also @ TechSpot: Top PC Games for this Holiday Season and Beyond
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Please elp: Virus.Win32.Delf.ak

Closed Thread
Page 1 of 2 1 2
Bookmark Thread Tools
  #1  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
Please elp: Virus.Win32.Delf.ak

Hi,
I noticed that there was a thread from someone who also had this problem i tried what was said on there but my anti spyware program keeps finding the virus. I did click remove but once the computer has rebooted its back.

I used xoftspy v 4.22 and it comes up with 3 instances of Virus.Win32.Delf.ak, all type: registry value, category: Trojan and the objects: system\currentcontrolset\services\svkp\enum\0 ,
system\currentcontrolset\services\svkp\enum\count
and finally
system\currentcontrolset\services\svkp\enum\next instance

I have zone alarm security firewall and anti virus, this didnt pick up the files, i also tried trendmicro online anti virus and anti spyware, they picked up other problems but not that one. Erm, I also used ss&d, i have ad-aware personal se, AVG anti spyware,AVG anti-rootkit and ccleaner I also tried the 4 tools on the help page but they came back clean.

I'm not sure if this is caused by the virus but when i tried to use smart system restore it failed, apart from than and a little bit of lagging my computer doesnt seem to be much different.

I use this computer for a lot of things so I'm really hoping that someone could help me to get rid of this if it's a threat.

I'm sorry if i wrote too much useless stuff I'm just hoping it could maybe help a little. I tend to panic when i see the words virus. ^_^;;;

I would really appreciate any help that anyone could give me.
kind regards,
Erii
Attached Files
File Type: txt ComboFix.txt (5.8 KB, 2 views)
File Type: txt AVG anti-spyware Report.txt (4.0 KB, 1 views)
File Type: log hijackthis.txt.log (9.2 KB, 1 views)
  #2  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
[B]Hello and welcome to Techspot.[/B]

Run the [URL="http://www.trendmicro.com/spyware-scan/"]Trend micro Antispyware scanner.[/URL]

Let me know the results.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
Thank you for your reply :)

I did the trend micro anti-spyware earlier and it did come up with something but i can't remember what, however i did it again just now like you said and it said:
'no spyware found'.

*note* The computer had been rebooted between the two spyware scans, don't know if that is important.

Hope that helps.
Kind Regards,
Erii

Last edited by Eriya; 03-29-2007 at 01:24 PM..
  #4  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
It looks like the Trend scanner may have got it.

See how it goes and post back if you have any more problems.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #5  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
I really hope your right i don't like having to fight with viruses.

Only problem is Xoftspy still says that those three instances i mentioned in my first post are still on my computer. :S

Kind Regards,
Erii
  #6  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
1. Click Start > Run.
2. Type regedit
3. Click OK.
4. Navigate to the subkey:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

5. In the right pane, delete the values(if there):

"ctflog manager" = "%Windir%\ctflog.exe"explore manager" = "%Windir%\explore.exe"
"inetinfomon manager" = "%Windir%\inetinfomon.exe"
"MPM manager" = "%Windir%\MPM.exe""service manager" = "%Windir%\service.exe"
"winlog manager" = "%Windir%\winlog.exe"

6. Navigate to and delete the subkey:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ExtA

7. Exit the Registry Editor.

Let me know if that helps. run Xoftspy again.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #7  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
Hi again

I went to
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
however the things you mentioned weren’t there all i had was:
CTFMON.exe
Peerguardian
Uniblue registry booster
Uniblue SpeedUpmyPc
uniblue SpyEraser

I also tried looking for:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ExtA

but i could only find:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext

Should i delete that one or am i supposed to keep it?

I really appreciate all of your help.
Kind Regards,
Erii.
  #8  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
No, don`t delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext

Download the Spysweeper trial from [URL="http://www.webroot.com/consumer/downloads/?WRSID=4f7136cb48c6890ca4e2457f0d2f48b0"]HERE[/URL] and see what it comes up with.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #9  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
ok i wont touch that then.

I downloaded spy sweeper and it came up with the following:
sogou toolbar , category: adware, risk rating: 4/5, traces found: 1, description: sogou toolbar is an adware program that may display advertisements on your system.
a cookie, category: cookie, risk rating: 1/5, traces found: 1, description: a Cookie is a cookie that may track the unique visitors to a web site, as well as their personal preferences.

thats all that came up but xoftspy still says the same old thing. ^_^;;


I've just realised I've been doing all this in normal mode is that ok?

Kind regards,
Erii
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Have you tried running your Xoftspy programme from safe mode? If not, give it a try.

I`m starting to think that Xofspy maybe giving you a false positive. This isn`t unheard of with xoftspy.

Post a fresh HJT log when done.

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #11  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
I ran Xoftspy in safe mode and it came up with the 3 same entries.

I've also done another hijackthis and I'll attach it.

It would kind of be a relief if thats what it is

Kind Regards,
Erii
Attached Files
File Type: log hijackthis.log (9.5 KB, 2 views)
  #12  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

[b]Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT).[/b] See how [URL="http://www.bleepingcomputer.com/forums/tutorial61.html"]HERE[/URL].

[b]In Windows Explorer, turn on "Show all files and folders, including hidden and system".[/b] See how [URL="http://www.bleepingcomputer.com/forums/tutorial62.html"]HERE[/URL].

Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

Geviosr

Close the services window.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - blank (file missing)

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - blank (file missing)

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - blank (file missing)

O23 - Service: Geviosr - GEAR Software Inc. - (no file)

Click on the fix checked button.

Close HJT and reboot your system.

Post a fresh HJT log and let me know if you`re still having the same problem.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #13  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
I was able to disable Geviosr through services.msc

and i was also able to fix all that you said in HJT except i could no longer find find:
O23 - Service: Geviosr - GEAR Software Inc. - (no file)

I just ran xoftspy again and it came up with the 3 instances again.

Here is a new hjt log for you

Thank you for keeping on trying to help me
Kind Regards,
Erii
Attached Files
File Type: log hijackthis.log (9.1 KB, 1 views)
  #14  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Download and install the free [URL="http://free.grisoft.com/doc/1"]AVG Antivirus[/URL] programme. Run the antivirus updates, then boot into safe mode and run a full system scan.

Let me know if it finds anything.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #15  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
Hi,

I downloaded AVG and went into safe mode,
AVG anti-virus just finished now and it didnt find anything. ^^;;

Kind Regards,
Erii.
  #16  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
In that case, I must conclude it`s a false positive by Xoftspy, since nothing else is picking up the supposed infection.

Besides AVG free which you have just installed, are you running any other antivirus programme? If you are, I suggest you uninstall it and keep AVG free.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #17  
Old 03-29-2007
Newcomer, in training
 
Location: England
Member since: Mar 2007, 10 posts
Well all of that for a false positive, I'm happy it isn't anything serious mind

I have the anti virus which comes with zone alarm security suite I'll switch that off now though.

Thank you very much for giving me your time and helping.
Kind Regards,
Erii.
  #18  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
No worries. I suggest you uninstall Xoftspy.

If you have any further virus/spyware problems, please post in this thread.

Regards Howard

[color=red][b]This thread is for the use of[/color] Eriya [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #19  
Old 03-31-2007
Newcomer, in training
 
Member since: Mar 2007, 3 posts
Hi Eirya and howard

I don't think it's a false positive, In fact I'm pretty sure it's not.
But I can't get rid of it either.
I found it using regedit, then watched as the entry was deleted when I clicked remove using xoftspy, It was removed.
Back again next time I rebooted.
Deleted manually,
Back again next time I rebooted.
Turned off system restore, used xoftspy to delete in safe mode,
Back again next time I rebooted.

At the moment all I do everytime I start up, is run xoft and delete the buggers before I do aything else.

I'd be grateful if anyone could post a definitive response for getting rid of it.
  #20  
Old 03-31-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Can you give me the path to the registry keys? I still can`t think why Xoftspy would be the only programme to detect this.

Regards Howard

[color=red][b]This thread is for the use of[/color] Saint M [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
Closed Thread
Page 1 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
How to remve Virus.Win32.Delf.ak Virus & Malware removal 5 03-28-2007 11:32 PM
I have a virus called Win32/SillyDl.Pw...Help! Virus & Malware removal 4 02-28-2006 10:35 AM
Pls. help can't clean Virus New Poly Win32 Virus & Malware removal 1 12-07-2005 12:37 AM
i got win32 virus....help Software & Utilities in General 2 10-18-2005 03:29 AM
Trojan Dropper Win32 Delf.fd Virus & Malware removal 4 11-25-2004 06:28 AM


All times are GMT -4. The time now is 04:42 PM.