Virus scans show nothing, What now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by BrokenArrows, Mar 20, 2007.

  1. BrokenArrows

    BrokenArrows Sergeant

    Last week my computer got infected from multiple viruses even though i had AVG scanner fully updated and running. Itook me along time to remove the visable viruses and trojans

    AVG now runs and does not report anything except c:/windows/system32/shell32.dll and c:/windows/system32/ntoskrnl.exe have been changed.
    Ad-Aware shows nothing besides cookies and the same with Spybot search and destroy.
    CounterSpy found a few more trojans and were all cleaned successfully.

    Ive ran all programs reccommended in the sticky.My computer still has problems.

    "SYSTEM" process runs between 45% and 55% sometimes holds on 100%
    My internet was always sending/recieving so i ran Ethereal packet sniffer to see what it was doing.

    I found that my computer is responsible for constantly sending e-mails through multiple free servers on port 25.
    Ones that i have noted below but they change every few minutes:

    lizard.kaluga.ru
    post.informind.ru
    fr6.aha.ru

    Alot of them seem to be russian.

    I dont know what data is being sent to these addresses.

    I assume some worm has made its way into one or all of the above files that i mentioned and is avoiding detection.

    How is this possible?

    Im attaching my hijack logs and other logs. Hopefully someone will be able to help.
     

    Attached Files:

  2. BrokenArrows

    BrokenArrows Sergeant

    I have stopped the trojan or whatever it is from sending the e-mails by blocking port 25 on my firewall.This has also solved my problem of slow internet

    But my computer is still running at 50% cpu at least. How can i stop this when the virus scans show nothing,.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run step 6 of the READ ME properly and then attach all the requested logs. (Note: I'm going to insert a special step in the below)
    • you need to uninstall all the old Sun Java versions as requested and install the current version from the link given in step 6. They are part of the reason for your infection and also are wasting resources. If you don't understand what these old versions are here is a list of them:
      • J2SE Runtime Environment 5.0 Update 10
      • J2SE Runtime Environment 5.0 Update 11
      • J2SE Runtime Environment 5.0 Update 3
      • J2SE Runtime Environment 5.0 Update 6
      • J2SE Runtime Environment 5.0 Update 9
    • now run this Special Removal Procedure mentioned in a link from the READ ME: Virtumonde aka Trojan Vundo Removal save the log from VundoFix
    • run BitDefender online scan and save the log as instructed and attach it here
    • run PandaActiveScan and save the log as instructed and attach it here
    • now you need to re-do the below scans and attach new logs since they should have been run after the above was already performed
      • GetRunKey
      • ShowNew
      • HijackThis
      • also attach the VundoFix log
    Thus you should now be attaching the below six logs
    • VundoFix
    • BitDefender
    • PandaActiveScan
    • GetRunKey
    • ShowNew
    • HJT
     
  4. BrokenArrows

    BrokenArrows Sergeant

    cool All that sorted my system. CPU now normal and spam mailing has stopped. Everything seems ok.

    Why is it that those online virus scanners find alot more than AVG & Norton and adaware and search and destroy.

    Its so pointless needing 6+ different scanners.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete the procedure I gave to you and attach the logs. I expect that you still have infected files on your system that were not removed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds