Hi,
My PC has been infected by Rootkit.Win32.TDSS.d. After several failed attempts of removing the virus I've decided to post here.
See attached for my log file created by Kaspersky Virus Removal Tool.
Any help would be greatly appreciated.
Thanks.
Hi,
My PC has been infected by Rootkit.Win32.TDSS.d. After several failed attempts of removing the virus I've decided to post here.
See attached for my log file created by Kaspersky Virus Removal Tool.
Any help would be greatly appreciated.
Thanks.
1. Please, disable System Restore and antivirus (if you have).
2. Execute this script in AVPTool:
3. After reboot execute this script in AVPTool:Код:begin SetAVZGuardStatus(True); QuarantineFile('C:\WINDOWS\system32\sdra64.exe',''); DeleteFile('C:\WINDOWS\system32\sdra64.exe'); BC_ImportDeletedList; ExecuteSysClean; BC_Activate; RebootWindows(true); end.
Upload file quarantine.zip, by link http://virusinfo.info/upload_virus.php?tid=75795Код:begin CreateQurantineArchive(GetAVZDirectory+'quarantine.zip'); end.
3. Make a new log of AVPTool.
4. Make a log of GMER http://virusinfo.info/showthread.php?t=51878
Сердце решает кого любить... Судьба решает с кем быть...
Many thanks for your quick reply.
I followed steps 1, 2 and 3 successfully. However when I try making a log file using GMER I either get a blue screen or the application crashes (see attached screenshot)
What do I do?
1. Start the file Vba32Arkit.exe with double click.
2. Press the button Start and let Vba32Arkit to make a FULL SCAN of your system.
3. After scanning press the button File -> Save Zipped.. an save the logfile.
4. Attach the logfile to your new message.
Последний раз редактировалось Aleksandra; 18.04.2010 в 08:06.
Сердце решает кого любить... Судьба решает с кем быть...
Thank you.
I've attached the VBA32ARKIT Log file here.
1. Replace C:\WINDOWS\System32\Drivers\isapnp.sys with a clean file from any similar system or from Windows CD using recovery console or Live CD.
2. Make a new log of Vba32Arkit.
Сердце решает кого любить... Судьба решает с кем быть...
Hi,
I replaced the isapnp.sys file from another clean machine then I restarted my PC and generated the log file you asked for. See Attached.
- Execute following script in Manual disinfection
and upload the C:\quarantine.zip over the link Upload quarantined files on the top of this page.Код:begin QuarantineFile('C:\WINDOWS\System32\Drivers\isapnp.sys',''); CreateQurantineArchive('C:\quarantine.zip'); end.
Hi,
I tried using the quarantine upload button at the top of the page however everytime i try and upload the file I am told that the file already exists. I've tried renaming the file which gives the same result.
Forgive me if I have broken the rules but I've attached the file to this post.
Regards
Check your system with Live CD: http://www.freedrweb.com/livecd/?lng=en
Сердце решает кого любить... Судьба решает с кем быть...
Aleksandra,
When I boot with Live CD I'm not sure if my system hangs once the interface is loaded or whether the mouse and keyboard are not operational. Is this normal?
I'm currently performing the scan using Live CD Safe Mode. I will let you know the results.
Статистика проведенного лечения:
- Получено карантинов: 1
- Обработано файлов: 2
- В ходе лечения вредоносные программы в карантинах не обнаружены