Author Topic: Viruses: trojan (win32:kavos)  (Read 25671 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Viruses: trojan (win32:kavos)
« Reply #30 on: June 18, 2009, 03:01:52 PM »
- Run MBAM again and this time when the scan is complete, all detections should have a check mark in the box to the left of the entry, leave them selected (or select if not selected). At the bottom of the window there is a button, Remove Selected, click that and the items will be removed.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Viruses: trojan (win32:kavos)
« Reply #31 on: June 18, 2009, 03:58:18 PM »
that's strange... have you seen any warning about klif.sys?

swaprules

  • Guest
Re: Viruses: trojan (win32:kavos)
« Reply #32 on: June 18, 2009, 04:20:32 PM »
Ran MBAM again . NOthing found . hat might be coz I had done avast scan after mbam in safe mode.
Here's the log.
Malwarebytes' Anti-Malware 1.38
Database version: 2301
Windows 5.1.2600 Service Pack 2

6/18/2009 7:46:13 PM
mbam-log-2009-06-18 (19-46-13).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 168284
Time elapsed: 28 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
@ MAxx original
No klif .sys .
Also lately avast is showing too many warnings about infected files whose locations are in folders called recyclers in various drive.Any clue?
What should I do next?
Is avast thorough scan in safe mode supposed to be very slow?50% in 3-4 hrs on 80 gb hdd?

micky77

  • Guest
Re: Viruses: trojan (win32:kavos)
« Reply #33 on: June 18, 2009, 05:13:20 PM »
Also lately avast is showing too many warnings about infected files whose locations are in folders called recyclers in various drive.Any clue?
Try running autorun eater, I know you ran flash disinfector,did it find anything ?

http://download.cnet.com/Autorun-Eater/3000-2239_4-10752777.html

swaprules

  • Guest
Re: Viruses: trojan (win32:kavos)
« Reply #34 on: June 18, 2009, 05:29:21 PM »
flash disinfector did nt find anything.It just said DONE!. RUnning the autorun eater now.
Edit : Autorun eater. It found fsaht.cmd in two or three places and removed it.Anything else to do?
« Last Edit: June 18, 2009, 05:33:01 PM by swaprules »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Viruses: trojan (win32:kavos)
« Reply #35 on: June 18, 2009, 05:33:17 PM »
It doesn't find things as such, but creates an autorun.inf 'folder' in each hard disk partition to prevent future infection. When run after you have inserted a USB device it does the same on that to prevent future infections being able to create an autorun.inf 'file.'
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

micky77

  • Guest
Re: Viruses: trojan (win32:kavos)
« Reply #36 on: June 18, 2009, 07:02:25 PM »
Anything else to do?

Try running Avira rescue cd,download from a clean pc,double click on file,burn to cd, insert into infected pc,reboot.
Report any findings

http://forum.avira.com/wbb/index.php?page=Thread&postID=730130#post730130

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Viruses: trojan (win32:kavos)
« Reply #37 on: June 18, 2009, 08:33:53 PM »
You were close to nailing it here after the MBAM run and you should have deleted the infected files, but that is all by the by now.
After deleting the MBAM detections, you would turn off your computer to finalize things.

http://forum.avast.com/index.php?topic=46120.msg387672#msg387672

Leaving the infections undeleted and then running the avast scan immediately after would have aggravated things. Likewise after striking lucky with MBAM, then a boot-time scan would have been a good thing to do at restart. I hadn't expected MBAM to dig out that much.

Also, all scans with the Graphic User Interface are slow, especially when a computer is infected. If you had deleted the MBAM detections and restarted the computer, I'm sure that a scan in Safe Mode would have run a lot smoother. But that is something to remember for next time. I had to run these things through so many times when I first started malware detection that I now do it by rote (practice). Which is much easier than having to write it out like this. So may help to let your computer sit for a while, then run it through again. If no good then look to recovery disk as micky77 says.

Your not helping things much either by running outdated Windows. Service pack 3 has been out for a year now and is markedly more secure than SP2. You need to keep up with Microsoft updates if you are running a Windows system. Also check your Java. These are equally serious issues as your virus detection.

Quote
Sun Java is down level and has security exposures.

Go to Add/Remove Programs and uninstall all Sun Java installs.

Install the latest Sun Java:
http://www.java.com/en/download/manual.jsp

Edit - btw good move to send infected files to avast. I took me a long time before I had the good sense to do that.
« Last Edit: June 19, 2009, 12:33:39 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

swaprules

  • Guest
Re: Viruses: trojan (win32:kavos)
« Reply #38 on: June 20, 2009, 06:37:18 AM »
BTw the MBAM log I had posted earlier showed no action taken coz the log was saved by me just after the scan and before i cliked on delete.I was wondering why it showed no action taken when i had clicked on delete.THe actual log (from MBAMs own records) is this one.
Umm why cant I see the log in normal mode only in safe mode?I ll post it up after i find it .
Urgent Edit : 3 new unknown processes running --> billy.exe oldmcdonald.exe wscntfy.exe
Edit 2 -> billy.exe and oldmcdonald.exe seem be associated with autorun eater .My bad!

Malwarebytes' Anti-Malware 1.38
Database version: 2301
Windows 5.1.2600 Service Pack 2

6/18/2009 9:22:57 AM
mbam-log-2009-06-18 (09-22-57).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 166472
Time elapsed: 39 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorDoctor (Rogue.ErrorDoctor) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\xdglur.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
d:\xdglur.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\xdglur.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\autorun.inf (Trojan.Agent) -> Quarantined and deleted successfully.
c:\fsaht.cmd (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
« Last Edit: June 20, 2009, 06:58:27 AM by swaprules »

micky77

  • Guest
Re: Viruses: trojan (win32:kavos)
« Reply #39 on: June 20, 2009, 07:02:38 AM »
Don't worry about old billy the goat  ;D Right click on the cone in the system tray and choose exit. So hows the pc now ? wscntfy.exe is to do with windows security centre.Did you run the rescue disc ?
« Last Edit: June 20, 2009, 07:04:19 AM by micky77 »

swaprules

  • Guest
Re: Viruses: trojan (win32:kavos)
« Reply #40 on: June 20, 2009, 01:53:17 PM »
Quote
You were close to nailing it here after the MBAM run and you should have deleted the infected files, but that is all by the by now.

So does it mean i have nailed it then and am free , albeit for the time being?

ANy more tests?

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Viruses: trojan (win32:kavos)
« Reply #41 on: June 20, 2009, 07:10:22 PM »
It means you keep the bugger nailed out of your system running for good, and keep ready to whammy any hope it has of re-occupying any place (if it is gone) or regaining any ground (if some or traces of it are still about). To be honest swaprules, you need to keep at it without doing anything sensational or spectacular, just putting into practice the defence actions that the forum has been providing. You may not be out of the woods yet. Malware are infinitely devious. However, by the sounds of things, you are certainly ahead of the play once again. Make sure to keep things that way, and may your problems be over.

Regards.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.