Ad-Aware detects but does not remove VX2

R

r_mervart

Adam Piggott said:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



It is important that you follow the disinfection procedures in Safe Mode.
Running the computer in Safe Mode will stop any spyware/virus before it
starts. Once it starts, it can stop other programs "seeing" it, or even
removing it.

Adam

I have tried that but it did not work. What actually happened was that this
time
Ad-Aware did not freeze and did remove all VX2 bits it found but
it did not find the VX2 process. Going back to normall Windows mode
that process is still there and detected by Ad-Aware.

Roman
 
R

r_mervart

Adam Piggott said:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



A very good point. I have found the web site http://www.spywarewarrior.com
a good starting reference for spyware information, including which programs
you can trust.

I have read through the PDF file attributed to Ian's "Removal Procedure B"
and can confirm it merely walks you through installing Kaspersky Antivirus
and does not seem to contain any malicious instruction or content.

If anyone's got a copy of the new/improved VX2 I'd be happy to have a few
rounds with it to see if I can get a removal procedure.

I have now found how to get rid of the process OICJVUX.EXE that was reported
by
Ad-Aware as VX2 malware. By chance I looked into startup and it was there. I
have
unticked it and as it did not start it was not detected by Ad-Aware but the
related
registry entries etc were. These I could get rid off using Ad-Aware. Then I
simply deleted
OICJVUX.EXE file. Hope this is now done.

Roman
 
R

r-waylon

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
r_mervart wrote:
It is important that you follow the disinfection procedures in Safe Mode.
Running the computer in Safe Mode will stop any spyware/virus before it
starts. Once it starts, it can stop other programs "seeing" it, or even
removing it.
Adam.
- --
Please replace dot invalid with dot uk to email me.
Apply personally for PGP public key.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)
iD8DBQFCLf/17uRVdtPsXDkRAjKYAJ9ziBmIGuWLtZxCPeLjvY69L9vRuACfR5qb
JeFVJaA/Fo7n/rlU5CRh0s8=
=2Yv/
-----END PGP SIGNATURE-----

Great!

(e-mail address removed)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top