Simple effective way to delete most virii.
So i had a virus i removed it theres one left in the boot secter i think and i load the screen the warning pops up theres a virus and its logs off and i try to log on and it repetivly does the same thing over again. What do i do? Its Xp Pro and i cna only get passed logg on to this user account and this it kicks me off within 5 seconds
After having more than my share of trouble with viruses (virii?) that keep coming back after removal, I've found an effective two-step method that usually does the trick.
(Addendum: If Windows is crashing, try Safe Mode).
First, if you don't already have a copy, install "
HiJack This" (versions
prior to 2.0 work best for this), free software that shows you EVERYTHING that installs when you startup Windows.
Look for programs that you can't easily identify.. often with meaningless filenames like "sjxckw.dll" (I just made that up, so don't look for it). If this is one of those viruses that re-install themselves every time you delete them, then there is AT LEAST ONE MORE such program in there (usually only two) that goes with it. Don't bother using HiJack to delete them, because it will not be able to delete the one that is "currently running". These viruses are installed as "Processes" that load so early in the boot process, no Antivirus program can load soon enough to delete them. You can delete one, but the other will simply put the deleted file back.
Write down the names of these mystery programs (including path. Usually "C:\Windows\system32\") and
reboot using the XP Installation CD.
After the drivers load, the first menu includes "R for Recovery Console". This gives you a DOS-like cli where you can make some system level changes.
It should detect your Windows installation as "1) Windows". Select it and enter your Admin password when prompted.
Change to the folder where the suspect files reside (if you are unfamiliar with DOS, simply type "CD" (Change Directory) followed by the path to the suspect files (ex: cd \Windows\System32).
Make sure the files you wish to delete are there by doing a DIR ("directory"). The "*" (asterisk) is a wildcard:
ex: dir "sj*.*"
If the file is found, RENAME it with with the REN command (only delete it if once you are POSITIVE it is safe to do so):
ex: ren "sjxckw.dll" "sjxckw.dxx"
Type QUIT to exit the Recovery Console and reboot. If the virus is gone, you can safely go back into the folder from Windows and delete them.
This simple procedure works better than just about anything else. Great for getting rid of troublesome reappearing Adware as well.
Let us know what happens.