After virus removal problems with saving files

Discussion in 'Malware Help (A Specialist Will Reply)' started by not_guilty, Aug 12, 2014.

  1. not_guilty

    not_guilty Private E-2

    I am really not sure were to post this, but it is connected with unwanted files/viruses etc removal. It is complex so please bear with me

    About a year and a half ago I've bought X-Mass present, spanky new Asus notebook for my sister in law.
    It came with pre-installed 2013 Kaspersky Internet suit, including installation media disk (KS program)
    I got curious or maybe greedy and used the media to install KS I-Suit on my high end ASUS Notebook. Which came with Win 7 Premium x64.
    On second internal HD I had recently installed Win 8 back then.
    (plus I have 2 different Linux OS's in total)

    Kaspersky on the first scan detected regw2.exe I did google and opinions were different about the file . but better safe than sorry.
    From MS: http://www.microsoft.com/security/p...y.aspx?Name=TrojanDropper:Win32/FakeFlexnet.A

    Personally I have no clue how it got there (the regw2.exe), since on my Win 7 on both Program Files folders (x86 & x64) I have in total 150 GB of stuff.
    on Win 8 I had very few programs installed.. nothing illegal (cracks, keygens etc) but still it got there.
    I did compare Win 7 progs installed versus Win 8 (with much, much less progs) even by process of elimination I cannot figure out who is guilty.

    Anyhow on the first KAS scan both on Win 7 and 8 I got positive result of infection. I applied recommended settings like removal and standard reboot.

    Now ever since the removal I cannot save file(s) to disk, it applies only to save as dialog to be specific no matter the extension. with the following error:
    "There are no more files"
    Search results brought me to many forums, including microsoft one. But everyone was clueless how the problem got there (contrary to me) and possible solutions were to no avail for me.

    http://answers.microsoft.com/en-us/...drive-in/f7f706af-4656-4692-9d33-599d983ad9ff

    Note
    I can create empty files any extension, and then renamed them and in this scenario any document/project I want to save I just overwrite by previously creating empty files.

    In my opinion Kaspersky is guilty, whatever the program did while removing the threat created my current problem.
    I wrote to Kaspersky support outlining the problem, but they never replied (?)

    On Win 7 I have restored the whole partition image and i was back in business. with Avast Internet Security.
    Then I used Microsoft tutorial, how to go about the removal of regw2.exe which included removal/changes registry entries plus removal the regw2.exe in /System32 folder.
    link:
    http://www.microsoft.com/security/p...?Name=TrojanDropper:Win32/FakeFlexnet.A#tab=2
    Problem solved.

    But I had no backup image for Win 8.
    Soon after I dumped Kaspersky and now I have free Comodo Firewall and free Avira on Win 8. Yippee :)
    But the problem is still there. :(
    Yes I could reinstall Win 8, but it is very nicely customized, and I don't want to go to trough headache of zillion reboots installing the right drivers
    plus tons of MS updates

    BTW Malwarebytes never had any problem with regw2.exe

    Now on Avast forum there is a thread about the file that is false positive.
    From the author of the reg2.exe NOT regw2.exe file and then the reply from the mods
    link :
    https://forum.avast.com/index.php?topic=30975.0
    Is this the reason that Avast scans never picked up as a threat because of misspell ? Extremely doubtful but anything is possible.

    I hate when different anti-virus vendors have different opinion(s)
    on any possible virus/trojan/worm etc

    Anyone here would want to give me some hints?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds