Author Topic: My computer is infected with Win32:Alureon-EJ [Rtk] and Win32:MalOb-A [Cryp]  (Read 3261 times)

0 Members and 2 Guests are viewing this topic.

illsun00

  • Guest
Please help. Malewarebyte detects it then deletes it but it comes right back. Avast boot scan didnt find them. Please advise.

Thanks,


Illsun00

Jtaylor83

  • Guest
Download and run RootRepeal.

illsun00

  • Guest
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time:      2009/11/30 23:04
Program Version:      Version 1.3.5.0
Windows Version:      Windows XP SP3
==================================================

Hidden/Locked Files
-------------------
Path: C:\WINDOWS\Prefetch\ROOTREPEAL.EXE-2A48A252.pf
Status: Visible to the Windows API, but not on disk.

Path: c:\documents and settings\user\local settings\temp\~df6e9c.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\user\local settings\temp\~df78e9.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\user\local settings\temp\~df85e8.tmp
Status: Allocation size mismatch (API: 32768, Raw: 16384)

Path: c:\documents and settings\user\local settings\temp\~dfe9a2.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Jtaylor83

  • Guest
Download ComboFix by sUBs from here or here onto desktop as a different filename.

Double-click on ComboFix

Click Run

Click Yes to agree to the Disclaimer of Warranty.

Click Yes to install Microsoft Windows Recovery console.

Click Yes to continue scanning.

Once ComboFix is finished scanning, a log will appear. Post or attach the ComboFix log.