Question:

What should i do to delete a file thats been affected by a virus but runs up everytime window starts,cant del

by  |  earlier

0 LIKES UnLike

Hay

Theres a file named Hberknal.sys in the c:/windows/system32/drivers folder which has been affected by some virus ( something like JS.Exploit etc. aint sure )

Only Nod32 is able to detect this virus but it cant delete it off or move to quarantine, it just shows the display msg and thats it.

SpywareTerminator can detect it and it asks to restart the pc and so it would delete the virus,but even that doesnt work [:s]

now please tell me a way to delete this virus off.

i've tried installing windows by deleting all my partitioned hard drives 3 times but that didnt remove it off either...

help me out please

 Tags:

   Report

6 ANSWERS


  1. Try disbaleing it from starting up. Go  to Start> Run and type in "msconfig".

    Go to the Startup Tab and uncheck the file.

    Now, reboot and open up Task Manager (CTRL+ALT+DEL) and make sure it isn't running in the processes tab. Try using NOD32 to delete it now.

    If that stil doesn't work, go to Start> Run> services.msc. Check if the file is under a service and if so, rightclick it and go to Properties. Under the drop down menu, choose Disable.

    Now reboot and try again.

    Hope that helps.

    PS, I do hope you are booting into Safe Mode (Press F8 when turning on the computer) and then running the scans....

    Good Luck.


  2. try a rootkit revealler such as

    http://www.sophos.com/products/free-tool...

    i used it to get rid  of files created by win antivirus 2008 that could not be deleted in safemode or via the prompt

    once i had run the rootkit revealler it stop the baddie program which then enabled my avast to delete the files in system32

    ^^^^^^^^^^^^^^^^edit

    you don't say if there were any rootkits??

    if you want to delete the file then boot using a dos floppy

    or download a live linux cd

    these run in ram and will not harm your O/S on the harddrive

    once you have mounted the hardrive you can navigate to the offensive file and delete it there.

    no malware can stop you doing this with a live cd, just make sure you don't delete anything else

    ^^^^^^^^^^^^^^^^^^^^^^^^^^^another edit

    I did hear about a virus that can hide from rootkit revealers but this is a concept rather than bieing in the wild

    can you be sure that it is not a false positive from the scanners that found it???

    have you tried another rootkit revealer such as the microsoft sysinternals one ( a great site for seeing what is going on in your pc)

    http://technet.microsoft.com/en-us/sysin...

    or blacklight from f-secure?

    when you say that you have deleted the partitions and reinstalled windows have you been disconnected from the internet and did you do a quick or full disk erase?

  3. Download Avast anti virus. Run the boot time scan. It will find it and delete it for good!

  4. ok, so we could think that your installation cds also effected. Try a clean xp installation cd. Format the system, install xp sp3 and then a good antivirus. but first, clean up the cds.

  5. TRY OUT OTHER ANTI VIRUS SERVICES FIRST .......BACK UP YOUR MOST IMPORTANT FILES.....BE WARNED, IT IS A SYSTEM FILE THE VIRUS HAS MESSED UP.........turn off system restore(turning it off removes every sytem restore point).........run all the anti virus you have.   After removal of all detected viruses, run a repair installation of your operating system.....You may also try out other anti-virus services.....AVG has version 8,  Avast has version 4.8, symantec has version 12......THATS A SYSTEM FILE THE VIRUS HAS MESSED UP, REMOVING IT COULD CAUSE ENORMOUS PROBLEMS.

  6. Sounds like a tough one. If you have several viruses on your computer I recomend that you re-install Windows. This is the best way of clearing virus, junk etc. By doing this you delete your partitions where the virus may be residing. have you tried AVG I think that it is pretty good, not sure if it will do the trick but I do recommend that you re-install Windows

Question Stats

Latest activity: earlier.
This question has 6 answers.

BECOME A GUIDE

Share your knowledge and help people by answering questions.