Help removing virus located in winsxs folder

ROBO731

New member
Member
VIP
Local time
1:05 AM
Messages
223
Avast has informed me that I have a virus located primarily in my Winsxs folder. I would like to remove it. Here are the results of the scan. I tried to click repair, but as you can see it is telling me that access is denied. I haven't really noticed any differences in my system lately and I'm not sure when I accumulated this virus/viruses. Hopefully I can remove it. Let me know if you need any more information. Any help would be greatly appreciated.
 

Attachments

  • Avast Scan Results.png
    Avast Scan Results.png
    27.5 KB · Views: 81

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
Okay, I re-scanned and now it says no virus found, but I still feel that I should check this out a bit.
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
Way too tiny to see, but I could see "Rootkit" :(
My best advice would be to wipe and do a 'clean install'.

You can never be sure that your OS will be stable again without a thorough cleaning.

Please read about Rootkits and what they do: Rootkit - Wikipedia, the free encyclopedia
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Hmm, well it seems like it's a pretty serious threat to me. I haven't noticed it, but I guess I'm not supposed to. Before I go any further I have some questions. I re-scanned with Avast and it said that there was no threat found. Do you think it's actually gone? If I do decide to re-install the operating system (which I would like to avoid if possible) what will I be able to recover. I have a lot of customized settings and what not. What do you think these rootkits might be doing to my system? Can they infect files I put on flash drives or other removable media? I understand there is an alternative to putting n a clean operating system, how might I do that? I know it's a lot of questions, sorry and thanks for your help guys.
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
Please see post #3 and #4 and read the referenced material.

Your answers are there.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Thanks, I have read both pages and they do not answer all my questions, that is why I posted my questions.
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
You could try TDSSKiller, which might fix some of the problems.

However, rootkits are deep infections which can either write a hidden boot sector or compromise OS files. And, rootkits tend to introduce other viruses to the system. Some rootkits are able to circumvent AV scans. The Sirefef virus does this by presenting a ligitimate file to the AV scanner. When an AV scan is run, the legitimate file is presented to the scanner and it comes back as clean. In reality, once the legitimate file is run, the OS switches to the rouge driver and the rootkit is active and running. The Microsoft site recommends a clean reinstall for most variants of rootkits.

Being that your initial scan showed multiple infected files, the best/safest choice is a clean install.

Also, note that your AV scanner was denied access to these files, hence, no action was taken to remove them. Also, don't you find it strange that despite the detection of multiple infected files to which no access was allowed by the AV, they disappeared during the second scan? This is typical of the latest virus strains adaptive behavior.

Yes, viruses will jump to USB & removable media drives.

You could have been infected in multiple ways, a compromised website, a false update, keygens, etc.

Have a look at this tutorial on making a system image & once the machine is cleaned (Do NOT make one now), make & keep a couple of these around. Next time something like this happens, it can save you a lot of time.

http://www.sevenforums.com/tutorials/663-backup-complete-computer-create-image-backup.html
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Okay thanks, I did find it strange. I figured that it was probably still there. Anyway, is it safe to save/backup any of my files? I have some files that I would like to keep. Also, this is my laptop and I have moved countless files between this computer and my desktop. Do you think that the other computer might be infected as well?
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
even if you remove the virus, always leave behind damages in files and many other things, the best option is FORMAT!
 

My Computer My Computer

Computer Manufacturer/Model Number
custom build pc
OS
windows7 ultimate x64bit
CPU
intel core2 extreme Qx9650 Quad core 3.00GHZ
Motherboard
Asus rampege extreme lga775 socket
Memory
corsair 2x4GB 2000 mhz
Graphics Card(s)
inno 3d nvidia geforce 430 gt
Sound Card
supreme fx creative 7.1
Monitor(s) Displays
log 17 inches (primary) - sumsung tv (secontary)
Hard Drives
western digital velosiraptor 600 GB 10000 rpm
PSU
thermaltake toughpower 1200watt 80 plus gold
Case
core (limited edition)
Cooling
cooler master V8
Hmm, although I hate to do it I guess I'll have to. There's just one folder that I need. I'll move it to a flash drive. How should I go about checking that file for infections?
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
unistall your antivirus and istall MSE again if you have already! make to your system full scan!!
 

My Computer My Computer

Computer Manufacturer/Model Number
custom build pc
OS
windows7 ultimate x64bit
CPU
intel core2 extreme Qx9650 Quad core 3.00GHZ
Motherboard
Asus rampege extreme lga775 socket
Memory
corsair 2x4GB 2000 mhz
Graphics Card(s)
inno 3d nvidia geforce 430 gt
Sound Card
supreme fx creative 7.1
Monitor(s) Displays
log 17 inches (primary) - sumsung tv (secontary)
Hard Drives
western digital velosiraptor 600 GB 10000 rpm
PSU
thermaltake toughpower 1200watt 80 plus gold
Case
core (limited edition)
Cooling
cooler master V8
MSE?
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
the free anti virus Microsoft security essentials!
 

My Computer My Computer

Computer Manufacturer/Model Number
custom build pc
OS
windows7 ultimate x64bit
CPU
intel core2 extreme Qx9650 Quad core 3.00GHZ
Motherboard
Asus rampege extreme lga775 socket
Memory
corsair 2x4GB 2000 mhz
Graphics Card(s)
inno 3d nvidia geforce 430 gt
Sound Card
supreme fx creative 7.1
Monitor(s) Displays
log 17 inches (primary) - sumsung tv (secontary)
Hard Drives
western digital velosiraptor 600 GB 10000 rpm
PSU
thermaltake toughpower 1200watt 80 plus gold
Case
core (limited edition)
Cooling
cooler master V8
Oh okay I'll give it a try. Do you think that the virus may have infected my other computer since I have transferred files between them? Also Since I need this one folder, is it okay to take it with me to the other computer?
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
nobody can gives a sure answer, but if you see it also to start to react strange(get slow, many apps fail to open, changments to your backround programs) is very possible, many viruses they are in your pc and you dont even understand it, we can just hope to didnt infect
 

My Computer My Computer

Computer Manufacturer/Model Number
custom build pc
OS
windows7 ultimate x64bit
CPU
intel core2 extreme Qx9650 Quad core 3.00GHZ
Motherboard
Asus rampege extreme lga775 socket
Memory
corsair 2x4GB 2000 mhz
Graphics Card(s)
inno 3d nvidia geforce 430 gt
Sound Card
supreme fx creative 7.1
Monitor(s) Displays
log 17 inches (primary) - sumsung tv (secontary)
Hard Drives
western digital velosiraptor 600 GB 10000 rpm
PSU
thermaltake toughpower 1200watt 80 plus gold
Case
core (limited edition)
Cooling
cooler master V8
K, I will probably just end up formatting and putting on a new copy of windows. One thing that I really need to know is if it is safe to move one of my folders to another computer.
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
Any thing you save from the infected computer is most likely infected also. Any other computer that you were networked with is most likely infected also. You are not dealing with some little toy infection when you spank it it will go away. This is one bad ass rootket that has probably infected more places in your system that your anti virus scan found.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Okay thanks for the info, but still, no one has told e what it might be doing/trying to do to my system.
 

My Computer My Computer

OS
Windows 7 Home Premium x64
CPU
Intel i7-2600K
Motherboard
ASUS Sabertooth Z77
Memory
G.SKILL Ripjaws (16 GB Total)
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Monitor(s) Displays
ASUS
Screen Resolution
1920x1080 (2 Monitors)
Hard Drives
Hitachi GST Deskstar 2 TB (HDD)
Samsung 840 Pro 256 GB (SSD)
PSU
SeaSonic X Series X650 Gold
Case
Antec DF 85
Keyboard
Microsoft SideWinder X4
Mouse
MadCatz M.M.O. 7 & Logitech G35
Internet Speed
50 down
Antivirus
Avast Free, SuperAntiSpyware Free, Malwarebytes Free
Browser
Mozilla Firefox
Come on now lets get serious. Because no one knows except the people who created it and a few experts that work in the anti virus field. For sure it wasn't created to make your computing life better.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top