Author Topic: Help: Rovnix & other infections possible cause of BSOD & loss of update service  (Read 7544 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
We are getting there :)

So far we have removed 2 bootkits, 1 Zero Access and  Adware that was well into double figures.  What AV was installed prior to you installing Avast ? 

Emilford85

  • Guest
We are getting there :)

So far we have removed 2 bootkits, 1 Zero Access and  Adware that was well into double figures.  What AV was installed prior to you installing Avast ?

Norton was on the pc. I used the norton removal tool to unistall it.Im guessing there were others on it before that. I see McAfee security scan plus in the programs menu, but I didnt check if a service was running.


BTW, I really appreciate your help man

JRT log attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
OK all adware now gone... Just a matter of clearing the orphans and oddballs now

Is the computer behaving in normal mode now ?

Emilford85

  • Guest
Is the computer behaving in normal mode now ?

Yep! No bluescreen. Windows update is back.

Will run otl for a log now

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Panda Security Toolbar
avast! Online Security
McAfee, Inc.
IOBit

Were previous Contenders
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Emilford85

  • Guest
OTL log attached now

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
That now looks good, all services running, zero access dead, adware consigned to history :)

OK I believe one of the infections was via a USB drive so we will slap some protection on for that now

Download MCShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives

Plug in the drive and McShield will start a scan

Then get the log which will be here :

Start > all programs > MCShield > logs > all scans

And post that


Are there any apparent problems outstanding ?

Emilford85

  • Guest
Its seems like everything has been fixed

Again,I really appreciate your help. Im gonna try to explain to her how to uncheck the boxes & read when she's installing programs


Installed mcshield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
OK you can use Avast to help here

Open Avast > Settings > Antivirus > Set hardened mode to aggressive


Then any unknown or low prevalence programme will ask to run.  If you are happy then select Add to Exclusions



Then set Avast to detect PUPs, click the cog next to file system shield



Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Delete JRT from the desktop

Run AdwCleaner and select uninstall

Remove ComboFix
  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall
     (Notice the space between the "x" and "/")
    then click OK



  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled
Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

Clear Restore Points

Go Start > All Programmes > Accessories > System tools
Right click Disc Cleanup and select run as administrator
When it pops up at the first prompt select OK after it has done some calculations the tabs will appear
Select More Options tab
Press Sytem Restore and Shadow Copies Cleanup button

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware



Malwarebytes.

Update and run weekly to keep your system clean


It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?Keep safe  :wave: