07-15-2009 02:34 PM
Hi, have a virus on my machine as every time I load up the internet an error comes up and it also affects my speed of the internet. When I close down the error the internet lanches, the virus is:
globalroot\systemroot\system32\MSIVXxnovtiipxrvtmy
Please can someone help
07-15-2009 02:45 PM
This particular Forum is for feedback and questions on the way the Forums operate so I've asked for you to be moved.
But are you using Norton Internet Security. Norton Anti VIrus or Norton 36y0?
Say which and then you'll end up in the right place but you won't get lost because moving leaves a link here that will take you there.
07-15-2009 03:03 PM
Hi Aliciaterry:
Please download and SCAN ONLY using GMER. Make sure all the boxes are checked, save log and you will be able to post it here for us to view via the "add attachments" link just below the post button. Quads is the guru who looks after the rootkit problems. He will be along to view your log.
07-18-2009 09:36 AM
Hi,
I have ran the gmer as instucted, please find the file attached. Thanks for your help.
07-18-2009 09:46 AM
Aliciaterry:
You have an MSIVX rootkit. It is nasty but not as difficult as some. Please also provide a Rootrepeal log to ensure that Quads has all the information he needs to remove it for you.
He will be along later today due to time zone considerations. He is also considerably backed up with these remediations at the moment, so please be patient, and we will stay in touch and keep you informed.
You could disable system restore, empty your browser caches, and dump your temp files to unload as much as possible. Don't do any banking or other privacy related activities until we get rid of it.
http://homepages.slingshot.co.nz/~crutches/RootRep
07-18-2009 08:52 PM
Hi
Now (read carefully) If you have Spybot S&D uninstall it.
Also during the restarts with Avenger if Your PC has a Startup repair center like with HP and Toshiba tell it to start Normally if it kicks in.
1. Download Avenger to your desktop,
Unzipped version http://homepages.slingshot.co.nz/~crutches/Avenger
Creators website http://swandog46.geekstogo.com/avenger2/avenger2.h
2. Click to run "Avenger.exe" (right click "Run as Administrator" if using Vista)
3. In the "Input script here:" copy and paste the script between the lines
Drivers to disable:
MSIVXserv.sys
Drivers to delete:
MSIVXserv.sys
Files to delete:
C:\Autorun.inf
D:\Autorun.inf
C:\WINDOWS\System32\drivers\MSIVXmbfwujwfwhdxpnbii
C:\WINDOWS\System32\MSIVXqrpicvmekqngdwchcnehiltcd
C:\WINDOWS\System32\MSIVXxnovtiixpxrvtmytxutxpximx
C:\WINDOWS\System32\MSIVXcount
C:\Users\TEMP\AppData\Local\Temp\~DFD46F.tmp
C:\Users\TEMP\AppData\Local\Temp\~DFD488.tmp
Registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\M
HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX
Here is a screenshot (script updated since shot)
Make sure the "Automatically disable any rootkits found" is NOT selected
4. Click "Execute"
You will be asked to restart the PC click "Yes", when the PC restarts the load screen will takes slightly longer, then when it looks as though windows is loading the PC will restart again.
Then when Windows fully loads the Avenger log will be loaded, showing files it could or could not find. C:\Avenger.txt
5. Restart the PC again, then see if you can install Update and run Malwarebytes http://www.filehippo.com/download_malwarebytes_ant
Quads
