PDA

Просмотр полной версии : Need to get rid of amvo and un9.cmd virus



akumudzi
27.03.2008, 22:35
I have been infected by a virus that disables the viewing of hidden files. no matter how many times I select the radio option to view hidden files in 'folder options' when i check back, it has gone back to select the option to hide them.
I have seen files like un9.cmd and some autorun.inf files in the c: root folder. Also some amvo files detected in the system32 folder.

What annoys is that after doing a system scan with Symantec and even NOD32 the files are quarantined (and I delete them from the quarantine and other precaustions (turning off system restore before full scan, deleting all temporary folder files etc...)) the machine gets infected again after its exposed to infected removable media. How do i get rid of this virus for good? How do I make sure that its not infected again?

I have attached the log files from AVZ and HJT.

Thank you.

drongo
27.03.2008, 23:38
AVZ - File - Custom scripts
Execute the following script (copy it, paste it in the script window of AVZ and execute):

begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\Installer\d0f715.msi',' ');
QuarantineFile('C:\Program Files\Dell\QuickSet\dadkeyb.dll','');
QuarantineFile('C:\WINDOWS\system32\wxvault.dll',' ');
QuarantineFile('C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.S YS','');
QuarantineFile('C:\WINDOWS\system32\preflib.dll',' ');
QuarantineFile('C:\WINDOWS\system32\detoured.dll', '');
QuarantineFile('C:\WINDOWS\System32\bcm1xsup.dll', '');
QuarantineFile('c:\windows\system32\wltrysvc.exe', '');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(6);
ExecuteRepair(8);
ExecuteRepair(9);
BC_Activate;
RebootWindows(true);
end.
Your computer will reboot.
Upload the quarantined files according to the Appendix 3 of the rules. (please upload using the link http://virusinfo.info/upload_virus_eng.php?tid=20559 )

akumudzi
28.03.2008, 08:18
I have uploaded the quarantined files.

Thanks.

AndreyKa
28.03.2008, 11:16
Files bcm1xsup.dll, d0f715.msi, dadkeyb.dll, detoured.dll, preflib.dll, wltrysvc.exe, wxvault.dll is clean.


How do I make sure that its not infected again?
1) Hold Shift key then attach flash disk to prevent autorun or disable it. http://en.wikipedia.org/wiki/Autorun
2) Don't do double click on flash disk, use folders tree.
3) Use some other AV. :)