Показано с 1 по 2 из 2.

Braviax.exe and possibly Mondo virus - Kaspersky Killed

  1. #1
    Junior Member Репутация
    Регистрация
    05.09.2008
    Сообщений
    1
    Вес репутации
    58
    Hi All,

    I am an IT Support Technician who is working remotely. The remote PC has a virus which stays in the system tray (White X, red circle background) which the user double clicked on and installed XP Security Center. The virus has killed Kaspersky for Workstations 6, updated with latest signatures (at the time) and will not allow it to start.

    I was able to run the Kaspersky Virus Removal Tool remotely (as system shell) and have the Manual Scan result attached. The automatic scan picked up numerous items which it neutralised, but the virus is still installed - I am running the automatic scan again now as I am sure it only removed 3 out of 21 threats before it decided it had to reboot.

    Does anyone have a script to remove this horrible thing?

    Its a 300 mile round trip to format the PC so it would be great if we didn't have to.

    Please see post below for report.

    Kind Regards,

    Thomas Greenwood
    8Networks, Manchester

    Report Attached

    Sorry
    Вложения Вложения
    Последний раз редактировалось Rene-gad; 05.09.2008 в 18:45.

  2. #2
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,164
    Вес репутации
    994
    I am afraid, under terminal session it will not work well.
    Is that a chance that someone will execute our scripts under local admin and logs of the Kaspersky Virus Removal Tool?

    Can you run there hijackthis?

    You can try this one:
    Disable antivirus if it's running.
    Please execute the following script in avptool:
    Код:
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     QuarantineFile('C:\WINDOWS\system32\karina.dat','');
     QuarantineFile('C:\WINDOWS\system32\_scui.cpl','');
     QuarantineFile('C:\WINDOWS\System32\drivers\tcpsr.sys','');
     QuarantineFile('C:\WINDOWS\System32\Drivers\Arx24.sys','');
     QuarantineFile('C:\WINDOWS\System32\Drivers\Beep.SYS','');
     TerminateProcessByName('c:\windows\system32\buritos.exe');
     QuarantineFile('c:\windows\system32\buritos.exe','');
     DeleteFile('c:\windows\system32\buritos.exe');
     DeleteFile('C:\WINDOWS\System32\drivers\tcpsr.sys');
     DeleteFile('C:\WINDOWS\System32\Drivers\Arx24.sys');
     DeleteFile('C:\WINDOWS\system32\karina.dat');
     DeleteFile('C:\WINDOWS\system32\_scui.cpl');
    BC_ImportAll;
    ExecuteSysClean;
    BC_DeleteSvc('Arx24');
    BC_DeleteSvc('tcpsr');
    BC_Activate;
    executerepair(6);
    executerepair(8);
    RebootWindows(true);
    end.
    Pack ( zip) (with pass virus)-> Qurantine_AVZ ( it is subfolder where your Kaspersky Virus Removal Tool exist)
    Please upload it by link http://virusinfo.info/upload_virus_eng.php?tid=29653

    Then make a new log in Kaspersky Virus Removal Tool and attach it to your next post.
    Remember to lunch Internet Explorer before making a new log.
    Последний раз редактировалось drongo; 05.09.2008 в 18:50.

Похожие темы

  1. Kaspersky Anti-Virus: forbidden incoming virus Trojan-Downloader.BAT.Small.aq
    От makstarikov в разделе Помогите!
    Ответов: 28
    Последнее сообщение: 29.06.2012, 14:01
  2. Virus infection - Kaspersky Virus removal tool Log file
    От ksantosh3006 в разделе Malware Removal Service
    Ответов: 1
    Последнее сообщение: 05.05.2010, 12:20
  3. Ответов: 5
    Последнее сообщение: 22.01.2009, 01:13
  4. Ответов: 60
    Последнее сообщение: 19.07.2008, 20:05
  5. Ответов: 52
    Последнее сообщение: 16.05.2008, 07:59

Свернуть/Развернуть Ваши права в разделе

  • Вы не можете создавать новые темы
  • Вы не можете отвечать в темах
  • Вы не можете прикреплять вложения
  • Вы не можете редактировать свои сообщения
  •  
Page generated in 0.01308 seconds with 20 queries