Anti-Vermins System Alert Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Xeander50, Jan 4, 2007.

  1. Xeander50

    Xeander50 Private E-2

    First Open up Control Panel / System / Advanced / System Restore

    turn it off

    now reboot your PC into Safe Mode
    on reboot hit F8 if your system has a smart boot
    you need to do this 2x First for Boot device
    Second for safe mode menu (be quick Windows like to load)

    In safe mode turn on view System and Hidden files
    Open Recycler and remove any "S-" files you find there
    these are Registry entries waiting to reinfect the registry

    now click Start and Run and type in regedit
    under Edit select Find
    type in cthkpcv.dll and search for this file entry
    you should only find ONE instance of this in registry

    now that registry entry is gone you need to reboot
    back into safe mode to remove the target file
    with registry entry running the file will not delete

    Back in Safe mode for Second Time
    C:\WINDOWS\SYSTEM32\cthkpcv.dll
    open my computer
    select windows folder
    select system32 folder
    right click view arrange by name
    find the file cthkpcv.dll
    highlight it and hit shift del to delete with
    no entry to recyle bin

    you are ready Reboot PC back into normal window
    also if you normally use restore ON return the setting to ON

    there are 4 other registry entries associated with this System Alert
    Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion

    I havent found them yet for exact listing but I will and update this post
    however with above steps you will stop getting the system alerts

    Edit:
    Found 1 Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run
    Delete entry Antivermins with data C:\Program Files\AntiVermins\AntiVermins.exe /h
    the target folder is not on my PC but remove the registry entry
     
  2. Xeander50

    Xeander50 Private E-2

    PART 2 Read Below First !!!!

    Found 2 Hkey_Classes_Root\TypeLib\{600B9825-0AC9-4541-8C42-73B405413560}\1.0\0\win32
    Entry Default data C:\Program Files\AntiVermins\AntiVermins.exe
    again Program Directory is not on system but remove entry

    Found 3 Hkey_Classes_Root\TypeLib\{600B9825-0AC9-4541-8C42-73B405413560}\1.0\HELPDIR
    Entry Default data C:\Program Files\AntiVermins\
    I dont have this target folder on my PC but delete registry entry

    Found 4 Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*
    Entry may vary on mine its g data C:\Documents and Settings\{Windows User Name}\Desktop\Antivermins.txt
    deleting this registry as well but the file is not on my desktop

    Found 5 Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt
    Entry may vary on mine its f data C:\Documents and Settings\{Windows User Name}\Desktop\Antivermins.txt
    again this points a txt file on desktop not on my system delete registry entry

    I am certain there are more in Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion
    I will have to make another run thru registry to find these perhaps run an online scan for Identification


    Apparently the registry entries are made in preparation for the download of the Anti-Vermins Malware
    software from the pop-up alert
    this however just infects you deeper (I did a web search and saw the malicious nature and did not D/L the software)
    this software mascarades as a AD-ware/Malware removal tool and is actually a high risk threat

    I hope this data will assist others in removing the System Alert and Registry entries from thier system.
     
  3. Xeander50

    Xeander50 Private E-2

    Second pass thru registry and no new entries found
    Have not had a Security Alert in systray in days
    definetly has removed the annoyance from my PC.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There's an easier way. Use SmitFraudFix as shown in message number 5 in the below thread:

    http://forums.majorgeeks.com/showthread.php?t=111304&highlight=antivermins

    It will remove this and a load of other issues and registry keys that you probably missed. For example antivermins will normally add a subkey under

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

    There is also a good chance that you have other malware if you had this infection. These infections frequently come with other baggage. You should run our READ & RUN ME FIRST Before Asking for Support sticky thread and attach your logs to be sure you are clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds