Author Topic: avast can't get rid of url:mal from wxw.cikh71ynks66.xcm which avast blocked.  (Read 16047 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Did it find the MBR TDL4 ?

wby526

  • Guest
Hello essexboy,

I also kept getting the cikh71 site blocked. Per your earlier post, I downloaded OTL and TDSSkiller. TDSSKiller detected 1 file and promted me to reboot. After the reboot, I check the report in my C:\ folder and it said the following:

Detected object count: 1
\HardDisk0 - will be cured after reboot
Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
Deinitialize success

Does this mean it's gone?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
That will usually cure the main infection - run Malwarebytes after that and you stand a reasonable chance of being clean