TrueGeek
asked on
rqvnlv encountered a problem and needs to close
Hi I keep getting this message when running my AVG that says "rqvnlv has encountered a problem and needs to close". i have searched the net and come up with no matches for this error or even any other reference to it. Has anybody heard of this error before? Is it possibly just the leftovers of a virus ( I removed over 1000 instances of viruses from the data on this computer and have wipe it clean 3 times now and don"t want to do that again)? help
ASKER
Hi rpgamergirl
since posting the request i went and looked in the process list and found a few processes that looked funny to me.
afisicx.exe
mabidwe.exe
solewxte.exe
I stopped these processes and ran spybot search and destroy which found and removed the affected files(apparently). I am already running malwarebytes in safe mode to double check but I will respond when it is done and I have checked the registry to see if these processes are still there.
since posting the request i went and looked in the process list and found a few processes that looked funny to me.
afisicx.exe
mabidwe.exe
solewxte.exe
I stopped these processes and ran spybot search and destroy which found and removed the affected files(apparently). I am already running malwarebytes in safe mode to double check but I will respond when it is done and I have checked the registry to see if these processes are still there.
ASKER
well isn't this interesting,
not only could I NOT stop AVG from running, I can't even uninstall it from this system. I did find the infections in the registry but could not delete them. Any ideas?? I am open to suggestions right now but will reformat this thing to simplify the matter. Here is the COMBOFIX log for your looksee.
thanks in advance
log.txt
not only could I NOT stop AVG from running, I can't even uninstall it from this system. I did find the infections in the registry but could not delete them. Any ideas?? I am open to suggestions right now but will reformat this thing to simplify the matter. Here is the COMBOFIX log for your looksee.
thanks in advance
log.txt
How to disable AVG's Resident Shield.
Right click the AVG icon and click Open.
In the Overview panel click on Resident Sheild > Uncheck the Resident Sheild Active box > Save Changes
afisicx.exe
mabidwe.exe
solewxte.exe
The above files are not showing in combofix log but combofix had deleted the drivers.
Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------------- ---------- ---------- ---------- ---------- ------
File::
c:\windows\system32\tdctxt e.exe
c:\windows\system32\28F.tm p
c:\windows\system32\286.tm p
c:\windows\adobe.bat
c:\windows\_id.dat
Driver::
tdctxte
-------------------------- ---------- ---------- ---------- ---------- ------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
Right click the AVG icon and click Open.
In the Overview panel click on Resident Sheild > Uncheck the Resident Sheild Active box > Save Changes
afisicx.exe
mabidwe.exe
solewxte.exe
The above files are not showing in combofix log but combofix had deleted the drivers.
Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
--------------------------
File::
c:\windows\system32\tdctxt
c:\windows\system32\28F.tm
c:\windows\system32\286.tm
c:\windows\adobe.bat
c:\windows\_id.dat
Driver::
tdctxte
--------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
ASKER
rpggamergirl:
this is the reuslt of your directions. I'm new to Combofix so tell me does this look like it did the trick?
thanks in advance
ComboFix.txt
this is the reuslt of your directions. I'm new to Combofix so tell me does this look like it did the trick?
thanks in advance
ComboFix.txt
ASKER
in regedit I did find an entry for mabidwe.exe in
HKEY_CURRENT_USER\software \microsoft \windows\c urrentvers ion\applet s\regedit which was under the last key entry and ended with LEGACY_MABIDWE
will this affect the system later on or is it ok?
HKEY_CURRENT_USER\software
will this affect the system later on or is it ok?
ASKER CERTIFIED SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER
Hi rpggamergirl:
first of all thanks for all your help. this has seemed to do the trick for this laptop. second of all THANKS FOR ALL YOUR HELP!! lol this was a messy system to work on with viruses and malware on all his jump drives and supposedly safe and secure backups. I have never used the Combofix before but it works great on those things that just wouldn't go away at the end.
again,,, thanks
first of all thanks for all your help. this has seemed to do the trick for this laptop. second of all THANKS FOR ALL YOUR HELP!! lol this was a messy system to work on with viruses and malware on all his jump drives and supposedly safe and secure backups. I have never used the Combofix before but it works great on those things that just wouldn't go away at the end.
again,,, thanks
TrueGeek,
You're welcome, glad we could assist.
To uninstall Combofix:
Go to Start > Run and 'copy and paste' next command in the field:
ComboFix /u
The above procedure will remove all files belonging to or related to Combofix(as well as its created backup) and will also reset System Restore.
Thanks!
You're welcome, glad we could assist.
To uninstall Combofix:
Go to Start > Run and 'copy and paste' next command in the field:
ComboFix /u
The above procedure will remove all files belonging to or related to Combofix(as well as its created backup) and will also reset System Restore.
Thanks!
Download Malwarebytes' Anti-Malware to your desktop, check for the tool's Updates before running a scan.
http://www.malwarebytes.or
Please download ComboFix by sUBs:
http://download.bleepingco
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.