Search This Blog

Friday, November 13, 2009

clean DHL trojan/virus

a break of DHL virus/trojan tricked many people. pull out hard drive, run scan from another PC via a USb enclosure.
use tools like symantec SEP, anti-malware, kill reader_s.exe under c:\windows\system32. run combofix, run MGtools. run kapersky virus removal tools.
then network not working, the device manager show all nic in yellow !. also add/remove program wont show program list, --- this can be get around by using ccleaner.
copy c:\windows\serivicepackfiles\nd*.* to c:\windows\system32\drivers.
restart to restore network connection. then add/remove program showing up properly.
remove SAV9.0. install microsoft security essentials, run full scan, it killed a reader_s.???? under c:\qoodoo directory which was a result of combofix.
I hate to re-install windows. virus/trojans like DHL is increasingly hard to get rid of without a clean/refresh reload.

1 comment:

  1. open the link for problem in sql server recovery download, if you’d like to get more information about other ways to process corrupted documents

    ReplyDelete