HELP with deleting possible virus

August 4th, 2016

Two start-up managers say I have a file C:\WINDOWS\system32\kdvgz.exe which is activated on startup. I cannot see it even though I can see other Hidden files.
When I disable it, it is re-enabled when I look again with a startup manager.
Google has no record of kdvgz.exe
Does anyone know what this file does, is it a virus?

Answer #1
Hello. Follow my instructions very carefully
I need a Combofix log to start off

  • Download ComboFix from the link below and save it to your Desktop
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

  • Exit all running applications and run ComboFix
  • Agree to it’s terms. Let it install the recovery console etc. It will do a series of scans. Do not click anywhere or do anything till it finishes as it might cause it to stall
  • It might reboot your PC. In any case it will come back with log (a text file)
  • Copy/paste the contents of the log inside a [code] box so I can give further instructions. This step is important

Good luck
Answer #2
^|^ thank you all for your help.
Could not download ComboFix, browser could not find the site.
You may be interested to know that the reason I could not see the file was because it had an Archive attribute.
Using a boot disc ERD commander I managed to see the file, remove the Archive attribute and rename the file. I could then remove it from startup with a startup manager.
Answer #3
Usually viruses will not be just a single file. There’ll be DLLs and other stuff hidden in there. They may not be necessarily in the system32 folder. The virus must have blocked Combofix’s download link as many do that these days. You should be able to download it now since the virus is inactive. Just to make sure you’re completely clean you should give it a run. It’ll take a few minutes

 

| Sitemap |