Hacktool Rootkit Nightmare...please Help!

Status
Not open for further replies.
Yahooooo?

You mean, the dns looks ok, or the whole HJT scan? I am keeping that champagne bottle ready for the good news...:)
 
Drinks Are On Me!!!

It's Cold Indeed! One Week In The Fridge (the Time It Took Me To Get Rid Of The Bloody Thing) Is More Than Enough!! Black Velvet For Everybody!!

Thank You Again To All Of You, You're The Real Deal!

Kk
 
Next week you'll have a new virus or some such, drink quick!

Now keep yourself clean:

Good up to date antivirus
Hardware or software firewall
Install Microsoft Antispyware Beta
Run ad-aware and spybot twice a week
Use Firefox for Internet surfing
NEVER click a popup or ad no matter what!
Password protect your administrator user accounts
Turn off remote desktop support and remote assistance
Turn on automatic updates for Windows
Don't download any programs without checking on http://www.spywareguide.com/
Use Spybot to Immunize you
Nevery try to find free cursors and/or free screensavers
Keep your tools (HJT, BHO Captor, CWShredder etc) up to date

And the list goes on.

cheers
 
Hacktool.Rootkit

I quarantine it and delete it through Norton Anti Virus. A few seconds later, the Virus Alert window popped up and the msdirectx.sys seems to be in my computer still. I found the file and tried to delete it. it is impossible to delete it because when i click delete, a window popped up saying i have to make sure that it is not protected or the disk is full, etc..

How to remove it from the computer for good?

-anna-
 
Hacktool Rootkit

I am running Windows XPSP2
The other day I tried to open TweakXP (which had been working fine) and got Norton AV msg saying it had found the Hacktool.rootkit in C:\windows\system32.

I have taken a log of HijackThis....pls can anybody help...am i at risk? or is it that i had just updated my virus defs and Norton had mis-interpreted a valid SVKP file?
 
Hacktool Rootkit

I am running Windows XPSP2
The other day I tried to open TweakXP (which had been working fine) and got Norton AV msg saying it had found the Hacktool.rootkit in C:\windows\system32.

I have taken a log of HijackThis....pls can anybody help...am i at risk? or is it that i had just updated my virus defs and Norton had mis-interpreted a valid SVKP file?

Logfile of HijackThis v1.99.1
Scan saved at 09:00:20, on 25/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
See the Read: How to... hacktool post at the top of the forum.

Run HJT in save mode and let it fix:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHealth\HelpCtr\System_OEM\blank.htm
Fix ALL your O1 - Hosts: entries
Fix ALL your O16 - DPF: entries
 
Took your advise

Thanks, I have deleted those entries in hjt, does this now mean that i have gotten rid of the svkp problem?..can i reinstall tweakxp?..or do i still need to do other stuff?

Many thanks :)
 
Other than the advice in the Hacktool post, there's NOTHING that I can do.
Scan the install-program before you install it, to see if that contains the virus.
Other than that, try it and best of Irish!
 
Status
Not open for further replies.
Back