Does Prevx CSI remove kdjev.exe and other concerns

Discussion in 'Malware Help (A Specialist Will Reply)' started by 3strokes, Aug 19, 2008.

  1. 3strokes

    3strokes Private E-2

    Hi
    Advanced Windows Care 2 which I installed from MajorGeeks found a Startup it didn't like and showed me c:\windows\system32\kdjev.exe
    All other items were known to me.
    I searched the Internet and there were only two instances where kdjev.exe was even mentioned. Both labelled it as Malware and Prevx claimed it could remove it.
    I actually went into the registry (Win XP Pro SP2) and deleted every instance I found of kdjev.exe but, as you will probably have guessed it's still there.
    So I downloaded (from MajorGeeks Downloads) and ran Prevx CSI. It declared me free of any Malware.
    However kdjev.exe is STILL there/here/somewhere on my system
    I have enabled "viewing" all system and hidden files, but I can't find it anywhere on my hard drives.

    I had, of course, read the READ & RUN ME first but thought I'd see if a simple run of Prevx would fix this problem.
    A problem which "could" have been the cause of my IE6 Google searches being redirected to http://click.so and so and to http:// yellow.pages.

    Now that I realize I will have to do the whole READ & RUN MR FIRST, my question is (I have already downloaded all the required tools and am ready for Step 2 of Windows XP Cleaning procedure and would like to know if I have to do it all in one session or if I can, for ex. run SuperAntiSpyware then Spybot S&D and then power OFF for the night and resume with the rest the next day.
    Thanks in advance
     
    Last edited: Aug 19, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be best to do all steps with consecutively without rebooting except where the applications themselves require the reboots and do so automatically. Many malware infections these days will spread and/or mutate on power downs and power ups.

    You could just disconnect your cable from the internet after installing and updating SUPERAntiSpyware and Spybot and then leave your PC on for the night. Note: Only one scan at a time.
     
  3. 3strokes

    3strokes Private E-2

    I want to thank you for the wonderful instructions and tools you have put together. I ran through the Read and Run me FIRST and it worked like a charm.

    The only problem (not really a problem but an extra task that took more than 55 minutes) I ran into was when trying to install the Win XP Recovery Console. My CD was not an SP2 and the page in Microsoft had been changed. Their method involved copying the CD's i386\ subdirectory onto my hard drive and download SP2 and integrate it into the re-installation and practically re-install Win XP-SP2. (Actually Combofixe's instructions were not up-to-date for the installation of the Recovery Console and I didn't want to register myself as a Forum user there, just to tell them this.)

    My computer "looks" and "acts" OK.
    Should I still send you the logs? Just in case?


    Thank you all, again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I have mentioned this to the creator of ComboFix but nothing has changed and he has requested us to link to those official instructions. We had our own previously which I preferred but we need to support the designers wishes.

    It is always worth having them checked out.
     
  5. 3strokes

    3strokes Private E-2


    Thanks.
    Attaching part 1
     

    Attached Files:

  6. 3strokes

    3strokes Private E-2

    And here's part 2

    Thanks
     

    Attached Files:

  7. 3strokes

    3strokes Private E-2

    Hi Chaslang
    Just wanted to let you know what I did after READ & RUN ME FIRST.
    (And I really am not trying to bump my thread. You can respond to it as per the older messages.....)

    In order to disable my AV tool (McAfee..... OK, don't laugh please) I un-installed it.

    After running all the R&R1st programs, I noticed that I had a lot of antispyware programs but no AVirus and my Firewall was the much maligned Windows XP Firewall. So, I decided to try ZoneAlarm Security Suite (for both Firewall and AV). I was on XP Pro SP2. ZoneAlarm requested a certain Hotfix. To install that Hotfix, Microsoft insisted on updating me to SP3 (which I did) and eventually ZoneAlarm Security Suite is ON and running.

    Just wanted to let you know that my registry must have changed from the time the logs I sent you were created and that, possibly, I know that I might be asked to run new logs.

    Thanks
    Ahmed
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs, it looks like your malware ( kdjev.exe) has been removed.

    If you are not having any more problems, we need to complete final instructions.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. 3strokes

    3strokes Private E-2

    As well as a few other evil pieces that I was not even aware of.

    It worked like a charm. :-D


    No offense meant, but I believe you may have been typing a bit too fast. Did you actually mean "Delete the C:\combofix folder from C:\" ?

    But when all has been said and done (in this case "done and then said") you guys are fabulous; helping computer users out of quicksand and rescuing us, just for the love of computing, is fantabulous. A Gazillion thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It could be written that way too but what was meant by that statement is to delete the C:\combofix folder that was created by running ComboFix. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds