Four dangerous objects remain, but can not be processed by Kasperky for Windows Workstations 5.0.712. Running on XP Professional.
Thank you for your help.
Four dangerous objects remain, but can not be processed by Kasperky for Windows Workstations 5.0.712. Running on XP Professional.
Thank you for your help.
Последний раз редактировалось Rene-gad; 20.07.2009 в 13:14. Причина: Quarantine removed
Your version of Antivirus is obsolete, this program cannot protect your system.
Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
Fix with Hijackthis
- Execute following scriptКод:O4 - HKLM\..\Run: [12177814] C:\Documents and Settings\All Users\Application Data\12177814\12177814.exe
After reboot:Код:begin SearchRootkit(true, true); SetAVZGuardStatus(True); StopService('netsik'); QuarantineFile('C:\WINDOWS\system32\drivers\netsik.sys',''); QuarantineFile('C:\Documents and Settings\All Users\Application Data\12177814\12177814',''); QuarantineFile('C:\WINDOWS\system32\regedit.exe',''); DeleteFile('C:\WINDOWS\system32\regedit.exe'); DeleteFile('C:\Documents and Settings\All Users\Application Data\12177814\12177814'); DeleteFile('C:\WINDOWS\system32\drivers\netsik.sys'); DeleteService('netsik'); BC_ImportAll; ExecuteSysClean; BC_DeleteSvc('netsik'); BC_Activate; RebootWindows(true); end.
- Execute following script
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool cleanmgr or CCleaner or ClearProgКод:begin CreateQurantineArchive('C:\quarantine.zip'); end.
- Close all the programs and start only Internet Explorer!!!
- Repeat 3 log files.
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=50306
- Attach 3 new logs to your new post..
I can not upload the log files as it says I have already done so.
Последний раз редактировалось Rene-gad; 20.07.2009 в 18:03.
I had followed all the steps and thought I had generated new logs, which is what I thought I sent you.
My sincere apologies, I seem to have in error sent you a prohibited file. I am sorry.
I will try again.
We are also downloading new version of Kasperky, will that clean the PC, without having to go through the steps you outlined earlier?
Finally the instruction <- Repeat 3 log files> was not clear to me and it was only after some thought that I understood what it meant. Maybe it would be clearer if it said <Repeat Analysis steps from Before you Post and attach log files avz_sysinfo.htm, avz_sysinfo.htm and hijackthis.log>
Thank you and you have been very helpful