| Answer» Hello there! I read through the "Read this before requesting help..." and got to the SAS part. I downloaded it to my desktop, but when I click the icon, it says there is an error and it needs to close.
 I don't know if any of this info will help, but let me fill you in on what brought me here.
 I have Symantec AntiVirus on my computer and when I do a scan it does detect these files:
 
 Hacktool.Rootkit
 packed.generic.200
 
 I try to delete the hacktool.rootkit and it will say 'delete successful' but it always detects it when I run another scan. It will not allow me to delete the packed.generic file.
 
 My computer has been acting funny the past few days and it is doing the whole redirect THING when I try to search with google or yahoo. Occasionally I will get a blue screen telling me WINDOWS needs to shut down. My OS is Windows XP. I do have Service Pack 2, but my computer will not allow me to install service pack 3.
 
 I've NEVER dealt with a computer virus before, so thank you so much for your help!
 download hijackthis and run the scan, after scanning is complete create a log and post the log on your next reply.
 
 One of the expert will take a look and report what is infected. i recommend evilfantasy will help. i think he is really gud and he is helpin with my problem rite now. I can download and run hijackthis even though the other steps haven't been completed? Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
 
 * Scroll down to Non-plug and Play Drivers and click the plus icon to open those drivers.
 * Search for any of the following:
 
 - Seneka.sys
 - clbdriver.sys
 - TDSSserv.sys
 
 * If you do find it, right click on it, and select Disable. Do not try to uninstall them.
 * Now reboot and see if you can run the scans that would not run.they need to see the log to find out what is infected, so they know what to do. you still need to do hijackthis after everything is completed to make sure they have been taken cared or not. Evilfantasy, I looked for the hidden devices you mentioned and none of those were there.Skip that and move on to the MalwareBytes scan.When I try to click EITHER of the links available for the download for the MBAM, it says Internet Explorer is unable to display the webpage.I just noticed in my programs...My Way Search Assistant. I am not able to remove it. I've never seen this program on my list before.Download SDFix by AndyManchesta and save it to your desktop.
 
 Before you begin the SDFix instructions you should copy these instructions in a Notepad file and save them to your desktop or print them for easy reference. Much of SDFix will be done in Safe mode and you will be unable to access this web page after booting into Safe mode.
 
 
 When using this tool, you must use the Administrator's account or an account with Administrative rights
 
 Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 KEY repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".Double click SDFix.exe and it will extract the files to %systemdrive%
(this is the drive that contains the Windows Directory, typically C:\SDFix).
DO NOT use it just yet.
 
 Open the SDFix folder and double click RunThis.bat to start the script.
 
 I'm not able to download the SDFix file from filedropper, either. I can get to the website, but when I click download, it just sits there. Nothing seems to happen. I was FINALLY able to download the Malwarebytes to my desktop by using Safari. However, when it finished installing, the two boxes were checked, but nothing launched. When i try to open it from my desktop, nothing happens.Type Y to begin the cleanup process.
It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.Press any Key and it will restart the PC.
When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log (from normal boot mode).
 
 Try booting into Safe Mode and install then run it. You won't be able to update it but it should be OK as is for now.When I try to log on to Windows in safe mode, it tells me my username/pwd is incorrect and it can't log me on. But, if I just log on normally, it's fine. Am I missing something?
 
 Thank you so much for all your help!Try downloading and run MBAM from here http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
 
 Post the log it creates.
 |