• Welcome to ForumKorner!
    Join today and become a part of the community.

Have a Virus? But your AV Cannot Detect it?

Dispersserfewsdcx

Onyx user!
Reputation
0
Okay. Im anX i'll Be helping you today! i will check this regularly to help others, i'd appreciate if others helped others too.

I suggest you run a scan with ESET Online Scanner. Download the executable and run it. It will start downloading its database. Once it is done, check all options for removal and continue on with the scan. This is a free online scanner that will remove any found infections. Be sure to be using Internet Explorer as your web browser. If you have any hacking tools, compress/zip and password protect your files in a folder, so ESET won’t remove them.

Download Malwarebytes' Anti-Malware
. Install it, and update to the latest version (Go to the 'Update' tab, then click 'Check for Updates'.) Run a full scan and remove everything it finds. It is also recommended you scan with Malwarebytes' offline.

Still not got it?
read ahead.




Step 1:
What issues are you having with your computer? Please be very specific.

Step 2:
REMOVED. Temp file cleaners should not be ran before malware removal due to viruses removing legitimate files into the temp directory. [Information from Geekstogo.com]

Step 3:
Please download Malwarebytes' AntiMalware.

Double click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform Full Scan, then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the entire report in your next reply.

Step 4:
Please download OTL from one of the following links
LINK 1
LINK 2
LINK 3
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
Under the Custom Scan box paste this in;

netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.

Step 5:
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
Double click the exe file.
If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO, then use the following settings for a more complete scan.



In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

NOTE: It is not unusual for GMER to take glitch and not scan. Just tell your helper.

Step 6:
Post in this thread / PM me.
and..
Include all the logs and information from the steps above using this template:

1.My issues are:

2.My MBAM log:

3.My OTL log:

4.My GMER log:

Issues encountered:

Code:
[color=#00BFFF][b]1.My issues are:[/b][/color] 

[color=#00BFFF][b]2.My MBAM log:[/b][/color] 

[color=#00BFFF][b]3.My OTL log:[/b][/color] 

[color=#00BFFF][b]4.My GMER log:[/b][/color] 

[color=#FF0000][b]Issues encountered:[/b][/color]
Some of this thread has been taken from Hackforums.net from Ass@ssin and Paradoxum.
 

Disruption

Member
Reputation
0
You are not allowed to rip stuff from HF. Reported.
You are not trained to request OTL logs due to the fact that no formal training was present thus leading to possible harm on a users computer.
 

the_lol

Onyx user!
Reputation
0
Thanks for this but are you legit?
 

Pink Floyd

Active Member
Reputation
0
Disruption you don't need to be dickish about it. If he knows computer safety, imo let him do this for us.
 

Dispersserfewsdcx

Onyx user!
Reputation
0
Disruption said:
You are not allowed to rip stuff from HF. Reported.
You are not trained to request OTL logs due to the fact that no formal training was present thus leading to possible harm on a users computer.

OMG. Read the whole fucking thread.
 

KaNe

Onyx user!
Reputation
0
Give credit to Ass@ssin and Paradoxum. They made it, not Omniscient.
 
Top