A machine I have been working on today - has had severe infection from several worms such as:
Blaster; Sasser; SDBOT; Donk; RBOT;& more that escape me for the moment - the machine has also been infected with many trojans that seem to change each time I run Sysclean through. Also lots of spy/adware including hijacks and cool web search. At first, I could do nothing in 'normal' mode - Antivirus, hijack this, msconfig, regedit - all disappear as soon as you try to launch them. I have run through several instances of sysclean in safe mode as well as spybot, adaware and the fix tools from symantec for blaster & sasser. I have made some progress and can now do a certain amount in normal mode but still have some autostart entries coming back despite heavy editing of the registry, editing system files with notepad and even sysedit - the processes which keep coming back are:
hostsvc.exe
spoolsvc.exe
I know that a format would be the easiest way around this but i'm annoyed now and don't want to be beaten....
I managed eventually to get hijack this to run in safe mode but deleting the processes in there hasn't helped either - just comes back again..........
Any ideas guys?
Thanking you
Kes
Blaster; Sasser; SDBOT; Donk; RBOT;& more that escape me for the moment - the machine has also been infected with many trojans that seem to change each time I run Sysclean through. Also lots of spy/adware including hijacks and cool web search. At first, I could do nothing in 'normal' mode - Antivirus, hijack this, msconfig, regedit - all disappear as soon as you try to launch them. I have run through several instances of sysclean in safe mode as well as spybot, adaware and the fix tools from symantec for blaster & sasser. I have made some progress and can now do a certain amount in normal mode but still have some autostart entries coming back despite heavy editing of the registry, editing system files with notepad and even sysedit - the processes which keep coming back are:
hostsvc.exe
spoolsvc.exe
I know that a format would be the easiest way around this but i'm annoyed now and don't want to be beaten....
I managed eventually to get hijack this to run in safe mode but deleting the processes in there hasn't helped either - just comes back again..........
Any ideas guys?
Thanking you
Kes