Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: AVG Trojan Generic9.AVLZ  (Read 6295 times)

0 Members and 2 Guests are viewing this topic.

tpolcha

    Topic Starter


    Hopeful
    AVG Trojan Generic9.AVLZ
    « on: January 31, 2008, 09:16:48 PM »
    AVG identifies a threat Generic9.AVLZ that I cannot remove. 
    Its path says C:\Program Files\Kaspersky Lab\ Kaspersky Internet Security 6.0\avp.exe

    History: 2 years ago I tried a trial Kaspersky A/V offer.  I couldn't delete it on my own.  I solicited Kaspersky and they issued me an uninstall tool.  Kaspersky was always still in the background; how I know it is, avp.exe always showed up in the 'Task Manager'.  That being said, since then there has not been a problem, I also didn't know I should worry about it.

    AVG now acknowledges the Trojan Generic9.AVLZ, I cannot remove it.  Threatfire once acknowledged it also.

    Step 3 SAV conducted and no log to report.

    Step 4 Dr Cureit conducted and no log to report.

    Step 5 Eset Nod32 conducted and the same, no log to report.

    Step 6 Java needs complied with.

    Step 7.  HJT log.  Entry item 4 & 23   

    I've tried using Window's Explorer to remove all Kaspersky files.  avp.exe doesn't show up in the task manager anymore but all the Kas files I find in Windows Explorer Kaspersky folders still refuse to be deleted. 
         
    I hope that was clear and not confusing.  Thanks, Tom

    [file cleanup - saving space - attachment deleted by admin]

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: AVG Trojan Generic9.AVLZ
    « Reply #1 on: January 31, 2008, 10:46:52 PM »
    Disable TeaTimer, as it'll interfere with the cleaning process:
    Right click Spybot's TeaTimer System Tray Icon.
    Click Exit Spybot-S&D Resident.
    TeaTimer closes.


    Open HJT. Checkmark following items:
    - O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
    - O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe (file missing)
    Click "Fix checked".
    Close HJT.

    Restart in Safe Mode.
    Open Windows Explorer, and delete Kaspersky Lab folder from C:\Program Files

    Restart in Normal Mode.
    Post new HJT log

    P. S. If the above didn't work, we'll use some other means to remove Kaspersky's leftovers.

    tpolcha

      Topic Starter


      Hopeful
      Re: AVG Trojan Generic9.AVLZ
      « Reply #2 on: February 01, 2008, 06:42:40 AM »
      Attempted suggested repairs with some problems:

      I successfully exited Spybot S&D Resident.

      I ran a new HiJack This scan... Entry 4 was already missing.  I didn't have to remove it.

      Entry #23 would not remove (FIX) and remained there.

      Restarted in safe mode, used Window's Explorer and successfully deleted the files in the Kaspersky 6.0 Lab folder.  Restarted PC.

      Ran a new HiJack This scan and save log.  Entry 23 remains present.

      Looks like I need some more help.  Thanks, Tom

       


      [file cleanup - saving space - attachment deleted by admin]

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: AVG Trojan Generic9.AVLZ
      « Reply #3 on: February 01, 2008, 09:38:39 AM »
      That's fine...

      Go Start>Run, type in:
      services.msc
      Click OK.
      Services window will open.
      Find:
      Kaspersky Internet Security service.
      If it's listed as Running, right click on it, click Stop
      Right click again, click Properties, and under Startup type select Disable from drop-down menu.
      Close window.

      Go Start>Run, type in:
      sc delete AVP (<---- watch for "spaces")
      Click OK.

      Restart computer.
      Post new HJT log.

      tpolcha

        Topic Starter


        Hopeful
        Re: AVG Trojan Generic9.AVLZ
        « Reply #4 on: February 01, 2008, 10:17:34 AM »
        Sorry, it was still unsuccessful.

        I found the Kaspersky entry in services.msc  It is listed as 'automatic'. 

        In properties, startup type; the choices are automatic, manual and disable.  I immedialty get a dialogue box that informs me '!access is denied'.  Thats all.  Closed services.msc

        I continued with next instruction anyway.

        Restarted PC and attached new HJT log.

        [file cleanup - saving space - attachment deleted by admin]

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: AVG Trojan Generic9.AVLZ
        « Reply #5 on: February 01, 2008, 10:24:38 AM »
        Quote
        I immedialty get a dialogue box that informs me '!access is denied'.
        Did you right click, and click Stop, first?
        Without it, you can't change Startup type.

        tpolcha

          Topic Starter


          Hopeful
          Re: AVG Trojan Generic9.AVLZ
          « Reply #6 on: February 01, 2008, 10:35:01 AM »
          Yes I rt clicked the entry, I don't get the option or chioce to 'stop'.  I guess because it is not listed as running or it is deeply protected by something.

          It is listed as 'automatic'.  I went into properties to try and disable it and that's when I'm being told I can't, that "access is denied".  It won't allow me to apply any changes and I have to cancel myself out of properties.

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: AVG Trojan Generic9.AVLZ
          « Reply #7 on: February 01, 2008, 10:38:24 AM »
          What is its status, listed in Status column?

          tpolcha

            Topic Starter


            Hopeful
            Re: AVG Trojan Generic9.AVLZ
            « Reply #8 on: February 01, 2008, 10:40:04 AM »
            It is a blank entry under the 'status' column.

            It is not reporting a status.

            Broni


              Mastermind
            • Kraków my love :)
            • Thanked: 614
              • Computer Help Forum
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 8
            Re: AVG Trojan Generic9.AVLZ
            « Reply #9 on: February 01, 2008, 10:48:08 AM »
            OK, then...

            Click Start>Run and type in:
            regedit
            Click OK.
            Navigate to:
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
            Scroll down the left pane, locate AVP service, right click it and select Delete.
            Reboot the system.

            Post new HJT log.

            tpolcha

              Topic Starter


              Hopeful
              Re: AVG Trojan Generic9.AVLZ
              « Reply #10 on: February 01, 2008, 10:56:35 AM »
              Unsuccessful.

              I followed the path, rt clicked AVP and selected delete.

              Dialogue box states: "Can't delete AVP: Error while deleting key".

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: AVG Trojan Generic9.AVLZ
              « Reply #11 on: February 01, 2008, 11:02:13 AM »
              Try Safe Mode

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: AVG Trojan Generic9.AVLZ
              « Reply #12 on: February 01, 2008, 11:02:57 AM »
              Oh, disable TeaTimer!

              patio

              • Moderator


              • Genius
              • Maud' Dib
              • Thanked: 1769
                • Yes
              • Experience: Beginner
              • OS: Windows 7
              Re: AVG Trojan Generic9.AVLZ
              « Reply #13 on: February 01, 2008, 11:17:11 AM »
              You could also DLoad install and run Stinger and AVG Anti-Spyware as well...
              " Anyone who goes to a psychiatrist should have his head examined. "

              tpolcha

                Topic Starter


                Hopeful
                Re: AVG Trojan Generic9.AVLZ
                « Reply #14 on: February 01, 2008, 11:29:03 AM »
                You did it Broni. 

                Incidently, from the beginning when you first mentioned I should exit from Spybot resident, I was ensuring that from all instructions.

                In safe mode, I was able to delete AVP from the registry, see HJT log. 

                Again thanks.  What was it?  Is Generic9 an actual malicious infection?

                Would AVG been able to take care of it the first time it recognized it if Tea Timer was never there?  As soon as AVG originally picked it up so did Tea Timer and of course my first reaction was to not allow a registry change attempt. 

                I know one of you folks made a comment somewhere to their disatisfaction with Tea Timer before.  Your advice please.

                And once again thank you.  As soon as I am re-employed, I owe you guy's--no bull I'll do it.



                [file cleanup - saving space - attachment deleted by admin]