Backdoor.Trojan

Hi

 

What are  "please analyse the results as I think there are still some problems. Thanks"   The problems are???

 

The Script only disables, removes and deletes the main rootkit files,  You will probably have to reinstall Malwarebytes and update the Definitions  the run a Full Scan of both it and Norton for detected any other files, like .tmp files.

 

Your files removed in that log

 


Hidden driver "gxvxcserv.sys" found!

ImagePath:  \systemroot\system32\drivers\gxvxcwcorbswuncunpcjblpdonpfagxrpuqdp.sys

Start Type:  4 (Disabled) 

Driver "gxvxcserv.sys" disabled successfully.

 

File "D:\Autorun.inf" deleted successfully.

 

File "C:\WINDOWS\system32\gxvxccounter" deleted successfully.

 

File "C:\WINDOWS\System32\drivers\gxvxcwcorbswuncunpcjblpdonpfagxrpuqdp.sys" deleted successfully

 

Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gxvxcserv.sys" deleted successfully

 

Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\gxvxc" deleted successfully.



You do have more ControlSet0**  (**= number)  entries for it but the  likes of Malwarebytes, SuperAntispyware etc should be able to remove the left overs.

 

Quads 

Hi

 

I have noticed I missed the .dll file so I didn't script it in,  Scanners should pick up on it now as the Infection should be inactive

 

It was way over on the right hand side of your log.

 

I have though placed it in the script now.

 

Quads