• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

need help with virus *urgentish*

BennyD

Banned
a few days ago i noticed a process called "beta.exe", this process was running and trying to access the internet.

i thought i'd end it and brought up task manager, then it just closed itself

i tried a few times but it would close every time, i think that this beta.exe was killing the task manager process

then i did "taskkill /f /im beta.exe" from a command prompt, that got it.

next i try and get it with a AV app but it can't find any, even with the latest definitions.

next thing i look in my startup and find 2 entries of this program, i remove these and think that i have got it, just to be safe i rename the beta.exe and restart

upon restarting i am greeted by the message "windows cannot find beta.exe" but there is nothing in the startup, or the registry that is starting it.

does anyone know how this could be trying to run? it's really starting to bug me now.

any help appreciated
 
heh, no really, i'm wondering what else could be launching this thing.

startup sentry couldn't find anything, nor could regcleaner
 
Did you check and see in msconfig.exe whether there are any entries in system.ini or win.ini or even services?
 
u should see the the retail-boxed version of this virus, its sometimes labeled as WinXP or something and made by a shady company named microsoft
 
Try running a scan on your system after you boot into safe mode. Sometimes that will correct the problem.
 
Start -> Run -> msconfig
See if it's in there, anywhere. If so, delete it but be careful what you delete.
 
You may want to check your Services. A virus can be started from there. Check for unusual service entry. I have seen a virus disguising itself as llS Web Service. Noticed the first two letters are lower case L's.
 
What sort of software are you running? Kazaa in the mix anywhere?

Which AV program(s) are you using?

Have you tried an anti-virus scan from safe-mode?
 
Originally posted by: Hossenfeffer
What sort of software are you running? Kazaa in the mix anywhere?

Which AV program(s) are you using?

Have you tried an anti-virus scan from safe-mode?

kazaa is in the mix, but i only download uninfectable files, i think it was installed with a piece of software

i'm using AVG 6

no, but i'll try that now
 
Back
Top