Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit I think - still after Formatting and Reinstalling clean windows 7


  • Please log in to reply
1 reply to this topic

#1 xplora

xplora

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:07 PM

Posted 13 November 2010 - 09:38 AM

hi

First of all, you guys are doing a fantastic job, kudos to all at BleepingComputer.

I have read through your pinned topics and general "todos" before posting a topic. I think I have a "new" variant as an infection. Most definately a rootkit and some. It was causing all sorts of redirects, installation of scareware / malware etc. Avira Antivir,Mcaffee, Microsoft SE, MBAM. Super etc. could not do anything. HJT wont show what I need to see. I often use a fantastic tool called WhatsRunning and it was showing several "not wanted" IP connections. But its just a whatson scanner. Now after going through the motions I used ComboFix also, which would get stuck up - BSOD in normal and safe mode. I also scanned with UnHackMe which was showing presence of TDL3+mutant RK. Manually I would wipe off the files from appdata etc. but obviously it would comeback since the RK / Backdoor / Malware was not completely out.

Hence, instead of trying to waste time removing it, I clean formatted and installed a fresh copy of windows 7. For a few days it was fine, but now its back again. Could be because I had to use few files from the other drives / backup although I made sure I fully scanned all drives before doing anything and I have not used any exe, dll, dat, sys, com etc. files from the old backups. Especailly since I cannot delete / wipe files in APPdata/temp etc. I also feel that it is manifesting itself as flash player util and google toolbar etc.

I was restraining myself from posting, but then I thought it would be a great help to me personally and might be if interest to others if a solution is found out, if this is a "new" version of a RK / Backdoor / Malware.

Thanks in Advance

- xplora -

BC AdBot (Login to Remove)

 


#2 Casey_boy

Casey_boy

    Bleeping physicist


  • Malware Response Team
  • 7,765 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:07 AM

Posted 15 November 2010 - 06:51 AM

Hi,

Welcome to BleepingComputer, my name is Casey and I'll be helping you out.

Firstly, you should never use ComboFix without trained supervision. This tool is very powerful and can cause serious damage to your PC.

Since your reformat, what anti-virus products do you have installed? Could you please run a scan with one of those and post me the log.

Could you also follows steps 6,7 and 8 in this topic: http://www.bleepingcomputer.com/forums/topic34773.html

Casey

If I have been helping you and I do not reply within 48hours, feel free to send me a PM.


* My Website * Am I Infected? * Malware Removal Help * If you'd like to say thanks *





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users