Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > Malware and Virus Removal

Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 22nd June 2009   #1
Member
 
Profile:
Join Date: Nov 2008
Location: Sarnia, Ontario, Canada
Posts: 6
Computer Experience:
intermediate
mrx65 Reputation Level


Exclamation [Active] Infected with trojan "ACVE"

I am trying a post under this section first so please read to the end to understand why. The main reason for the post is a trojan called "ACVE" (not fully sure about the name as it is hiding very well). It is on another computer. I have googled ACVE, but only found programs that would help if they were on before the virus. This is why I think using another computer may work. I have taken the computer to a computer shop with a very good name where they scanned it and deleted/rebuilt the whole user file (there was too much corruption to save the user). But the virus came back the next day and increases each day. I have software that claims to be able to remove it, but ACVE blocks them from even starting and it also prevents me from searching various parts of the C drive (I have used the hunt and delete method in the past to weaken or remove various programs).

My theory is to remove the infected hard drive from the other computer and connect it to my computer, scan/remove the virus with the software on my computer, and then place it back into the original computer. Wisely, I have seen the possible "side effects" of such an action and figured I should consult someone much wiser than I first. First I don't want the virus to cross over to my computer and secondly it is a main drive and may not "like" or survive being a temporary slave drive. I have an external case that currently houses an external cd drive with a USB connection to my computer. It is designed to connect to internal hardware like a cd drive or hard drive. My computer is running XP and the infected one has XP pro.

My ultimate theory on this is that the maker of the virus may have over looked or is unable to "defend" the virus from this kind of attack. Plus this would give me the ability to safely scan (in theory) several times and check for damage to and hopefully save the confidential files stored on it. I am open to posting a virus thread, but given the strength of the virus' defences I am thinking this the best way and not the easiest to get around them, if it will work.
thanks,
greg

mrx65 is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 22nd June 2009   #2
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,546
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

Welcome to WindowsBBS

The only members competent to advise/assist in this matter are our trained malware analysts - this is not a Hardware issue.

I have moved your thread with title edit to that the Malware & Virus Removal forum for their attention.

PeteC is online now   Reply With Quote
Old 22nd June 2009   #3
Administrator
 
Admin.'s Avatar
 
Profile:
Join Date: Dec 2001
Location: 35⁰ 53'55.1" N, 14⁰ 28'37.5" E
Posts: 3,248
Computer Experience:
***
Admin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation Level

My System

Hi,

Read this post as indicated at the top of this forum & follow the instructions.

Admin. is offline   Reply With Quote
Old 25th June 2009   #4
Member
 
Profile:
Join Date: Nov 2008
Location: Sarnia, Ontario, Canada
Posts: 6
Computer Experience:
intermediate
mrx65 Reputation Level


I appreciate the reply. I thought I had followed the posting instructions. I posted under the other forum first as I know very little about the virus and if a USB connection can be made, it would open up the drive to the programs I have to identify the virus. I don't have the mirror on the infected computer just yet as I was trying to prevent the virus from copying confidential files to the internet. I do have it done for my computer and plan on running it on the infected computer now that I have copied/deleted the confidential files. Do you think the mirror will show what virus it is? All I have to go on is what Malwarebytes claims is there. This is the same program that the computer shop used and said that the virus is gone. I am trying to avoid another trip to the computer shop as we really don't have the money to spend on it right now. The virus is very well defended and some cases it blocks copying them from a stick. Or worse yet, will shut them down if they get too "close" even if run from the stick.
thanks,
greg

mrx65 is offline   Reply With Quote
Old 26th June 2009   #5
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 4,603
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System

Download the program listed below on good computer, move it to bad computer...

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  4. Double click on combofix.exe & follow the prompts.
  5. When finished, it will produce a report for you.
  6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

Make sure, you re-enable your security programs, when you're done with Combofix.

broni is offline   Reply With Quote
Old 28th June 2009   #6
Member
 
Profile:
Join Date: Nov 2008
Location: Sarnia, Ontario, Canada
Posts: 6
Computer Experience:
intermediate
mrx65 Reputation Level


Thanks. I will try this and see what happens. May be a couple of days as I am sick today.
thanks,
greg

mrx65 is offline   Reply With Quote
Old 28th June 2009   #7
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 4,603
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System

No problem
Get well

broni is offline   Reply With Quote
Old 17th July 2009   #8
Member
 
Profile:
Join Date: Nov 2008
Location: Sarnia, Ontario, Canada
Posts: 6
Computer Experience:
intermediate
mrx65 Reputation Level


Thanks. I think I am ready to attack this now. I just wanted to clarify what script blocking is. I have found various things about it on the internet, but still not 100% sure. Does it only include explorer/firefox etc? I'm not 100% sure what is on that computer, but anti virus etc are generally easy enough to turn off. It is the script blocking that has me lost.
thanks,
greg

mrx65 is offline   Reply With Quote
Old 17th July 2009   #9
Member
 
Profile:
Join Date: Nov 2008
Location: Sarnia, Ontario, Canada
Posts: 6
Computer Experience:
intermediate
mrx65 Reputation Level


Do I post a copy of the report that it generates here? I read about it on the download site and they recommend it.
thanks,
greg

mrx65 is offline   Reply With Quote
Old 18th July 2009   #10
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 4,603
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System

I'm glad, you feel better

Just turn your antivirus, and firewall off.
If you use Windows Defender, or/and Spybot, turn them off as well.

Yes, paste Combofix log back here.

broni is offline   Reply With Quote
Old 22nd July 2009   #11
Member
 
Profile:
Join Date: Nov 2008
Location: Sarnia, Ontario, Canada
Posts: 6
Computer Experience:
intermediate
mrx65 Reputation Level


another road block

Combofix won't start. I turned off the firewall and AVG. I have tried to run it from the USB stick as well. I also tried a "back door" approach, I have Starter installed and selected Combofix to start at startup. Still does not work. Spybot is on, but I can't start it to turn it off after I did an update, so not sure if that is what is blocking it or not. I have had a lot of trouble getting antivirus\spyware to start right away on that computer. AVG and spyware doctor all came back clean when they finally started (it took a few days). I am starting to think that the virus will corrupt scan programs etc before it will let them start. So far, Malwarebytes is the only one to "find" ACVE. I have deleted the file that it says is infected (c:windows\... dllcache\cdaudio.sys). I was able to scan with Spybot, via a right click launch at the file, but it found nothing. There is still something wrong the computer. I have had the power supply replaced within the last month, but the computer continues to restart on its own in a regular pattern. It is a short time that sometimes gets to the desktop, but if you persist it will eventually stay running as long as you want or until you restart it. It is a bit random, but mostly predictable. There is an occasional restart after an hour or 2. It will stay running even at peak capacity, so I am thinking that it's not the power supply. Scan programs or windows explorer when in certain parts of the windows file would set off a restart. This doesn't seem to be the case anymore.
I am starting to reconsider my original approach of connecting the harddrive via a USB to this computer and scanning as a slave drive. I am not sure exactly how to do it, but I do have the equipment (I think) to do it. I have an external case that converts an internal part to an external part. It currently houses an internal cd rom.
thanks,
greg

mrx65 is offline   Reply With Quote
Old 23rd July 2009   #12
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 4,603
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System

Delete your copy of Combofix, and check my PM to you.
broni is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Resolved] First google redirects, now page load error sakurajiru Malware and Virus Removal 17 8th May 2009 17:38
[InActive] XP Malware mcseadogs Malware and Virus Removal 20 8th October 2008 04:04
[Resolved] Need help with Spyware and Virus Removal Please Rey Malware and Virus Removal 10 28th September 2008 23:13
How do I get rid of Infostealer.Gampass & Downloader?? dmcmillen Malware and Virus Removal 15 18th May 2008 02:27
Unknown Virus - vicious James Brandon Malware and Virus Removal 17 15th March 2005 04:44


All times are GMT +1. The time now is 09:49.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]