The removal tool reports there was nothing to clean; however, anti-virus alerts continue to pop up listing the same problem
Main Topics
Browse All TopicsCan any one of you have the removal tool for this virus.
Thanks
Siddu
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Try Combofix, but we need to look at the log so we can use a script for any bad files not removed during its first run.
Please download ComboFix by sUBs:
http://download.bleep
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Take a look at his thread , may be of help
Also this worm is actually a DLL using a random name , take note of which file your antivirus detects this as
you havea few options from here
1- try something like Unlocker or process explorer to kill the process handles thus allowing you to manually delete the file, you can browse to where the DLL is located , right click & choose Unlock , or use process explorer to kill the DLL handle from within the module it is injected to (most likely running under SYSTEM) ,then delete the file immediately.
2- Use the tool built in Malwarebytes "More Tools" section called "FILEASSASIN" to delete the detected files on reboot.
3-Run Combofix & hijack this , then show us the logs.
I would try option 1 first, but also please post a hijack this log anyway.
Kaspersky has provided a special removal tool for this. You may refer to the following links.
http://www.viruslist.com/e
http://support.kaspersky.c
scan using avast antivirus
http://www.avast.com/eng/a
Business Accounts
Answer for Membership
by: Admin3kPosted on 2009-01-13 at 10:08:02ID: 23365462
All Kido Variants can be removed using AVZ scanner by Kaspersky labs
which is a portable Antivirus running AVP signatures / engine
http://devbuilds.kas persky-lab s.com/devb uilds/AVZ/ avz4.zip
I would reccomend running the scan in safe mode to ensure complete cleanup.