06-14-2009
01:50 PM
- last edited on
06-14-2009
04:00 PM
by
shannons
I can't remember what tipped me off, but something isn't right on my computer. Current symptoms are that all anti-spyware sites are blocked and what I can download either won't run or can't get the updates in order to run. I also have the problem of Google results linking to sites that aren't consistent with the link. I have run a couple of things, rootrepeal and gmer, and they've noted MSIVX...dll and MSIVX....sys files as potential issues. I've tried running scans in safe boot mode and while I can scan them, they don't resolve the issue. Please suggest what steps to take next.
[edit: Changed subject to reflect issue.]
06-14-2009 01:59 PM
06-14-2009 02:07 PM
Please run RootRepeal as in this post http://community.norton.com/norton/board/message?b
And GMER, http://www.gmer.net/ and "Scan" then "Save" the log, then due to the possible side post the log on http://pastebay.com/ and PM me the link. Use your Norton Name on Pastebay
Quads
06-14-2009 07:34 PM
I have your logs, I just have to script
Quads
06-14-2009 08:40 PM
Hi RegalEagle
Your GMER log is actually cut short, possibly due to a character limit
Last line shown ".text"
Please paste the rest of the log from "---- Devices - GMER 1.0.15 ----" and below
Thanks
Quads
06-16-2009 03:39 AM
06-16-2009 01:51 PM
Thanks Now I have a complete log to look through and script
Quads
06-16-2009 06:06 PM
Hi
Go to http://community.norton.com/norton/board/message?b
Download Avenger, when you get to step 3. Use the script below instead of the one on the other post as I have added your random files. SO
3. In the "Input script here:" copy and paste the script between the lines
Drivers to disable:
MSIVXserv.sys
Drivers to delete:
MSIVXserv.sys
Files to delete:
C:\Autorun.inf
D:\Autorun.inf
C:\WINDOWS\system32\drivers\MSIVXfpqebwwxpiswvenob
C:\WINDOWS\system32\drivers\MSIVXpxettvasrnemkooic
C:\WINDOWS\system32\drivers\MSIVXuytmnaqqiptkkaxqo
C:\WINDOWS\system32\MSIVXpvymtqimexcpdqpsvymktfnpc
C:\WINDOWS\system32\MSIVXbnixqaxvkdsiborkveqxuehwt
C:\WINDOWS\system32\MSIVXtcpitqpqhykempvydbqnnhbnp
C:\WINDOWS\system32\MSIVXgyusdbpapbginsojyucbcvvrt
C:\WINDOWS\system32\MSIVXxqfgfomfgbghveijmpekageds
C:\Windows\System32\MSIVXcount
Registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\M
HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX
It will create a log afterwards.
Quads
06-16-2009 07:31 PM
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
Hidden driver "MSIVXserv.sys" found!
ImagePath: \systemroot\system32\drivers\MSIVXuytmnaqqiptkkaxq
Start Type: 4 (Disabled)
Rootkit scan completed.
Driver "MSIVXserv.sys" disabled successfully.
Driver "MSIVXserv.sys" deleted successfully.
Error: file "C:\Autorun.inf" not found!
Deletion of file "C:\Autorun.inf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: could not open file "D:\Autorun.inf"
Deletion of file "D:\Autorun.inf" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Error: file "C:\WINDOWS\system32\drivers\MSIVXfpqebwwxpiswveno
Deletion of file "C:\WINDOWS\system32\drivers\MSIVXfpqebwwxpiswveno
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\drivers\MSIVXpxettvasrnemkooi
Deletion of file "C:\WINDOWS\system32\drivers\MSIVXpxettvasrnemkooi
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "C:\WINDOWS\system32\drivers\MSIVXuytmnaqqiptkkaxq
Error: file "C:\WINDOWS\system32\MSIVXpvymtqimexcpdqpsvymktfnp
Deletion of file "C:\WINDOWS\system32\MSIVXpvymtqimexcpdqpsvymktfnp
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\MSIVXbnixqaxvkdsiborkveqxuehw
Deletion of file "C:\WINDOWS\system32\MSIVXbnixqaxvkdsiborkveqxuehw
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\MSIVXtcpitqpqhykempvydbqnnhbn
Deletion of file "C:\WINDOWS\system32\MSIVXtcpitqpqhykempvydbqnnhbn
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "C:\WINDOWS\system32\MSIVXgyusdbpapbginsojyucbcvvr
File "C:\WINDOWS\system32\MSIVXxqfgfomfgbghveijmpekaged
File "C:\Windows\System32\MSIVXcount" deleted successfully.
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\
Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
It looks good - Norton found one spyware program during a quick scan and quarantined it, MalwareBytes downloaded and is scanning - nothing so far. I'll set Norton on a full scan tonight as well. Everything seems to be working correctly, so I thank you heartily.
06-16-2009 07:49 PM
From the log
File "C:\WINDOWS\system32\drivers\MSIVXuytmnaqqiptkkaxq
File "C:\WINDOWS\system32\MSIVXgyusdbpapbginsojyucbcvvr
File "C:\WINDOWS\system32\MSIVXxqfgfomfgbghveijmpekaged
File "C:\Windows\System32\MSIVXcount" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\
Make sure the Malwarebytes database is up to date,
No, problem, one more down
Quads
