Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Need help with recurring virus

28 Dec 2011   #1
Heartwork

windows 7 home premium x64
 
 
Need help with recurring virus

Hi guys, a couple weeks ago I was watching a stream on twitch.tv and my browser closed and a fake Windows Security Center popped up and started running a scan telling me I had to get the premium Windows security (I don't recall the exact name of what it was telling me I needed to get). Anyway I opened the task manager and saw a bunch of processes called "aak.exe" running so I figured that was the virus. I used "end process tree" to shut them all down then tried to run Avira (I had Avira and PrevX3.0 both running on my machine at the time). When I tried to open any program (Firefox, any program) it immediately hijacked that command and the fake antivirus started scanning again. I again shut it down with task manager and each time I tried to open something I'd have to go through the whole "open with" process and find the launcher. In the mean time I ran scans with Avira and PrevX3.0 and both found no problems so I opened firefox again to get the virus prompt and found the location of the .exe file from the task manager (it had put aak.exe into the C:\users\xxxxxx\AppData\Local folder). I deleted aak.exe and then tried to open Firefox again, but again had to go through the "open with" process. I downloaded CCleaner thinking the virus had forced all my applications to run through the aak.exe location which I had deleted. I cleaned my registry and everything worked fine so I figured I had gotten rid of it.

A week later the same problem occurred but instead of it been aak.exe it was running through ibh.exe. The file was in the same location and I took the same steps to temporarily fix it.

Since then I've run Lavasoft's AdAware and Avast and both have come up clean. Anyone have any help before I have to take that horrible plunge and reformat?


My System SpecsSystem Spec
.
28 Dec 2011   #2
jimbo45

Linux CENTOS 7 / various Windows OS'es and servers
 
 

Hi there
I keep saying to people that the ONLY 100% successful way to cleanse a computer is to restore a CLEAN image from a recent backup --- if you don't have one then a new re-install is required.

I certainly would NEVER trust a "Cleansed" computer --- if AV software can't be guaranteed to be 100% effective why should we expect "cleansing" software to be 100% effective either.

Keep your OS / Programs on different drive(s) / partition(s) to your data / music / email etc.

BACKUP regularly -- plenty of good backup stuff out there -- Macrium, Acronis, Paragon etc etc.

These will also create bootable restore USB's / DVD's too so you can even recover after wiping the whole HDD clean.

A typical W7 restore will take at the most around 25 mins -- so BACKUP regularly -- it will save NO END OF HASSLE in these circumstances. You will generally only need to recover the OS partition -- your data will remain intact.

As an added level of protection you could create a W7 Virtual machine and ONLY do your web surfing from that machine. Then if it gets infected just ditch it and load a new VM. (When you create a VM you can "clone" it as well. Keep several clones available in case you have to get rid of a VM).

Cheers
jimbo
My System SpecsSystem Spec
28 Dec 2011   #3
Jacee
Microsoft MVP

Windows 7 Ultimate 32bit SP1
 
 

Do you have Advanced Anti Keylogger on your machine?
AAK - aak.exe - Program Information

If not, do the following please:

Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

Save as flush.bat to your desktop.
Double click on the flush.bat file to run it.Vista and Windows 7... right click the .bat file and choose to run as Administrator. Your computer will reboot itself.


Next, download TDSSKiller and save it to your Desktop.
  • Extract the file and run it.
  • Once completed it will create a log in the root directory (usually C:\).
  • Please post the contents of that log in your next reply.
My System SpecsSystem Spec
.

28 Dec 2011   #4
Heartwork

windows 7 home premium x64
 
 

@Jacee
No, I don't have Advanced Anti-Keylogger. When I get back from work I'll do what you told me and post a log.
My System SpecsSystem Spec
28 Dec 2011   #5
Jacee
Microsoft MVP

Windows 7 Ultimate 32bit SP1
 
 

Okay
My System SpecsSystem Spec
28 Dec 2011   #6
Heartwork

windows 7 home premium x64
 
 

As an aside, what I find interesting is two different .exe files have been the source of my problem (aak.exe and ibh.exe), is this a common thing for malware or trojans? The second time it occurred (with ibh.exe as the problem) Avast wanted me to "sandbox" my browser when I opened it, but again said my system was clean when I ran the scan.
My System SpecsSystem Spec
28 Dec 2011   #7
jimbo45

Linux CENTOS 7 / various Windows OS'es and servers
 
 

Hi there
Just bite the bullet -- forget the "Monday Morning Quarterbacking" -- whatever went wrong has gone wrong and it really in this situation isn't any point in trying to analyse Why or How -- just FIX IT.

To Fix it I'd go for either of the solutions outlined in the my previous post in this thread. Also consider the VM option two.

Any other course of action will take you AGES and you can never be 100% certain that the problem has been REALLY solved.

Cheers
jimbo
My System SpecsSystem Spec
28 Dec 2011   #8
brianzion

Operating System : Windows 7 Home Premium Edition 6.01.7600 SP1 (x64)
 
 

i suggest you run kaspersky free virus remover tool >> http://goo.gl/k2x1s i have used this with great success as well as clients and friends please follow the instructions.

Kaspersky Virus Removal Tool 2011


Quote:
Kaspersky Virus Removal Tool 2011 is a free software intended to disinfect infected computers, removing viruses, Trojans, and spyware, as well as any other types of malware. Kaspersky Virus Removal Tool 2011 uses the same highly efficient algorithms for detecting malware as Kaspersky Anti-Virus. Algorithms include a full-functional anti-virus scanner, technologies developed for detecting vulnerabilities in installed applications and operating systems, and a technology for running scripts intended for removing complex and compound viruses. The utility can be used as a free anti-virus software.

Kaspersky Virus Removal Tool 2011 is not intended for real-time protection of computer. After the disinfection of the computer is complete, the application should be uninstalled from the hard drive and replaced with the real-time protection anti-virus

Kaspersky Virus Removal Tool 2011 provides no update function. The up-to-date version of the application with the latest version of anti-virus databases is always available on the website of Kaspersky Lab Technical Support service.

Quote:
Advantages:

The application is absolutely free.
Simple application interface.
Installation on an infected computer. Including:
in Safe Mode of Microsoft Windows;
when a real-time protection of anti-virus is running.
The installation process does not require interaction with the user anymore.
Closing the main window is enough to uninstall the application form a computer.
Automatic scan and disinfection:
search of malware using signature databases;
heuristic analyzer;
search and neutralization of rootkits;
search of applications with known vulnerabilities;
non-signature search of malware based on "cloud" technologies (when Internet access is available).
Manual scan and disinfection:
collection of information about an infected computer and system;
interactive creation of disinfection scripts.
What's new in Kaspersky Virus Removal Tool 2011:

The user interface has been improved.
The application installation and uninstallation have been simplified.
A full-functional use of the application from a flash card has been implemented.
The process self-defense has been implemented.
The advanced disinfection has been improved.
Compatibility with real-time protection anti-virus applications has been improved.
Active use of the "cloud" technology of Kaspersky Security Network.
My System SpecsSystem Spec
28 Dec 2011   #9
Jacee
Microsoft MVP

Windows 7 Ultimate 32bit SP1
 
 

Quote:
Legitimate aak.exe file is not related to any security threats. However, a spyware or adware program can use the same or similar file named to compromise users.
So you have malware that will diquise itself.... and run at startup.
My System SpecsSystem Spec
28 Dec 2011   #10
jimbo45

Linux CENTOS 7 / various Windows OS'es and servers
 
 

Hi everyone
I still think my solution (recover from a good backup or re-install) is the only sensible solution in this situation.

Had the OP followed one of my original suggestions --he would be UP AND RUNNING with a 100% clean computer had he done this between NOW (GMT 21.50) and the time of my previous post approx 2 hrs before..

Sometimes -- and I address this even to real GURU type guys -- time spent on analysing a "One off" type of scenario just isn't worth it if you can fix the entire problem using alternative methods that don't rely on post analysing the the original problem.

As an Engineer -- I just want to get stuff working again. If I'm the designer etc I would probably be more interested in the "Why it broke" scenario but in general I just want "to get the show on the road again" as fast as possible.

Cheers
jimbo
My System SpecsSystem Spec
Reply

 Need help with recurring virus




Thread Tools Search this Thread
Search this Thread:

Advanced Search




Similar help and support threads
Thread Forum
Recurring events in outlook stop recurring
We have multiple conference rooms with resources in active directory so we can schedule meetings in the conference rooms. Recently, I'm not sure for how long, whenever someone creates a recurring event with no end date when you go into the event on the conference room calender it only shows...
Microsoft Office
Possible Memory Leak Virus - Anti-virus detects nothing?
Hello, I am needing some support on what is exactly taking up all the RAM on my brother's PC as after about 8 hours of uptime, 65% of my Physical Memory is being used up with nothing really open. I did some research and found out it was a possible memory leak or virus, so I first tried to run...
Performance & Maintenance
how to fix / clean windows from ramnit virus and virut virus?
my windows infected ramnit virus and virut virus,how to clean them?
System Security
I have a virus and unable to run/download anti-virus software
Hi, This is my first time posting to the forum. I am not that knowledgeable with computers, but can follow basic instructions. My laptop is acting funny--I think I have a virus. However, I am unable to run any anti-malware or anti-virus software. I try to run McAfee and I get an error...
System Security
Want ideas for Virus removal if virus shows up in safemode CMD
Hi, Looking for general ideas on how everyone else handles a strong virus. If the virus is showing up in Windows regular mode, it opens in safemode and opens in safmode with command prompt. Besides the usual such as boot to repair mode and use system restore, dock hard drive to another pc and...
System Security
BSOD recurring last 4 days possible virus?
Is Windows 7 . . . - x86 (32-bit) or x64 ? Mine is 64 - the original installed OS on the system? Computer built- Windows 7 installed on it - an OEM or full retail version? Full retain version - What is the age of system (hardware)? computer built 2 months ago - What is the age of OS...
BSOD Help and Support


Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 09:43.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App