One day, I found out my AVG.exe and Spybot S&D exe files (along with several other stuff, like motherboard programs) were just missing. I heard the hard-drive spinning, but I wasn't doing anything too intensive, so I opened up my processes and saw this one process that was a bunch of numbers, so I ended that and the hard-drive stopped spinning. Lucky I caught that fast, because I think that was deleting some of my stuff. From there on I knew something was wrong. First, I downloaded the latest AVG definitions tried rebooting into safe-mode, but when I did this, once I picked safe-mode from the start-up menu (via F8 on reboot), after it loaded some files, it would just restart. So I started trying to install various anti-virus programs, but they all failed:
AVG - I got an error saying I couldn't install it because of a missing exe file or something.
Kaspersky - It says I don't have admin rights.
Spybot - The exe file gets deleted the moment it's installed.
The funny thing is, I'm the only account on my XP, and it's the admin account. One thing I have been noticing lately is that when my screensaver runs, I get logged out. This didn't happen before. I also now have to click on my account to enter windows on a startup, which also never happened before. It would usually just go into windows using my account, but when I had to click on my account to enter, I thought nothing of it. But it may be a clue to some of you.
Then I tried running online scans, Kaspersky told me there were infections (but the online scan doesn't remove anything), I ran several others: Trend would get stuck, several others could not update and such.
The only one I got to run and actually remove some files was BitDefender. It picked up some files in C:\WINDOWS\exefld, and basically they were a bunch of numbers with an exe extension. I restarted, tried to boot into safe mode but failed. The problem was still there, so I opened that folder and the icons were like two keys.
While running these scans, a window popped up saying my windows files were changed and it might screw up windows. So it wanted me to reinstall XP.
I started to realize this was a rootkit, so I tried to find some removers.
F-secure - I couldn't finish updating
Sophos? rootkit remover - can't install, don't have admin rights.
So now I'm stuck. I have ran chkdsk and it was fine. I haven't had a chance to get a HJT log yet, but will do so soon.
Basically, I can't install any virus removal software, I can't boot into safe mode, my windows files are being changed and exe files are disappearing.
EDIT: Oh yea, I've checked my processes as well, and nothing seems to be irregular, but I'm not too sure.
Edited by kenhcwoo, 30 November 2007 - 09:12 AM.