Author Topic: INFECTED - artemis, redirect, physicaldrive0 mrb tdl4, rootkit - please help  (Read 3904 times)

0 Members and 1 Guest are viewing this topic.

jaysun5555

  • Guest
this thing is killing me.... LOL! i read through a bunch of threads about this, and was tempted to just kinda follow the instructions essexboy has given several others, (run aswMBR, OTH, OTL, and ComboFix, -- basically i was about to do everything he said to someone else except the part about posting any logs,) but figured maybe i should do this the right way. i am ready to follow instructions! save me, jeebus!!

Gargamel360

  • Guest
Here be the official "get started" instructions>>http://forum.avast.com/index.php?topic=53253.msg451454#msg451454, but it sounds like you pretty much already have the gist of most of it.  Please post the logs as attachments when finished, and wait for essexboy to read them over and recommend anything further.

jaysun5555

  • Guest
alright, ran aswMBR, which seems to have popped a serious cap in this thing... i've attached the logs from before and after the "fix."  then, i ran OTH/OTL... i've attached the log from that as well... interpretation would be much appreciated. thanks.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89678
  • No support PMs thanks
I'm not familiar with the OTL log, but the aswMBR seems to have cleared the MBR rootkit.

So what symptoms are you experiencing after the MBR Rootkit removal ?

Someone else will have to pick up on this one, almost 3am here and I'm calling it a night.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

jaysun5555

  • Guest
thanks, gargamel and david. well, it's only been about 2 hrs but i'm no longer experiencing any symptoms... just figured i'd see if old boy can give me the official thumbs up.. i'm committed to not vanishing from this thread until it's a confirmed repair.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89678
  • No support PMs thanks
You're welcome.

It is certainly a good sign that you aren't getting any symptoms.

Now that the rootkit element has gone, I would run another avast Quick/Full System scan and see if it finds anything that would otherwise have been hidden.

Might also be worth running MBAM:
If you haven't already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).
MalwareBytes Anti-Malware (MBAM), On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security