also @ TechSpot: Metro: Last Light Performance, Benchmarked

I think my computer could have a virus

Discussion in 'Virus and Malware Removal' started by sjoseph, Oct 27, 2008.

  1. sjoseph Newcomer, in training

    Since the end of last week my computer has been acting like it has a virus. It started with error messages about my anti-virus software not being able to update. When I tried to go to the AV site it would tell me that my network connection was down. I could not go to any AV sites (AVG, Symantec, Lavasoft, etc...) all of them came back with errors. I could get to other sites like Google and ESPN but not AV sites. When I ran my anti virus software it came back with nothing found. But it usually finds cookies and small things so I knew something was up. So I booted my computer in safe mode and ran the Microsoft Malicious Software Removal Tool and it found 3 major threats, then I ran AVG and it found some more. Then I ran Ad Aware and cleaned up all my temp files. I brought my computer back up to regular mode and I can now get to the AV sites and my AV software can update but I get these random alerts from my AV software saying that different Trojans are being found. One of the ones that came up talked about a Trojan Horse Downloader.Generic.7.BDNN The process name it had listed was C:/windows/system32/svchost.exe. I ran HJT and will post the log in the next message, can someone help me?
  2. sjoseph Newcomer, in training

    I can't seem to post the HJT log file because the board software keeps saying I have a link attached and I can't post messages with links. I don't see a link in the file so I am not sure what it is complaining about can someone tell me how I can post the HJT log file?
  3. almcneil Newcomer, in training Posts: 1,547

    There's one very good, excuse, OUTSTANDING, anti-spyware utility you haven't tried yet: Spybot Search & Destroy. I recommend my customers use 3 anti-spyware utilities to stay on top of Spyware and you have run 2 of them: AVG and Ad-Aware 2008. You need a thrid and it's Spybot. Although Spybot finds the least spyware, it targets the NASTY spyware, the kind that's trying to change something on your computer and instead, messes it up. Spybot is the best at detecting adn removing this type of spyware.

    You can download Spybot here

    Repost if you still are experiencing problems.
  4. Auguss Newcomer, in training Posts: 16

  5. sjoseph Newcomer, in training

    I have used Spybot Search and Destroy before and every time I have run it in the past it removed something that caused another program to stop working. But since I have tried so many things and it is still on there I will try this tool as well. I am very good at keeping my AV software up to date and running it on a regular basis but somehow this one got through my defenses. I will let you know if Spybot gets rid of it. Thanks.
  6. herr5407 Newcomer, in training Posts: 118

    I would recommend using Malwarebyte's Antimalware as well. I've ran this freeware virus/spyware scanner on machines that were completely infested and it has cleaned everything out perfectly.

    Anti-Malware AND RogueRemover Free
    http://www.malwarebytes.org/
     
  7. Auguss Newcomer, in training Posts: 16

    USE ANY OR ALL OF THESE I HAVE ALL OF THESE BECAUSE EACH ONE HAS A DIFFERENT FEATURE JUST DISABLE ALL OF THE AUTO START/REAL TIME PROTECTIONS FEATURES TO SAVE RAM/MEMORY
    ----------------------------------------------------------------------------
    >>Virus Protection<<
    -Spyware Blaster (immunizations)
    http://www.javacoolsoftware.com/
    -Spybot Search and Destroy (scanner, immunizations, autorun viewer)
    http://www.safer-networking.org/
    -Anti-Malware (all around good anti-malware)
    http://www.malwarebytes.org/
    -RougeRemover Free (fake virus, trojan remover)
    http://www.malwarebytes.org/
    -Spyware Terminator (scanner, immunizations)
    http://www.spywareterminator.com/
    -SUPERAntiSpyware (scanner)
    http://www.fileresearchcenter.com/
    -WinPatrol (autoruns, ***scans/display hidden files feature and can remove the some rootkits from the file that hide it***, many other features )
    www.winpatrol.com
    >>Maintenance<<
    -CCleaner (cleans temp files regulatory, autorun viewer)
    http://www.ccleaner.com/
    -Filehippo.com FREE Update Checker (use this to update all software on your computer download the "FileHippo.com Update Checker")
    www.filehippo.com
    >>Hosts file<<
    ***For information on the "hosts file" go to: http://en.wikipedia.org/wiki/Host_file it will give you the information needed to understand a Hosts file for the three programs below***
    -HOSTSMAN (get this to block a lot of bad sites, domains, and etc with hosts file)
    http://www.abelhadigital.com/
    ***Here are some extra update sources after you become familiar with the program***
    ***Right click and copy shortcut and past in "manage update sources" under the "tools" menu***
    http://www.hosts-file.net/download/hphosts.zip
    http://hostsfile.mine.nu/Hosts.zip
    http://www.grc.com/sn/hosts_mvps_org.txt
    http://members.dialmaine.com/drdole/Apps/SCoooBYsHosts.zip
    http://pgl.yoyo.org/adservers/serverlist.php?showintro=0;hostformat=hosts
    -Advance hosts manager (very good advance hosts manager with good updates, can also use the update sources above)
    http://bluetack.co.uk/download/hosts20setup.exe
    -Hosts Switch (turn on/off the hosts file only supports the Hosts Manager from B.I.S.S. -> http://wwwbluetack.co.uk )
    http://bluetack.co.uk/download/switch13setup.exe
    >>Advanced<<
    ***below are some last resort virus removal - these can be very dangerous if you delete the wrong items***
    -Unlocker 1.8.* (force a delete on some file by unlocking it from the running process)
    http://ccollomb.free.fr/unlocker/
    -Hijack This
    http://www.merijn.org
    -GOOGLE SEARCH "SysInternals AutoRuns" download this program from Microsoft TechNet and run this to check system autoruns.
    -Also from the same Microsoft Technet get the "Rootkit Revealer" also by SysInternals
    -If all else fails for file deletion try a program called Combo-Fix or ComboFix
    http://www.bleepingcomputer.com/combofix/how-to-use-combofix
  8. sjoseph Newcomer, in training

    OK, I have run SpyBot which found more problems and I fixed them. Then I ran the Malwarebytes which found 11 infected files which it fixed. I am rerunning AVG to see if it finds anything. I am running all of these in safe mode because SpyBot couldn't remove somethings while the computer was running normally. I will let you know how it goes.

    Thanks
  9. kimsland Ex-TechSpotter Posts: 18,353

    Have a look at:

    Viruses/Spyware/Malware Preliminary Removal Instructions

    This is the proceedure that TechSpot has confirmed works

    All support should quote this proceedure first before all other utilities

    @Auguss please remove your capitals in your posts
    If you are just copying and pasting, you are best to provide the link only
    Otherwise this thread by sjoseph may get too long.

    We are helping the member, not providing stacks of program links ?!
  10. Auguss Newcomer, in training Posts: 16

    Unless you know how to personally/manually know how to remove the virus or want to explain step by step you have to point the person to a program that can help or do the job and maintain a good working order computer. I made this list from scratch and added short descriptions to help the user. I removed the caps and deleted empty space as requested you made a valid point.
  11. kimsland Ex-TechSpotter Posts: 18,353

    Yes I just did above

    But you pointing to all those programs, actually doesn't help
    Hey that's exactly what you said!
  12. Auguss Newcomer, in training Posts: 16

    What?

    Where?
  13. kimsland Ex-TechSpotter Posts: 18,353

    The huge list above :confused:

    Anyway don't worry
    I actually like your list
    And I have copied it plus kept you as the originator of it, if anyone asks I'll refer directly to your post :grinthumb
  14. sjoseph Newcomer, in training

    Had power outages all day yesterday with the high winds here in the east so I haven't had a chance to try anything new, I will let you know how it goes tonight. I haven't rebooted since I ran SpyBot so I want to see if that may have gotten my issues.
  15. Auguss Newcomer, in training Posts: 16

    Malware Remover

    Try Malware Remover before you reboot.
  16. sjoseph Newcomer, in training

    Actually I think I also did Malware Remover as well. I will have to see if it is on my computer but I think I ran both of these. Being off a day has a pain as I really wanted to see how it did. I will let you know if I see anything when I reboot.
  17. almcneil Newcomer, in training Posts: 1,547

    Let us know is any of the spyware symptoms have disappeared and what's left to be fixed.

    BTW, what's your name?

    Best,
    -- Andy
  18. momok Newcomer, in training Posts: 2,272

    Thread moved. Clearly a malware related issue.
  19. sjoseph Newcomer, in training

    I ran SpyBot and the Malware software and when I restarted my computer the AVG Resident Shield came up with an alert that a virus was found in Win32/Cryptor. Every time I reboot my computer Resident Shield tells me that it has found a virus in a different file (last time it found a Trojan Horse called Downloader.Generic.7.BDNN, which when I Googled this file I found nothing). Which makes me believe that the virus is just giving itself generic names so that I can't find out what it is. It seems like the virus is hanging out in my System Volume Information folder because that is the location of the file name that was opened when the alert was triggered. But what it finds each time differs. Has anyone seen anything like this? I am about to just give up and restore my computer back to the factor defaults.

    BTW my name is Susan and I really do appreciate everyone's help with this.
  20. Auguss Newcomer, in training Posts: 16

    Wow sounds like a pretty good one. dont know im going to have to let one of the better people help you with that one. im not going to give you some bad info on it. i just hope every time the virus scanner removes it. use all your options that you can possibly think of start downloading trials from higher credible websites AVG, Bitdefender, Avast (most of the time good). Avira, try some of them, install the trials update and then if it finds something remove it and then uninstall to save yourself hte space on you HDD.

    MOST of the virus scanner WILL have a conflict with other virus scanner for kernel resources. just install one at a time. not every anti virus has the same definitions as it competitor,

    you could also try Spyware Doctor Pretty good anti-spyware and Adaware Free edition pretty good anti-adware