Author Topic: Rootkit Infection!  (Read 8319 times)

0 Members and 1 Guest are viewing this topic.

darkgr33n

  • Guest
Re: Rootkit Infection!
« Reply #15 on: March 27, 2011, 02:20:05 PM »
cool, will give it another run and save as ansi later tonight when i'm back.
thanks

darkgr33n

  • Guest
Re: Rootkit Infection!
« Reply #16 on: March 27, 2011, 08:21:15 PM »
Hi

Here is the ANSI version of my OTS log [as one file now its ansi].

I've haven't had a recurrence of the ROOTKIT warning from avast, but I did download and run MBAM ... er, it discovered 868 threats that needed to be deleted ...

ANSI log attached, thanks.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit Infection!
« Reply #17 on: March 27, 2011, 09:38:57 PM »
Yep looking at that I can see why - did MBAM remove all the IFEO registry settings and the disallow run ones ?

This is a big fix so I will attach it as a text file download it to your desktop


  • Start OTS
  • Then press the Run Fix button and a dialogue box will pop up asking for the location - select the fix.txt you downloaded 
  • Then click the Run Fix button at the top
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix.  Post that information back here

I will review the information when it comes back in.

darkgr33n

  • Guest
Re: Rootkit Infection!
« Reply #18 on: March 28, 2011, 04:54:37 PM »
Hi

Yep - there was a shed load of IFEO settings that MBA found, and 16 [0-15] disallow run ones. All removed now.

Thanks for the sorting a fix file for me, nice one  8)

I've run the fix in OTS, and the log is attached.

Thanks again!

Cam Gibb

  • Guest
Re: Rootkit Infection!
« Reply #19 on: March 28, 2011, 05:38:06 PM »
aswmbr.exe just fixed what Malwearbytes missed. Thanks Avast! support :-) I'm trying your trial version 6 :-)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit Infection!
« Reply #20 on: March 28, 2011, 07:39:00 PM »
What problems do you have remaining darkgr33n ?

darkgr33n

  • Guest
Re: Rootkit Infection!
« Reply #21 on: March 28, 2011, 08:10:14 PM »
What problems do you have remaining darkgr33n ?

As far as I can tell, we're as clean as a whistle ...

Thanks for all of your help pondus and essexboy [i'm one too!]

Cheers!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit Infection!
« Reply #22 on: March 28, 2011, 08:34:25 PM »
Run OTS and hit the cleanup button and it shall disappear  ;D