3.3K Posts

September 9th, 2007 09:00

Copy the data below in Bold text to Notepad and save it to your Desktop as "findthese.bat" but without those quote marks.

@ECHO Searching ...
@ECHO off
dir "%SYSTEMDRIVE%"\bdldr.dll /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "%SYSTEMDRIVE%"\fx3_s.exe /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "C:\Windows\System32\drivers\bypass.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "C:\Windows\System32\drivers\m11j.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "C:\Windows\System32\drivers\r!3.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "C:\Windows\System32\drivers\kdjhsg.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt



Now double click on the .bat file on your Desktop and allow the batch to run. When it completes the command prompt window will disappear. At this point, navigate to:
C:\found.txt and Double-Click the text file. Copy the contents and paste it back here in this thread. Thanks!

September 9th, 2007 11:00

Hi,
 
i did the following and nothing happened. The found.txt was empty. I kind of guessed it was because i installed windows on E drive. Anyway i changed the c:/ to e:/  and did the search again.
 
@ECHO Searching ...
@ECHO off
dir "%SYSTEMDRIVE%"\bdldr.dll /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir"%SYSTEMDRIVE%"\fx3_s.exe /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "E:\Windows\System32\drivers\bypass.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "E:\Windows\System32\drivers\m11j.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "E:\Windows\System32\drivers\r!3.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
dir "E:\Windows\System32\drivers\kdjhsg.sys" /q/a/o:gn/s/x > "%SYSTEMDRIVE%"\found.txt
 
 
Found.txt came up with this
 
" Volume in drive E has no label.
 Volume Serial Number is 48DC-DEF4"
 
 
thats all. .

3.3K Posts

September 9th, 2007 19:00

Quote: i did the following and nothing happened. The found.txt was empty. I kind of guessed it was because i installed windows on E drive.
Good move. After attending a funeral for a friend yesterday who lost their 20 year old son, and having gone about 28 hours with no sleep and still resolving more than 20 different user's log requests for assistance, I would say the oversight is understandable...I apologize nonetheless.

Anyway i changed the c:/ to e:/ and did the search again.
Well, you changed more than the drive letter I can see...regardless, as it appears the search didn't find a single one of those files because you don't have the malware hacktool.rootkit on your system.

Norton is well known for reporting a false positive regarding that particular malware...when did you last update your application?

Please perform a scan with F-Secure Online Scanner
Follow the directions in the F-Secure page for proper Installation.
1. Scroll down and click the" Start scanning" button.
2. You may receive an alert on the address bar at this point to install the ActiveX control.
3. Click on that alert and then click " Install ActiveX component".
4. Read the license agreement and click " Accept".
5. Click " Custom Scan" and be sure the following are checked:
  • Scan whole System
  • Scan all files
  • Scan whole system for rootkits
  • Scan whole system for spyware
  • Scan inside archives
  • Use advanced heuristics
6. When the scan completes, click the " I want to decide item by item" button.
7. For each item found, Select " Disinfect" and click " Next".
8. When done, click the " Show Report" button, then copy and paste the entire report into your next reply.

September 19th, 2007 14:00

hello, i am back. . .
 
I tried downloading the scanner a few times but failed.
I did manage to after quite a number of times. but the scan was too long. I was doing it right after finished my work to get ready for bed, the wait was too long!
 
Anyway a few times, it managed to detect tracking cookies. But that was about all it managed to find.
 
I gave up in the end. I just transfered my important documents, reformatted the pc and installed everything again.
Now i am using AVG.
 
 
Originally was i using an expired version of Norton Antivirus 2004, and it worked great. My computer was so fast.
Then just recently i bought 2007 Norton Security and right after that, my computer speed dropped tremendously. Along with the hacktool problem. .
 
 
Anyway I have only one last problem nwo which i cannot seem to solve.
The "My computer" Icon is on my desktop. I double click to open it and now when i open any drive, it asks me wat program i want to use to open. And i cannot check the box that says "always use this program".   However If i use the folder tree, it works fine. I have never had such problems in all my years of using windows till now. . i wonder if it has to do with the virus. .


Message Edited by rheographics on 09-19-2007 11:56 PM

3.3K Posts

September 19th, 2007 15:00

Since you reformatted, the hjt issue should be cleared. Any virus should have been wiped as well with the reformat.

You should post your issue in the windows xp forum now since it's not a hjt issue. Thanks!
No Events found!

Top