help me get rid of this virus!!!!!!!!!!!!!!!!!

Discussion in 'malware problems & news' started by cheater87, Jun 23, 2005.

Thread Status:
Not open for further replies.
  1. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    its called C:\WINDOWS\system32\blawin3.exe. mcafee can't quarintine it or delete it. please help me.
     
  2. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    Have you tried getting rid of it in safe mode?
     
  3. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    its not showing in safe mode aaahhhh this is horrible
     
  4. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    I just searched network associates knowledge base on malware and can not find your malware. you need to do an online scan and see if it might be a false positive. click on my signature (online scans and more) and you will find a list of online scans. I would try at least two of them, I would recomend one of them be trend micros house call online scan here
     
  5. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    will the free online scans work with mcafee or another anti virus software on the computer?
     
  6. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    it found it again and it still can't get rid of it.
     
  7. mzjazz2u

    mzjazz2u Registered Member

    Joined:
    Jun 23, 2005
    Posts:
    25
    Location:
    Somewhere over the rainbow
    I see an alert at Symantec's site for a backdoor trojan called bla. And if affects the system folder. Could it be that? What are they symptoms, or how does it affect your computer? Symantec says you get so many illegal operation errors that sometimes you can't even shut down the computer. It also says it will cause your computer to display the blue warning screen. Does this sound familiar?
     
  8. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    nope how do i delete it in safe mode? i know how to get safe mode not to delte files. and if it is a false positive what damage can happen if i delete it? oh and my virus files are up to date so i don't need to update it.
     
  9. Randy_Bell

    Randy_Bell Registered Member

    Joined:
    May 24, 2002
    Posts:
    3,004
    Location:
    Santa Clara, CA
    Assuming you can find the file in Safe Mode, you can move it to a removable disk [CD, Zip, floppy] so that you have backup in case it is a false positive. But if both McAfee and one of the online scanners are flagging the file, it is probably real malware [not false]. You can probably also manually add it to McAfee's Quarantine while in Safe Mode, if you want to do that. Files in Quarantine are encrypted and thus isolated from the rest of your filesystem. Good Luck .. ;)
     
  10. mzjazz2u

    mzjazz2u Registered Member

    Joined:
    Jun 23, 2005
    Posts:
    25
    Location:
    Somewhere over the rainbow
    I don't find any information on blawin3 on any of the major antivirus sites. What symptoms is it having on your system?Have you tried running adaware or Spybot SD? Sometimes those have picked up and cleaned files that my antivirus software couldn't. If McAfee can't clean it then it's probably in use and McAfee may be able to quarantine it in safe mode. Good luck. I just spent almost a week getting rid of a stubborn worm that kept hiding and coming back.
     
  11. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    spybot,adaware SE, microsoft anti spyware, spywaredoctor can't find it and mcafee can't find it in safe mode only in non safe mode. and it can't delete or quarintine its annoying
     
  12. mzjazz2u

    mzjazz2u Registered Member

    Joined:
    Jun 23, 2005
    Posts:
    25
    Location:
    Somewhere over the rainbow
    Well this may not work and it's a shot in the dark. But one of the things I finally did to get rid of the worm I had was I downloaded the trial copy of Panda Titanium antivirus, started to install it and uninstalled my Norton antivirus when prompted and ran Panda. Panda picked it up and cleaned most of it. Then it gave me enough information about the files left so that I could go into safe mode and remove them. Also had to use the "find" feature in the registry to make sure there was nothing there. One of the problems with yours is that I can't find any information on it to know what files it has dumped, if any, on your PC. Plus, we haven't heard what the symptoms have been for you. Also, Adaware had a bunch of updates in the last 12 hours so you may want to try updating that and running it again. AFter I updated adaware this morning, it picked up some lingering effects in my system restore. Maybe it won't work.... but maybe it will! Many of these tips, I had gotten from mod Jooske here and I just had to try everything suggested and in different combinations as well.
     
  13. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    this is the family laptop and i don't think they would like me to uninstall mcafee. so am i screwed now?
     
  14. ravin

    ravin Registered Member

    Joined:
    May 2, 2003
    Posts:
    241
    Location:
    South Carolina
    if you are sure you want to delete the file! go to diamondcs.com.au and download (dellater). remember where you save the download to as you will need to go to a command prompt and change directories to this location. then just type dellater (path):\(filename) and hit enter. exit from command window. then reboot machine it will be deleted before OS gets loaded. Note: there is a read me text file included with the download in case you get confused. Hope this helps. :-*
     
Loading...
Thread Status:
Not open for further replies.