Author Topic: Can't find my virus - help please!  (Read 4670 times)

0 Members and 1 Guest are viewing this topic.

laurabob05

  • Guest
Can't find my virus - help please!
« on: June 29, 2010, 05:40:13 AM »
Hello!

So I upgraded from the free Avast! to Avast! Pro and two days later I have a hijacker virus - go figure! Clicking on links takes me to random pages. also, not sure if it is related but there's been an svchost.exe listed in my processes that's taking up tons of ram. (I have XP home edition and as far as I know there's no way to figure out what is doing that)

I ran a bootscan with Avast pro and ran Malwarebytes in safe mode, and neither found any virus but I'm still getting hijacking occasionally.

I saw other posts where people who couldn't find their virus were advised to run OTL and post the logs here, so I did that.

I hope someone can help! Thank you!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Can't find my virus - help please!
« Reply #1 on: June 29, 2010, 09:14:45 AM »
Quote
I ran a bootscan with Avast pro and ran Malwarebytes in safe mode
Malwarebytes works best in normal mode


ziucqea

  • Guest
Re: Can't find my virus - help please!
« Reply #2 on: June 29, 2010, 01:22:19 PM »
My suggestion is trying Norton Rescue Tools. Download Noton Power Eraser. If necessary, try Norton Bootable Recovery Tool (both of which don't entail installings). NPE got some false positives, though( most of which are cookies).
http://security.symantec.com/nbrt/npe.asp

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Can't find my virus - help please!
« Reply #3 on: June 29, 2010, 01:34:00 PM »
Does Norton Power Eraser detect that many false positives?
The best things in life are free.

ziucqea

  • Guest
Re: Can't find my virus - help please!
« Reply #4 on: June 29, 2010, 01:51:48 PM »
I haven't got a chance to try it myself. But according to what others say, it's fairly good; it's uaually used to rescue computers after it's infected by cleaning viruses 'powerfully'. But the problem is that it doesn't seem to got a high detection rate(or maybe it's not sensive to viruses in China?).

laurabob05

  • Guest
Re: Can't find my virus - help please!
« Reply #5 on: June 29, 2010, 03:53:08 PM »

Malwarebytes works best in normal mode



I ran it in normal mode a couple of days ago and it didn't find anything then either.

ziucqea

  • Guest
Re: Can't find my virus - help please!
« Reply #6 on: June 29, 2010, 04:31:35 PM »
Emsisoft a-squared Free 4.5, then.
http://www.emsisoft.com/en/software/download/
Upgrade it to 5.0 after downloading. Today 5.0 was released but can only be attained by upgrading the current program. I think a2 will put it on its website soon.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Can't find my virus - help please!
« Reply #7 on: June 29, 2010, 05:17:43 PM »

Malwarebytes works best in normal mode



I ran it in normal mode a couple of days ago and it didn't find anything then either.
OK, EssexBoy is notified and will check your log`s, so wait for he`s advice .... ;)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can't find my virus - help please!
« Reply #8 on: June 29, 2010, 09:20:57 PM »
Hi are you connecting via a router ?  Do the redirects occur in both IE and Firefox or just one of them ?

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

Code: [Select]
:OTL
[2010/06/06 18:40:33 | 000,005,416 | ---- | M] () -- C:\Documents and Settings\HP_Administrator\r

:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.

laurabob05

  • Guest
Re: Can't find my virus - help please!
« Reply #9 on: July 01, 2010, 12:34:46 AM »
Hi are you connecting via a router ?  Do the redirects occur in both IE and Firefox or just one of them ?


Yes, i have a router. And I'm not sure, i only used Firefox and it was redirecting with that. I tried IE just now and it didn't do it, but it doesn't do it all the time (it stopped for a few days and started again and stopped again) so I don't know if it is effecting IE.

The combofix file just saved itself as "log"

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can't find my virus - help please!
« Reply #10 on: July 01, 2010, 09:00:54 PM »
Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).