Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the HijackThis Log Help forum, or the "First Steps" link at the top right of each page.

Reply
 
Thread Tools
Old 01-29-2007, 07:48 PM   #1 (permalink)
Registered User
 
Join Date: Oct 2006
Posts: 79
OS: winxp


rootkit woes

Hi,

Can anyone help?

I had to reinstall windows xp to clear up a problem left over from a spyware program. I had been cleared of spyware by the hijack this people and trend pc cillin found no viruses, etc. After reinstall I only went to these websites: firefox, earthlink, trend micro cillin. I redownloaded pc cillin and ran it. It found a worm: sdbot.dyx and said it was in winsvc.exe and could not be removed or quarantined.

I printed out the instructions on their website to remove the virus manually, but first tried reinstalling windows again. (Yes, a real reinstall, by removing the old partition, etc...). Still, I had the virus, which caused pop-up windows trying to get me to connect to suspicious websites, slowing down my computer, and kicking me off the internet when I tried to download protective features, such as windows updates and trend pc cillin (the second time).

I've tried following their instructions for removal which involved going into the edit registry and deleting files with winsvc.exe. I found none.

I've tried calling trends tech support, who were not too helpful. I was told if I couldn't find those files then I must not have a virus...

I've tried running pc cillin again to see if the virus is still there and the program won't scan for virus'. It gets stuck.

How can I get rid of this *&%*&^(*** thing?
dbstone is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 01-30-2007, 05:30 AM   #2 (permalink)
Moderator, Microsoft Support
 
POADB's Avatar
 
Join Date: Jul 2004
Location: United Kingdom
Posts: 6,209
OS: XP SP2


Hi dbstone

The best thing you can do is revisit the HJT Help Forum with a new HJT log and the details you have posted above. The Security Team are trained in this type of detection and removal.

G'luck
__________________


POADB is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 06:38 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82