 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
Windows 7 - Need help with recurring virus |
12-28-2011
|
#1 | | windows 7 home premium x64 |
Need help with recurring virus Hi guys, a couple weeks ago I was watching a stream on twitch.tv and my browser closed and a fake Windows Security Center popped up and started running a scan telling me I had to get the premium Windows security (I don't recall the exact name of what it was telling me I needed to get). Anyway I opened the task manager and saw a bunch of processes called "aak.exe" running so I figured that was the virus. I used "end process tree" to shut them all down then tried to run Avira (I had Avira and PrevX3.0 both running on my machine at the time). When I tried to open any program (Firefox, any program) it immediately hijacked that command and the fake antivirus started scanning again. I again shut it down with task manager and each time I tried to open something I'd have to go through the whole "open with" process and find the launcher. In the mean time I ran scans with Avira and PrevX3.0 and both found no problems so I opened firefox again to get the virus prompt and found the location of the .exe file from the task manager (it had put aak.exe into the C:\users\xxxxxx\AppData\Local folder). I deleted aak.exe and then tried to open Firefox again, but again had to go through the "open with" process. I downloaded CCleaner thinking the virus had forced all my applications to run through the aak.exe location which I had deleted. I cleaned my registry and everything worked fine so I figured I had gotten rid of it.
A week later the same problem occurred but instead of it been aak.exe it was running through ibh.exe. The file was in the same location and I took the same steps to temporarily fix it.
Since then I've run Lavasoft's AdAware and Avast and both have come up clean. Anyone have any help before I have to take that horrible plunge and reformat?
| My System Specs | | OS windows 7 home premium x64 |
12-28-2011
|
#2 | | W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi |
Hi there
I keep saying to people that the ONLY 100% successful way to cleanse a computer is to restore a CLEAN image from a recent backup --- if you don't have one then a new re-install is required.
I certainly would NEVER trust a "Cleansed" computer --- if AV software can't be guaranteed to be 100% effective why should we expect "cleansing" software to be 100% effective either.
Keep your OS / Programs on different drive(s) / partition(s) to your data / music / email etc.
BACKUP regularly -- plenty of good backup stuff out there -- Macrium, Acronis, Paragon etc etc.
These will also create bootable restore USB's / DVD's too so you can even recover after wiping the whole HDD clean.
A typical Windows 7 restore will take at the most around 25 mins -- so BACKUP regularly -- it will save NO END OF HASSLE in these circumstances. You will generally only need to recover the OS partition -- your data will remain intact.
As an added level of protection you could create a Windows 7 Virtual machine and ONLY do your web surfing from that machine. Then if it gets infected just ditch it and load a new VM. (When you create a VM you can "clone" it as well. Keep several clones available in case you have to get rid of a VM).
Cheers
jimbo | My System Specs | | System Manufacturer/Model Number Custom built OS W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi CPU Q9400 QUAD Motherboard P5QL-CM Memory 8GB Graphics Card On Motherborad Sound Card Realtek HD audio Monitor(s) Displays Apple Cinema display Mouse Toshiba wireless laser Hard Drives 4 X 1TB SATA Internet Speed > 20MB up |
12-28-2011
|
#3 | | Windows 7 Ultimate 32bit SP1 |
Do you have Advanced Anti Keylogger on your machine? AAK - aak.exe - Program Information
If not, do the following please:
Copy and paste these lines in Note pad. @Echo on pushd\windows\system32\drivers\etc attrib -h -s -r hosts echo 127.0.0.1 localhost>HOSTS attrib +r +h +s hosts popd ipconfig /release ipconfig /renew ipconfig /flushdns netsh winsock reset all netsh int ip reset all shutdown -r -t 1 del %0
Save as flush.bat to your desktop.
Double click on the flush.bat file to run it.Vista and Windows 7... right click the .bat file and choose to run as Administrator. Your computer will reboot itself.
Next, download TDSSKiller and save it to your Desktop. - Extract the file and run it.
- Once completed it will create a log in the root directory (usually C:\).
- Please post the contents of that log in your next reply.
| My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Other Info ATI HDMI Audio |
12-28-2011
|
#4 | | windows 7 home premium x64 |
@Jacee
No, I don't have Advanced Anti-Keylogger. When I get back from work I'll do what you told me and post a log. | My System Specs | | OS windows 7 home premium x64 |
12-28-2011
|
#5 | | Windows 7 Ultimate 32bit SP1 |
Okay | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Other Info ATI HDMI Audio |
12-28-2011
|
#6 | | windows 7 home premium x64 |
As an aside, what I find interesting is two different .exe files have been the source of my problem (aak.exe and ibh.exe), is this a common thing for malware or trojans? The second time it occurred (with ibh.exe as the problem) Avast wanted me to "sandbox" my browser when I opened it, but again said my system was clean when I ran the scan. | My System Specs | | OS windows 7 home premium x64 |
12-28-2011
|
#7 | | W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi |
Hi there
Just bite the bullet -- forget the "Monday Morning Quarterbacking" -- whatever went wrong has gone wrong and it really in this situation isn't any point in trying to analyse Why or How -- just FIX IT.
To Fix it I'd go for either of the solutions outlined in the my previous post in this thread. Also consider the VM option two.
Any other course of action will take you AGES and you can never be 100% certain that the problem has been REALLY solved.
Cheers
jimbo | My System Specs | | System Manufacturer/Model Number Custom built OS W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi CPU Q9400 QUAD Motherboard P5QL-CM Memory 8GB Graphics Card On Motherborad Sound Card Realtek HD audio Monitor(s) Displays Apple Cinema display Mouse Toshiba wireless laser Hard Drives 4 X 1TB SATA Internet Speed > 20MB up |
12-28-2011
|
#8 | | Operating System : Windows 7 Home Premium Edition 6.01.7600 SP1 (x64) |
i suggest you run kaspersky free virus remover tool >> http://goo.gl/k2x1s i have used this with great success as well as clients and friends please follow the instructions. Kaspersky Virus Removal Tool 2011 Quote: Kaspersky Virus Removal Tool 2011 is a free software intended to disinfect infected computers, removing viruses, Trojans, and spyware, as well as any other types of malware. Kaspersky Virus Removal Tool 2011 uses the same highly efficient algorithms for detecting malware as Kaspersky Anti-Virus. Algorithms include a full-functional anti-virus scanner, technologies developed for detecting vulnerabilities in installed applications and operating systems, and a technology for running scripts intended for removing complex and compound viruses. The utility can be used as a free anti-virus software. Kaspersky Virus Removal Tool 2011 is not intended for real-time protection of computer. After the disinfection of the computer is complete, the application should be uninstalled from the hard drive and replaced with the real-time protection anti-virus
Kaspersky Virus Removal Tool 2011 provides no update function. The up-to-date version of the application with the latest version of anti-virus databases is always available on the website of Kaspersky Lab Technical Support service. Quote: Advantages:
The application is absolutely free.
Simple application interface.
Installation on an infected computer. Including:
in Safe Mode of Microsoft Windows;
when a real-time protection of anti-virus is running.
The installation process does not require interaction with the user anymore.
Closing the main window is enough to uninstall the application form a computer.
Automatic scan and disinfection:
search of malware using signature databases;
heuristic analyzer;
search and neutralization of rootkits;
search of applications with known vulnerabilities;
non-signature search of malware based on "cloud" technologies (when Internet access is available).
Manual scan and disinfection:
collection of information about an infected computer and system;
interactive creation of disinfection scripts.
What's new in Kaspersky Virus Removal Tool 2011:
The user interface has been improved.
The application installation and uninstallation have been simplified.
A full-functional use of the application from a flash card has been implemented.
The process self-defense has been implemented.
The advanced disinfection has been improved.
Compatibility with real-time protection anti-virus applications has been improved.
Active use of the "cloud" technology of Kaspersky Security Network. | My System Specs | | System Manufacturer/Model Number packard bell IXTREME M5722 OS Operating System : Windows 7 Home Premium Edition 6.01.7600 SP1 (x64) CPU Processor : Intel Core 2 Quad Q8300 @ 2500 MHz Motherboard Mainboard : Packard Bell (Acer EG43M ) Memory Physical Memory :8GB Corsair4x 2GB 800MHz C5 DDR2 Graphics Card Video Card : ATI Radeon HD 5500 Series Sound Card Video Card : ATI Radeon HD 5500 Series Monitor(s) Displays PACKARD BELL Viseo 23" : Maestro 23.1" Benq 22" V2220 led : Screen Resolution Current Display :1920x1080p pixels at 60 Hz in HD LED Keyboard Gigabyte Aivia K8100 Mouse TRUST-Wireless Laser Mouse - Carbon edition MI-7770C PSU XFX ProSeries 550W PSU Case PACKARD BELL IXTREME Cooling System Blower Current: 150mA Air Flow16CFM ;Akasa 90mm rear Hard Drives Hard Disks : WDC (1000 GB)
Drive C: (Hard Disk) : 428 GB available on 491 GB
Drive D: (Hard Disk) : 426 GB available on 492 GB
SAMSUNG spinpoint HD103SJ 1000.2 GB
(X 2) KINGSTON SSD NOW V 30GB Internet Speed TP-LINK > TL-WN951N / AV200 Gigabit Powerline Adapters Other Info EXTRA COOLING>(FAN CONTROLLER) PC Bay Cooler 3 x 40mm fans; Akasa AK-HD-BL Blue hard drive cooler 2 x 40 mm fan 4500 rpm 29.7 dBA
Bios> American Megatrends Inc.
Version : P01-A1
Date : 08/31/2009 |
12-28-2011
|
#9 | | Windows 7 Ultimate 32bit SP1 |
Quote: Legitimate aak.exe file is not related to any security threats. However, a spyware or adware program can use the same or similar file named to compromise users. So you have malware that will diquise itself.... and run at startup. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Other Info ATI HDMI Audio |
12-28-2011
|
#10 | | W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi |
Hi everyone
I still think my solution (recover from a good backup or re-install) is the only sensible solution in this situation.
Had the OP followed one of my original suggestions --he would be UP AND RUNNING with a 100% clean computer had he done this between NOW (GMT 21.50) and the time of my previous post approx 2 hrs before..
Sometimes -- and I address this even to real GURU type guys -- time spent on analysing a "One off" type of scenario just isn't worth it if you can fix the entire problem using alternative methods that don't rely on post analysing the the original problem.
As an Engineer -- I just want to get stuff working again. If I'm the designer etc I would probably be more interested in the "Why it broke" scenario but in general I just want "to get the show on the road again" as fast as possible.
Cheers
jimbo | My System Specs | | System Manufacturer/Model Number Custom built OS W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi CPU Q9400 QUAD Motherboard P5QL-CM Memory 8GB Graphics Card On Motherborad Sound Card Realtek HD audio Monitor(s) Displays Apple Cinema display Mouse Toshiba wireless laser Hard Drives 4 X 1TB SATA Internet Speed > 20MB up Need help with recurring virus problems? All times are GMT -5. The time now is 01:12 AM. |  |