Author Topic: Would I have a virus?  (Read 5250 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Would I have a virus?
« on: September 18, 2014, 10:36:03 PM »
Avast! blocked a virus 7 times today.
(I share my computer)
The other person using it got a spam e-mail from someone they believed to be a friend (didn't check the address to tell, I did and it was spam), and they opened it. They got linked to a doctor's website about dieting and weight loss, and then left the PC away for upwards of ~6 hours. 7 blocked viruses were attempting to enter, according to the logs. I'm running a scan now, do I have a virus?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Would I have a virus?
« Reply #1 on: September 18, 2014, 10:45:22 PM »
to find out, follow instructions   https://forum.avast.com/index.php?topic=53253.0
attach Malwarebytes / Farbar Recovery Scan Tool / aswMBR logs


REDACTED

  • Guest
Re: Would I have a virus?
« Reply #2 on: September 18, 2014, 10:47:26 PM »
to find out, follow instructions   https://forum.avast.com/index.php?topic=53253.0
attach Malwarebytes / Farbar Recovery Scan Tool / aswMBR logs
Do I have to run full scans? They crash my computer.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Would I have a virus?
« Reply #3 on: September 18, 2014, 10:51:35 PM »
it is explained in instructions .... read it all several times before you start so you know what to do




REDACTED

  • Guest
Re: Would I have a virus?
« Reply #4 on: September 18, 2014, 11:10:24 PM »
it is explained in instructions .... read it all several times before you start so you know what to do
It said nothing about full scans.

REDACTED

  • Guest
Re: Would I have a virus?
« Reply #5 on: September 18, 2014, 11:37:13 PM »
First log, MBAM scan.

REDACTED

  • Guest
Re: Would I have a virus?
« Reply #6 on: September 19, 2014, 03:49:05 AM »
Will DL other things and follow up with more logs tomorrow.
Can you guys do anything with the MBAM logs?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Would I have a virus?
« Reply #7 on: September 19, 2014, 07:17:57 AM »
No...... we need Farbar Recovery Scan Tool logs first



« Last Edit: September 19, 2014, 03:46:53 PM by Pondus »

REDACTED

  • Guest
Re: Would I have a virus?
« Reply #8 on: September 19, 2014, 10:29:30 PM »
No...... we need Farbar Recovery Scan Tool logs first
Alright. Will do!

REDACTED

  • Guest
Re: Would I have a virus?
« Reply #9 on: September 19, 2014, 10:36:57 PM »
Running Farbar.

REDACTED

  • Guest
Re: Would I have a virus?
« Reply #10 on: September 19, 2014, 10:40:59 PM »
Logs.

REDACTED

  • Guest
Re: Would I have a virus?
« Reply #11 on: September 21, 2014, 01:39:07 AM »
Chromes been crashing alot for the past few days, would that have anything to do with it?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Would I have a virus?
« Reply #12 on: September 21, 2014, 12:24:15 PM »
First thing to do is remove Norton

Go to control panel > Programmes and features
Uninstall the following programme :

Norton
Symantec


Then download to your desktop :

http://liveupdate.symantec.com/upgrade/NRnR/English/NRnR.exe

Run this programme

After the reboot

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
GroupPolicyUsers\S-1-5-21-4097291917-2600669319-952315789-1000\User: Group Policy restriction detected <======= ATTENTION
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} ->  No File
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

REDACTED

  • Guest
Re: Would I have a virus?
« Reply #13 on: September 21, 2014, 05:51:04 PM »
First thing to do is remove Norton

Go to control panel > Programmes and features
Uninstall the following programme :

Norton
Symantec


Then download to your desktop :

http://liveupdate.symantec.com/upgrade/NRnR/English/NRnR.exe

Run this programme

After the reboot

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
GroupPolicyUsers\S-1-5-21-4097291917-2600669319-952315789-1000\User: Group Policy restriction detected <======= ATTENTION
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} ->  No File
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
The Norton is paid for and I don't know any serial numbers/passcodes for it, so I couldn't get it things back if it got removed, and the others sharing the computer would likley get angry. Can I do anything else besides remove Norton?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Would I have a virus?
« Reply #14 on: September 21, 2014, 05:58:02 PM »
Yes remove Avast, you cannot have two AV's running on the same computer and expect no problems