O
oversky
From ntbtlog.txt (xp boot log file), I found out there is a driver
file changed its name everytime I reboot.
Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
Loaded driver \SystemRoot\System32\Drivers\a5mzjxub.SYS
Loaded driver \SystemRoot\system32\DRIVERS\cfosspeed.sys
However, when I login xp, I can't find the suspect file.
This possible virus also appears in registry (HLKM/System/
CurrentControlSet/Services/), and also changes its name when I reboot.
I have used NOD32 2.7 (with updated virus code) to scan the hardrive
in safe mode, but no luck.
Can anyone give me some idea and tool to pin out this virus? Thank
you.
file changed its name everytime I reboot.
Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
Loaded driver \SystemRoot\System32\Drivers\a5mzjxub.SYS
Loaded driver \SystemRoot\system32\DRIVERS\cfosspeed.sys
However, when I login xp, I can't find the suspect file.
This possible virus also appears in registry (HLKM/System/
CurrentControlSet/Services/), and also changes its name when I reboot.
I have used NOD32 2.7 (with updated virus code) to scan the hardrive
in safe mode, but no luck.
Can anyone give me some idea and tool to pin out this virus? Thank
you.