BleepingComputer.com: Trojan.Agent/Gen-FakeAlert[Local] and Possible Rootkit Infection

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

Trojan.Agent/Gen-FakeAlert[Local] and Possible Rootkit Infection Need help making sure machine is clean & protected.

#16 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 08 February 2012 - 09:54 PM

Can you tell me specifically what Endpoint is deleting? Most AVs have a log you can access - I'd like the full file path to whatever it is detecting, please.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#17 User is offline   drews247 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 39
  • Joined: 14-December 10

Posted 12 February 2012 - 02:48 AM

this is all i can find in the log
Combo Fix.exe Trojan.ADH.2 Cleaned by deletion File C:\Users\Drew\Desktop\
the attachments might help more

let me know if there is anywhere i should look

Attached File(s)



#18 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 12 February 2012 - 09:24 AM

That was helpful, thanks. Those were all false positives. Is the ComboFix icon gone from your desktop now? Please do this for me:

Open notepad and copy/paste the text in the quotebox below into it:

Quote

@echo off
dir /a /s "C:\combofix" > log.txt
notepad log.txt
del log.txt


Save this as peek.bat Choose to "Save type as - All Files"
It should look like this: Posted Image
Double click on peek.bat & allow it to run. A notepad file will open. Copy that information into your next reply, please.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#19 User is offline   drews247 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 39
  • Joined: 14-December 10

Posted 12 February 2012 - 03:21 PM

The CFuninstall icon is still there, but the combofix icon is not.

here is what was in the log:

Volume in drive C has no label.
Volume Serial Number is 9287-437C

#20 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 12 February 2012 - 03:33 PM

Thanks, that all indicates a successful uninstall. You may delete the stand-alone uninstaller from your desktop now. Take care.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#21 User is offline   drews247 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 39
  • Joined: 14-December 10

Posted 12 February 2012 - 04:39 PM

Is my computer all clean?

If so, thanks so much for your help!

#22 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 12 February 2012 - 04:58 PM

It was my pleasure. Your logs appear to be clean! Take care.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

#23 User is offline   RPMcMurphy 

  • Bleeping *^#@%~
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,397
  • Joined: 16-May 10
  • Gender:Male

Posted 13 February 2012 - 11:12 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may Posted Image

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users