hdav.exe?

Swifty

New member
Power User
Local time
1:29 AM
Messages
390
Location
Sioux Lookout, Ontario
Alright well I had not been on my computer all day today and when I had signed onto my computer my task bar was not showing. I tried going into the task manager and I ran explorer.exe and my screen just flashed like crazy it would pop up then disappear multiple times and below it hdav.exe showed up about 4 times bouncing explorer.exe around.

And basically my computer is pretty well virus infected I am pretty sure I have ran multiple scans with BitDefender anti virus and malicious searches, I also used Tuneup utilities and spy bot search and destroy some of it could not be deleted I know that bitDefender detects a trojan when my computer starts up but when I try to put it in quarenteen it drives my computer nuts.

Just now my browser keeps directing me to inappropriate sites and possibly illegal ones at that most, I can't do a system restore because my computer says it fails each time, BitDefender does not detect anything under its anti virus section but in malicious it does. Some of it can not be deleted.

If any one can suggest some help that would be great without having to reformat my computer, I really can't afford to lose everything not now and I have no way of backing up my things.

And I don't doubt that this Trojan/Virus is stealing my information right now so I am trying to keep off of personal websites at the moment.
Thanks
Swifty.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 Professional
CPU
Intel i5-4690k
Motherboard
MSI Z97 Gaming 5
Memory
Corsair Vengeance Pro Series 16GB DDR3 1866mhz
Graphics Card(s)
R9 390 8GB
Monitor(s) Displays
24" Acer 3D monitor
Hard Drives
2TB Seagate HDD
120GB Adata SSD
PSU
750 watt
Case
Zalmann Z9
Cooling
Fan
Keyboard
Razer Deathstalker
Mouse
Anker Gaming Mouse
Internet Speed
20MB/S
Antivirus
AVG
Browser
Google Chrome
Alright well I had not been on my computer all day today and when I had signed onto my computer my task bar was not showing. I tried going into the task manager and I ran explorer.exe and my screen just flashed like crazy it would pop up then disappear multiple times and below it hdav.exe showed up about 4 times bouncing explorer.exe around.

And basically my computer is pretty well virus infected I am pretty sure I have ran multiple scans with BitDefender anti virus and malicious searches, I also used Tuneup utilities and spy bot search and destroy some of it could not be deleted I know that bitDefender detects a trojan when my computer starts up but when I try to put it in quarenteen it drives my computer nuts.

Just now my browser keeps directing me to inappropriate sites and possibly illegal ones at that most, I can't do a system restore because my computer says it fails each time, BitDefender does not detect anything under its anti virus section but in malicious it does. Some of it can not be deleted.

If any one can suggest some help that would be great without having to reformat my computer, I really can't afford to lose everything not now and I have no way of backing up my things.

And I don't doubt that this Trojan/Virus is stealing my information right now so I am trying to keep off of personal websites at the moment.
Thanks
Swifty.


Do you have a backup of your data? If I were you I would download malwarebytes and run a scan just to get started. Hdav.exe seems to be a virus and I cant find any infomation saying it is used for anything else.

Boot into safe mode, run malwarbytes. Did you have an anti virus app on the computer when it was infected?

Ken
 

My Computer

Computer Manufacturer/Model Number
HP Pavillion dv-7 1005 Tx
OS
Win 8 Release candidate 8400
CPU
[email protected]
Memory
4 gigs
Graphics Card(s)
Nvidia 9600M
Sound Card
HD built-in
Monitor(s) Displays
17" Wxga
Screen Resolution
1440x900
Cooling
none
Internet Speed
45Mb down 5Mb up
Do you have a backup of your data? If I were you I would download malwarebytes and run a scan just to get started. Hdav.exe seems to be a virus and I cant find any infomation saying it is used for anything else.

Boot into safe mode, run malwarbytes. Did you have an anti virus app on the computer when it was infected?

Ken

All I know is hdav.exe messes with applications and it runs on start up, it can rename itself and make copies of itself as different forms as well as making new forms of itself.

I have also done a scan with Prevx and it detected the files I described, but I need a license key typical.

And now I am trying the program you told me about.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 Professional
CPU
Intel i5-4690k
Motherboard
MSI Z97 Gaming 5
Memory
Corsair Vengeance Pro Series 16GB DDR3 1866mhz
Graphics Card(s)
R9 390 8GB
Monitor(s) Displays
24" Acer 3D monitor
Hard Drives
2TB Seagate HDD
120GB Adata SSD
PSU
750 watt
Case
Zalmann Z9
Cooling
Fan
Keyboard
Razer Deathstalker
Mouse
Anker Gaming Mouse
Internet Speed
20MB/S
Antivirus
AVG
Browser
Google Chrome
MalwareBytes Anti-Malware is good as long as it will actually run. Some viruses have a script that can cause it to not install/run, hence why you should try in safe mode, or there are other work arounds you can find via google or another search provider.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba P775-S7100
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core i5-2450M @2.5 GHz
Memory
6 GB DDR3 1333MHz
Graphics Card(s)
Intel HD 3000
Monitor(s) Displays
Built-in 17.3" LED; 22" Insignia NS-L22Q-10A
Screen Resolution
1600x900; 1360x768
Hard Drives
750 GB Hitachi
1TB Seagate FreeAgent External
Internet Speed
Verizon DSL Speed(Down/Up): 3360 Kbps / 800 Kbps
Antivirus
MSE and MBAM Pro
Browser
IE10
here are the names of the ones that prevx found

-hkpop.dll
-Hdav.exe
-lkpop.dll
-l84alx.exe
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 Professional
CPU
Intel i5-4690k
Motherboard
MSI Z97 Gaming 5
Memory
Corsair Vengeance Pro Series 16GB DDR3 1866mhz
Graphics Card(s)
R9 390 8GB
Monitor(s) Displays
24" Acer 3D monitor
Hard Drives
2TB Seagate HDD
120GB Adata SSD
PSU
750 watt
Case
Zalmann Z9
Cooling
Fan
Keyboard
Razer Deathstalker
Mouse
Anker Gaming Mouse
Internet Speed
20MB/S
Antivirus
AVG
Browser
Google Chrome
hi....d/l hitman pro and scan...it has 30 days free removal and has five av engines including prevx,dr web.ikarus,A2,nod,g data

after hitman d/l and scan with mbam
 

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home
So I used mbam and hitman pro it made my computer faster and as far as I know deleted most of the problems but when I rebooted after hitman it said that windows needed to repair itself and both of those programs no longer exist on my computer so I had to reinstall them, any idea? a few of the virus names popped up too, one in cmd.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 Professional
CPU
Intel i5-4690k
Motherboard
MSI Z97 Gaming 5
Memory
Corsair Vengeance Pro Series 16GB DDR3 1866mhz
Graphics Card(s)
R9 390 8GB
Monitor(s) Displays
24" Acer 3D monitor
Hard Drives
2TB Seagate HDD
120GB Adata SSD
PSU
750 watt
Case
Zalmann Z9
Cooling
Fan
Keyboard
Razer Deathstalker
Mouse
Anker Gaming Mouse
Internet Speed
20MB/S
Antivirus
AVG
Browser
Google Chrome
So I used mbam and hitman pro it made my computer faster and as far as I know deleted most of the problems but when I rebooted after hitman it said that windows needed to repair itself and both of those programs no longer exist on my computer so I had to reinstall them, any idea? a few of the virus names popped up too, one in cmd.

1.hmmmm.......was that after restart before boot?
scanners usually delete persistent malware that way when they are not active.
2.restart again.....do you get the popup ?
3.give HMP and prevx one more run.
 

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home
If you can download and burn an iso to a cd, suggest download

BitDefender Rescue CD

Boot to safe mode, remove system restore points. Reboot to the Rescue CD and run scans. Reboot to safe mode and scan with MalwareBytes. Virus can and will hide in your Restore Points, and reinfect after you start windows. A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Can you give us more detail on what happened after the reboot. I'm not sure exactly what what happened, and without knowing that I can't help any. Some others might be able to.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba P775-S7100
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core i5-2450M @2.5 GHz
Memory
6 GB DDR3 1333MHz
Graphics Card(s)
Intel HD 3000
Monitor(s) Displays
Built-in 17.3" LED; 22" Insignia NS-L22Q-10A
Screen Resolution
1600x900; 1360x768
Hard Drives
750 GB Hitachi
1TB Seagate FreeAgent External
Internet Speed
Verizon DSL Speed(Down/Up): 3360 Kbps / 800 Kbps
Antivirus
MSE and MBAM Pro
Browser
IE10
Can you give us more detail on what happened after the reboot. I'm not sure exactly what what happened, and without knowing that I can't help any. Some others might be able to.
Well after scanning with Hitman, it stated that some of the deleted malware/trojans what ever that was on my computer needed my computer to restart before it could delete them fully, so I rebooted and then it loads up to the screen where it says loading windows files and then goes into windows repair and says that my computer failed to boot up, and it is repairing any errors, then when I finally log in, Hitman and Malwarebytes no longer exist on my entire computer. I am guessing this "trojan" or "virus" is causing this. Every time I log in BitDefender says "Trojan detected" and I select to put it in the virus vault, but Hitman said that it had deleted it as well as Malwarebytes.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 Professional
CPU
Intel i5-4690k
Motherboard
MSI Z97 Gaming 5
Memory
Corsair Vengeance Pro Series 16GB DDR3 1866mhz
Graphics Card(s)
R9 390 8GB
Monitor(s) Displays
24" Acer 3D monitor
Hard Drives
2TB Seagate HDD
120GB Adata SSD
PSU
750 watt
Case
Zalmann Z9
Cooling
Fan
Keyboard
Razer Deathstalker
Mouse
Anker Gaming Mouse
Internet Speed
20MB/S
Antivirus
AVG
Browser
Google Chrome
Can you give us more detail on what happened after the reboot. I'm not sure exactly what what happened, and without knowing that I can't help any. Some others might be able to.
Well after scanning with Hitman, it stated that some of the deleted malware/trojans what ever that was on my computer needed my computer to restart before it could delete them fully, so I rebooted and then it loads up to the screen where it says loading windows files and then goes into windows repair and says that my computer failed to boot up, and it is repairing any errors, then when I finally log in, Hitman and Malwarebytes no longer exist on my entire computer. I am guessing this "trojan" or "virus" is causing this. Every time I log in BitDefender says "Trojan detected" and I select to put it in the virus vault, but Hitman said that it had deleted it as well as Malwarebytes.

I think it's as I posted, you need to get rid of your restore points, and do your scanning outside of windows, with a boot cd, then cleanup in safe mode. Hopefully it can get at what's hiding. A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba P775-S7100
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core i5-2450M @2.5 GHz
Memory
6 GB DDR3 1333MHz
Graphics Card(s)
Intel HD 3000
Monitor(s) Displays
Built-in 17.3" LED; 22" Insignia NS-L22Q-10A
Screen Resolution
1600x900; 1360x768
Hard Drives
750 GB Hitachi
1TB Seagate FreeAgent External
Internet Speed
Verizon DSL Speed(Down/Up): 3360 Kbps / 800 Kbps
Antivirus
MSE and MBAM Pro
Browser
IE10
It sounds like this virus means business. Did you try booting into safe mode? If all else fails, sometimes the best thing to do is a clean install. Then you know that no viruses exist on the machine.

http://www.sevenforums.com/tutorials/91339-ssd-hdd-optimize-windows-reinstallation.html
http://www.sevenforums.com/tutorials/1649-clean-install-windows-7-a.html?ltr=C

EDIT: it looks like some people still have other advice. I would save the clean install for a last resort.
Yea I am trying not to reformat my computer in fear of losing all my files, because I have no way of backing anything up as far as I know, I do not own a external hard drive or blank cd's and I am tight on cash right now because of having to save it for my rent.

I might just put up with it until I can move out in august and have money then so I can afford an external HDD but right now I am trying to see if I can get rid of it without the reformat.

No I have not tried it on safe mode because I can't get to it with my television as a monitor because when I start up only half the screen shows because of the resolution. But if there is another way to do it from msconfig that would be great I can try it there.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 Professional
CPU
Intel i5-4690k
Motherboard
MSI Z97 Gaming 5
Memory
Corsair Vengeance Pro Series 16GB DDR3 1866mhz
Graphics Card(s)
R9 390 8GB
Monitor(s) Displays
24" Acer 3D monitor
Hard Drives
2TB Seagate HDD
120GB Adata SSD
PSU
750 watt
Case
Zalmann Z9
Cooling
Fan
Keyboard
Razer Deathstalker
Mouse
Anker Gaming Mouse
Internet Speed
20MB/S
Antivirus
AVG
Browser
Google Chrome
You have a "Backdoor" Trojan .... change all of your passwords, using another known 'clean' computer.

You will also need to flush your DNS cache and restore MS's original Hosts file.
Copy and paste these lines in Note pad.
@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

Save as flush.bat to your desktop. Right click on the file, choose to run as Administrator. Your computer will reboot itself.

Now, run an Antivirus scan and an Anti-malware scan.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
You have a "Backdoor" Trojan .... change all of your passwords, using another known 'clean' computer.

You will also need to flush your DNS cache and restore MS's original Hosts file.
Copy and paste these lines in Note pad.
@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

Save as flush.bat to your desktop. Right click on the file, choose to run as Administrator. Your computer will reboot itself.

Now, run an Antivirus scan and an Anti-malware scan.
Thanks wherever you found that out, surely it works perfectly all problems solved I don't even see anymore pop ups of the trojan thankfully. Thanks a lot Jacee
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 Professional
CPU
Intel i5-4690k
Motherboard
MSI Z97 Gaming 5
Memory
Corsair Vengeance Pro Series 16GB DDR3 1866mhz
Graphics Card(s)
R9 390 8GB
Monitor(s) Displays
24" Acer 3D monitor
Hard Drives
2TB Seagate HDD
120GB Adata SSD
PSU
750 watt
Case
Zalmann Z9
Cooling
Fan
Keyboard
Razer Deathstalker
Mouse
Anker Gaming Mouse
Internet Speed
20MB/S
Antivirus
AVG
Browser
Google Chrome
Jacee is an expert on virus removal. I figured as soon as she said something the problem would be solved.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba P775-S7100
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core i5-2450M @2.5 GHz
Memory
6 GB DDR3 1333MHz
Graphics Card(s)
Intel HD 3000
Monitor(s) Displays
Built-in 17.3" LED; 22" Insignia NS-L22Q-10A
Screen Resolution
1600x900; 1360x768
Hard Drives
750 GB Hitachi
1TB Seagate FreeAgent External
Internet Speed
Verizon DSL Speed(Down/Up): 3360 Kbps / 800 Kbps
Antivirus
MSE and MBAM Pro
Browser
IE10
Great help Jacee, should he do anything else?

A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Back
Top