Показано с 1 по 2 из 2.

infected XP-Home laptop

  1. #1
    Junior Member Репутация
    Регистрация
    01.02.2009
    Сообщений
    1
    Вес репутации
    56

    infected XP-Home laptop

    Hi,

    I have an infected WinXP Home laptop. I was able to remove several viruses from it with other software but it is still not fixed. Virus-scans show nothing, but I have these symptoms:
    1. Many antivirus software websites are blocked (tracert attempts to any URL containing "lavasoft", for example, is routed to 127.0.0.1 but there is no entry in the hosts file that should be doing that).

    2. Some antivirus software will not run - either at all, or until it is renamed.

    3. After installing Kaspersky AV just now, as soon as I connected an ethernet cable (to a live router) Kaspersky noted that about 25 attempts were made to connect to "known phishing sites". I blocked those, but clearly something bad is still on this system.

    This problem persisted even after I booted into the Recovery Console from an XP install CD and re-wrote the MBR with fixmbr, and the boot sector of the system partition with fixboot. I have no idea how this thing is still loading, though now I suspect that it has simply modified some of the main system files.

    I have downloaded and run (in safe-mode) the Kaspersky Virus Removal Tool. I am attaching the result file generated from "Collect System Information". Any advice would be great - thanks!!

    --Jeff
    Вложения Вложения

  2. #2
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,164
    Вес репутации
    994
    Please download in my signature special avz. Put in new folder, for example on Desktop.
    Disconnect from internet, unload/exit antivirus
    lunch it and execute this script:
    Код:
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     QuarantineFile('C:\WINDOWS\system32\opnnKDwt.dll','');
     QuarantineFile('C:\WINDOWS\system32\btnnbr.dll','');
     QuarantineFile('C:\WINDOWS\system32\geBttrRl.dll','');
     QuarantineFile('C:\WINDOWS\system32\ezSP_Px.exe','');
     QuarantineFile('C:\WINDOWS\system32\datcpl.exe','');
     QuarantineFile('C:\WINDOWS\system32\PRISMSVR.EXE','');
     QuarantineFile('C:\WINDOWS\system32\drivers\usbvideoo.sys','');
     QuarantineFile('C:\WINDOWS\system32\AWINDIS5.SYS','');
     QuarantineFile('C:\WINDOWS\System32\DRIVERS\PxHelp20.sys','');
    BC_ImportAll;
    BC_Activate;
    RebootWindows(true);
    end.
    Please upload the quarantine according to appendix 3 of rules, by link http://virusinfo.info/upload_virus_eng.php?tid=38695
    Let us know, when you done.
    Последний раз редактировалось drongo; 11.02.2009 в 11:44.

Похожие темы

  1. Laptop infected but cannot remove threats
    От maye59 в разделе Malware Removal Service
    Ответов: 2
    Последнее сообщение: 07.09.2010, 07:17
  2. help me please..my laptop is infected
    От amr222222 в разделе Malware Removal Service
    Ответов: 6
    Последнее сообщение: 14.02.2010, 16:14
  3. Laptop Infected - Kaspersky IS 2010 Cannot Completely Install
    От invictus28 в разделе Malware Removal Service
    Ответов: 1
    Последнее сообщение: 07.12.2009, 14:39
  4. Spywares in my laptop
    От Marcelo в разделе Malware Removal Service
    Ответов: 1
    Последнее сообщение: 29.11.2009, 01:28
  5. rootkit infected laptop
    От chris в разделе Malware Removal Service
    Ответов: 1
    Последнее сообщение: 25.07.2008, 23:44

Свернуть/Развернуть Ваши права в разделе

  • Вы не можете создавать новые темы
  • Вы не можете отвечать в темах
  • Вы не можете прикреплять вложения
  • Вы не можете редактировать свои сообщения
  •  
Page generated in 0.00379 seconds with 18 queries