My Windows XP PRO SP3 was infected by Kido. But I don't know is infected by other virus?!? Can you help me?
My Windows XP PRO SP3 was infected by Kido. But I don't know is infected by other virus?!? Can you help me?
You should make log in normal mode, not in the safe mode like you did.
Please read carefully: http://virusinfo.info/showthread.php?t=9184
*Нажми и выполни, если хочешь чтобы помощь улучшилась и ускорилась
*MyFirefox Portable
special avz @ rapidshare.com
md5: 2091925798B7909E010E3F7E328C5F0D
Switch off/Disable:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Cure
After reboot execute following script in Manual CureКод:begin SearchRootkit(true, true); SetAVZGuardStatus(True); StopService('fqigke'); StopService('catchme'); StopService('Pl1080nipoce'); QuarantineFile('C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\catchme.sys',''); QuarantineFile('Pl1080nipoce.sys',''); QuarantineFile('C:\WINDOWS\system32\drivers\xjncfjv.sys',''); DeleteFile('C:\WINDOWS\system32\drivers\xjncfjv.sys'); DeleteFile('C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\catchme.sys'); DeleteFile('Pl1080nipoce.sys'); DeleteFile('C:\WINDOWS\system32\drivers\Pl1080nipoce.sys'); DeleteService('Pl1080nipoce'); DeleteService('fqigke'); DeleteService('catchme'); BC_ImportAll; ExecuteSysClean; BC_DeleteSvc('Pl1080nipoce'); BC_DeleteSvc('fqigke'); BC_DeleteSvc('catchme'); ExecuteRepair(6); ExecuteRepair(9); BC_Activate; RebootWindows(true); end.
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool cleanmgr or CCleaner or ClearProgКод:begin CreateQurantineArchive('C:\quarantine.zip'); end.
- Close all the programs and start only Internet Explorer!!!
- Repeat a log file in normal mode.
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Upload the C:\quarantine.zip over the link Upload quarantined files on the top of this page.
- Attach a log to your new post..
Finally, logs in normal mode.
Последний раз редактировалось Rene-gad; 10.05.2009 в 11:54.
-Fix with Hijackthis
Nothing suspicious more. Is your problem solved?Код:O2 - BHO: (no name) - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - (no file)
No, is not. The pc present this situation follow:
1. After scan, Hijackthis is closed, automatically;
2. Sometimes, logon is locked in blue screen - no response mouse or keyboard, but I see activity in the hd;
3. Combofix offer memory error with blue screen.
Thatґs all.