Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Is My Rootkit Completely Removed?


  • Please log in to reply
No replies to this topic

#1 Poptartjake

Poptartjake

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:06:38 AM

Posted 22 March 2018 - 10:33 AM

After having dealt with a nasty rootkit of some kind (Blocrypt?) for the last 2 days, I finally seem to have made progress on its removal. I'm just looking for some advice as to what tools I should run/post the logs from so someone with more experience than myself can confirm I've been successful. 

I've used about every tool in my toolbelt and some new ones. The list below should be everything that I've used since the infection occurred. 
Malwarebytes
MBAM Rootkit BETA
EMSIsoft Emergency Kit
Zamana (currently scanning with)
Hitmanpro
TDSSKiller
Roguekiller
AdwCleaner
SUPERANTIspyware
Combofix
CCleaner
Microsoft Security Essentials


Yesterday, I ran GMER and was alerted to the presence of a rootkit. This morning, GMER does not return the same alert and the processes which were associated with the infection are no longer running.

I'm just hesitant to call this system "clean" as it still feels a little abnormal. It's still a bit more sluggish than normal and the desktop icons will flicker (refresh) every so often which I never recall happening before.
 


Edited by Poptartjake, 22 March 2018 - 10:34 AM.


BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users