(PROBLEM)
Now a days this is a very popular problem that when every time you delete "jwgkvsq.vmx" from your removable drive from the following location -------
".\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx" then every time it recreates. But when you scan your system with antivirus then no-one can not detect this.
(SYMPTOMS)
You can not see your hidden files in your computer. You can not open some websites like microsoft.com, spywareterminator.com etc.
(SOLUTION)
To clean up system which automatically creates autorun.inf and RECYCLER folder with jwgkvsq.vmx, download and run this program. After reboot, the system probably will complain about missing dll file. To fix it manually, you can use regedit or msconfig:
Regedit:
(1) run regedit.exe (start menu, run: regedit.exe),
(2) search the dll file name (CTRL+F)
(3) delete the entry which contains the missing dll file. Usually, the entry should be found on registry location: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Or MsConfig:
(1) run msconfig.exe (start menu, run: msconfig.exe),
(2) go to startup tab
(3) Uncheck the Startup Item which contains missing dll file on the command.
To clean up the infected flash disk or external disk with FAT file system, simply delete the autorun.inf and RECYCLER folder. But if it has NTFS file system, windows will complain about having unauthorized access to the file and folder. You can use Linux and mount the NTFS volume (probably it must be mounted forcefully with options -o force), then delete them. Live CD such as Ubuntu will do.
That's all :)
Updated:
If the above cleaning process didn't work (somehow, the above process works perfectly on my PC but has no effect on my friend's), scan the system using this tool. After scanning, there are probably some unaccessible files (check the log file). then:
(1) find suspicious hidden dll file on \windows\system32\,
(2) boot to save mode
(3) change the ownership of the file (right click, properties, security, click advanced.. the rest I expect you know how.. ;) ), then
(4) change the access permissions for everyone,
(5) delete the dll file manually.
Perhaps, step (3) to (5) can be applied to remove the autorun.inf and RECYCLER folder too..
That's all :)
Updated #2:
For those who have trouble downloading from antivirus website, I add mirrors for the antivirus:
(1) http://happyfunz.net/antivirus/FixDownadup.zip (MD5 sum: 2363a7fce1919a42095b018f7b49b1aa)
(2) http://happyfunz.net/antivirus/anti-Downadup-EN.zip (MD5 sum: 053c297c3bdb1f86f141176db3d1b42c)
PS. Turn off System Restore and unplug your network before executing the removal tool. Otherwise, the virus might not be cleaned up. And refer to microsoft bulletin here to update the vulnerable patch.
If none of the above methods works for you, perhaps you should try to follow the cleaning process from microsoft knowledge base here.
(Result)
I have succesfully deleted this virus.......after removing the above virus ,,scan with latest kaspersky internet security2009...it will remove the virus called "kido" unless you follow the above procedure....if not it will come again & again even though you remove it...!
Saturday, March 14, 2009
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment