Explorer closes due to virus

djlolly42

Honorable
Jul 31, 2013
33
0
10,540
1
I recently caught a trojan virus that has latched itself to the Google folder in Program Files (x86), i have tried deleting the folder, tried deleting it from cmd, tried in safe mode and none of these will delete it, when i try to delete it in normal windows 7, it just crashes windows explorer, in AVG in safemode, the folder which it is in is locked, and when i try to navigate that folder, it says it has been moved to another location and i cant open it. AVG is currently saying there are no threats so hopefully i have got rid of it, but just in case, can anybody give me help on how to manually delete it? i have removed the folder from appdata\local and have removed it from regedit, although i can still open chrome :/ it doesnt seem to be doing any damage, apart from not letting me delete the folder or remove chrome from the control panel. When i installed the file that caused it, it came up as adobe flash installer and automatically started installing stuff, i stopped it halfway through, i have removed adobe flash too in case that has anything to do with it. All help is appreciated
 

Dogsnake

Distinguished
If it is (was) a Trojan go to www.malwarebytes.org and download the free version. I would run a full system scan in safe mode and repeat after in normal mode. I would also go to system restore and delete all restore points. Many of these things infect the restore points as well and can reinsert themselves form the restore location. AVG is ok but misses about 20% from the comparisons I have read. You can install flash from the adobe site without danger. Check this out (http://www.softpedia.com/get/System/System-Miscellaneous/Unlocker.shtml. It will unlock the locked folder letting you delete it. It is probably locked because there is a service or other process open, being run from the folder. So the Trojan may still be active in some way. The unlocker will kill the process and let you delete the folder.
 

djlolly42

Honorable
Jul 31, 2013
33
0
10,540
1


Thank you so much, i know it was a trojan because they were called trojan generic/crypt/something else, If it comes back i shall try this and provide feedback, that is a big help, thank you
 

ASK THE COMMUNITY

TRENDING THREADS