Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Possible Rootkit Infection

  • Please log in to reply
1 reply to this topic

#1 alex_tomcat


  • Members
  • 1 posts
  • Local time:07:41 PM

Posted 17 May 2016 - 04:36 PM



I'm facing a strange situation this week with my desktop, like sudden unreadable hdd drives (all my drivers are in perfect condition as i can see through CrystalDiskInfo),

long time boot ups and one BSOD today.I used both ESET Smart Security and SuperAntispyware to scan for malware or virus but nothing came up.I was worried that it might be a rootkit so i downloaded TDSSKiller and GMER and scaned for possible rootkit infections.TDSSKiller found nothing.One the other hand the first time i used GMER it found something under Rootkit/Malware category.Fortunatelly i saved the log file because the second time i did the search,for more accurate results it caused a BSOD after 10-15 seconds.


Any suggestions would be appreciated


Here is the GMER log

GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2016-05-17 23:27:36
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-4 WDC_WD20EVDS-63T3B0 rev.01.00A01 1863,02GB
Running: alitis.exe; Driver: C:\Users\strogof\AppData\Local\Temp\fxlirfog.sys

---- User code sections - GMER 2.2 ----

.text  C:\Program Files\ESET\ESET Smart Security\ekrn.exe[788] C:\Windows\system32\kernel32.dll!SetUnhandledExceptionFilter  0000000077669010 4 bytes [C3, 00, 00, 00]

---- EOF - GMER 2.2 ----

BC AdBot (Login to Remove)


#2 boopme


    To Insanity and Beyond

  • Global Moderator
  • 73,530 posts
  • Gender:Male
  • Location:NJ USA
  • Local time:11:41 AM

Posted 18 May 2016 - 09:52 AM

Hi Alex, let's get a deeper look. Repost this data with the FRST log in this guide. Start at step 6.
Please follow this Preparation Guide and post in a new topic.
Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users