This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] KAVO AND TAVO

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me in this problem aMalwarebytes' Anti-Malware 1.28 Database version: 1193 Windows 5.1.2600 Service Pack 2 3/4/2005 8:31:56 AM mbam-log-2005-03-04 (08-31-43).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 59105 Time elapsed: 24 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 3 Registry Keys Infected: 0 Registry Values Infected: 3 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 19 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\kavo1.dll (Spyware.OnlineGames) -> No action taken. C:\WINDOWS\system32\ckvo0.dll (Trojan.Agent) -> No action taken. C:\WINDOWS\system32\tavo0.dll (Rootkit.Agent) -> No action taken. Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kamsoft (Trojan.FakeAlert.H) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kava (Spyware.OnlineGames) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tava (Rootkit.Agent) -> No action taken. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\ckvo.exe (Trojan.FakeAlert.H) -> No action taken. C:\WINDOWS\system32\kavo0.dll (Spyware.OnlineGames) -> No action taken. C:\WINDOWS\system32\kavo1.dll (Spyware.OnlineGames) -> No action taken. C:\WINDOWS\system32\kavo.exe (Spyware.OnlineGames) -> No action taken. C:\9yqusig.bat (Trojan.Agent) -> No action taken. C:\WINDOWS\system32\ckvo0.dll (Trojan.Agent) -> No action taken. C:\WINDOWS\system32\ckvo1.dll (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru1.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru2.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru3.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru4.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru5.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru6.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru7.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru8.tmp (Trojan.Agent) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temp\tru9.tmp (Trojan.Agent) -> No action taken. C:\WINDOWS\system32\tavo0.dll (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\tavo1.dll (Rootkit.Agent) -> No action taken. C:\WINDOWS\system32\tavo.exe (Rootkit.Agent) -> No action taken.
Hello and Welcome to the forum.

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net

2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Give it atleast 20-30 minutes to finish if needed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI