• Welcome Guest, to the Spybot Forums! It's 2025, and we just upgraded our forum software.

    Today is Safer Internet Day, and with our new forum, you can finally use passkeys to login. That was about time!

    Of course, you could ask if a forum is still useful, with so many social media networks out there where you might already have an account, and met a lot of users. You can now use your login from some of those networks to log in here. And by posting here, your question and data is stored on our servers and not automatically shared with a whole social media network.

    We'll also start using the forum for small bits of information, announcements and more again.

deleting infected files

ivenoidea

New member
I am a computer novice trying to help my grandson solve his computer problems. It seems he has a Trojan virus on his computer. I followed steps written on previous posting in the forum and found the virus by using Kaspersky web skanner. Here are the results.

C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\GZ7RE41T\xoce[1].ani Infected: Trojan-Downloader.Win32.Ani.c skipped

C:\Program Files\NewDotNet(2)\newdotnet4_80(2).dll Infected: not-a-virus:AdWare.Win32.NewDotNet.b skipped

C:\System Volume Information\_restore{67D185F6-9A00-485B-A01D-93229F7E2E9E}\RP663\A0054673.exe Infected: Trojan-Clicker.Win32.Small.kg skipped

C:\System Volume Information\_restore{67D185F6-9A00-485B-A01D-93229F7E2E9E}\RP663\A0054675.exe Infected: Trojan.Win32.Small.hl skipped

C:\System Volume Information\_restore{67D185F6-9A00-485B-A01D-93229F7E2E9E}\RP663\A0054676.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume Information\_restore{67D185F6-9A00-485B-A01D-93229F7E2E9E}\RP663\A0054677.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume Information\_restore{67D185F6-9A00-485B-A01D-93229F7E2E9E}\RP663\A0054678.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume Information\_restore{67D185F6-9A00-485B-A01D-93229F7E2E9E}\RP663\A0054679.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume Information\_restore{67D185F6-9A00-485B-A01D-93229F7E2E9E}\RP663\A0054680.exe Infected: not-a-virus:Dialer.Win32.gen skipped

C:\WINNT\system32\SchoolGirls2-uninstall.exe Infected: not-a-virus:Dialer.Win32.gen skipped

As I said I am a novice, as is my grandson. We dont know how to delete to infected files that were detected. I tried right clicking on the files in the kaspersky report but nothing happened. I dont know eneough about computers to be able to find the files in the computer and delete them. Please give some advice to a silly old man.
 
Hi ivenoidea,

Welcome to the Spybot forum :)

It's not as bad as you think :bigthumb:

Most of those are in system restore - where they can't infect, but we'll get rid of those towards the end.

1. Go to the Control Panel and look in Add/Remove programs. Find this in the list:

NewDotNet (or New.net)

Highlight it and press *remove*

2. Clean up the cache and other temporary files.

Go to Start > Run and type in the box: cleanmgr

Wait while windows scans your system and then it will present a list when done. Make sure these three are checkmarked and press *ok* to delete them:

Temporary Files

Temporary Internet Files

Recycle bin

3. Go to Step 4 in this link:
http://forums.spybot.info/showthread.php?t=288

and follow that step to produce a Hijackthis log. Please post that log back here in your topic. We can go from there :-)
 
Back
Top