everytime I fire up my pc I get a warning from AVG saying it has detected a worm called adir.dll in my system32 directory. If I go for the heal option, delete option in AVG or physically go into the directory and manually delete the file it always reappears when I reboot the pc. What do I need to do to delete it permanently and stop it reappearing?
try deleting you temp internet file?
sometimes works
or go to gris soft web site. see if they can help
linky
might help....
or doing the virus scanning etc in safe mode...
[Edited on 8/1/07 by BenB]
TURN OFF SYSTEM RESTORE!
Sorry to shout, but its the biggest difficulty with removing viruses there is. Likewise scan and fix in safe mode too and delete all of the temporary
files on your computer.
David
Thanks for all of the advice guys. I have deleted all of my temp internet files, turned off system restore and done a full virus check in safe mode (no viruses found) and still the adir.dll file appears each time I reboot. Not too sure what to try next.
Run msconfig (go to the start menu, Run... and type 'msconfig' ) and check what's being started when the PC is booted. Most things are
fairly obvious what they are, but if you don't recognise something google it's name to find out.
[Edited on 8/1/07 by martyn_16v]
According to Sophos (linky) You probably have the Lager-M trojan. Look out for 'taskdir.exe' in MSConfig, that's what's doing the nasty ever time you reboot
If you have a file running when your computer boots you need to remove the registry entry that is causing it to run, and the file as well. You can manually find the file, and the easiest way to remove the registry entry is using hijackthis (free download)
Sorted
Martyn you were spot on with taskdir.exe. I ran msconfig and found it. Also found another little nasty and got rid of that as well. I also downloaded
and ran hijackthis and that found references to the same files which I got rid of. I can see it would be easy to do some serious damage with
hijackthis if you were not careful.
Thanks everyone for your help.