07-30-2009 10:46 AM - edited 07-30-2009 10:47 AM
07-30-2009 11:23 AM
Hollowxsako:
It might first be useful to check for malware.
Please run a SysProt log for us so we can check your system for rootkit activity. You will need to disable Norton auto-protect while you run the scan.
Choose report or log, check all the boxes and scan.
You will be able to post the log here using the "add attachments" link just below the orange post button.
http://homepages.slingshot.co.nz/~crutches/SysProt
07-30-2009 12:15 PM
07-30-2009 04:11 PM
Hi Hollowxsako:
You do have a new rootkit infection. Quads has been advised and will look at your log a bit later. He will advise you of the next steps.
07-30-2009 06:47 PM
Hi
1. Download Combofix to your Desktop, http://www.bleepingcomputer.com/combofix/how-to-us
Don't use yet.
2. I have Personal Messaged you the script between the lines, look for the yellow envelope at the upper right hand side. Copy the Script.
3. Open Notepad and paste it in to notepad with the first line being killall::
4. Save the script as "CFScript.txt" CFScript.txt is what you see on your desktop after saving.
5. Disable Nortons Auto-Protect and Firewall.
6. Drag and drop CFScript.txt on top of Combofix.exe, like when you drop files into the recycle bin.
7. Combofix will start, When it is scanning don't move the mouse cursor inside the box, can cause freezing.
Then try Malwarebytes http://www.filehippo.com/download_malwarebytes_ant
Quads
07-31-2009 08:48 AM
07-31-2009 10:04 AM
07-31-2009 11:41 AM
Hi
All I did was do enough to hopefully take the service and .sys file.
There should be 2 .dll's and .dat files at least. Plus still hidden registry entries.
Quads
08-03-2009 03:32 PM
hollowxsako here again my norton 360 is not scanning and i think i have a virus when i click on a page it takes me to a different site help plz
here is the sysprot log if you need it
08-03-2009 07:00 PM
Hollowxsako:
Quads was not finished when you left. You still have part of the rootkit. Wait until I get you moved back on the same thread.
