Cannot Delete Virus Files In System Folders


  1. Posts : 2
    Windows 7 64-bit
       #1

    Cannot Delete Virus Files In System Folders


    My Windows 7 64-bit computer has become infected with the ConHost virus. There are dozens of copies of the executable in the Windows/winsxs folder. I start up in Safe Mode, launch Windows Explorer, Run As Administrator, navigate to the files and, you guessed it, Microsoft is too busy protecting my viruses to let me delete them. Sometimes it says I need Trusted Installer permission, sometimes System permission. If the person at Microsoft who came up with that idea was here with me it wouldn't be pretty. Can someone tell me how I can take control of the computer that I paid for? And maybe someone should tell Mr. Microsoft that this is making me want to find a computer running a different OS (not affiliated with Microsoft).
      My Computer


  2. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #2

    ConHost virus is a Trojan disguised to look like it's a MS protector file ... it of course is not from MS.

    In the registry it will look something like this:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Conhost.exe " = "%AppData%\<random>.exe"
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Conhost.exe " = "%AppData%\<random>.exe"

    %AppData%\<random>.exe
    %CommonAppData%\<random>.exe
    C:\Windows\Temp\<random>.exe
    %temp%\<random>.exe

    C:\Program Files\<random>

    Let's see if we can detect it running in the background. Download DDS from one of these links:
    DDS.com
    DDS.pif
    • Disable any script blocking protection
    • Double click the dds icon to run the tool.
    • When done, DDS will open two (2) logs:
      1. DDS.txt
      2. Attach.txt <--- will be minimized in the task tray
    • Save both reports to your desktop.

    Include the contents of both logs in your next post.
      My Computer


  3. Posts : 2
    Windows 7 64-bit
    Thread Starter
       #3

    Jacee

    I appreciate the suggestion, but I've never heard of DDS and I am cautious about downloading files I don't know about. Can you tell me the complete name of this program or provide a link to it's creator's website? My other option is I can re-install my OS and restore my work files. Fortunately I've saved them all off the computer.

    Thanks

    Steve
      My Computer


  4. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #4

    DDS by sUBs, "doesn't do squat". It just shows me what's running. :)
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:38.
Find Us