Cannot delete trojan file

pain55

Member
C:/Windows/System32/drivers/swjghtws.sys

That file is a trojan detected by hitman pro, avira and malwarebytes. They could not delete it so i manually tried to delete the file, however an error came up saying : cannot read from the source file or disk.

Please can someone help, its a virus and it just won't get deleted.
Thanks in advance.
 

My Computer

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Mouse
    Dell USB 4 button optical
    Keyboard
    Dell USB
    Other Info
    DSL provided by ATT
OK, that is your decision. Read the link that I left you.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Mouse
    Dell USB 4 button optical
    Keyboard
    Dell USB
    Other Info
    DSL provided by ATT
Go to google and type in AVG rescue CD, and download the ISO and burn it, and boot with it, make sure u update it, and then run a scan.
 

My Computer

System One

  • Manufacturer/Model
    Hp pavillion a6110n
    CPU
    amd athlon 64 x2 live! 4400+
    Memory
    4 gigs 3.3 useable
    Graphics card(s)
    Finally! SAPPHIRE 100283L Radeon HD 5770 (Juniper XT) 1GB 12
    Monitor(s) Displays
    generic pnp monitor
    Screen Resolution
    1280x1024
    Hard Drives
    7.2k rpm 1 linux ubuntu partition 1 vista partition 1recovery partition 1 windows 7 partition 1linux swap partition
    PSU
    500W, antc earthwatts EA500
    Case
    normal black case
    Cooling
    fans
    Mouse
    logitech mouse (small to fit hand perfectly)
    Keyboard
    saitek cyborg gaming keyboard
    Internet Speed
    dsl
    Other Info
    2.3 ghz amd
Have your tried Microsoft Security Essentials? Its free and constantly updated with new virus definitions. I have used it since it cam out and works awesome. Should take it away without a problem.

Hope this helps.
 

My Computer

System One

  • Manufacturer/Model
    HP Pavilion DV7-1129wm Entertainment PC
    CPU
    AMD Turion X2 RM-72 Dual Core @ 2.1GHz
    Memory
    2 x 2 GB Hyundai DDR2 400 MHZ
    Graphics card(s)
    ATI Mobility Radeon HD 3200 @ 256 MB
    Sound Card
    IDT High Definition Audio/SRS Premium Sound/Altec Lansing
    Monitor(s) Displays
    17" Laptop Screen
    Screen Resolution
    1440 x 900 laptop, external 17 in LCD 1024 x 768
    Hard Drives
    WD Scorpio Blue 320 GB SATA 5400 RPM Toshiba 68 GB SATA 5400 RPM Second Drive (backup)
    PSU
    8 Cell Lithium Ion Battery
    Case
    Laptop with "light up" HP Logo on outside
    Cooling
    Insane air coming out of Targus dual fan cooler
    Mouse
    Microsoft Wireless Mobile Mouse 3000 / Touchpad
    Keyboard
    Full Keyboard with numpad
    Internet Speed
    Comcast Cable 20 MBps
    Other Info
    Used Primarily for CAD design using SolidWorks 2010. Also I love to watch HD movies using the HDMI output(Netflix). Linked to my Xbox 360 for Windows Media Center 3 USB ports + USB/eSata HP Remote for Windows Media Center and Quickplay Internal Dual Layer DVD+/-RW External HP Lightscribe Dual Layer DVD+/-RW HP Webcam and Microphone
Thanks for replies guys,

If i try to re-name the file, or move it, another error comes up saying:

'a device attached to the system is not functioning'

Please can someone help, this seems to be a file error of some kind...
 

My Computer

Try taking ownership of the file. Add "Take Ownership" to Explorer Right-Click Menu in Win 7 or Vista - How-To Geek

Become system account (equivalent to root in linux). Enable Vista's hidden administrator, and password-protect its XP equivalent | Workers' Edge - CNET News

Have you tried doing this in safe mode? repeatedly press f8 on startup (usually after the post screen).

Try running sfc /scannow to check for file integrity

Use a file shredder/deleter program: File Deleter - Free software downloads and software reviews - CNET Download.com

Go to google and type in AVG rescue CD, and download the ISO and burn it, and boot with it, make sure u update it, and then run a scan.
^^^^^^^^^^^^^^^^^Have you tried that?^^^^^^^^^^^^^^^^^^^^
 

My Computer

System One

  • Manufacturer/Model
    Hp pavillion a6110n
    CPU
    amd athlon 64 x2 live! 4400+
    Memory
    4 gigs 3.3 useable
    Graphics card(s)
    Finally! SAPPHIRE 100283L Radeon HD 5770 (Juniper XT) 1GB 12
    Monitor(s) Displays
    generic pnp monitor
    Screen Resolution
    1280x1024
    Hard Drives
    7.2k rpm 1 linux ubuntu partition 1 vista partition 1recovery partition 1 windows 7 partition 1linux swap partition
    PSU
    500W, antc earthwatts EA500
    Case
    normal black case
    Cooling
    fans
    Mouse
    logitech mouse (small to fit hand perfectly)
    Keyboard
    saitek cyborg gaming keyboard
    Internet Speed
    dsl
    Other Info
    2.3 ghz amd
Hello,

If that guide that Richard send you has not helped, then follow this. There is a high chance that this is not the only file that is in this one virus. Often there is other evil code at work stopping any attempts to remove any other parts. Please download and run the beta HiJackThis generating a log file. Save and upload the log file here and I will take a look at it for you. Remember, if this is a bad virus, then removal could be very complex. If you are not comforatable with this, let me at least have a look at the HiJackThis log and ask someone to help.

HijackThis - Trend Micro USA

Richard
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS 420
    CPU
    Intel Core 2 Quad Q9300 2.50GHz
    Motherboard
    Stock Dell 0TP406
    Memory
    4 gb (DDR2 800) 400MHz
    Graphics card(s)
    ATI Radeon HD 3870 (512 MBytes)
    Sound Card
    Onboard
    Monitor(s) Displays
    1 x Dell 2007FP and 1 x (old) Sonic flat screen
    Screen Resolution
    1600 x 1200 and 1280 x 1204
    Hard Drives
    1 x 640Gb (SATA 300) Western Digital: WDC WD6400AAKS-75A7B0 1 x 1Tb (SATA 600) Western Digital: Caviar Black, SATA 6GB/S, 64Mb cache, 8ms Western Digital: WDC WD1002FAEX-00Z3A0 ATA Device
    PSU
    Stock PSU - 375W
    Case
    Dell XPS 420
    Cooling
    Stock Fan
    Mouse
    Advent Optical ADE-WG01 (colour change light up)
    Keyboard
    Dell Bluetooth
    Internet Speed
    120 kb/s
    Other Info
    ASUS USB 3.0 5Gbps/SATA 6Gbps - PCI-Express Combo Controller Card (U3S6)
Hello,

If that guide that Richard send you has not helped, then follow this. There is a high chance that this is not the only file that is in this one virus. Often there is other evil code at work stopping any attempts to remove any other parts. Please download and run the beta HiJackThis generating a log file. Save and upload the log file here and I will take a look at it for you. Remember, if this is a bad virus, then removal could be very complex. If you are not comforatable with this, let me at least have a look at the HiJackThis log and ask someone to help.

HijackThis - Trend Micro USA

Richard


Ok i will try to
thanks for help guys :)
 

My Computer

have you tried using the removal tools in safe mode?
 

My Computer

System One

  • Manufacturer/Model
    home brews
    Motherboard
    pc1 msi k7delta, pc2 asus kn79txd evo
    Memory
    pc1 2gb crucial, pc2 4gb gskill ripjaws
    Graphics card(s)
    pc1 bfg 7800gs, pc2 shapphire 5770 vapor-x
    Sound Card
    onboard
    PSU
    corsair hx
    Case
    jeantech phong
    Cooling
    pc1, handmade waterblocks,passive cooling, pc2 corsair h50
    Mouse
    logictech mx510s wired
C:/Windows/System32/drivers/swjghtws.sys

That file is a trojan detected by hitman pro, avira and malwarebytes. They could not delete it so i manually tried to delete the file, however an error came up saying : cannot read from the source file or disk.

Please can someone help, its a virus and it just won't get deleted.
Thanks in advance.

It seems odd that searching that filename didn't turn up a single additional hit. Just this one. Are you sure you don't have a virtual CD or some other virtual device installed?
 

My Computer

System One

  • Manufacturer/Model
    HP Pavilion m9515y
    CPU
    Phenom X4 9850
    Memory
    8 GB
    Graphics card(s)
    Some Radeon Cheapie with 512 MB Ram
    Monitor(s) Displays
    CRT
    Screen Resolution
    1280x1024
    Hard Drives
    750 GB SATA 3G 2 SIIG Superspeed docks w/WD Caviar Black Sata II or III
Do this.

Type msconfig in the Start Menu search.

Select Diagnoistic startup.

click apply and ok, then reboot.

During reboot go to safe mode by pressing F8 before Vista's Boot logo/Screen.

in safe mode try running that scan and delete the particular file.

Reboot in normal.

Check for the Virus/Trojan by rescanning again in Normal mode.

if system works perfectly then type msconfig in Start Menu Search box

Select Normal instead of Diagnoistic, click apply and ok and reboot.

That's it.
 

My Computer

System One

  • Manufacturer/Model
    HTPC/Desktop PC/Gateway LT2104u
    CPU
    Intel Pentium 4 2.8Ghz with HT/3.0Ghz with HT/Atom N450
    Motherboard
    GIGABYTE GA-81915ME-C/Intel D865GBF/Acer LT21
    Memory
    2x1GB DDR 400Mhz/512x2GB DDR 400Mhz/1GB DDR2-800Mhz
    Graphics card(s)
    ECS 9800GT 512 DDR3/ Sapphire HD3650 AGP 8x 512MB/Intel 3150
    Sound Card
    Turtle Beach RIVERIA 5.1 SPDIF Out/SoundMAX AD1985/Realtek H
    Monitor(s) Displays
    SONY BRAVIA KLV-32V300A V-Series/ KLV-19T400A/ Built-in
    Screen Resolution
    1920x1080/1980x1080/1024x600
    Hard Drives
    MAXTOR 40GB WD ESSENTIAL EDITION 1TB USB Hitachi HDT721010SLA360 1TB SATA 150/ 250GB Toshiba
    PSU
    OCZ Fatal1ty 550W/
    Case
    Lian-Li v351, Lancool K-62 DragonLord
    Mouse
    Logitech Combo
    Keyboard
    Logitech Combo
    Internet Speed
    512 Kbps
Hallo pain55, just another suggestion i have not tried this but it may work.

I noted in your earlier post you have Malwarebytes installed in the "More Tools" tab is a tool called "File Assassin" you may want to give it a go?

Let us know if it is any good, i am curious
 

My Computer

System One

  • Manufacturer/Model
    Hewlett Packard, compaq presario CQ60-305AU
    CPU
    AMD Athlon QI-46 2.1 Ghz
    Motherboard
    Wistron 303C
    Memory
    2048 Mb DDR2 SD Ram
    Graphics card(s)
    NVidea GE Go Force 8200M G / 256Mb dedicated grapics memory
    Sound Card
    MCP78S NVidea High definition
    Monitor(s) Displays
    15.6" High Definition Brightview Widescreen
    Screen Resolution
    1336x768
    Hard Drives
    Toshiba MK2555GSX ATA
    Mouse
    Synaptics PS2/Touchpad
C:/Windows/System32/drivers/swjghtws.sys

That file is a trojan detected by hitman pro, avira and malwarebytes. They could not delete it so i manually tried to delete the file, however an error came up saying : cannot read from the source file or disk.

Please can someone help, its a virus and it just won't get deleted.
Thanks in advance.

It seems odd that searching that filename didn't turn up a single additional hit. Just this one. Are you sure you don't have a virtual CD or some other virtual device installed?

Well i searched up the file name and it doesn't seem to exist, also i don't think i have any virtual devices installed. By the way, when i got to the file's properties, there is no details of security etc. One final thing, the date modified time changes with every minute that passes i.e. it is almost as if it is running in the background.
 

My Computer

Run System Restore in Safe Mode
Run the Windows System File Checker to have Windows check your important system files.
We also recommend running Ccleaner to clear out any unneeded temp file and check your registry for problems. Just be sure to backup the registry when prompted.
When searching for your boot.ini file make sure that you have the show hidden files and folders option checked in My Computer and that you select that option when searching under advanced options.
If nothing seems to work then you may want to try a Windows repair installation which will reinstall Windows and leave your programs and files intact. If you don't get the option to repair when you boot from your Windows CD then that means there is some corruption and you won’t be able to use this option. If possible it’s always a good idea to backup your data first.
 

My Computer

Back
Top