I have tried everything i no to try and get get rid of this virus , worm or whatever it is. I am sending out 1000’s of e-mail and i am getting notice from my ISP that they have suspended me sending anymore. WHich is find I don’t even use e-mail on this drive.
Whats happening is i am getting notices flashing up from Avast sayint there warning there are lots of e-mails being sent i have had to turn that off so i can even use the PC.
I have done scans with Avast, Spybot,Spy sweeper etc they are all saying there in no problem.
My ISP suggested i start in Safe Mode and do a scan from there. When i try and start in Safe Mode the PC shuts down and restarts (this has never happened before)
If anyone has any advice on how i might get rid of this thing i would be very greatful
The chances are that this might be hidden by a rootkit and some malware also stops you getting into safe mode for obvious reasons.
Also see, anti-rootkit, detection, removal & protection http://www.antirootkit.com/software/index.htm. Try these as they are some of the more efficient and user friendly anti-rootkit tools.
Please download Deckard’s System Scanner (DSS) and save it to your Desktop.
[*]Close all other windows before proceeding.
[*]Double-click on dss.exe and follow the prompts.
[*]When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
.
You can attach the logs by using the additional options button on the reply page.
Thanks for the help lads, i have done a rootkit check with pandasotfware nothing was found.
I have downloaded and run DSS but had problems getting it to sort out hijack this so ran hijackthis on its own. I have attached the log. Hope thats what is required.
Something that is really odd but that maybe you should be aware of, when i try to log into this site to send the log, my system crashes, other sites and loggins are ok, i get a blue screen with " starting memory dump" strange! So i have made a copy of the log and am sending it from a different drive. Its like it knows " worry worry!
If anyone can help with this i would be very greatful as i have tried everything i no.
The DSS log would have been useful to show what else is going on. But if you can’t get it to run we will use another scanner.
Download ComboFix from Here or Here to your Desktop.
Do not run it yet. First rename combofix.exe to bugout.exe
Open Spybot and make sure teatimer is disabled, we will re-enable afterwards. To do so do the following
Click mode
click Advanced mode
if you get a warning answer “yes”
click tools
click resident
uncheck resident “teatimer” and SDHelper if installed
click allow change
reboot
Double click bugout.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix’s window while its running. That may cause it to stall.