Quote:

G'day Marc,
try this root kit killer from Sophos. My staff have had good success with it and it's free:
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html





G'day Lawrie,
Many thanks for your post.

I downloaded and ran Sophos yesterday.
In normal mode:
- the tool found 6 or 7 hidden files (most in temp folders) but did not recommend cleaning them

[“Files tagged as Removable: Yes (but clean up not recommended for this file)”]

I followed this advice and then scanned in safe mode.
This was more interesting.
First of all, a warning and yellow triangle informing me :
Error: Could not initialize kernel driver memsweep.sys.
The tool did however continue with its scan!

In addition to the hidden files it found in normal mode, it also returned a number of locked registry keys which it could not remove.

This time I cleaned up the files tagged as Removable and rebooted to normal mode.

For some reason, I did not get the promised log:
“Once you have restarted your computer, a dialog box displays the files you selected for removal and the action taken.”

No time then to properly test the effects of this operation, but I did note that:
- apparently the unexplained instances of iexplore.exe when IE is closed are not starting up
- there were no web site redirects (but I only tried one of two searches, all using the Opera/Google combination)
- the strongly recommended Kaspersky rootkit removal app. which could not be executed (tdsskiller.exe) would still not run, even if renamed and with BitDefender AV disabled.
-