Root kit infection
We have a windows 7 32 bit machine which has been infected with a root kit virus. The first clue to the infection was that McAfee Anti Spyware had been disabled even though it is locked down and needs a password to be disabled. We could not re-enable it. Then, looking into services we had hundreds of new services with the description 'New service would allow parents to control their children's online activity', although most were not started. The other noticeable thing is that during shutdown it would hang and have to be powered off. Scanning with the tools requested by majorgeeks before opening this thread revealed a number of root kits which some seemed to have been removed. We can now start McAfee spyware module and the computer now shuts down without hanging. We are still noticing though firefox and IE automatically shutting down within 30 seconds of opening and we are still seeing those hundreds of services when viewing services. Attached are logs requested. When trying to run combofix we had the error "Windows cannot find "NIRKMD". Make sure you typed the name correctly, and then try again." pop up a number of times although it seemed to run successfully and removed infections. Root Repeal we could not get to run. Our McAffe was completely disabled.
Thanks in advance for your help!
|