Antivirus XP virus on computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Deebo16, Jun 26, 2008.

  1. Deebo16

    Deebo16 Private E-2

    Hey how's it going? I'm looking for a little help. Was trying to install a DVD copier program on my other computer and ended up with a virus. Now whenever trying to run a program or anything, I'm told that I don't have the correct permissions. Also on startup, a new Antivirus XP virusscan runs at all times. Trying to scan with Kaspersky, but it does not clean up each virus that it finds. After restarting and thinking everything is gone, the virus loads itself again. Looking for some help please. Thank you in advance.

    I will be posting a HIJACKTHIS log in a few minutes after I run the scan on the other computer.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    No!! It will be deleted. Please read the sticky threads. You need to do the below.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Deebo16

    Deebo16 Private E-2

    Ok I will do this and get back to you.
     
  4. Deebo16

    Deebo16 Private E-2

    Here's my update. I've attached the logs and zip files. Thanks for the help. I don't see the Antivirus XP 2008 program installed anymore and the computer seems to be running better.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the requested log from ComboFix. Did you have a problem running it? Based on what I see on your Desktop you did not rename it properly.
     
  6. Deebo16

    Deebo16 Private E-2

    I did have a problem running it. I thought I was supposed to rename it "cf.exe"? Is that not correct?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What problem? You need to be specific.

    Yes it is but you named it like below which is a quote from your logs:
    Notice the two exe file extensions. This probably happened because you did not follow the step in the READ ME to enable viewing of hidden files and also extensions. It should be enabled now though because running MGtools will force those changes to be completed.

    Rename it properly and then try running it again. Also if it does not run in normal boot mode, try safe boot mode. It would be good if you get this to run since we need the log to check for other problems and also it is useful in cleaning up additional malware I see that is still on your PC. Don't forget the instructions for running ComboFix did say you have to shutdown other protection programs. Kaspersky may be getting in your way of running ComboFix. Too bad it did not get in the way of the malware being installed in the first place which is what it should be doing. ;)
     
    Last edited: Jun 28, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I decide to continue on with your malware removal using another tool but I would still like to see a ComboFix log if you can get it to run.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdvxi.exe] C:\WINDOWS\system32\kdvxi.exe
    O4 - HKLM\..\Run: [Windows Update Service] C:\WINDOWS\svchost.exe
    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. Deebo16

    Deebo16 Private E-2

    Here are my two new attachments.

    I was able to run the regedit4 successfully with no problems.
     

    Attached Files:

  10. Deebo16

    Deebo16 Private E-2

    Was able to run the ComboFix this time without a problem after making the corrections.
     

    Attached Files:

    • log.txt
      File size:
      12.7 KB
      Views:
      1
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to tell me how things are working. Your logs are clean but since you ran ComboFix after doing my fix you will need to rerun just the step for adding the fixME.reg patch to the registry again.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds