Help - Search - Members
Full Version: REcycler threat notification
Kaspersky Lab Forum > English User Forum > Protection for Small and Medium Businesses
saana_ms
hi,

i am using Kaspersky Businesss Space security. in one of my machine the kaspersky client was disabled automatically..

i uninstall the client and reinstall the client but it was not installed. when i click C: and D :
in my machine the error message show s like that :

c:\recycler\s -1-3-68-100008515-100004571-1000013254-2654.com

pls tell me the solution..

Regards,
Saravanan
dawinci
QUOTE(saana_ms @ 31.03.2009 07:43) *
hi,

i am using Kaspersky Businesss Space security. in one of my machine the kaspersky client was disabled automatically..

i uninstall the client and reinstall the client but it was not installed. when i click C: and D :
in my machine the error message show s like that :

c:\recycler\s -1-3-68-100008515-100004571-1000013254-2654.com

pls tell me the solution..

Regards,
Saravanan


Hi,

sounds like you're infected with malicious code. Please provide actual sysinfo and avzlog.

If you're on a vista-kernel based operating system start AVZ using rightclick "run as administrator".

* update AVZ ("File", "Database Update")
* enable zip compression ("File", "System Analysis" => "Add System Analysis log to ZIP")
* start scan in same window


Afterwards probide "avz_sysinfo.zip" -- thx.

Regards,
dawinci

saana_ms
Actually i am using WinXp as client machine ..

pls tell me the step by step procedure to remove the threat...


i am not able to online scan thro kaspersky...
dawinci
QUOTE(saana_ms @ 31.03.2009 14:49) *
Actually i am using WinXp as client machine ..

pls tell me the step by step procedure to remove the threat...
i am not able to online scan thro kaspersky...

Please provide Systeminfo and AVZ log as already requested. You can also add gmer logfile.
saana_ms
this is the screen shot ..

here u can get the kaspersky was deactivated...


pls tell me how to get the systeminfo and other .....
dawinci
QUOTE(saana_ms @ 31.03.2009 15:28) *
this is the screen shot ..

here u can get the kaspersky was deactivated...
pls tell me how to get the systeminfo and other .....

sysinfo and avzlog.

If you're on a vista-kernel based operating system start AVZ using rightclick "run as administrator".
* update AVZ ("File", "Database Update")
* enable zip compression ("File", "System Analysis" => "Add System Analysis log to ZIP")
* start scan in same window

_
Using RescueDisk:
* download RescueDisk (grab it!)
* burn iso to cdrom (nero, alcohol,...)
* boot from cdrom
* update virus patterns
* scan your computer
* disinfect if anything is malicious
saana_ms
The FTP is not working to download the Rescuedisc..

is any other options ....


actually we are not fully implemented the admin kit toll..

the kaspersky client is running individually in every machine..


if we run the rescuedisk will enough to remove the threat?
dawinci
QUOTE(saana_ms @ 31.03.2009 15:50) *
The FTP is not working to download the Rescuedisc..

is any other options ....
actually we are not fully implemented the admin kit toll..

the kaspersky client is running individually in every machine..
if we run the rescuedisk will enough to remove the threat?

FTP server is working for me, no problem.

It should be enough to run the rescuedisk, yeah. I dunno which malware infects you, so let's wait for your feedback wink.gif

saana_ms
rescue disk please..


please help me to get it ......
olegos
QUOTE(saana_ms @ 31.03.2009 09:09) *
rescue disk please..
please help me to get it ......

Use an ftp client to go to ftp.kaspersky.com. A browser is timing out for me too, but ftp client works.
dawinci
QUOTE(olegos @ 31.03.2009 17:36) *
Use an ftp client to go to ftp.kaspersky.com. A browser is timing out for me too, but ftp client works.

QUOTE(olegos @ 31.03.2009 17:36) *
Use an ftp client to go to ftp.kaspersky.com. A browser is timing out for me too, but ftp client works.

For me both (FTP Client/Browser) methods are working, np! Try another (not infected) system; cmd:

C:\Users\John>ftp ftp.kaspersky.com
Connected to prd.geo.kaspersky.com.
220 FTP server ready.
User (prd.geo.kaspersky.com:(none)): anonymous
331 Guest lohttp://forum.kaspersky.com/style_images/kl/folder_editor_images/rte-bold.pnggin ok, send your e-mail address as password.
Password: john@aol.com
230 User logged in.
ftp> cd devbuilds
ftp> cd RescueDisk
250 CWD command successful.
ftp> lcd C:\Temp
Local directory now C:\Temp.
ftp> ls
200 PORT command successful.
150 Opening ASCII mode data connection.
kav_rescue_2008.iso
226 Transfer complete.
ftp: 21 bytes received in 0.00Seconds 21000.00Kbytes/sec.
ftp> type binary
200 Type set to I.
ftp> get kav_rescue_2008.iso
200 PORT command successful.
150 Opening BINARY mode data connection.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.