Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Trojan.downloader.keenval.f removal
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Trojan.downloader.keenval.f removal  
Forum Quick Jump
 
New Topic Post reply to : Trojan.downloader.keenval.f removal Printable version of : Trojan.downloader.keenval.f removal
[ << Previous Thread | Next Thread >> ]

Gwen
New Member


Date Joined Nov 2004
Total Posts : 9
 
   Posted 11-11-2004 12:57 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
I was wondering if there's anyone out there who knows how to remove trojan.downloader.keenval.f ?

Much appreciated...it seems I'm not the only one with this problem.

Gwen
:p
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-11-2004 10:33 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Heycool
Tell if it fix it;-)


Touch
Back to Top
 

Gwen
New Member


Date Joined Nov 2004
Total Posts : 9
 
   Posted 11-12-2004 12:06 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Hello Touch,

Thanks so much for replying.
The BitDefender Antivirus report said: Scanning successful. No viral code found...which I find troubling as BullGuard tells me on a daily basis that it has detected trojan.downloader.keenval.f and keenval.g.
I scanned with a free trial version of NoAdware yesterday and it detected 40 infected files, BUT it wanted $30 US payment to get rid of them.
I'd really like to beat these beasts.

Any other suggestions?

Much thanks,
Gwen :p
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-12-2004 11:30 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
This?;-)
Run this scanner – mwav exe : http://home9.inet.tele.dk/le01/Sikkerhed.htm
Activate all, in settings- Scan

Download Spybot Search and Destroy here : http://www.safer-networking.org/index.php?page=mirrors if it is not already installed on your computer
Install the program and then start it. Once the program has started make sure you are in the Spybot-S&D section. Click on the "Search for Updates" button. Download all updates. In some cases the program will restart after an update. When updated, click on the Immunize "Scan System" button. When the Check is over, fix all marked with red
 
 

Open adaware and Click the "Check for updates now" line on the main screen. Click the "Connect" button on the webupdate screen.

If an update is available download it and install it. Click the "Finish" button to go back to the main screen.

Click on the Settings button (gear symbol in the upper right corner of the main status screen) in the quick launch toolbar to open the General settings screen. Check the "Automatically quarantine objects prior to removal" setting and then click "Proceed" to save your changes

Click the "Scan now" button in the main menu on the left side of the main status screen or use the "Start" button in lower right corner. This will open the Preparing System Scan screen. Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. Then select "Use custom scanning options" and click "Customize". This will open the Scan Settings Page. Make sure all of the following are On with a "green" checkmark:

Scan within archives
Scan active processes
Scan Registry
Deep-scan Registry
Scan my IE Favorites for banned URLs
Scan my Hosts File

Then Click the Advanced Button on the left side to open the Advanced Settings screen. Make sure the following is on with a "green" checkmark:

Others are optional to be checked or unchecked.

Then click on the "Tweak" Button to open up the tweak settings.

Open up the Scanning Engine section and make sure ll of the following are On with a "green" checkmark:

Scan registry for all users instead of current user only

Make sure the following is unchecked with a "red" X:

Unload recognized processes & modules during scan.

Open up the Cleaning Engine section and make sure all of the following are On with a "green" checkmark:

Always try to unload modules before deletion
During Removal, unload Explorer and IE if necessary
Let Windows remove files in use at next reboot.

Click the "Proceed" button to save settings.

Click the "Next" button to start the scan.

When a scan is completed the Performing System Scan screen will change name to "Scan Complete".

Click the "Next" button to get to the Scanning Results screens where more information about the objects detected during the scan is available.


To fix all the bad critical objects do the following:

Right click on one of them to open up the selection screen. Click the "Select All" button to select all entries.

When all are selected Click "Next" and then "OK" in the pop-up window to confirm the removal.

Plug-Ins for Ad-Aware (VX2 Cleaner)
Download the free VX2 Cleaner here : http://download.lavasoft.de.edgesuite.n...leaner.exe

Close Ad-Aware SE build 1.04 and Ad-Watch (if running)
Install the VX2 Cleaner
Start Ad-Aware SE build 1.04
Go to “Plug-ins”
Select the VX2 Cleaner plug-in and click “Run Plugin”
If your computer isn’t infected, click “Close”.

If your computer is infected:

Select “Clean System”
Reboot your computer
Scan your computer with Ad-Aware
Remove any VX2 objects detected
Reboot your computer again
Run a second scan to make sure the files have been removed from your computer


Touch
Back to Top
 

Gwen
New Member


Date Joined Nov 2004
Total Posts : 9
 
   Posted 11-12-2004 7:24 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Touch,

I followed your advice diligently and believed the nasty critters to be gone. The third scan with Ad-Aware came back clean.
However, BullGuard has just notified me once again that is has caught the virusesL Trojan.Downloader.Keenval.F and Kennval.G in the file: c:\system volume information\_restore{cv9cc49b-e1b9-4026-a3...
and goes on to say: BullGuard Action: BullGuard has blocked this virus - your computer has NOT been infected. This same message appeared several times before I started implementing all your advice.
So, do I have this virus or not? And why can't BullGuard lay the smackdown and get rid of it?

Despite my desperate pleas, you are a lifesaver. Thanks so much for the time your spending on my virus problems.

What do you think?
Gwen :p
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-12-2004 8:04 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Reason is (probably) this folder- c:\system volume information\_restore{cv9cc49b-e1b9-4026-a3... stores information, including virus and other nasty things. But it is a locked folder. try this:
 
Run full antivirus scan. Reboot, enable system restore. tell if it help;-)
 


Touch
Back to Top
 

Gwen
New Member


Date Joined Nov 2004
Total Posts : 9
 
   Posted 11-12-2004 10:00 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Ok. Upon running the anti-virus scan (Bull Guard) (after deactivating the system restore), one infected file was located:
c:\documents and settings\user\local settings\temp\perfectnavuninstall.exe

It also mentioned that I have 28 I/O errors (?)

I will reboot and run the anti-virus again...

My, these buggers are sticky!
Will let you know how next anti-virus turns out.

Gwen

ps. IF I reinstalled my OS would that do the trick? Although I would really rather not do that! :p
Back to Top
 

Gwen
New Member


Date Joined Nov 2004
Total Posts : 9
 
   Posted 11-12-2004 10:03 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Touch, I should add this...from the anti-virus scan mentioned in my last posting (a couple of seconds ago!)
Gwen
//-----------------------------------------------------------------
//
// BullGuard report file
//
// Created on: 12/11/2004 16:53:40
//
//-----------------------------------------------------------------


Summary:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=>related.htm Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet.zip=>My Altnet Shares/Bullguard Protection/plugins.cab.cab Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINDashBar.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINDashBar.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator.zip=>GatorUninstaller_cme_u.log Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator1.zip=>GatorUninstaller_cme.log Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator1.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator2.zip=>GatorPdpSetup.log Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator2.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator3.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\GAINGator3.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav1.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav1.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav2.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav2.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav3.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav3.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav4.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\KeenValuePerfectNav4.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip=>sbRecovery.reg Password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip=>sbRecovery.ini Password protected
C:\Documents and Settings\user\Local Settings\Temp\perfectnavUninstall.exe=>(NSIS o)=>zlib_nsis0002 Infected Trojan.Downloader.Keenval.F
C:\Documents and Settings\user\Local Settings\Temp\perfectnavUninstall.exe=>(NSIS o)=>zlib_nsis0002 Disinfection failed - Trying second action
C:\Documents and Settings\user\Local Settings\Temp\perfectnavUninstall.exe=>(NSIS o)=>zlib_nsis0002 Move failed
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>arrow1.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>arrow2.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bck1.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bck2.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt11.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt12.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt13.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt21.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt22.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt23.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt31.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt32.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt33.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt41.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt42.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt43.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt51.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt52.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt53.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt61.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>bt62.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox1.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox2.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox3.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>checkbox4.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>default.skn Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>defbtn1.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>defbtn2.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>defbtn3.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph1.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph2.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph3.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph4.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph5.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph6.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>glyph7.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>main.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>preview.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>sprite1.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>tab1.bmp Password protected
C:\Documents and Settings\user\Desktop\aawsepersonal-105.exe=>wise0023=>tab2.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow1.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow2.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck1.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck2.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt11.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt12.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt13.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt21.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt22.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt23.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt31.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt32.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt33.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt41.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt42.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt43.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt51.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt52.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt53.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt61.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt62.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox1.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox2.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox3.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox4.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>default.skn Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn1.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn2.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn3.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph1.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph2.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph3.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph4.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph5.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph6.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph7.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>main.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>preview.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>sprite1.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>tab1.bmp Password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>tab2.bmp Password protected

Statistics

Scan path : C:\
Folders : 1259
Files : 99731
Archives : 626
Packed files : 11971
Identified viruses : 1
Infected files : 1
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 0
Copied files : 0
Moved files : 0
Renamed files : 0
I/O errors : 28
Scan time : 00:20:39
Scan speed (files/sec) : 80

Virus definitions : 94257
Scan plugins : 12
Archive plugins : 37
Unpack plugins : 4
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[ ] Copy to quarantine
[X] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[ ] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-13-2004 7:37 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Seems to many of them are in Temp folders!
 
Delete files/folder from the following directories (But not the directory itself, for example delete all files/folder IN temp.
C:\Windows\Temp\
C:\Documents and Settings\<Your Profile>\Local Settings\Temp\
C:\Documents and Settings\<All other users Profile>\Local Settings\Temp\
C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\
 <<<This will delete your files in your internet cache--including cookies.
C:\Documents and Settings\<All other users Profile>\Local Settings\Temporary Internet Files\
Empty your "Recycle Bin"


About DSO: http://www.nsclean.com/dsostop.html
 
Check for updates for Windows and Internet Explorer. Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/


Touch
Back to Top
 

Gwen
New Member


Date Joined Nov 2004
Total Posts : 9
 
   Posted 11-13-2004 7:53 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Touch,

After following your advice: "Run full antivirus scan. Reboot, enable system restore. tell if it help;-)" I have not (fingers crossed!) received alerts to the presence of a virus.

I looked for the folders in c:\documents and settings\user\temp and other listed in your last posting and they do not exist.
However, there is a folder c:\documents and settings\user\cookes with the 27 text files and a .DAT file. Should I delete them?
Also, wrt Internet Explorer - I have disabled it. With the firewall I use I do not even let it access the internet. Should I activate it long enough to download the critical updates (if there are any I need)?

Comp is better than ever thanks to you!
Gwen :p
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 11-13-2004 9:05 (GMT +1)    Quote: Trojan.downloader.keenval.f removalAlert an admin about: Trojan.downloader.keenval.f removal
Heycool
 
Use Ccleaner to remove Tmp and txt (cookie) Files. Dat files can be in use, so maybe they won´t be deleted
http://www.ccleaner.com/
 
What Firewall have you?
And wait with updates, untill firewall works properly.
 
Glad to hear, it is running bettersmilewinkgrin
 
Will you check more nasty things?
Download  Hijackthis:  :  http://danborg.org/spy/HJT/hijackthis.exe
 
Unzip to own permanent folder. You will notice the Scan button has become a Save Log button. Click the Save Log button and Highlight the Entire Log by pressing Ctrl+A and Copy it.
 
Post it here, as-New Topic: http://www.bullguard.com/forum/10/


Touch
Back to Top
 
New Topic Post reply to : Trojan.downloader.keenval.f removal Printable version of : Trojan.downloader.keenval.f removal
 
Forum Information
Currently it is Saturday, November 21, 2009 4:17 PM (GMT +1)
There are a total of 73.034 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
39 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Constant scanning andskipped files? (3)21-11-2009 14:33:51 (Dickens)
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)