09-05-2009 06:55 PM
Ok
Please run Malwarebytes again and see if the registry entry appears again even after removal the first time.
Quads
09-06-2009 06:23 AM - edited 09-06-2009 07:01 AM
the registry entry has reappeared, showing the same rootkit
EDIT: tried deleting the entry again, this time the computer rebooted and corrected several files during setup (this did not happen the first time I tried removing the entry). Currently running another Malware scan, will post results when the scan finishes.
Thanks for your help so far
09-06-2009 08:47 AM
09-06-2009 12:28 PM
Step 3. Registry
If you have Spybot S&D installed remove it "AND disable Norton Auto-Protect" As Norton now detects part of Avenger
Also during the restarts with Avenger if Your PC has a Startup repair center like with HP and Toshiba tell it to start Normally if it kicks in.
1. Download Avenger to your desktop,
Unzipped version http://homepages.slingshot.co.nz/~crutches/Avenger
OR Creators website http://swandog46.geekstogo.com/avenger2/avenger2.h
2. Click to run "Avenger.exe" (right click "Run as Administrator" if using Vista)
3. In the "Input script here:" copy and paste the script between the lines
Drivers to disable:
rotscxrnkomudj
Drivers to delete:
rotscxrnkomudj
Files to delete:
C:\WINDOWS\system32\drivers\rotscxkdulrscp.sys
Registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\rotscxrnkomudj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\rotscxrnkomudj
Here is a screenshot (script updated since shot)
Make sure the "Automatically disable any rootkits found" is NOT selected
4. Click "Execute"
You will be asked to restart the PC click "Yes", when the PC restarts the load screen will takes slightly longer, then when it looks as though windows is loading the PC will restart again.
Then when Windows fully loads the Avenger log will be loaded, showing files it could or could not find.
Quads
09-06-2009 02:20 PM
09-06-2009 04:47 PM
Hi
I would say Avenger got it and any backup entry
The log should be located at C:\Avenger.txt.
Quads
09-07-2009 12:47 AM
09-07-2009 12:49 AM
Hi
No problem
All fixed
Quads
