09-02-2009 06:10 AM
09-02-2009 06:33 AM
Welcome to the Norton Community
Please run a SysProt log for us so we can check your system for rootkit activity. You will need to disable Norton auto-protect while you run the scan, as well as any other antimalware program you may have installed on your PC.
Once it is downloaded to your desktop, right click on the SysProt icon, go to properties, and click unblock and apply.
Choose log, check all the boxes except show hidden objects only and then scan.
You will be able to post the log here using the "add attachments" link just below the orange post button.
http://homepages.slingshot.co.nz/~crutches/SysProt
We look forward to the time when the Power of Love will replace the Love of Power. Then will our world know the blessings of peace. ~William Ewart Gladstone
09-02-2009 06:43 AM
09-02-2009 06:48 AM
We look forward to the time when the Power of Love will replace the Love of Power. Then will our world know the blessings of peace. ~William Ewart Gladstone
09-02-2009 07:11 AM
09-03-2009 03:48 PM
Hi
I have sent you a personal Message, look for the Yellow Envelope near the upper right hand corner.
Quads
09-04-2009 01:02 PM
Hi
Continuation of Stage 1, File removal (same program to continue step 1)
Now the registry entries will be greyed out I think, will get them later.
Tick (check) these entries (little square box beside each entry) Only the entries below, not the others
C:\WINDOWS\system32\rotscxlsrttimm.dll
C:\WINDOWS\system32\rotscxbnrjlksr.dat
C:\WINDOWS\system32\drivers\rotscxkdulrscp.sys
C:\WINDOWS\system32\rotscxamryfwxi.dll
C:\WINDOWS\system32\rotscxdvblovrb.dat
Then click the Clean items button
Follow the prompts to remove them and restart your computer.
After reboot, a dialog box displays the files you selected for removal and the action taken.
Step 2 after Once I know that is completed
Quads
09-05-2009 08:55 AM
09-05-2009 11:37 AM
Hi
Quads
09-05-2009 03:17 PM
yes, NIS was installed and running normally before the infection. I have run a full scan with Malwarebytes, I'll attach a logfile of what it found.
