also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

Hacktool.Rootkit & Generic7.QOV

Discussion in 'Virus and Malware Removal' started by sevenwishes, Sep 26, 2007.

Thread Status:
Not open for further replies.
  1. sevenwishes Newcomer, in training

    Hi

    Every time I shut down and restarted my computer, Symantec AntiVirus detected a Hacktool.Rootkit in my computer. Symantec kept reporting it was deleting the virus, except it kept respawning upon restarting my computer. I was having no luck and stumbled upon your website.

    I followed the instructions under "Viruses/Spyware/Malware, preliminary removal instructions" and have attached the requested log files.

    The AVG Antirootkit programme didn't detect anything.

    The AVG Antispyware did detect the trojan Generic7.QOV, which was promptly deleted. This occurred before I booted the computer into safe mode. The AVG Antispyware did not detect anything when I ran the program under safe mode. I was wondering if the Hacktool.Rootkit was still in my computer and what, if anything, I needed to do to erase the trojan Generic7.QOV.

    Thanks in advance
  2. Jase123 Banned

    Delete the following, but first let Howard check it over, as i am still in training.

    * O23 - Service: SQDEZKEEFM - Unknown owner - C:\DOCUME~1\pablof\LOCALS~1\Temp\SQDEZKEEFM.exe (file missing)

    Also do this:

    Turn off System restore. See how Here.
    This will delete all system restore points and any nasties in them.

    That is probably why the virus keeps returning.

    Regards Jase :)

    This thread is for the use of sevenwishes only. Please do not post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
Thread Status:
Not open for further replies.