Author Topic: win32:mal0b-x [cryp]  (Read 15777 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:mal0b-x [cryp]
« Reply #30 on: October 27, 2009, 07:45:57 PM »
Did you run combofix ?

bricksterr

  • Guest
Re: win32:mal0b-x [cryp]
« Reply #31 on: October 27, 2009, 09:27:39 PM »
Thanks hugely Essexboy! Combofix found a root kit. This explains the clean scans and then reappearances of this nasty little ****. I think I'm good now although I haven't been running the machine for long now. I can now boot into safemode which I wasn't able to before. System is snappier and no more warnings. Would combo fix have remedied the situation in your opinion?

"c:\documents and settings\Sean\Application Data\inst.exe

"Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p "

My only concern presently is that XP firewall shuts off momentarily after logging in but then again it's been doing that for well over a year now. Just an MS glitch? I think so. I think I'll check my router settings while I'm at it.

Thanks again.
« Last Edit: October 27, 2009, 09:31:44 PM by bricksterr »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:mal0b-x [cryp]
« Reply #32 on: October 27, 2009, 09:51:22 PM »
Could you let me see the log please as Combofix sometimes misses the newer variants of files.  Even though it is updated near daily