Thanks so much for replying. The BitDefender Antivirus report said: Scanning successful. No viral code found...which I find troubling as BullGuard tells me on a daily basis that it has detected trojan.downloader.keenval.f and keenval.g. I scanned with a free trial version of NoAdware yesterday and it detected 40 infected files, BUT it wanted $30 US payment to get rid of them. I'd really like to beat these beasts.
Download Spybot Search and Destroy here : http://www.safer-networking.org/index.php?page=mirrors if it is not already installed on your computer Install the program and then start it. Once the program has started make sure you are in the Spybot-S&D section. Click on the "Search for Updates" button. Download all updates. In some cases the program will restart after an update. When updated, click on the Immunize "Scan System" button. When the Check is over, fix all marked with red
Open adaware and Click the "Check for updates now" line on the main screen. Click the "Connect" button on the webupdate screen.
If an update is available download it and install it. Click the "Finish" button to go back to the main screen.
Click on the Settings button (gear symbol in the upper right corner of the main status screen) in the quick launch toolbar to open the General settings screen. Check the "Automatically quarantine objects prior to removal" setting and then click "Proceed" to save your changes
Click the "Scan now" button in the main menu on the left side of the main status screen or use the "Start" button in lower right corner. This will open the Preparing System Scan screen. Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. Then select "Use custom scanning options" and click "Customize". This will open the Scan Settings Page. Make sure all of the following are On with a "green" checkmark:
Scan within archives Scan active processes Scan Registry Deep-scan Registry Scan my IE Favorites for banned URLs Scan my Hosts File
Then Click the Advanced Button on the left side to open the Advanced Settings screen. Make sure the following is on with a "green" checkmark:
Others are optional to be checked or unchecked.
Then click on the "Tweak" Button to open up the tweak settings.
Open up the Scanning Engine section and make sure ll of the following are On with a "green" checkmark:
Scan registry for all users instead of current user only
Make sure the following is unchecked with a "red" X:
Unload recognized processes & modules during scan.
Open up the Cleaning Engine section and make sure all of the following are On with a "green" checkmark:
Always try to unload modules before deletion During Removal, unload Explorer and IE if necessary Let Windows remove files in use at next reboot.
Click the "Proceed" button to save settings.
Click the "Next" button to start the scan.
When a scan is completed the Performing System Scan screen will change name to "Scan Complete".
Click the "Next" button to get to the Scanning Results screens where more information about the objects detected during the scan is available.
To fix all the bad critical objects do the following:
Right click on one of them to open up the selection screen. Click the "Select All" button to select all entries.
When all are selected Click "Next" and then "OK" in the pop-up window to confirm the removal.
Close Ad-Aware SE build 1.04 and Ad-Watch (if running) Install the VX2 Cleaner Start Ad-Aware SE build 1.04 Go to “Plug-ins” Select the VX2 Cleaner plug-in and click “Run Plugin” If your computer isn’t infected, click “Close”.
If your computer is infected:
Select “Clean System” Reboot your computer Scan your computer with Ad-Aware Remove any VX2 objects detected Reboot your computer again Run a second scan to make sure the files have been removed from your computer
I followed your advice diligently and believed the nasty critters to be gone. The third scan with Ad-Aware came back clean. However, BullGuard has just notified me once again that is has caught the virusesL Trojan.Downloader.Keenval.F and Kennval.G in the file: c:\system volume information\_restore{cv9cc49b-e1b9-4026-a3... and goes on to say: BullGuard Action: BullGuard has blocked this virus - your computer has NOT been infected. This same message appeared several times before I started implementing all your advice. So, do I have this virus or not? And why can't BullGuard lay the smackdown and get rid of it?
Despite my desperate pleas, you are a lifesaver. Thanks so much for the time your spending on my virus problems.
Reason is (probably) this folder- c:\system volume information\_restore{cv9cc49b-e1b9-4026-a3... stores information, including virus and other nasty things. But it is a locked folder. try this:
Ok. Upon running the anti-virus scan (Bull Guard) (after deactivating the system restore), one infected file was located: c:\documents and settings\user\local settings\temp\perfectnavuninstall.exe
It also mentioned that I have 28 I/O errors (?)
I will reboot and run the anti-virus again...
My, these buggers are sticky! Will let you know how next anti-virus turns out.
Gwen
ps. IF I reinstalled my OS would that do the trick? Although I would really rather not do that!
Touch, I should add this...from the anti-virus scan mentioned in my last posting (a couple of seconds ago!) Gwen //----------------------------------------------------------------- // // BullGuard report file // // Created on: 12/11/2004 16:53:40 // //-----------------------------------------------------------------
Summary:
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=>related.htm Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet.zip=>My Altnet Shares/Bullguard Protection/plugins.cab.cab Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINDashBar.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINDashBar.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator.zip=>GatorUninstaller_cme_u.log Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator1.zip=>GatorUninstaller_cme.log Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator1.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator2.zip=>GatorPdpSetup.log Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator2.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator3.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator3.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav1.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav1.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav2.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav2.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav3.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav3.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav4.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav4.zip=>sbRecovery.ini Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip=>sbRecovery.reg Password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip=>sbRecovery.ini Password protected C:\Documents and Settings\user\Local Settings\Temp\perfectnavUninstall.exe=>(NSIS o)=>zlib_nsis0002 Infected Trojan.Downloader.Keenval.F C:\Documents and Settings\user\Local Settings\Temp\perfectnavUninstall.exe=>(NSIS o)=>zlib_nsis0002 Disinfection failed - Trying second action C:\Documents and Settings\user\Local Settings\Temp\perfectnavUninstall.exe=>(NSIS o)=>zlib_nsis0002 Move failed C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>arrow1.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>arrow2.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bck1.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bck2.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt11.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt12.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt13.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt21.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt22.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt23.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt31.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt32.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt33.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt41.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt42.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt43.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt51.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt52.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt53.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt61.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt62.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox1.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox2.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox3.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox4.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>default.skn Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>defbtn1.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>defbtn2.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>defbtn3.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph1.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph2.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph3.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph4.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph5.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph6.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph7.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>main.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>preview.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>sprite1.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>tab1.bmp Password protected C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>tab2.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow1.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow2.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck1.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck2.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt11.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt12.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt13.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt21.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt22.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt23.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt31.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt32.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt33.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt41.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt42.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt43.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt51.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt52.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt53.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt61.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt62.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox1.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox2.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox3.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox4.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>default.skn Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn1.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn2.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn3.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph1.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph2.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph3.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph4.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph5.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph6.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph7.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>main.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>preview.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>sprite1.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>tab1.bmp Password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>tab2.bmp Password protected
Delete files/folder from the following directories (But not the directory itself, for example delete all files/folder IN temp. C:\Windows\Temp\ C:\Documents and Settings\<Your Profile>\Local Settings\Temp\ C:\Documents and Settings\<All other users Profile>\Local Settings\Temp\ C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ <<<This will delete your files in your internet cache--including cookies. C:\Documents and Settings\<All other users Profile>\Local Settings\Temporary Internet Files\ Empty your "Recycle Bin"
Check for updates for Windows and Internet Explorer. Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"
After following your advice: "Run full antivirus scan. Reboot, enable system restore. tell if it help" I have not (fingers crossed!) received alerts to the presence of a virus.
I looked for the folders in c:\documents and settings\user\temp and other listed in your last posting and they do not exist. However, there is a folder c:\documents and settings\user\cookes with the 27 text files and a .DAT file. Should I delete them? Also, wrt Internet Explorer - I have disabled it. With the firewall I use I do not even let it access the internet. Should I activate it long enough to download the critical updates (if there are any I need)?
Unzip to own permanent folder. You will notice the Scan button has become a Save Log button. Click the Save Log button and Highlight the Entire Log by pressing Ctrl+A and Copy it.
Currently it is Saturday, November 21, 2009 4:17 PM (GMT +1) There are a total of 73.034 posts in 17.116 threads. In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil. 39 Guest(s), 0 Registered Member(s) are currently online. Details