Bad virus on computer not being picked up by Avast

G

Guest

Guest
I have a virus called important.exe which is apparantly a bitcoin miner and is chewing up my CPU. It keeps automatically launching even after ending the process in task manager. The file comes up in C:\Users\"name"\AppData\Local\Temp\nhq so when I delete it, it's recreated and I can't find what keeps creating the program. I've gone through my Programs and Features and no suspicious programs are there. After doing a full system virus scan through Avast it's shown up as completely clean. I know that this virus can be picked up after scanning my system with SpyHunter4 although I have to register to actually remove the virus which I have no intention of doing. Essentially, I'm looking for a reliable antivirus/malware program that is free and able to pick up this virus.
 
Solution
Download the programs Process Monitor, and Process Explorer from Microsoft Technet. Fire up Process Explorer, kill the file, you will then see what process starts it back up. The program kill will be in Red, and the process that starts it up will be Green. You can then Freeze the processes that are causing the issue, delete the file from the temp folder, and then kill both of the processes. After that, run Anti-Malwarebytes a time or 2. You can also create yourself a WDO bootable usb drive. It's the Windows Defender Anti-virus, but since you're creating it as a bootable USB, it will boot up, and scan your entire windows system with completely up to date AV signatures in OFFLINE mode. This is a really good way to perform a thorough scan...

Rhinofart

Distinguished
Jan 30, 2006
44
0
18,610
Download the programs Process Monitor, and Process Explorer from Microsoft Technet. Fire up Process Explorer, kill the file, you will then see what process starts it back up. The program kill will be in Red, and the process that starts it up will be Green. You can then Freeze the processes that are causing the issue, delete the file from the temp folder, and then kill both of the processes. After that, run Anti-Malwarebytes a time or 2. You can also create yourself a WDO bootable usb drive. It's the Windows Defender Anti-virus, but since you're creating it as a bootable USB, it will boot up, and scan your entire windows system with completely up to date AV signatures in OFFLINE mode. This is a really good way to perform a thorough scan on a windows system so that any hidden rootkits and such won't start up early in the boot process, and block your AV / AMW scans from detecting all the crap that's on your system.
 
Solution
G

Guest

Guest
Thanks so much Rhinofart. I was running Malwarebytes as I was trying your solution but I didn't need the Malwarebytes in the end because this worked perfectly! Kudos to you Sir, couldn't find anything like this online!
 

Rhinofart

Distinguished
Jan 30, 2006
44
0
18,610


No problem. Happy to help.