Avenger program/problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by allbuggedout, Jun 7, 2006.

  1. allbuggedout

    allbuggedout Private E-2

    Hi, can somebody help me with a problem I am having with getting the Avenger program to run the "malwarewipe" removal solution.
    When I try to extract the script provided by "chaslang" I quote:-

    Files to delete:
    %systemdrive%\mw_install.exe
    %windir%\mw_install.exe
    %windir%\system32\mw_install.exe
    %systemdrive%\Documents and Settings\Administrator \desktop\malwarewipe.lnk
    %systemdrive%\Documents and Settings\Administrator\Start Menu\malwarewipe 4.0.lnk
    %systemdrive%\Documents and Settings\Administrator \Application Data\Microsoft\Internet Explorer\Quick Launch\malwarewipe 4.0.lnk

    Folders to delete:
    %systemdrive%\program files\malwarewipe
    %systemdrive%\documents and settings\administrator\start menu\programs\malwarewipe

    the Avenger program says that there is no such script available!
    I have copied it to my clipboard and subsequently into word.

    Please help as I am being plagued by this malwarewipe. Everytime I go on line it swamps my browser with internet explorer websites which overloads my connection!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some info was deleted from the end of the procedure by mistake. I added it back in. Try it now.

    Seems our images of what it looks like are missing now. I'll have to find out where I have them and re-upload.

    Please follow the directions in the Malwarewipe Removal Procedure. It tells you what to do if still having problems at the end.
     
    Last edited: Jun 8, 2006
  3. allbuggedout

    allbuggedout Private E-2

    Malware query/Result of Avenger search and destroy

    Hi, I was able to eventually use the Avenger program to remove "malwarewipe". However as the results show it did not find the "malwarewipe" program, but I still have the same online problems with unwanted linked internet explorer web sites.

    What ever is instigating this invasion is and has imported desktop icons, that when clicked on starts up my default browser and directs it to the web site.

    There are two icons, #1 onlinesecuritysolution.net #2 freetestonline.net
    As well as an icon that appears on the main bar at the bottom of the screen. This icon is a yellow triangle with an exclamation mark, every 3 minuites or so a pop up text bubble appears with the message:-

    "System has detected 4 active spyware applications

    that may cause your computer to crash and restart, slow it to a crawl and even shut down entirely
    click the icon to get rid of unwanted spyware"

    All of these icons and the two web sites appear to be linked to other web sites such as playeurolotto.com, updatesystem.com, entertainsite.com, thespygaurd.com plus a casino and adult sex site.
    I am also getting so called system alerts telling me that it has discovered 4 errors and that my computer has slowed down, I have increased spam etc...
    click OK to install anti spyware.

    Since I have been having these problems I downloaded the Lavasoft firewall program to help fend of these intrusions it has worked to some degree but because there is so much intrusion it to is interfering with the smooth flow of my internet work and surf.

    Any help you can give me with this would be greatlfully recieved!

    Here are the results of the Avenger scan:-

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\fxuxkdxv

    *******************

    Script file located at: \??\C:\Program Files\pcmkhkak.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:



    File C:\mw_install.exe not found!
    Deletion of file C:\mw_install.exe failed!

    Could not process line:
    C:\mw_install.exe
    Status: 0xc0000034



    File C:\WINDOWS\mw_install.exe not found!
    Deletion of file C:\WINDOWS\mw_install.exe failed!

    Could not process line:
    C:\WINDOWS\mw_install.exe
    Status: 0xc0000034



    File C:\WINDOWS\system32\mw_install.exe not found!
    Deletion of file C:\WINDOWS\system32\mw_install.exe failed!

    Could not process line:
    C:\WINDOWS\system32\mw_install.exe
    Status: 0xc0000034



    Could not open file C:\Documents and Settings\Administrator \desktop\malwarewipe.lnk for deletion
    Deletion of file C:\Documents and Settings\Administrator \desktop\malwarewipe.lnk failed!

    Could not process line:
    C:\Documents and Settings\Administrator \desktop\malwarewipe.lnk
    Status: 0xc000003a



    Could not open file C:\Documents and Settings\Administrator\Start Menu\malwarewipe 4.0.lnk for deletion
    Deletion of file C:\Documents and Settings\Administrator\Start Menu\malwarewipe 4.0.lnk failed!

    Could not process line:
    C:\Documents and Settings\Administrator\Start Menu\malwarewipe 4.0.lnk
    Status: 0xc000003a



    Could not open file C:\Documents and Settings\Administrator \Application Data\Microsoft\Internet Explorer\Quick Launch\malwarewipe 4.0.lnk for deletion
    Deletion of file C:\Documents and Settings\Administrator \Application Data\Microsoft\Internet Explorer\Quick Launch\malwarewipe 4.0.lnk failed!

    Could not process line:
    C:\Documents and Settings\Administrator \Application Data\Microsoft\Internet Explorer\Quick Launch\malwarewipe 4.0.lnk
    Status: 0xc000003a



    Folder C:\program files\malwarewipe not found!
    Deletion of folder C:\program files\malwarewipe failed!

    Could not process line:
    C:\program files\malwarewipe
    Status: 0xc0000034



    Could not open folder C:\documents and settings\administrator\start menu\programs\malwarewipe for deletion
    Deletion of folder C:\documents and settings\administrator\start menu\programs\malwarewipe failed!

    Could not process line:
    C:\documents and settings\administrator\start menu\programs\malwarewipe
    Status: 0xc000003a


    Completed script processing.

    *******************

    Finished! Terminate.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware query/Result of Avenger search and destroy

    Please do not start new threads for your problem. You had already begun one so I merge you back to the original.
     
  5. allbuggedout

    allbuggedout Private E-2

    Hi, chaslang,
    Sorry, I`m new to post boards and I don`t have much experience with the rules concerning threads.
    However I do still have a pressing problem with my ventures online and would appreciate any imput you may be able to give me, so that I can sort the problem out. Whilst Iwas online last night my service provider went of line because it was bombarded by internet explorer websites that appeared all at the same time.
    I would also like to mention that I do not have broad band, as it is not yet available where I live. If that has any relevence?

    Further to my previous post, one of the web sites that has tryed to access my computer is "www7.logih.com/777/help.asp".

    Also the icon I mentioned with the yellow triangle and exclamation mark, also informs me that "your computer is infected with spyware managing popups (OHPE ver 4.12_23).Click the icon etc..."

    All these unwanted intrusions seem to be linked to Win_32EXE.

    As Ive mentioned any help you may be able to suggest would be most welcome as I am pretty much a novice with computers and the pitfalls of internet surfing!

    Thanks!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have just completed the rest of the directions in the Malwarewipe Removal Procedure. At the end it says:
    That is what you shoud do. Also remember logs should be attachments. What you posted previously for the avenger.txt log was inline text.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds