I recently installed a program given to by my friend, unfortunately it contained what I believe to be a rootkit trojan.
I am running:
Vista x86 Service Pack 2
Kaspersky IS 2009 (which found the trojan)
I have already ran the Combofix and have included the results in this post. As well I have already tried deleting this file via Kaspersky by rebooting my system
of which nothing happens. I still get the trojan alert. Kaspersky tells me that I cannot delete this file (windows\system32\geyekrbbdxqefi.dll--Trojan.Win32.Agent2.lav)
becauase it is being used by another program. I do get the an alert box whenever I try to open any program which says: globalroot\systemroot\system32\geyekrbbdxqefi.dll
is either not designed to run on Windows or it contains an eroor. Try installing the program again using the original installation media or contact your system administrator or
software vendor for support.
Thanks in advance....
Combofix log removed. ~ OB
Edited by Orange Blossom, 21 August 2009 - 09:13 AM.