I’ve deleted all files infected and detected with kaspersky. I just used PREVX CSI and 2 more have appeared in system32:

[b]HLDRRR.EXE
Disagree with this determination?
This executable program has a file size of 587,583 bytes, it is called HLDRRR.EXE and is located in the %windir%\system32\drivers\ folder.
This file is considered unsafe and is part of the malware group, Backdoor.SdBot.gen. It was first seen on Sunday, Jan 6 2008. It has only been seen by one user in this section of the community. The file has only been seen in FRANCE.
HLDRRR.EXE has been seen to perform the following behaviors:

  • The Process is packed and/or encrypted using a software packing process
    HLDRRR.EXE has been the subject of the following behaviors:
  • Added as a Registry auto start to load Program on Boot up

WINTEMS.EXE
Disagree with this determination?
This executable program has a file size of 471,556 bytes, it is most frequently called WINTEMS.EXE and is most frequently located in the %windir%\system32\ folder.
This file is considered unsafe and is part of the malware group, Trojan.Mitglieder. It was first seen on Saturday, Dec 8 2007. It has been seen frequently by 27 users in this section of the community. The file was first seen in ITALY but has been seen in other locations, including The EUROPEAN UNION.
WINTEMS.EXE has been seen to perform the following behaviors:

  • The Process is packed and/or encrypted using a software packing process
  • The Process is polymorphic and can change its structure
  • This Process Creates Other Processes On Disk
  • Executes a Process
  • This Process Deletes Other Processes From Disk
  • Creates a TCP port which listens and is available for communication initiated by other computers
  • Registers a Dynamic Link Library File
  • Makes outbound connections to other computers using NETBIOSOUT protocols
  • Can communicate with other computer systems using HTTP protocols
    WINTEMS.EXE has been the subject of the following behaviors:
  • Added as a Registry auto start to load Program on Boot up
  • Created as a process on disk
  • Executed as a Process
  • Deleted as a process from disk
  • Terminated as a Process[/b]

“It seems that you have a bagle og rootkit virus. Very agressive viruses and you will not be able to install avast, kaspersky or any of the usually used antivirus programs.”

What am I supposed to do then?