A Digital Age Deserves A Digital Leader

A personal "removal" experience...WinAntiVirusPro-

A personal "removal" experience...WinAntiVirusPro-

Postby kd1966 » Thu Jul 20, 2006 2:46 am

Scene: Home where some elderly folks have lived over 35 years........... got a Dell about 2 years ago and everything works great! Introduce some grand-kids.......... unknown computer savvy............ anyhow I arrive on the scene............

Apparantly all the problems started when this "red icon" started popping up, which is/was the WinAntiVirus 2006............. I didn't make the mistake of trying to "run" the program fortunately...........

I went into safemode and ran some standard scans (Ewido, AdawareSE) and deleted much of what was causing problems.........BUT there seemed to be something that kept coming back.............

I checked for rootkits and such - thankfully none - and I eventually got this one "licked"...... ^*^ but not without much hassle. Using my online research skillz I could not locate the "offending" files for a description of the originator, as stuff just kept coming back over and over..........

I finally traced some of the files to names:
pafmb.dat
jdpjpm.exe
ckckv.exe
ALL UNDER %windir%\system32 (except ckckv.exe which was %windir%\PSS)
Not only that, but this was causing a process to run 3X, amhnp.exe, but although I could see it in TaskMgr initially, it was INVISIBLE to processexplorer (Sysinternals) for a good awhile.

I think I ran rootkit identifier programs about 3 or 4 times........ NOTHING came up. I thought I would run an online scan, but the best one I had (Panda) would ONLY REMOVE VIRUS, NOT a DANG THNG ELSE!! Unless you paid, of course....... :x

I was finally able to get rid of this through registry editing in safemode, along with renaming/moving the resulting files after deleting........... and also installing Avast! after removing Mcafee Virus scan (It a Dell, dude..lol) and running a boot scan on restart to remove the offending files that I did not have "permission" to remove, even after renaming.........
PRO PLATINUM
User avatar
Posts: 6831
Joined: Tue Aug 09, 2005 2:00 am
Location: USA - GSO - NC

Postby NT50 » Thu Jul 20, 2006 10:41 pm

Instead of Avast ..... I understand it is free..... why didn't you intsall trail NOD32 and let it take care of it for you??????
Dogs Have Owners; Cats Have Staff
PROfessional Member
User avatar
Posts: 8220
Joined: Sat Jun 19, 2004 4:46 pm
Location: Jackson, TN USA
Real Name: Jeff Replogle

Postby augie » Thu Jul 20, 2006 10:59 pm

kd1966 wrote:Scene: Home where some elderly folks have lived over 35 years........... got a Dell about 2 years ago and everything works great! Introduce some grand-kids.......... unknown computer savvy............ anyhow I arrive on the scene............


Give the kids a Guest account. Period. I'm sure the folk there won't like that answer, education along with supervision is the answer, But I doubt the seniors could do that. Set up a guest account that can't install squat! Problem solved, for the Dell at least. :whistle As for the grankids, well: _-~~~ :devil , not really but they should be stopped!
Everything that irritates us about others can lead us to an understanding of ourselves. -- Carl Jung

eVGA X58 tri-SLI, i7 930 @ 3.8GHz., Corsair 6GB Dominator, Inno3D GTX470, eVGA260
ASUS P8P67 Pro, i7 2600K @4.60 GHz, 8GB RAM, eVGA GTX 460
Community Director
User avatar
Posts: 7870
Joined: Mon Aug 26, 2002 1:55 am
Location: Laurentians, Quebec

Postby kd1966 » Thu Jul 20, 2006 11:12 pm

NT50 wrote:Instead of Avast ..... I understand it is free..... why didn't you intsall trail NOD32 and let it take care of it for you??????


I asked them about that, but they were "hesitant" about trialware after this fiasco. Avast! did a fine job of killing this beast during the bootscan, and I didn't want to really "burden" them with having to call me back in 30 days when it expired (Even though I don't mind making a $$ or 2...) :whistle
I have a feeling I'll be getting called back there anyhow (Not for the Virus stuff, but more of a "tutor" role)
PRO PLATINUM
User avatar
Posts: 6831
Joined: Tue Aug 09, 2005 2:00 am
Location: USA - GSO - NC

Postby augie » Thu Jul 20, 2006 11:21 pm

kd1966 wrote:
NT50 wrote:Instead of Avast ..... I understand it is free..... why didn't you intsall trail NOD32 and let it take care of it for you??????


I asked them about that, but they were "hesitant" about trialware after this fiasco. Avast! did a fine job of killing this beast during the bootscan, and I didn't want to really "burden" them with having to call me back in 30 days when it expired (Even though I don't mind making a $$ or 2...) :whistle
I have a feeling I'll be getting called back there anyhow (Not for the Virus stuff, but more of a "tutor" role)


LOL, look up!
Everything that irritates us about others can lead us to an understanding of ourselves. -- Carl Jung

eVGA X58 tri-SLI, i7 930 @ 3.8GHz., Corsair 6GB Dominator, Inno3D GTX470, eVGA260
ASUS P8P67 Pro, i7 2600K @4.60 GHz, 8GB RAM, eVGA GTX 460
Community Director
User avatar
Posts: 7870
Joined: Mon Aug 26, 2002 1:55 am
Location: Laurentians, Quebec

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 2 guests

cron
cron