Basmi Virus Kido

Virus Kido – Download Kido Killer terlebih dahulu di : http://blog.rioyotto.info/download-gratisfree/

Tentang Kido yg merupakan family dari Net-Worm.Win32.Kido

  • Kido membuat file autorun.inf dan RECYCLED{SID<….>}RANDOM_NAME.vmx di removable drives (kadang juga di folder sharing dalam network)
  • Disimpan di system sebagai file DLL dengan nama yang random misalnya, c:windowssystem32zorizr.dll
  • dirinya juga di register di system services dengan nama yg random contohnya: knqdgsm
  • Kido mencoba menyerang jaringan komputer lewat port  445 atau 139 TCP port, dengan menggunakan MS Windows vulnerability MS08-067.
  • Kido juga mencoba mengakses website berikut untuk mengetahui IP Address komputer yg terinfeksi (rekomendasi utk lakukan konfigurasi network firewall untuk monitoring koneksi ke website2 berikut) :
  • Produk Anti-Virus product dengan enabled Intrusion Detection System informasi serangan terhadap Intrusion.Win.NETAPI.buffer-overflow.exploit

MS Windows 95/MS Windows 98/MS Windows ME operating systems cannot be infected with this network worm.

You are recommended to do the following on all hosts to prevent workstations and file servers from getting infected with the worm:

  1. Install Microsoft patches MS08-067, MS08-068, MS09-001 (on these pages you will have to select which operating system is installed on the infected PC, download corresponding patch and install it).
  2. Disable autorun of executable files on removable drives:
    1. download the utility KidoKiller (kk.zip) and extract it, for example, to disk C:
    2. open command line prompt:
      1. Windows Vista: Start > All programs > Standard > Run > type in cmd > press Enter.
      2. Windows XP/Server: Start > Run > type in cmd > Press Enter.
    3. run the file kk.exe with switch -a:
      • specify path to the file kk.exe.For example, if it is located on disk C:, you should use the following the command:
        C:kk.exe -a
      • press Enter.

Cara mengatasi Kido :

  1. Download the archive kk.zip and extract the contents into a folder on the infected PC
  2. Disable the component File Anti-Virus of the Kaspersky Anti-Virus for run time of the utilityif you have one of the following Kaspersky Lab applications installed on the infected PC:- Kaspersky Internet Security 2011;
    – Kaspersky Anti-Virus 2011;
    – Kaspersky Internet Security 2010;
    – Kaspersky Anti-Virus 2010;
    – Kaspersky Internet Security 2009;
    – Kaspersky Anti-Virus 2009;
    – Kaspersky Internet Security 7.0;
    – Kaspersky Anti-Virus 7.0;
    – Kaspersky Internet Security 6.0;
    – Kaspersky Anti-Virus 6.0.
  3. Run the file kk.exe

    If you run the kk.exefile without any switches, the utility will put a stop to active infection (kill threads and remove hooks), perform a memory scan and a scan of critical areas vulnerable to infection, clean up the registry, and scan flash drives.
     
  4. Wait till the scanning is complete.Warning If Agnitum Outpost Firewall is installed on the computer where the utility KidoKiller has been launched, it is necessary to reboot the PC after the utility finishes its work.
  5. Perform a full scan of your computer with Kaspersky Anti-Virus.

 

Switches to run the file kk.exe from the command prompt

 

Switch Description
-f Scan hard disks.
-n Scan network drives.
-r Scan flash drives, scan removable hard  USB and FireWire disks.
-y End program without pressing any key.
-s Silent mode (without a black window)
-l <file name> Write info into a log.
-v Extended log maintenance (the switch -v works only in combination with the -l switch).
-z Restore the following services:

  • Background Intelligent Transfer Service (BITS),
  • Windows Automatic Update Service (wuauserv),
  • Error Reporting Service (ERSvc/WerSvc),
  • Windows Defender (WinDefend),
  • Windows Security Center Service (wscsvc).
-x Restore display of hidden system files.
-a Disable autorun from all drives.
m Monitoring mode to protect the system from getting infected.
-j Restore the registry branch SafeBoot (if the registry branch is deleted, computer cannot boot in Safe Mode).
-help Show additional information about the utility.

For example, in order to scan a flash drive and write a detailed log into the file report.txt (which will be created in the setup folder of the file kk.exe), use the following command:

KK.exe -r -y -l report.txt -v

in order to scan another disk or partition, D for example:

KK.exe -p D:

Leave a Reply

Your email address will not be published. Required fields are marked *