Solved Unable to run anti virus programs

Status
Not open for further replies.

brandonc_06

Level 1
Thread author
Apr 7, 2017
13
Dataup.exe Winvmx.exe and start up Cpx I cannot disable. I also have drmkpro64.sys virus. The problem is Winvm client runs like 5 of them and I end them and they start back up. I cannot use any antivirus programs because it says "Requested resources in use". I even tried Rkill and that doesn't work to stop it from happening. I tried deleting everything off the computer from a reset and it tells me something has occurred and no changed were made and then it brings me back to windows
 

Attachments

  • FRST.txt
    137.5 KB · Views: 2
  • Addition.txt
    65.7 KB · Views: 3
  • Like
Reactions: Sunshine-boy

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


Please download Zemana AntiMalware and save it to your Desktop.
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please restart your computer manually.
  • Open Zemana AntiMalware again.
  • Click on
    4zu6vb.jpg
    icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • The only left thing is to attach saved report in your next message.
 
  • Like
Reactions: robin hood

brandonc_06

Level 1
Thread author
Apr 7, 2017
13
Here is the report from the program.
 

Attachments

  • 2017.04.09-14.26.18-i0-t92-d10.txt
    4.4 KB · Views: 9

brandonc_06

Level 1
Thread author
Apr 7, 2017
13
I ran it twice more and it is unable to remove "svccmx", "drmkpro64.sys", and "tprdpw32.exe"
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Download
51a5f31352b88-icon_MBAR.png
Malwarebytes Anti-Rootkit to your desktop.
  • Double-click the icon to start the tool.
  • It will ask you where to extract it, then it will start.
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder and paste the content of the following files in your next reply:
    • "mbar-log-{date} (xx-xx-xx).txt"
    • "system-log.txt"
 
  • Like
Reactions: Sunshine-boy

brandonc_06

Level 1
Thread author
Apr 7, 2017
13
No its saying the same thing which unfortunately makes me screwed. Its impossible to remove this virus believe it or not. Nobody is able to remove this dumb virus drmkpro64.sys. Which brings more viruses after a period of time. It doesn't let me open any anti virus programs. The only one is the one you sent me and I was surprised it actually lets it open, but it doesn't remove drmkpro64.sys
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
It can be removed, don't worry. It just need a little more force.


Please download Farbar Recovery Scan Tool x64 and save it to a flash drive.
  • Plug the flashdrive into the infected PC.
  • Click Start and while holding Shift key on your keyboard click Power --> Restart.
Note: It is important that you keep Shift key pressed while doing this or it won't work.
  • Now you should get a window like this where you need to click Troubleshoot.
Windows-10-2.jpg

  • In the next window, click Advanced options and select Command Prompt.
  • Now you should log in into your account and after that Command Promptwindow.
notepad.png
Access the notepad and identify your USB drive

In the Command Prompt please type in:
Code:
notepad
and press Enter.
  • When the notepad opens, go to File menu.
  • Select Open.
  • Go to Computer and search there for your USB drive letter.
  • Note down the letter and close the notepad.


FRST.gif
Scan with Farbar Recovery Scan Tool

Once back in the command prompt window, please do the following:
  • Type in e:\frst64.exe and press Enter.
    You need to replace e with the letter of your USB drive taken from notepad!
  • FRST will start to run. Give him a minute or so to load itself.
  • Click Yes to Disclaimer.
  • In the main console, please click Scan and wait.
  • When finished it will produce a logfile named FRST.txt in the root of your pendrive and display it. Close that logfile.

Transfer it to your clean machine and include it in your next reply.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Download attached fixlist.txt and save it to your USB flashdrive as fixlist.txt

>> Boot into Recovery Environment


Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your USB flashdrive.


>> Exit out of Recovery Environment and post me the log please.



Try to boot Windows normally...




FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

Attachments

  • fixlist.txt
    1.6 KB · Views: 24

brandonc_06

Level 1
Thread author
Apr 7, 2017
13
Okay here is what I got.
 

Attachments

  • FRST.txt
    150 KB · Views: 8
  • Addition.txt
    64.5 KB · Views: 6
  • Fixlog.txt
    3.4 KB · Views: 7

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.



How is your computer behaving now?
 

Attachments

  • fixlist.txt
    27.3 KB · Views: 17
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top