Visitor
2Bleu
Posts: 2
Registered: ‎08-02-2009
MSIVX strikes again... :(
[ Edited ]

It's so frustrating to see so many of these come up and having to get "individualized" scripts to repair...  from seeing previous posts regarding this ROOTKIT, I'm including my scan results.  Please help.

 

Message Edited by 2Bleu on 08-07-2009 09:23 AM
delphinium
Posts: 9,680
Kudos: 2,856
Solutions: 283
Registered: ‎11-21-2008
Re: MSIVX strikes again... :(

Nice logs to work with 2bleu.  The problem with rootkits is that they hook into the very base of the operating system which makes them dangerous to remove.  Done incorrectly, you can lose enough of your OS to make reformatting necessary.  Quads is very skilled in this type of remediation.

 

He will be available later due to time zone factors to provide you with tools and assistance.

 

In the meantime, I would recommend diabling system restore, clear your web browser caches and dump your temp files.

 

 

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Bot Obliterator
Quads
Posts: 13,951
Registered: ‎07-21-2008
Re: MSIVX strikes again... :(

Hi

 

Now  (read carefully) If you have Spybot S&D uninstall it.

 

Also during the restarts with Avenger if Your PC has a Startup repair center like with HP and Toshiba tell it to start Normally if it kicks in.

 

1. Download Avenger to your desktop,

 

Unzipped version http://homepages.slingshot.co.nz/~crutches/Avenger/

OR  Creators website http://swandog46.geekstogo.com/avenger2/avenger2.html with zipped version to the unzip to desktop 

 

2. Click to run "Avenger.exe"  (right click "Run as Administrator" if using Vista)

 

3. In the "Input script here:" copy and paste the script between the lines

 


Drivers to disable:

MSIVXserv.sys

 

Drivers to delete:

MSIVXserv.sys

 

Files to delete:

C:\Autorun.inf

D:\Autorun.inf

C:\WINDOWS\System32\drivers\MSIVXpidddqmetjvdcqnflbubrvnrbmxroufe.sys

C:\WINDOWS\System32\MSIVXiqpqwethsdgpmnpudntroekigqcojjei.dll

C:\WINDOWS\System32\MSIVXxbdtvtkuuqnayprftutvgacbcrmeqvnc.dll

C:\WINDOWS\System32\MSIVXcount

 

Registry keys to delete:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX 


 

Here is a screenshot (script updated since shot)

 

Avenger.jpg

 

Make sure the "Automatically disable any rootkits found" is NOT selected

 

4. Click "Execute"

 

You will be asked to restart the PC click "Yes", when the PC restarts the load screen will takes slightly longer, then when it looks as though windows is loading the PC will restart again.

Then when Windows fully loads the Avenger log will be loaded, showing files it could or could not find.

 

5. Restart the PC again, then see if you can install  Update and run Malwarebytes http://www.filehippo.com/download_malwarebytes_anti_malware/

 

Quads 

Visitor
2Bleu
Posts: 2
Registered: ‎08-02-2009
Re: MSIVX strikes again... :(

Thank you again Quads!  Everything worked as expected. 

I'm sure I speak for most everyone when I say your work is greatly appreciated.

 

 

Bot Obliterator
Quads
Posts: 13,951
Registered: ‎07-21-2008
Re: MSIVX strikes again... :(

Hi

 

No problem

 

Quads