Author Topic: sfsgsftav.exe virus got by avast  (Read 3149 times)

0 Members and 1 Guest are viewing this topic.

cox573

  • Guest
sfsgsftav.exe virus got by avast
« on: March 10, 2010, 05:03:26 PM »
I just got infected from a web page with a virus that installed itself here
C:\Documents and Settings\USER\Local Settings\Application Data\sohham\sfsgsftav.exe

It poped up with a screen that looks alot like avast saying it had detected virus and would scan. Then it disable anything I tried to run, taskmanager, control panel, notepad. It would say their executable was infected and then shut them down. It also got to IE and prevented webpages from loading even though I could tracert route through cmd prompt.

I had to deny access to sohham directory through command line cacls. Restart in safe mode then manually delete it and remove the registry entries. I had to reset IE addins and settings to default then redo the settings I wanted.

Avast never caught it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37621
  • Not a avast user
Re: sfsgsftav.exe virus got by avast
« Reply #1 on: March 10, 2010, 05:09:09 PM »
Check your computer for Malware with

Malwarebytes Antimalware http://filehippo.com/download_malwarebytes_anti_malware/
after install click UPDATE and run quick scan, click on REMOVE SELECTED to quarantine anything found

SUPERAntiSpyware http://filehippo.com/download_superantispyware/
Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26

If anything is found come back and post the scan logs here

cox573

  • Guest
Re: sfsgsftav.exe virus got by avast
« Reply #2 on: March 10, 2010, 06:31:45 PM »
Traced the malware back to www.nyguardian.com. Fake news site pushing the Google Money Masters scam.