infected with kxvo.exe and other programs are having problems.

Discussion in 'Malware Help (A Specialist Will Reply)' started by sleepy_eyes, Mar 23, 2008.

  1. sleepy_eyes

    sleepy_eyes Private E-2

    hi,

    i'm new here and i'm hoping that someone can help me clean my computer as i have had no reply in other forums.

    i've done the "READ & RUN ME FIRST" procedure and i think some of my problems have been solved (i.e. disabled task manager and admin tools) but i'm not sure whether my computer is really clean so i'm hoping for some assistance. one problem that i still have is that some programs on my computer are terminating abnormally (the "program X has encountered a problem and needs to close. sorry for the inconvenience" error pops up). such is that case for my AVG antivirus updater. my burner also behaved the same way before the READ & RUN ME FIRST procedure. i'm not sure if there are any other programs that behave this way. anyway, here are my logs and i hope that you could help me. i'd really appreciate it. thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. sleepy_eyes

    sleepy_eyes Private E-2

    hi TimV, thanks for the quick reply. i'm currently in the office so i'll perform those tasks when i get home. i'll get back to you after i've done the things you've asked me to do.

    i have a couple questions that i forgot to put on my first post:

    1. when i got infected, i had my removable hard disk plugged in to my desktop. i had a feeling it got infected so i plugged it in to another computer and tried to clean in manually. i was able to delete an instance of ojbss9gv.com and autorun.ini. should i assume that it's clean already or should i plug it in to my desktop again and run scans with my computer?

    2. while reading the procedures on how to run mgtools, i received one error regarding the .net framework not being installed on my system. do you have any idea where i can get it? and are there any special instructions for it to be installed?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. sleepy_eyes

    sleepy_eyes Private E-2

    hi,

    i've performed the instructions you've given me. my system seems better now. i have access to my admin tools again such as task manager, cmd, etc. and i'm experiencing no more slowdown. however, some of my programs, most notably my avg antivirus still has problems. the most prevalent problem that i'm having with avg is that when it updates, an error pops up saying that "this program has performed an illegal operation and needs to close" so i can't update my antivirus. is this due to kxvo.exe or is it unrelated? would you suggest just reinstalling avg? hope you could give me some feedback regarding my questions here and in the post above. thanks.

    below are my new logs.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, it may have messed with AVG...so just uninstall and re-download it.

    Also use windows explorer to find and delete these:
    C:\WINDOWS\unins000.dat
    C:\WINDOWS\unins000.exe
    C:\WINDOWS\dump631f.tmp
    C:\WINDOWS\dump6dcd.tmp

    Let me know if you are having any other problems.
     
  7. sleepy_eyes

    sleepy_eyes Private E-2

    ok, i'll just reinstall avg.

    i've deleted the things you mentioned. anything else i should do?

    in scanning my external HD, should i run everything on the READ ME & RUN FIRST section? or would scanning with SAS and spybot s&d be enough?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sas and spybot should do it ....let me know if they find anything.

    When we are done, I will give you the final cleanup.
     
  9. sleepy_eyes

    sleepy_eyes Private E-2

    hi,

    i've run SAS and spybot s&d on my hard disks.

    SAS found one object on my C:\ (adware.urlblaze) which is a browser helper object but other than that, there was nothing. my external HD was clean.

    spybot didn't find anything on both my HDs.

    what's the next step for me?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know:

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  11. sleepy_eyes

    sleepy_eyes Private E-2

    that's great news. i'll work on those when i get home later.

    i have a few questions again. i just want to get your opinions/suggestions regarding a few things.

    1. i was instructed to rename combofix.exe to cf.exe, should rename it back for the uninstallation to work?

    2. i've read the "how to protect yourself from malware" instructions and i have almost all of the needed programs on my machine. i think the reason why i got infected was i uninstalled my firewall (zonealarm 7) since i was having some issues with it. i'm looking into getting a new firewall, maybe comodo since i've seen good reviews about it. would you advise getting comodo?

    3. i also have ad-aware 2007 on my desktop at home. i have the free one so there's no real time protection, so i'm thinking of uninstalling it and just replace it with SAS. would you recommend that?

    sorry if i'm asking so many questions. i'm not really an expert at this but i'm really concerned about my computer's security. thanks for bearing with me.
     
  12. sleepy_eyes

    sleepy_eyes Private E-2

    hi,

    just an update. i've performed all the final steps that you gave me. everything is fine. i just have to install a new firewall which i'm working on as i type.
     
  13. sleepy_eyes

    sleepy_eyes Private E-2

    i've just finished installing comodo free personal firewall 3.0. do you have some sort of tutorial on how to use these? i'm not sure about what to do with the alerts that it gives me. it would be helpful if i could get a tutorial of how to use it.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The alerts should be telling you what is trying to either access your computer (usually as a result of doing an update or a large installation from a compressed download), so you would know what it is and allow it .....or, something is trying to access your computer ...again, something trusted or not.

    I would suggest that you ask those questions in the software section. They will be more than happy to answer all those questions. :)
     
  15. sleepy_eyes

    sleepy_eyes Private E-2

    ok thanks TimW! i'll try to swing by that forum instead regarding my questions. thank you again for all your help and patience. really appreciate it. :)
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds