Running ComboFix followed by SuperAntiSpyware or MalwareBytes will give you good results.
Main Topics
Browse All TopicsHi All
I have a computer that is badly infected. HiJackthis will not remove it and Combofix will not run. How do I get rid of Reader_S.exe. I see 3 instances in the registry.
Help... Don
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Thanks for the responces,
I have tried all those. During the SuperAntiSpyware scan, I get a blue screen error Page_Fault_in_nonpaged_are
I am going to suggest that you download an antivirus such as AVG (http://free.avg.com/) or Avast (http://www.avast.com/eng/
In case those antiviruses don't install straightaway, then you can use this method:
Download Dr Web Cure It Live CD from: http://www.freedrweb.com/l
Reader_S.exe is a file dropped by virut, usually with virut infection I suggest a reformat depending on how long the pc has been infected.
See if you can download Dr.WebCrureIt, it's good for removing virut infected files, and then see if a renamed combofix will run afterwards. Or as already suggested use the LiveCD.
http://www.freedrwe
If the above methods did not do the trick , try the below link
http://www.symantec.c
Ok peeps.......After 2 days of scanning and deleteing, it looks like the 'Reader_s' is gone.....for now. The machine seems to be running OK. However I can't get the Device Manager to work. When I try to open the Device Manager from System Properties>Hardware Tab>Device Manager I get this window....."Windows cannot find 'mmc.exe'. Make sure you typed the name correctly, and then try again. To seach for a file, click the Start Button, and then click Search." Any clues?
Thank You Thank You Thank You
Don
Go here http://www.microsoft.com/d
Try installing the new Microsoft Management Console MMC
That should overwrite older mmc. Your virus probably infected the mmc.exe and it got deleted.
Let me know.
Hey NaturaTek,
Thanks for the link. I downloaded and installed....still didn't work. I think it could be a deeper problem because I went to the Control Panel> Administartive Tools> Computer Management and got this: "This file does not have a program associated with it for performing this action. Create an association in the folder options control panel" ....Then the "Open With" window opens with choices like Internet Explorer, Word Pad, Paint, Picture Viewer...
Thanks, Don
Download http://www.dougknox.com/xp
And double click the reg file inside, merge it
SWEET NIBLETS! I got it back!
Heres what I did. I went to my other machine, copied the mmc.exe file to a flash drive. Then I copied it directly into the System32 folder.. rebooted, went to device manager and got this :"The procedure entry point ?pickicondlg@@YGHPAUHWND_@
I'm not exactly sure what happened but its going now......Thank You Again, Don
Hello Vee Mod
Help me out here.....So, the solutions I accepted were wrong? I used some of the advice provided. The Kaspersky Boot CD was a great tool. It took a while to run, but I was able to remove infections. Also....If I could not get other virus removal programs to install normally, I tried to install/run them in "Safe Mode". Was this a wrong move? I really don't remember if I had good results with virus removal while running in Safe Mode. Should I accept another solution?
Thanks, Don
NaturaTek -
You are the one who needs to learn how to 'read correctly'.
They told you at least half a dozen times in that forum to run MBAM in Normal Mode.
The only suggestion you received after all your comments about 'Safe Mode' that 'it wouldn't do any harm' to use Safe Mode.
It doesn't do any good - and the program is NOT designed to run in 'Safe Mode' - and the program IS designed to run in Normal Mode - and Safe Mode is not as effective as Normal Mode - but you are right in a very minimal restrictive way: there is "no problem" running it in Safe Mode.
Business Accounts
Answer for Membership
by: warturtlePosted on 2009-05-29 at 06:50:33ID: 24502849
Hello,
r.com/comb ofix/how-t o-use-comb ofix
or MalwareBytes Anti-Malware (www.malwarebytes.org) and do a scan with any of them. If they don't install, then download them again and save with a completely different name and install them.
Have you followed all the instructions required for ComboFix?? They are at: http://www.bleepingcompute
This includes disabling antivirus protection before running ComboFix, and not clicking in the ComboFix window while its running.
Secondly, I am going to suggest downloading ComboFix again and save it with a different name like jabba.exe and then execute it. You might want to download and install either SuperAntiSpyware (www.superantispyware.com)
Hope it helps.