam cleaned the file out, did the warnings disappear?
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:58.
Find Us