Help - Search - Members - Calendar
Full Version: fire wall and virus
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
hol
My computer (gateway) with windows xp is not allowing me to enable my firewall. It is permantely on the unrecommended choice of not enabling the firewall. Also my computer has been infected with a virus named Troj/Rootkit-U detected in
C:/WINDOWS/system32/haxdrv.sys - Overall, my comuter is not allowing me to successfully use internet explorer
LoPhatPhuud
First:
Download, install and run the Microsoft Malicious Software tool. Instructions and link are here: http://www.microsoft.com/downloads/details...&displaylang=en


Second:
Do a full system scan with yoour AV product, include the contents of archive if your AV product will do that. Remove all that it finds unles syou are positive an item is safe.


Third:
PLease download the following zip file:
http://www.sysinternals.com/files/rootkitrevealer.zip

Unzip it to its own folder on your desktop.

Open the folder you created and double click on rootkitrevealer.exe

From the File menu, select 'Scan'

When the scan is finished, selectg 'Save...' from the File menu and save the log file.

Post the contents of RootkitReveal.txt in this thread.


Fourth:

Download *Hijack This!* (current version is 199.1)
http://www.castlecops.com/downloads-file-328.html
http://www.merijn.org/files/hijackthis.zip

Unzip to a folder other than your Desktop or the Temp folder. Then, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that and copy & paste its contents here.

Most of what it lists will be harmless or even essential, don't fix anything yet. Someone will be along to tell you what steps to take after you post the contents of the scan results.


Last:
Would you please use HiJackThis to produces startup list and post it here:
1. From HJT main screen, click 'Config' button
2. Click 'Misc Tools' button
3. Check both boxes to the right of 'Generate StartupList Log' button
4. Click 'Generate StartupList Log' button
5. Click 'Yes' in the next dialog
6. Save the log and post a copy in this thread.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.