Hoo boy...

by That One Guy

Could be a number of things causing the problem, but one thing to be aware of in the current landscape of malware is that stealth technology is becoming increasingly popular in malware design. I am not saying that you have stealthed malware, but it is a possibility as the symptoms match.

I highly recommend running all of your anti-malware scans in safe mode to reduce the number of processes that launch on startup. (Use 'safe mode with networking')

In addition I recommend sweeping with several different anti-malware applications.

Microsoft Security Essentials is a decent first sweep tool (http://windows.microsoft.com/en-US/windows/products/security-essentials )
I tend to follow up with Trend Micro Housecall to catch anything MSE misses (http://housecall.trendmicro.com/ )
Following that, Rootkit Revealer is a decent start at finding hidden fun stuff on your system (http://technet.microsoft.com/en-us/sysinternals/bb897445 )
Scan with GMER as well (http://www.gmer.net/ )
After this you get into anti-spyware utilities.
Hijack This! is a good start (http://free.antivirus.com/hijackthis/ )
Be sure to run the HJT log through the analyzer here (http://www.hijackthis.de/ )
Finally, Spybot Search and Destroy is a good all-purpose anti-spyware tool (http://www.safer-networking.org/en/index.html )

Caveat emptor, a full sweep with the above software eats at least 8 hours of time. I usually budget two full days for malware removal if I am asked to save a heavily-infected system. More if it turns out to be something incredibly nasty, as the state of the art in anti-detection and anti-removal tricks advances faster than the good guys can keep up.

Rootkit Revealer and Hijack This will both have entries detected even on clean systems, and require some technical know-how to interpret usefully.

Finally, even with all the above software run, there is no guarantee that it will actually disinfect your system. Stealthing technology is a hydra, for every one method we learn to detect and nullify seven more rise to take its place.

Posted on Jan 3, 2012, 1:02 PM

Respond to this message

Goto Forum Home
Responses

  1. Tried most of those... but. Thru-Hiker, Jan 3, 2012
    1. System Idle.... That One Guy, Jan 3, 2012

eXTReMe Tracker