Reply
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: NIS 2009 disabled

Ok 

 

Please run Malwarebytes again and see if the registry entry appears again even after removal the first time.

 

Quads 

Regular Visitor
tragic82
Posts: 9
Registered: ‎09-02-2009

Re: NIS 2009 disabled

[ Edited ]

the registry entry has reappeared, showing the same rootkit

 

EDIT: tried deleting the entry again, this time the computer rebooted and corrected several files during setup (this did not happen the first time I tried removing the entry). Currently running another Malware scan, will post results when the scan finishes.

 

Thanks for your help so far

Message Edited by tragic82 on 09-06-2009 07:01 AM
Regular Visitor
tragic82
Posts: 9
Registered: ‎09-02-2009

Re: NIS 2009 disabled

the most recent scan continues to show the same rootkit, despite Anti-Malware's attempts to remove it (twice). Computer seems to be running normally aside from this.
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: NIS 2009 disabled

Step 3. Registry

 

 

If you have Spybot S&D installed remove it  "AND disable Norton Auto-Protect"  As Norton now detects part of Avenger

 

Also during the restarts with Avenger if Your PC has a Startup repair center like with HP and Toshiba tell it to start Normally if it kicks in.

 

1. Download Avenger to your desktop,

 

Unzipped version http://homepages.slingshot.co.nz/~crutches/Avenger/

OR Creators website http://swandog46.geekstogo.com/avenger2/avenger2.html with zipped version to the unzip to desktop 

 

2. Click to run "Avenger.exe"  (right click "Run as Administrator" if using Vista)

 

3. In the "Input script here:" copy and paste the script between the lines

 


Drivers to disable:

rotscxrnkomudj

 

Drivers to delete: 

rotscxrnkomudj

 

Files to delete:

C:\WINDOWS\system32\drivers\rotscxkdulrscp.sys

 

Registry keys to delete:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\rotscxrnkomudj

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\rotscxrnkomudj


 

 

 

Here is a screenshot (script updated since shot)

 

Avenger.jpg

 

Make sure the "Automatically disable any rootkits found" is NOT selected

 

4. Click "Execute"

 

You will be asked to restart the PC click "Yes", when the PC restarts the load screen will takes slightly longer, then when it looks as though windows is loading the PC will restart again.

Then when Windows fully loads the Avenger log will be loaded, showing files it could or could not find.

 

Quads  

Regular Visitor
tragic82
Posts: 9
Registered: ‎09-02-2009

Re: NIS 2009 disabled

completed stage 3, however, no log appeared following the reboot. when i turned auto-protect on again (20-30 mins after reboot), it produced a report stating it had blocked an adware popup, presumably something to do with avenger. However, I've run a Malware scan, which didn't find the rootkit, so it looks like avenger worked anyway.
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: NIS 2009 disabled

Hi

 

I would say Avenger got it and any backup entry

 

The log should be located at C:\Avenger.txt.

 

Quads 

Regular Visitor
tragic82
Posts: 9
Registered: ‎09-02-2009

Re: NIS 2009 disabled

Quads, you are a legend. Thanks very much for your all your help!
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: NIS 2009 disabled

Hi

 

No problem

 

All fixed

 

Quads