I’m getting nearly every 15 minutes a warning from avast, that a virus was blocked. The warning says the virus goes over svchost.exe and tries to communicate with getmeegan.info. I searched with avast over my system, but avast didn’t find anything. I let also search malwarebytes anti-malware over my system, but the scanner also finds nothing.
So what hit me and how can I get rid of it?
Attach your logs. (MBAM, OTL and aswMBR…!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0
Ok, here are the log files.
Hi there could you resave the OTL file as ANSI also could you attach the Avast alert … Right click the icon and select show last popup
Both log files and the screenshot of the avast alert.
Good, now you’ve to be patient…
Ta the screenshot showed me the culprit. This may take two or three runs to kill
Download and Install Combofix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
- IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png
http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png
[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.
Notes:
- Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
- Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
- If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Since the reboot I got no more alert warnings from avast. It seems, that the problem was removed. My computer is running without any problems.
I wouldn’t call that a problem, the Killer Network Manager was removed from the autostart. The networkcard is alive, internet is working, so no problem. I reinstalled Windows last week trough new hardware and still checking if I need that manager or not.
Thank your for the help.
Hmm, avast and malwarebytes anti-malware didn’t find the problem - is there a way to find such problems in the future? That is my first problem with a virus, that I couldn’t fix alone.
Interestingly, the first of these links was blocked by my Avast as a malware site!
Ooops somehow my response did not post yesterday weird… xp-AntiSpy was the problem with its call home function, maybe it is not as legitimate as I thought
I have uploaded the first link for Avast to reanalyse and allow
How is the computer behaving now ?
The computer is behaving normal, no problems, no alerts.
xp-AntiSpy? I installed it last week and the avast warnings start yesterday. I’m using that version of xp-AntiSpy since some years (under WinXP and Windows 7). Could maybe a maleware program corrupt somehow xp-AntiSpy?
To my second question, what can I do for the future to avoid such problems? Should I use another maleware scanner additionally?
There is the possibility that it was a tampered with install, where did you get it from ?
Subject to no further problems
I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems
Now the best part of the day ----- Your log now appears clean
A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:
Download and run Delfix
https://dl.dropboxusercontent.com/u/73555776/delfix.JPG
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
CryptoPrevent install this programme to lock down and prevent crypto ransome ware
https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG
Update and run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe
Where I did get it from? I think I get from the xp antispy site, but I’m not sure. That is now 4,5 years ago - yes i’m having that version for that long time.
Thank you again and I will check CryptoPrevent.
hello, wanted to know if after running combofix I just reboot my system in order to eliminate the problem. Is it so?
Err no combofix is a powerful tool that should not be used willy nilly as if it is the wrong type of infection you are using it on it could ruin your day. What problems are you having
blocked notification getmeegan
Is the alert still there after combofix ?