Reply
Visitor
corvese210
Posts: 5
Registered: ‎07-01-2009

Need Help! Removing Infostealer

Hi, I couldn't find my exact problem on this board so if it does exist somewhere could you please just direct me to that. When I run a system scan there are no problems found, but as soon as I open Internet, Norton finds the Infostealer. It started as 1 affected area now it is up to 18 Files and 1 Browser Cache. 

It reads as follows:

 

globalroot\systemroot\system32\msivxxfmiuiywkaocjyqlnrkbwnshpalqpujt.dll

 

Again, this message appears 18 times in the Details window.

 

Could you please help me ASAP as this is slowing down my computer extremely and causing all sorts of problems for me.

 

Thank you very much for any help you can give! 

Visitor
corvese210
Posts: 5
Registered: ‎07-01-2009

Re: Need Help! Removing Infostealer

I have seen a few other similar threads but the .dll name is a little different on mine so I was not sure if it mattered.
Volunteer
yogesh_mohan
Posts: 5,302
Registered: ‎07-29-2008

Re: Need Help! Removing Infostealer

Which is the Norton program(name and version) you use? Also, mention your Operating System details.

 

First, run LiveUpdate repeatedly until you see the message that "No more Updates...". Then start your computer in Safe Mode, and try to run a scan using your Norton program. If you are using Norton 2009 version, double-click the Norton icon on desktop and it will prompt you to run the scan, you can click Yes.

Visitor
corvese210
Posts: 5
Registered: ‎07-01-2009

Re: Need Help! Removing Infostealer

I have already run the safe mode scan and no issues were found. 
I am running Windows XP Home Edition SP2. My Norton software is 16.5.0.134.
 I also downloaded GMER and am currently running a scan now.
Visitor
corvese210
Posts: 5
Registered: ‎07-01-2009

Re: Need Help! Removing Infostealer

Here is the GMER log. I stopped it early because it was scanning my MatLab files and it was taking hours. It looked to me that it found the problems though because they were in red. Let me know if this is incomplete.

 

 

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Need Help! Removing Infostealer

Bad news Corvese210:

 

You do have an MSIVX rootkit. The GMER looks excellent.  Quads will be along with a fix, but it may take some time.  We only have one Quads and a number of rootkits.  You could do a few things in the meantime.  Disable system restore, dump your temp files and browser caches.

 

Download Malwarebytes for use when you have finished Quads' chores.

 

http://www.malwarebytes.org 

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Visitor
corvese210
Posts: 5
Registered: ‎07-01-2009

Re: Need Help! Removing Infostealer

Thanks so much, I look forward to hearing from Quads for the fix.

 

 

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Need Help! Removing Infostealer

Hi

 

Now  (read carefully) If you have Spybot S&D uninstall it.

 

Also during the restarts with Avenger if Your PC has a Startup repair center like with HP and Toshiba tell it to start Normally if it kicks in.

 

1. Download Avenger to your desktop,

 

Unzipped version http://homepages.slingshot.co.nz/~crutches/Avenger/

Creators website http://swandog46.geekstogo.com/avenger2/avenger2.html with zipped version to the unzip to desktop 

 

2. Click to run "Avenger.exe"  (right click "Run as Administrator" if using Vista)

 

3. In the "Input script here:" copy and paste the script between the lines

 


Drivers to disable:

MSIVXserv.sys

 

Drivers to delete:

MSIVXserv.sys

 

Files to delete:

C:\Autorun.inf

D:\Autorun.inf

C:\Windows\System32\drivers\MSIVXlhtarsvdcdeuwqxrqumqfwxvrbomphqp.sys  

C:\Windows\System32\MSIVXxfmiuiywkaocjyqlnrkbwnshpalqpujt.dll

C:\Windows\System32\MSIVXorkoyjkyxsruxdspumnjoxblrsftidvb.dll

C:\WINDOWS\System32\MSIVXcount

 

Registry keys to delete:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX 


 

Here is a screenshot (script updated since shot)

 

Avenger.jpg

 

Make sure the "Automatically disable any rootkits found" is NOT selected

 

4. Click "Execute"

 

You will be asked to restart the PC click "Yes", when the PC restarts the load screen will takes slightly longer, then when it looks as though windows is loading the PC will restart again.

Then when Windows fully loads the Avenger log will be loaded, showing files it could or could not find.

 

5. Restart the PC again, then see if you can install  Update and run Malwarebytes

 

Quads