Forum Home
Press F1
 
Thread ID: 104764 2009-11-07 23:23:00 Please help with virus! jahar (15384) Press F1
Post ID Timestamp Content User
828050 2009-11-07 23:23:00 Hello!

I just recieved a pack generic 254 virus (so says my computer) and I can't seem to delete it or qurantine it. It will not let me shut down my computer or change me user on the computer from the start menu. I can turn it off by holding the power button but that does not fix the problem. Can someone please help me with how to get this off the computer.

Thanks a bunch!!!
jahar (15384)
828051 2009-11-07 23:28:00 Post a HJT log

www.trendsecure.com
whellington (15030)
828052 2009-11-07 23:28:00 Disable system restore. WHAT AV program are you using??

Boot into safe mode / networking then post a HJT log
Speedy Gonzales (78)
828053 2009-11-07 23:29:00 Sounds like some Windows files are infected too.

Try booting in safe mode(tap F8 on boot and select Safe Mode with networking) and see if it happens.

Then scan with MalwareBytes and then post a log here.

Blam
Blam (54)
828054 2009-11-08 05:04:00 You will need help with this one otherwise you will never shift it.

Remove these files:
\system32\0004436c.001
\system32\eflvon.dll

And these reg files:
HKEY_LOCAL_MACHINE\system\controlset003\services\s vchost\parameters\
servicedll = %systemroot%\system32\eflvon.dll

HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svchost\parameters\
servicedll = %systemroot%\system32\eflvon.dll

HKEY_LOCAL_MACHINE\system\controlset001\services\s vchost\parameters\
servicedll = %systemroot%\system32\eflvon.dll

If you dont know how to remove the reg entries I can set you a script to remove them.
Pancake (6359)
1