Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: prefect on July 15, 2011, 03:01:09 PM

Title: I seem to have a virus; can I create a boot disk?
Post by: prefect on July 15, 2011, 03:01:09 PM
I am not an Avast customer yet (I will probably be in about ten minutes). This morning, I seem to have gotten a virus on my home computer -- javaupdate.exe (from a non-trusted publisher) kept trying to run and attrib.exe was apparently making everything on my desktop "hidden".

That computer is shut down now, and a friend has recommended Avast for its rescue/recovery abilities.

My question is this: is there an Avast bootup/recovery application I can burn to a CD and use on my home system before I've installed Avast on it? If so, is that included with the Avast anti-virus purchase/download, or is it a separate item?

Thank you.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: DavidCo on July 15, 2011, 04:13:25 PM
Avast paid has a boot time scan built in.
For free there are others
Or wait for a guru here - Essexboy perhaps
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: prefect on July 15, 2011, 04:24:54 PM
My current workaround scheme is A) boot into "Safe Mode" B) hope the virus doesn't work in safe mode C) install Avast from a CD I'll burn now that I've downloaded the installer and license.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: psw on July 15, 2011, 04:34:47 PM
You can try to make DrWeb CureIt! liveCD
http://www.freedrweb.com/livecd/
and make scan when booted fron it.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: REDACTED on July 15, 2011, 04:37:06 PM
My current workaround scheme is A) boot into "Safe Mode" B) hope the virus doesn't work in safe mode C) install Avast from a CD I'll burn now that I've downloaded the installer and license.



Make a log of HiJackThis http://www.filehippo.com/download_hijackthis/ utility and attach the log to the site.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: REDACTED on July 15, 2011, 04:40:45 PM
You can try to make DrWeb CureIt! liveCD
http://www.freedrweb.com/livecd/
and make scan when booted fron it.


http://www.freedrweb.com/livecd/how_it_works/

http://www.freedrweb.com/cureit/how_it_works/
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: prefect on July 15, 2011, 04:56:45 PM
You can try to make DrWeb CureIt! liveCD
http://www.freedrweb.com/livecd/
and make scan when booted fron it.

Thanks much; this is just the kind of thing I was looking for. So I'll be burning two CDs; one with DrWeb to boot with, and one with Avast and HijackThis to install once I get into safe mode.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: Tgell on July 15, 2011, 06:07:11 PM
Avast paid has a boot time scan built in.
For free there are others
Or wait for a guru here - Essexboy perhaps

The free version gives me the option to do a boot time scan.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: DavidCo on July 15, 2011, 06:23:08 PM
@Tgell
I didn't know that - cheers ;D

As far as the live CD's go I like Avira 'cos it lets me choose what to do with anything it finds.
Renaming is my fave'
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: prefect on July 16, 2011, 02:35:55 PM
My current workaround scheme is A) boot into "Safe Mode" B) hope the virus doesn't work in safe mode C) install Avast from a CD I'll burn now that I've downloaded the installer and license.



Make a log of HiJackThis http://www.filehippo.com/download_hijackthis/ utility and attach the log to the site.

Here's that Hijackthis log file.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: essexboy on July 16, 2011, 02:52:23 PM
Hi hijackthis does not look at the malware hijack points any more, so in reality it is pretty useless

You can run this from either safe or normal mode.  This version has a .scr extension so if you download it with firefox you will need to right click and select save as

 To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire (http://www.mediafire.com/) and post the sharing link.

Download OTS (http://oldtimer.geekstogo.com/OTS.scr)  to your Desktop
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check


%SYSTEMDRIVE%\*.exe
/md5start
volsnap.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT


Please attach the log in your next post.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: prefect on July 16, 2011, 08:21:16 PM
Here's the OTS log. Avast recommended I run OTS.exe in sandbox mode, so I did. If that's a problem, let me know, and I'll run it normally.

Thanks.
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: essexboy on July 16, 2011, 08:48:07 PM
Could you run it normally please as there are a few areas it could not look at

What problems do you have when you boot to normal mode ?
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: prefect on July 16, 2011, 09:03:50 PM
I'm sorry I haven't given details of what I've done so far.

 1. I used the DrWeb rescue disk to boot. That found four infected files, which I deleted.
 2. I ran unhide.exe to remove the "hidden" attribute that had been applied to many of my files, including everything on the desktop.
 3. I installed Avast, did a quick scan and then a full scan.
 4. I checked the Windows registry's "Run" section, and found an entry to run a file in C:\ProgramData that had a modification date of 2011/07/15 -- about the time that the problems started. I deleted that registry entry.
 5. The file properties for that file said that it was "Tshark". There was another file with a different name that also claimed to be Tshark. I deleted both of those files, even though they didn't come up as positive under virus scanning. (I'm a bit worried that I don't see them in the recycle bin now.)

I'm not having any problems that I'm aware of now, and I can log in to my computer like I used to, but I'm hoping these logs can confirm or deny the state of my system.

Thanks.

Download link: http://www.mediafire.com/?q9aei19nifj8es3
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: essexboy on July 16, 2011, 09:44:15 PM
Looks good - you did well  ;D

No apparent malware that I can see
Title: Re: I seem to have a virus; can I create a boot disk?
Post by: prefect on July 16, 2011, 09:56:24 PM
Looks good - you did well  ;D

No apparent malware that I can see

Thanks everybody for all the help; I really appreciate it. (I'm still deeply ashamed that I got a virus; thought I was better than that. Probably time to look into locking things down a little tighter.)