Long time user of avast!, this is the first time my computer has got something that Avast hasn’t been able to solve.
Looking at my Avast log it shows signs of “win32:Trojan-gen(other)” in C:\WINDOWS\sqlserver.dll, “win32:Maha-I [trj]” in C:\WINDOWS\maya.exe and “rootkit: Hidden File” in C:\WINDOWS\system.in\CRLDS3D.DLL and signs of “Win32:Autorun-APS [Wrm]” in C:\Recycler
The problems started a couple days ago, Avast would detect the virus when I boot up, but couldn’t delete it. Avast would then boot up and run outside of windows (said virus was to do with Operating System), and it looked like it had deleted virus, but as soon as I go back into Windows virus is there. Massive slowdown in Explorer, and my XP Firewall is always turned “off” when I boot up computer (although I can turn it back on).
Some troubleshooting I took:
Installed PC Tools Firewall Plus as a protective measure. Not sure if it will make a difference but I figured it’s probaly better than XP Firewall.
Downloaded HijackThis and got logfile. Going to post (below) hoping you guys can help:
I don’t know what that Service “PnkBstrA” is. It looked suspicious so I blocked it’s access using PC Tool Firewall Plus. I have no idea if that’s what he problem is or not.
I have no idea how to read the above log, hoping that you guys can help me out. I’m very nervous right now about what might be wrong. I’m the definition of “User End Only” in terms of my computer knowledge. Whatever is wrong is way beyond my knowledge of knowing how to clean.
[quote]Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:06, on 2008-12-09
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
PnkBstrA seems to be safe, but you could submit that too if you are still suspicious.
pnkbstra.exe is a process. This is usually installed with latest games like Battlefield 2142 and America's Army. This is usually detected as malware but if removed will effect the games installed especially when online.
Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
Use SUPERantispyware, MBAM or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete them.
I think it is more likely caused by avast alerting when you tried to upload it (is that what happened) ?
You are then I assume getting an avast alert on the suspicious attachment, yes ?
You could pause the Standard Shield before you upload the file to virustotal, but I don’t like to be unprotected only for a short time, so I would suggest the following:
Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.