Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Virus/Malware Virus /Rootkits Thread, Work In Progress

views
     
jovi
post Sep 3 2008, 11:54 PM

New Member
*
Junior Member
15 posts

Joined: May 2005
From: Kuala Terengganu


QUOTE(bagata @ Jul 9 2008, 11:23 AM)
erm... sorry if its inappropriate for this post to b at here...

i wanna ask for help as my comp was infected by a trojan named PSW.OnlineGames.AWIU (thread detected by my AVG free version) is there anyway to remove this trojan as my AVG keeps detect this trojan access my comp files... and another matter is tat now i cant open my C and D drive directly, when i click the driver (C and D Drive) a windows will pop out (sumthng lik "open with" window) and i hav to access my C and D drive using explore option... icon_question.gif
*
QUOTE(Deani_77 @ Aug 27 2008, 05:38 PM)
Mine was infected by that virus too. Been detected by Eset. But new problem occured, I cannot enable option to show my hidden file. Anybody have the solution?
*
hi,
for bagata's problem i think any new antivirus can handle that problem. it is actually a problem that cause by a file named 'autorun.inf'. if antivirus cannot delete the file, you can delete it manually. the file attribute is hidden and system. so therefore you need to show hidden file and uncheck hide protected operating system file to see it.you'll be warn when you uncheck the hide protected operating system file but it's ok. when u the file just delete it. restart the pc then it'll be just fine.

but when u effected by kavo like worm-trojan. it patch ntdetect file so that you cannot see the hidden file. to solve this
you need to follow the instruction below. this tool only can be run in windows xp and 2000 only.


1. Disable “System Restore” on your System (Accessories > System Tools > System Restore)
2. Click here to download this file - kavo killer
3. Unzip and extract it anywhere
4. Restart your PC in safe mode (for WinXP, before the WinXP screen comes in, press F8 repeatedly until you come to the start-up options)
5. Locate the exe file and double-click on it
6. Click on the top right-most button (the only button with an icon)
user posted image
7. When finished. Reboot
8. Just to be sure, set your anti-virus to scan at boot time and restart again to make sure the Kavo.exe is no more

That’s it. Let me know if this post has helped you.

(courtesy of http://mrbadak.com/2008/01/11/remove-kavo-easily/)
jovi
post Sep 5 2008, 11:01 AM

New Member
*
Junior Member
15 posts

Joined: May 2005
From: Kuala Terengganu


ok Deani, sory for that. i did not check the file.BTW this should be ok. i upload it myself.

download link
http://rapidshare.com/files/142720162/kavo_killer.rar.html

i'm using kaspersky Internet security 2009 and it's ok. eset sometime detect apps like this as virus. i don' know why. but if its still detected it as virus please turn off ur antivirus.

if u worried being infected, please change ur antivirus first.

please follow the instruction for further steps

hope this will do.

keep updating so i can give more support. TQ

jovi
post Sep 10 2008, 09:19 AM

New Member
*
Junior Member
15 posts

Joined: May 2005
From: Kuala Terengganu


QUOTE(bean_man @ Sep 7 2008, 12:16 AM)
Hi Jovi,
asking the TS to disable his antivirus without checking first is a bad advice. You should ask the TS to check the file content by uploading to Jotti or Virustotal for results that are more affirmative.
*
Thx bean_man for ur advice. it is actually my bad by advising Deani to do that, but i do that with a very good reason. i've been using the program for almost a year now for virus removing service and it works just fine. even for the second link i, upload it myself. it's the same tools that i've using for almost a year. the steps that i have copy from other site is the same steps that i have been using. it just a fast way to write an instruction without writing it. biggrin.gif

BTW thx for ur advice. i'm sending this app to Jotti or Virustotal as u advised for more confirmation. i'm new here and looking forward for more reply TQ


Added on September 10, 2008, 9:41 ami've send the file to Jotti and Virustotal and both give partially bad result. sad.gif . some detected it as trojan. but from my experience it will not effected your windows. i'm using Kaspersky Internet Security which is i' ve red the no 1 internet security app for now, and KIS detect nothing. lastly it may be up to Deani to decide weather to try it or not. biggrin.gif . for me b4 i found this tools, the only way to resolve the prob is to reinstall the windows icon_rolleyes.gif

This post has been edited by jovi: Sep 10 2008, 09:41 AM
jovi
post Sep 10 2008, 12:05 PM

New Member
*
Junior Member
15 posts

Joined: May 2005
From: Kuala Terengganu


QUOTE(bean_man @ Sep 10 2008, 10:35 AM)
I DL the file and checked an indeed it is a partial result. But the classification of trojan means to me that i should be aware about running it as it could very well install a backdoor that you did not know about.
*
Yap u should be aware for that situation. maybe i'll start google around the net to find new safer solution for this. its involve some registry modification and maybe replace new ntdetect file on the system using bart pe will do. But i'll try find it first.TQ biggrin.gif

 

Change to:
| Lo-Fi Version
0.0150sec    0.49    7 queries    GZIP Disabled
Time is now: 11th December 2025 - 07:45 PM