I don't know very much about viruses; I went to a website recently and aVast blocked a few trojans that tried to enter my computer. I ran virus scans with aVast!, Spybot, and Ad-Aware 2007 and no viruses were found. How likely is it that if a virus somehow managed to initially get past my anti-virus programs, it could further avoid detection by all three virus scanners? Also, if there was a virus on my computer, would it always show up under the running processes listed in Task Manager?

Recommended Answers

All 26 Replies

Ah your fine its nothing to worry about i always run into site's like that and i love the Avast its great.

How likely is it that if a virus somehow managed to initially get past my anti-virus programs, it could further avoid detection by all three virus scanners? Also, if there was a virus on my computer, would it always show up under the running processes listed in Task Manager?

I would say it could be very likely all three could show clean but you could still have something on there. AdAware especially is not the program it used to be. Avast and Spybot both are very good programs but there ARE certain Trojans which are not picked up by those two.
No, if there IS a virus or Trojan on the computer it will not always show in the task manager, it would have to be running at the time to show in the task manager. There are some that only run at start up and then shut down. There are others that would only run when specific programs are used and if you don't happen to be using those programs at the time then the infection would not be running and wouldn't show in the task manager. There are some which place themselves into your task scheduler and only run at specified times in order to download more infected files.
You all ready have run two programs which show nothing and that it great, but since Avast did warn you then you know that you were "under attack", to be very safe then I would suggest the following:
download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.
Reboot the computer

Download and run a Full System Scan with HiJackThis. Save the log and post back here with the MBA-M log and the HiJackThis log.
It is better to be safe than sorry.

commented: Just making the rep count :) +36

To cut a long post short. The answer to your question is Yes a 'virus' as you say can hide from all three scans. And No!Task manager does not pick up ALL process. Remeber theres a BIG difference between viruses, trojans, and spyware, adware. Anyways im not explaining all that. I would recomend to you to get a copy of Kaspersky with up to date signitures. I would further recomend a rootkit scanner. Rootkits are programs that are able to hide sometimes even from the best of AV. I would also recomend an advance task manager to view all running processes

No need for another av program, Avast is excellent.

JHolland1964, I did everything you said, I attached the two log files; can you determine if I have any more trojans / viruses from the log files? I guess it's hard to determine what the trojans on my computer have been doing this whole time; for all I know, somebody has my credit card number and passwords if they were key loggers (right?).

Is Process Explorer by Sysinternals a good advanced task manager (that's what I have now) ? I had trouble following everything on it so I just use the regular task manager.

Your logs look good. Doesn't appear to me that you had anything which would be a password stealer on there. You don't appear to be running a firewall, unless you are running the Windows Firewall.
Now your infections were from downloaded programs...torrent downloads.
One way to avoid this of course is NOT do it. But if you must then one thing you must do is SCAN every downloaded file with your AV program AND MBA-M BEFORE opening.
Another prevention measure is to use the program SpywareBlaster. It is really a MUST have.

SpywareBlaster doesn't scan for and clean spyware--it prevents it from being installed in the first place. SpywareBlaster prevents the installation of ActiveX-based spyware, adware, dialers, browser hijackers, and other potentially unwanted programs. It can also block spyware/tracking cookies in IE, Mozilla Firefox, Netscape, and many other browsers, and restrict the actions of spyware/ad/tracking sites.

Download, install, update and enable all. Close the program, that's it. Just check manually for updates weekly.

Okay, thanks jholland, you've been really helpful I appreciate it. Just out of curiosity, how can you tell the trojans weren't keyloggers without looking at the source code of them?

I just go through the names given. There are many places online which will give you the particulars of these trojans, what they do, where they come from, etc. Most of the reputable av sites will give this info if you have the file name. Remember, all this has to be known before there can be a good remover developed.

Another prevention measure is to use the program SpywareBlaster. It is really a MUST have.
Download, install, update and enable all. Close the program, that's it. Just check manually for updates weekly.

Aside from being free, are there advantages to SpywareBlaster over the Protection Module in Malwarebytes' Anti-Malware (which you have to pay the registration fee in order to get)?

Ken

SpywareBlaster does NOT run in the background, therefore it uses no resources.

I would say it could be very likely all three could show clean but you could still have something on there. AdAware especially is not the program it used to be.

Actually, Ad-Aware is fantastic, as is MalwareBytes. For best results on either utility, boot your system in Safe Mode, as gives the best hit rate and allows maximum access for the utilities to source and remove probs :)

Actually, Ad-Aware is fantastic, as is MalwareBytes. For best results on either utility, boot your system in Safe Mode, as gives the best hit rate and allows maximum access for the utilities to source and remove probs :)

Malwarebytes' should NEVER be run in safe mode UNLESS it is impossible to run in Normal Mode.

Safe mode doesn't let MBAM load all it's drivers which are often necessary for the best detection and removal results. MBAM works in safe mode but is crippled, so if at all possible it should be used in normal mode in an admin account.

MBAM is designed to work in normal mode. It's simply most effective when run this way. Other tools like Spybot Search & Destroy work pretty much the same in normal mode vs safe mode, but MBAM does not and that's the most important thing to remember. Nothing bars you from using it in safe mode, but the results just probably won't be as good as they would if run from normal mode.
MBAM is stronger from regular mode . This is by design as a lot of new malware runs from safemode also so you gain nothing anyway . There are also multiple infections that as part of their first step blow away the entire safeboot keyset

What exactly is the difference between booting in safe mode vs. booting in Normals Mode?

Malwarebytes' should NEVER be run in safe mode UNLESS it is impossible to run in Normal Mode.

Sorry, but experience has shown me otherwise. Personally in most serious cases, tend to run both in normal Admin boot, then re-run in safe mode to finish off.

And yes some malware tries to disable Safe Mode, but there are usually ways to get around it (setting boot in safe mode from MSConfig for starters often still available if the usual F8 option disabled).

Normal mode is how you boot your computer all the time. All your drivers are loaded, your anti-virus program and firewall will be loaded and running, display adapters and audio adapters will be fully functional.
In safe mode, you have access to only basic files and drivers (mouse, monitor, keyboard, mass storage, base video, default system services, and no network connections). There also is a safe mode with networking available also, which would allow you to access the internet while in safe mode. Of course this leaves the computer unprotected but at times this may be necessary as there are some infections which will prevent the download and install of clean up tools needed to rid the computer of infection. By booting to safe mode very often these infections cannot start up either and therefore you can download necessary clean up tools.

Sorry, but experience has shown me otherwise. Personally in most serious cases, tend to run both in normal Admin boot, then re-run in safe mode to finish off.

And yes some malware tries to disable Safe Mode, but there are usually ways to get around it (setting boot in safe mode from MSConfig for starters often still available if the usual F8 option disabled).

The information I have given concerning the proper usage of Malwarebytes' comes directly from the Malwarebytes' forum on the proper usage of their tool.

http://www.malwarebytes.org/forums/index.php?showtopic=9991&pid=48828&mode=threaded&start=#entry48828

http://www.malwarebytes.org/forums/index.php?showtopic=18813&pid=96391&mode=threaded&start=#entry96391

The information I have given concerning the proper usage of Malwarebytes' comes directly from the Malwarebytes' forum on the proper usage of their tool.

http://www.malwarebytes.org/forums/index.php?showtopic=9991&pid=48828&mode=threaded&start=#entry48828

http://www.malwarebytes.org/forums/index.php?showtopic=18813&pid=96391&mode=threaded&start=#entry96391

I'm aware of that - thus the preference to run in both modes. While yes some malware now loading in Safe Mode, a large number of the core system processes they would normally lock into are not running, making removal easier.

I have to agree with Judy regarding MBA-M and Safe mode. She is correct in stating that if at all possible it should be run in Normal Windows boot.

Of course, working in Safe Mode does offer advantages for other tools as well as for manual removal.....

Sorry, but experience has shown me otherwise. Personally in most serious cases, tend to run both in normal Admin boot, then re-run in safe mode to finish off.

I believe you have that backwards ;) In serious cases it is often necessary to start in Safe Mode first.

And yes some malware tries to disable Safe Mode, but there are usually ways to get around it (setting boot in safe mode from MSConfig for starters often still available if the usual F8 option disabled).

This is bad advice, period. Please see CJ's comments about forcing Safe Mode and why it is a bad idea to do so:

http://www.dslreports.com/forum/r18150258-Dont-Force-Safe-Mode-on-Infected-PC

BTW: I do not mean to come off as a hectoring know-it-all ;)
A lot is "lost in translation" in a forum setting. It's just that I've been doing this for a lot of years and have seen a lot of bad advice in "open" forums such as here at Daniweb.

Heck, I've given my share of bad advice in the past - I used to tell people to disable System Restore before beginning the malware cleaning process. Thankfully, my friend Blender at SpywareWarrior was able to talk me out of that ill-conceived notion.... LOL! All she said was: An infected Restore Point is better than none at all.......

Cheers All :)
PP

It's ok PhilliePhan, some ppl think they know better than the manufacturers :).

I'm aware of that - thus the preference to run in both modes. While yes some malware now loading in Safe Mode, a large number of the core system processes they would normally lock into are not running, making removal easier.

If you were aware of it, you should not have posted the opposite.

It's ok PhilliePhan, some ppl think they know better than the manufacturers :).

No, sometimes it just helps to think beyond their scope at times (not always, but at times). As I did mention, I do run in tandem with Ad-Aware, so what one misses the other catches.

I have to agree with Judy regarding MBA-M and Safe mode. She is correct in stating that if at all possible it should be run in Normal Windows boot.

Of course, working in Safe Mode does offer advantages for other tools as well as for manual removal.....

Was very interesting to note the MSConfig method of forcing Safe Mode now only recommended for XP... which is probably the last time I had to force Safe Mode in that manner (well, with the exception of a couple of early Vista hiccups). Will take that on board.

I believe you have that backwards ;) In serious cases it is often necessary to start in Safe Mode first.

I've heard others take that preference, but had more success hitting in normal boot first, then in Safe Mode (minimal processes). I s'pose the logic being that in Normal Boot both utilities get to catch the active processes, and then re-booting directly in Safe Mode allows a final clean-up before the malware has the chance to re-populate.

This is bad advice, period. Please see CJ's comments about forcing Safe Mode and why it is a bad idea to do so:
http://www.dslreports.com/forum/r18150258-Dont-Force-Safe-Mode-on-Infected-PC

Again, point taken :) Although am actually curious as to whether the tactic of hitting malwatre first in Full Boot might not be why I haven't encountered a failure to re-boot in Safe Mode.

LOL! It looks like we have hijacked this thread and turned it into a nice little discussion. Not that that is a bad thing – too often these discussions take place behind the scenes in the admin threads of various forums. Maybe crunchie can break this off into a new thread?

It's ok PhilliePhan, some ppl think they know better than the manufacturers

That’s too true!
However, to play the devil’s advocate for a minute, many of us who are “self-taught” often used to prefer operating in Safe Mode (I imagine this holds true for you as well). And many of the scanners we used to use were more effective in Safe Mode. But, the times and the tools and the malware have changed.

No, sometimes it just helps to think beyond their scope at times (not always, but at times). . . .

You are absolutely right – Thinking outside the box is always good. “Back in the day” –LOL- we needed to do that a lot. One of the reasons I have stopped volunteering as much in forums is that the process has become boring:

Run MBA-M.
Run ComboFix.
Clean stragglers.
Rinse and repeat.

Boring for helpers, but absolutely great in simplicity for people with malware on their compys.

In the days before ComboFix/VundoFix/SmitfraudFix/LooktoMeFix and all the others, we ripped the baddies out manually kicking and screaming. There were a few baddies that took months to find a cure for.....

I remember some of the baddies (and I'm sure crunchie does as well) and how we had to battle them on the fly, often chasing ghosts or our own tails – Have a look at some of these threads (and see some of my bad System Restore advice on display):

VX2 - before a removal tool was developed:
http://forums.majorgeeks.com/showthread.php?t=49886

Wareout - the first time I saw it and long before Lonny developed his removal tool:
http://forums.majorgeeks.com/showthread.php?t=68734

Haxdoor - before anybody knew what it was:
http://forums.majorgeeks.com/showthread.php?t=54566

It is a whole different process these days and not nearly as challenging.....

Was very interesting to note the MSConfig method of forcing Safe Mode now only recommended for XP... ..
...... and then re-booting directly in Safe Mode allows a final clean-up before the malware has the chance to re-populate. . . . .
. . . .curious as to whether the tactic of hitting malwatre first in Full Boot might not be why I haven't encountered a failure to re-boot in Safe Mode......

-- You should not force Safe Mode in XP.
-- If you can hit the malware in Normal boot, no real reason to try again in Safe Mode.
-- The re-populate argument for Safe Mode after cleaning is a bit weak, don't you think ;)
-- Whether you get the malware or not has no bearing on Safe Boot and the registry as those keys have already been altered by the malware. The keys won't magically revert to normal or restore themselves upon removal of the offending malware (unless you ran a tool that repairs/restores the the re-written or deleted keys, of course).

Cheers All :)
PP

I absolutely hated L2M infections. If the poster rebooted or had a bsod before you got all the files, they just re-populated :). I had some fixes going for weeks :(.

I absolutely hated L2M infections. If the poster rebooted or had a bsod before you got all the files, they just re-populated :). I had some fixes going for weeks :(.

Yes - I remember that well. Another of the tricky "multi-step" fixes that could go on for a week, even with Atri's L2Mfix....
Do you have a "favorite" malware? LOL!
I remember the early Vundo when it was delivered as drive-by StopGuard downloads. I managed to work out a nice fix procedure for those well before any of the tools were developed - That was fun because we actually had to do so much by hand that you really felt as though you were accomplishing something as opposed to having somebody run an "all-encompassing" tool such as MBA-M or ComboFix which do all the work for you, for the most part....

PP :)

-- If you can hit the malware in Normal boot, no real reason to try again in Safe Mode.
-- The re-populate argument for Safe Mode after cleaning is a bit weak, don't you think ;)

Maybe not the best explanation, but seriously.... have faced infections where, have run BOTH MWB and Ad-Aware in full boot (with Admin), they claim they have detected and pulled out everything, reboot in safe mode, run them again, and guess what... they both pick up extra pieces. My first experiment with this method was dealing with that blasted MyWebSearch f@cker!

Have hit a few bugs along the way where this also proved true. I'm know that the majority of the time, running just the once in full boot is sufficient, but have just learnt to be extra cautious (yes maybe paranoid, but there you go).

...have faced infections where, have run BOTH MWB and Ad-Aware in full boot (with Admin), they claim they have detected and pulled out everything, reboot in safe mode, run them again, and guess what... they both pick up extra pieces. ....

I do not think we are talking about the same types of malware.

I think I might have misunderstood you - At the very least, we are operating with different ideas of what the malware cleaning process entails.

Merely running multiple scanners, whether in Safe Mode or not, is insufficient to clean many infected machines. Granted, MBA-M is the best scanner/remover to come along in a long time (the last one I liked was EWIDO - it was waaaay better than AdAware and Spybot at the time) , but I would venture that if you had a heavily infected machine and used your scanners, there would still be malware on board. If you then ran ComboFix, I bet it would find and remove additional baddies and still miss some, though it is likely they would show up in the log and could then be dealt with via a script for ComboFix.

Before MBA-M, it was rare for tools such as AdAware and Spybot, etc... to be able to keep up with baddies such as the ones crunchie and I discussed. Very specified tools (smitfraudFix, for example) were needed. AdAware and SpyBotSD were useless. I really have no confidence in AdAware - especially since their white-listing of objectionable items a few years back.

Also, these scanner/removers often left orphans and remnants in the registry and elsewhere - A tool is only as good as its DB and definitions.
Really, I still believe the best mode of cleaning is to have a knowledgeable person look over a few basic scanlogs, such as DDS below.....

Along those lines, I am surprised we here at daniweb rely on HJT - its best days are behind it ;)
I preferred the now defunct Deckard's System Scanner. Better yet, I'd use DDS by sUBs:
http://download.bleepingcomputer.com/sUBs/dds.scr

Cheers :)
PP

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.