KVG.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by icephoenix, Dec 22, 2005.

  1. icephoenix

    icephoenix Private E-2

    Hello,

    I've done all the instructions in the announcement at the top except for one, the Panda software scan kept giving me an error and not letting me scan, and I must have restarted 5 or 6 times, but it still didn't work.
    I got this trojan from a phpbb forum that I (used to) go to, and I'm having such a tough time being rid of it, so this is my last shot before I get someone to help me format.
    From the other infected forum members I know it's called KVG.exe, but they don't seem to know anything about how to get rid of it.
    Let's see...
    Adaware SE found 4 tracking cookies and an MRU list, and had it delete them.
    Spybot found a few registry entries, one for CoolWWWSearch and a handful called Windows Security Center, and I had it fix those. (I attached a screenshot)
    CWShredder found an entry from About:Blank and I had it fix that.
    Both MS AntiSpywares found nothing.
    I had to run all these things twice because the power went out while I was running the BitDefender scan. All the scans except for Spybot came up with nothing; Spybot found the same few registry entries I'd had it fix the first time I ran it.
    BitDefender found a whole lot of things, but they were mostly in the quarantine folder that my antivirus software keeps; and as I said before, the Panda scan wouldn't work for me, I hope you can still help me.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Double check the properties of the below smss.exe file to make sure it belongs to Microsoft. This is not normally the location that Microsoft would have this running from. It should be in the system32 folder.
    C:\xphome\smss.exe

    For now, I'm going to work under the assumption that the above file is bad.

    Did you install the below keylogger? If not, add it to the below list of things to fix with HJT and also delete the file later in safe mode.
    O2 - BHO: - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - C:\xphome\system32\ib6.dll

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\xphome\smss.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O4 - HKCU\..\Run: [klop] C:\xphome\KVG.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\xphome\KVG.exe

    To be safe, we will only rename the below file instead of deleting it.
    Right click on C:\xphome\smss.exe and select Rename. Change the name to smss.xxx

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  3. icephoenix

    icephoenix Private E-2

    The smss.exe file looks like it's signed by Microsoft, but I attached a screenshot anyway because I'm not sure that was the right place to look.
    I renamed it anyway, and everything's working just fine now, I'll attach a new log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there also an smss.exe in the c:\xphome\system32 folder?

    So are all you malware issues gone?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess when you said:
    You must not have been talking about this forum! :)
     
  6. icephoenix

    icephoenix Private E-2

    Yes, there's also an smss.exe in the system32 folder.
    Yes, it looks like all my malware problems are gone. Thank you very much for helping!
    And no, I got it from another forum. :3
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! And for now leave the smss.exe in the c:\windows folder renamed. It is will probably be okay to delete it since you do have the correct one in system32, but just wait a couple days to make sure you do not run into any problems.

    Well no that you know which forum to come to for answers ;) , continue on to the below to help keep you clean:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds