Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Virus/Malware Virus /Rootkits Thread, Work In Progress

views
     
bean_man
post May 2 2008, 05:01 PM

Casual
***
Junior Member
371 posts

Joined: Aug 2006


QUOTE(ningyozukai @ May 2 2008, 04:33 PM)
I come across the worm Allapple-Gen which attacks my services.exe and forcing my computer to restart in 45 seconds.

It also duplicates a lot of htm or html files in all over random files.

Since I am at work today, I just gather enough information to go home to battle it again tonight.

1) look for service.exe or services.exe besides the one in C:\Windows\System32
2) Look around registry editor at the Run section.
2) Turn off system restore
3) Scan the computer in safe mode. I am using NOD32

Wish me luck.
*
remember to sent samples of the infected file to samples@eset.sk so that other users of NDO32 can stay protected.
bean_man
post Sep 7 2008, 12:16 AM

Casual
***
Junior Member
371 posts

Joined: Aug 2006


QUOTE(jovi @ Sep 5 2008, 11:01 AM)
ok Deani, sory for that. i did not check the file.BTW this should be ok. i upload it myself.

download link
http://rapidshare.com/files/142720162/kavo_killer.rar.html

i'm using kaspersky Internet security 2009 and it's ok. eset sometime detect apps like this as virus. i don' know why. but if its still detected it as virus please turn off ur antivirus.

if u worried being infected, please change ur antivirus first.

please follow the instruction for further steps

hope this will do.

keep updating so i can give more  support. TQ
*
Hi Jovi,
asking the TS to disable his antivirus without checking first is a bad advice. You should ask the TS to check the file content by uploading to Jotti or Virustotal for results that are more affirmative.
bean_man
post Sep 10 2008, 10:35 AM

Casual
***
Junior Member
371 posts

Joined: Aug 2006


QUOTE(jovi @ Sep 10 2008, 09:19 AM)
Thx bean_man for ur advice. it is actually my bad by advising Deani to do that, but i do that with a very good reason. i've been using the program for almost a year now for virus removing service and it works just fine. even for the second link i, upload it myself. it's the same tools that i've using for almost a year. the steps  that i have copy from other site is the same steps that i have been using. it just a fast way to write an instruction without writing it. biggrin.gif

BTW thx for ur advice. i'm sending this app to Jotti or Virustotal as u advised for more confirmation.  i'm new here and looking forward for more reply TQ


Added on September 10, 2008, 9:41 ami've send the file to Jotti and Virustotal and both give partially bad result. sad.gif . some detected it as trojan. but from my experience it will not effected your windows. i'm using Kaspersky Internet Security which is i' ve red the no 1 internet security app for now, and KIS detect nothing. lastly it may be up to Deani to decide weather to try it or not.  biggrin.gif  . for me b4 i found this tools, the only way to resolve the prob is to reinstall the windows  icon_rolleyes.gif
*
I DL the file and checked an indeed it is a partial result. But the classification of trojan means to me that i should be aware about running it as it could very well install a backdoor that you did not know about.
bean_man
post Sep 11 2008, 04:01 PM

Casual
***
Junior Member
371 posts

Joined: Aug 2006


QUOTE(Jass @ Sep 11 2008, 11:00 AM)
Hi,
I failed to perform the above. when i type in attrib kavo.exe -r -a -s -h when i run CMD as instructed, it said file not found - kavo.exe.  I've scanned my pc using spyeraser, it listed out the file infected are:
c:\windows\system32\kavo1.dll
c:\windows\system32\kavo.exe
c:\windows\system32\kavo0.dll

Please refer to the attached for log file.

Now, my pc has problem to click link from the website. It will freeze when i click on link. I've to use ctrl & alt to close the IE otherwise my pc will hang.
*
Looking at this. I would suggest that you look for an emergency boot Cd such as Avira rescue system CD and burn a copy and run that. Run a scan and it should pick some of the viruses up. But bear in mind that you may lose some functionality as the damage from the virus would most likely be done.
bean_man
post Nov 5 2008, 09:56 AM

Casual
***
Junior Member
371 posts

Joined: Aug 2006


QUOTE(sgwc @ Nov 4 2008, 12:31 PM)
I need help regarding my situation right now. To keep it simple I write the details in points.

EDITED:

1. There's a shady program running in my pc. I found it in my Task Manager and the program is tyjkfww.exe or something like that. So I just kill the process but it still keep on opening itself.

2. The "virus" disabling my antivirus. I even fiin out that my antivirus's .exe file has been deleted.

3. I noticed that i have that program "tyjkfww.exe" at any root folder of any drive (like C://,D:// except for CD/DVDROM drive) with its own autorun.inf. Yeah, they're hidden but luckily my ACDSee program can 'see' them. I tried to unhide them but can't because they keep on hiding.  I tried to delete them but they still exist. And here i thought that there is no use for me to format my pc.

4. I also noticed that the program "tyjkfww.exe" will not open if i use "right click-->explore" a root folder rather than double clicking the root folder.

5. I still have my folder options but can't unhide hidden files and folders.

6. I no longer can view any pictures using the usual windows picture preview.

Are there any cleaner for this?

Oh my... i keep on editing my post...

7. It seems that my pc keeps on utilizing its cpu at 50% even though i have closed all programs.
*
Please post this on the tech support corner. A malware helper will aid you.

 

Change to:
| Lo-Fi Version
0.0163sec    1.27    7 queries    GZIP Disabled
Time is now: 12th December 2025 - 02:16 AM