Author Topic: Help interpret Rootkit logs  (Read 3165 times)

0 Members and 1 Guest are viewing this topic.

raybie

  • Guest
Help interpret Rootkit logs
« on: July 10, 2012, 06:35:04 PM »
« Last Edit: July 10, 2012, 06:54:39 PM by raybie »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help interpret Rootkit logs
« Reply #1 on: July 10, 2012, 07:20:02 PM »
Did you run GMER before or after TDSSKiller ?

raybie

  • Guest
Re: Help interpret Rootkit logs
« Reply #2 on: July 10, 2012, 08:08:41 PM »
Tools already used (in order from first to last):
tdsskiller
AVG AV scan
prevx webroot secureanywhere (Didn't save log)
rootkitrevealer
MBAM
unhackme regrun (Removed a lot of infections with this)
icesword120
SpyBHORemover (Didn't save log, recall removing a couple of BHOs)
OTL
FSS
RogueKiller
GMER
RootRepeal
AVG rootkit scan

New tools used since last post:
SpyDLLRemover log: http://www.joeygalaxy.com/avlogs/SpyDllRemover.html
aswMBR => Scan just finished, log is attached

Tools yet to be used:
Sophos Virus Removal Tool
Dr.Web CureIt!
ComboFix

Awaiting your instruction before I proceed further :)

Massive thanks for your precious time!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help interpret Rootkit logs
« Reply #3 on: July 10, 2012, 08:22:23 PM »
Quote
Disk 0 malicious Win32:MBRoot code @ sector 625121283 !
With the old sinowal bootkits they left a copy of the files on a high sector of the disc.  They are totally inert there and are of no consequence..  However, the only way to remove it is to format the drive.  Which is not really needed

raybie

  • Guest
Re: Help interpret Rootkit logs
« Reply #4 on: July 10, 2012, 08:30:27 PM »
Great :D So is it safe to assume I am clean or not yet?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help interpret Rootkit logs
« Reply #5 on: July 10, 2012, 08:33:57 PM »
Well the only thing left to throw at it is the kitchen sink  ;D ;D