Page 1 of 2 12 LastLast
Results 1 to 10 of 19
  1. #1
    Rookie
    Overall activity: 7.0%

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,138
    Liked
    24 times
    Points
    44,879

    Got infected but can't remove it

    Hi,

    I need your help again. I am running KIS 09 8.0.0.506.If I were not mistaken, this morning my PC got infected with this worm which KIS could not do anything. It told me to skip (Do not perform any actions) which was recommend. I think was from my father's pendrive. He didn't opened the pendrive. Just copied some file containing his photos he had taken and transfered it to the pendrive. I personally set my KIS proactive defences (Files and memory) to scan :
    a) all removeable drive
    b) all hard drives
    c) system memory
    d) disk boot sectors
    e) startup objects.

    My scan for it is a) Heuristic Analysis
    b) Deep scan

    I have runned a full scan and it found another virus of the same type in the C:\Documents and Settings\Network Service\Local Settings\Temporary Internet Files\Content.IE5\0YWUMNO7\nwlco[1].jpg and KIS successfully deleted it away.
    But the same virus cannot be deleted in another place. The details are as follow :
    Name of virus :Net-Worm.Win32.Kido.ed
    Location : C:\windows\system32\rkrnab.dll
    Reasons cannot Disinfect or Delete : write access is denied

    What does this Net-Worm.Win32.Kido.ed virus does?

    What should I do? I know if I manually remove it, I will be touching my system32 files which I know is the core of the computer. When that happens, the running process of my computer will be affected. If I do delete it, it will be like leaving a gaping hole in my system which I don't want.

    This are the actions I am thinking of taking.
    a) Uninstall KIS and go for NIS. Hopefully Nis will be able to remove it.
    b) Stick to KIS and and don't do anything as my computer is running smoothly. No clues a virus is present.
    c) Stick to KIS and deleting it manually. My last resort as I know somehow the running of my computer will be affected.

    Please advice me as I do not like this kind of things. Powerless to do anything.

    P.S Happy Chinese New Year to those who celebrates Chinese New Year. Do enjoy the abundance gorgeous food. Hehe...


    Thank you in advance for helping me out.
    Thoughts are like a never ending ocean where it is deep, endless and dangerous

  2. #2
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Location
    Australia
    Posts
    3,884
    Liked
    0 times
    Points
    20,463
    Download FileAssasin and delete the file with it. Virus creators use the WINDOWS folder to drop in viruses because they know most users would think "Oh it must be important" and freak out.
    The file doesn't sound legitimate to me too.

  3. #3
    Tech God
    Overall activity: 0%

    Join Date
    Jan 2008
    Location
    South Africa
    Posts
    1,279
    Liked
    14 times
    Points
    1,853
    It seems as if you are infected with the conficer worm. Ceyfer covered it in detail here.

  4. #4
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    U might probably infected by the Worm:Win32/Conficker.B


    "Stars and the Sun"


  5. #5
    Junior Techie
    Overall activity: 0%

    Join Date
    Dec 2008
    Posts
    148
    Liked
    0 times
    Points
    3,702
    will it/theworm let you download them A/Ss onto infected machine ceyfer.

  6. #6
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Quote Originally Posted by laylow21 View Post
    will it/theworm let you download them A/Ss onto infected machine ceyfer.
    On ur own infected Pc the worm might blocked those AV/AS sites - It depends how the worm penetrated ur system?

    So the best thing is download the said remover on the other Pc

  7. #7
    Newbie
    Overall activity: 0%

    Join Date
    Jan 2009
    Location
    Near Computers
    Posts
    14
    Liked
    0 times
    Points
    2,397
    If u have windows fully updated then type mrt in run command box and follow the instructions and remember Kis is best but u have to update it daily.

  8. #8
    Experienced User
    Overall activity: 0%

    Join Date
    Dec 2008
    Location
    inside my hamster cage
    Posts
    152
    Liked
    0 times
    Points
    7,228
    I got infected about 3 weeks ago with a virus or worm or something, ( i forgot the name, will post the print Screen of Malwarebyte when detected it, if i still have it :d) the symptom was that my computer show Windows Error Reporting Services very frequently, the Windows automatic updates is disable,unable to browse any AV or anti spyware website, unable to update my KIS. every time i update my windows my IE show Google main page eventhouhg the link in the address bar is windowsupdate.

    KIS 2009 Detect Nothing, Spybot S&D detect one trojan called IPChanger.W32. but still the same symptom after reboot, my computer cleaned after i scanned with Malwarebyte's, but you need to turn off system restore.

    Do not uninstall KIS 2009,stay with it, but you can download Malwarebyte's and install it together withs KIS, my KIS 2009 just fine with Malwarebyte's.

    i don't know if my computer was infected with Conficker, i hope it was not. :d.

    Ps: i just uploaded the screen show the detected file by Malwarebyte's.
    Attached Images Attached Images
    Last edited by Rekhyt; 01-29-2009 at 09:15 PM.

  9. #9
    Newbie
    Overall activity: 0%

    Join Date
    Jan 2009
    Posts
    7
    Liked
    0 times
    Points
    2,488
    i googled the worm name and found this for you :

    Step 1: Use Windows File Search Tool to Find kvnab.dll Path

    1. Go to Start > Search > All Files or Folders.
    2. In the "All or part of the the file name" section, type in "kvnab.dll" file name(s).
    3. To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button.
    4. When Windows finishes your search, hover over the "In Folder" of "kvnab.dll", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete kvnab.dll in the following manual removal steps.


    Step 2: Use Windows Command Prompt to Unregister kvnab.dll Files

    1. Open the Windows Command Prompt, go to Start > Run > type cmd and then click the "OK" button.
    2. Type "cd" in order to change the current directory, press the "space" button, enter the full path to where you believe the kvnab.dll DLL file is located and press the "Enter" button on your keyboard. If don't know where kvnab.dll DLL file is located, use the "dir" command to display the directory's contents.
    3. To unregister "kvnab.dll" DLL file, type in the exact directory path + "regsvr32 /u" + [DLL_NAME] (for example, :C\folder\> regsvr32 /u kvnab.dll.dll) and press the "Enter" button. A message will pop up that says you successfully unregistered the file.
    4. Type in "dir /A name_of_the_folder" (for example, C:\folder), which will display the folder's content even the hidden files.
    5. To change directory, type in "cd name_of_the_folder".
    6. Once you have the file you're looking for type in del "name_of_the_file".
    7. To delete a file in folder, type in "del name_of_the_file".
    8. To delete the entire folder, type in "rmdir /S name_of_the_folder".

    Step 3: Detect and Delete Other kvnab.dll Files

    1. Select the "kvnab.dll" process and click on the "End Process" button to kill it.


    - Restart and that should do it ... but i recommend you check also by safe mode

  10. #10
    Experienced User
    Overall activity: 0%

    Join Date
    Dec 2008
    Location
    inside my hamster cage
    Posts
    152
    Liked
    0 times
    Points
    7,228
    Just Google type name of worm you mentioned above and Google find this link, i hope this will give you more information to help you more :

    http://www.threatexpert.com/report.aspx?md5=7bb455ea4a77b24478fba4de145115eb

    good luck man

    Uuppss.... , I just realized that Ceyfer already posted the link i provided above, sorry everyone,specialy ceyfer.
    Last edited by Rekhyt; 01-30-2009 at 09:39 AM.

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. am i infected?
    By imgonagetusucka in forum Spyware/Viruses
    Replies: 2
    Last Post: 07-17-2011, 12:25 PM
  2. Replies: 3
    Last Post: 02-06-2011, 09:10 PM
  3. IS my pc infected? please help
    By sid8010 in forum Spyware/Viruses
    Replies: 4
    Last Post: 09-08-2010, 08:49 PM
  4. What if I WANT to be infected?
    By Gabethebabe in forum Spyware/Viruses
    Replies: 31
    Last Post: 12-13-2009, 03:20 PM
  5. Replies: 5
    Last Post: 03-23-2009, 07:25 PM
All times are GMT +8. The time now is 10:10 AM.