Can't remove virus with AVG

Discussion in 'Malware Help (A Specialist Will Reply)' started by TinaS, Jul 8, 2009.

  1. TinaS

    TinaS Private E-2

    Ran a full system scan with AVG Free and it came up with 2 infections, both in the same folder - "C:\System Volume Information\_restore{624D041B-9C1D-4D7A-9E2C-6A4B022D569B}\RP485\A0091120.exe:
    (the other had more tagged on the end - \$JF\pwdump\lsremora.dll) "Trojan horse PSW.OnlineGames3.GLN";"Infected"

    and 3 spyware - all in "C:\System Volume Information\_restore{624D041B-9C1D-4D7A-9E2C-6A4B022D569B}\RP485\A0091120.exe: (one has \$JF\pwdump\pwdump6_setup.exe) (another has \$JF\pwdump\servpw.exe) (the last has \$JF\pwdump\servpw64.exe)
    "Potentially harmful program Tool.KS";"Potentially dangerous object"
    "Potentially harmful program Tool.KV";"Potentially dangerous object"
    "Potentially harmful program HackTool.HKB";"Potentially dangerous object"

    The problem is, when I click on Remove All Unhealed Infections - I get this message: Moved object is bigger than the archive size limit. C:\System Volume Information|_restore{624D041B-9C1D-4D7A-9E2C-6A4B022D569B}\RP485\A0091120.exe

    I can click on Go to file or Ignore. If I go the file, it takes me to this file, which I have no clue what to do with it. If I choose Ignore, nothing gets healed.

    Any help would be appreciated!!!
     
  2. TinaS

    TinaS Private E-2

    I'm attaching the log files as requested in the Read and Run Me First post.

    Thanks!

    Tina :)
     

    Attached Files:

  3. TinaS

    TinaS Private E-2

    Last log file!

    Tina
     

    Attached Files:

  4. TinaS

    TinaS Private E-2

    O.K. :confused I guess no one can help me with this, but thanks for looking at it. I think I got it figured out. I disabled my System Restore, rebooted, scanned again and nothing came up on that scan. So I'll restore the System Restore and try scanning again.

    Better luck next time, right?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We work threads from oldest to newest. That means there will be a lag between when you post and when it comes up in our queue. Today is you lucky day, :)

    Now, as you found out, the only way to remove infections in the system restore files is to toggle system restore.

    However, you have one file that needs to be removed, so use windows explorer to find and delete:
    c:\windows\system32\f9t.dat

    Now you have this installed:
    Itivity Test

    But your HJT log shows that the service for this is missing all the files:
    Did you try to uninstall it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds