Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Rootkits
#1
Hi Britec and friends from Britec :

Nice meeting you.
In my XP PC , AVG register 44 Rootkits , were 36 until short , AVG can not fix them , Malwarebytes do not see them .
Britec said on one youtube , if you use TDSkiller do not delet , cure or skipe or you will loose the booting  , but in another youtube he said , delet. So I don't now and don't want to format. The summaty that I coppied from AVG is in the attachment.

I hope the hacker has not taken the other PC trough the network and I hope you can help me .

Huh
THX
Bea


Attached Files
.pdf   Summery.pdf (Size: 64.71 KB / Downloads: 2)
Reply

#2
Hey Bea, Welcome to the forum.

Step 1

[Image: tdsskiller-logo.png] Run TDSSKiller Scan

·         Please download [Image: tdsskiller-logo.png] TDSSKiller and save the file to your Desktop.

·         Right-Click [Image: tdsskiller-logo.png] TDSSKiller.exe and Run as administrator.

·         Click Change parameters. Place a checkmark next to Detect TDLFS file system.

·         Click Start Scan. please be patient and  Don't use computer while scan is running.

·         If infected files are found, please change the action to skip.

·         Click Continue and close TDSSKiller.

·         Look for log file in root directory that's c:\  please copy  contents of the log and paste it in your next post.


Step 2

[Image: aswMBR-icon.png] Run Scan with aswMBR


Please download [Image: aswMBR-icon.png] aswMBR and save it to your desktop.
Please temporary
disable your Anti-Virus and Anti-Malware software.

·         Right-click [Image: aswMBR-icon.png] aswMBR.exe and Run as Administrator.

·         Click Yes to Allow Virtualisation.

·         Click Yes to download the latest anti-virus definitions for aswMBR from avast.

·         Click Scan.

·         Once completion, you will see Scan finished successfully. Click Save log.

·         Please copy log and post on your next reply
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#3
Hi Britec :

I downloaded TDSS on another PC , will copy with flash , can't install on desktop ,onlt on a temp in C:\
Do I run it of line or on line ? Disconet the internet ?

At the end I will donate , but please give me a PayPall account , is all I have , I'm in the Netherlands.
THX
Bea
Reply

#4
(12-08-2014, 06:08 PM)Beatriz Alma Wrote:  Hi Britec :

I downloaded TDSS on another PC , will copy with flash , can't install on desktop ,onlt on a temp in C:\
Do I run it of line or on line ? Disconet the internet ?

At the end I will donate , but please give me a PayPall account , is all I have , I'm in the Netherlands.
THX
Bea

I would disconnect from the net (but it doesn't matter too much as its just a scan)
PayPal is one of the options offered.
Reply

#5
OK THX Britec and Guilty , I'll do the TDSS now , scary.
we'll do it with PayPall later.
Reply

#6
Don't forget to run aswMBR
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#7
(12-08-2014, 08:31 PM)Beatriz Alma Wrote:  OK THX Britec and Guilty , I'll do the TDSS now , scary.
we'll do it with PayPall later.
if aswMBR.exe doesn't work you can try dr web cure it which it can repair damage windows files and folders https://www.freedrweb.com/download+cureit/?nc=t&lng=en
Reply

#8
Hi Britec , nsm0220 & friends

I coppied TDSSkiller from flash to the infected PC , to temp in C:\ , dubble click there , clicket on Detect TDLFS file system. Not from the desktop , can't access it .
he found no serious threads only suspicious objects medium risk , ousb2hub and ousbehci . (I guess for signature )

Malwarebytes don't see the rootkids , only AVG , does , a friend told me that AVG internet security  is very sensitive and if I don't close well  the rubbish will be taken as rootkids . I don't know .
Don't dare to install aswMBR.exe because I'have to disconect AVG and Malwarebites , thats all protection I have now .

If you think I am still infected or the programs are fooling me , please help .
If you think I am clean , tommorrow I'll Paypall a gift for you .
And defititelly I'll post you on my FB and Youtube.


Thank you .
Greatings Bea


Attached Files
.pdf   Enemigo PiPO AVG RT.pdf (Size: 65.15 KB / Downloads: 0)
.jpg   AVG report.jpg (Size: 89.31 KB / Downloads: 8)
.jpg   AVG 17 thread.jpg (Size: 66.55 KB / Downloads: 9)
Reply

#9
Please follow instructions carefully, your not running all the programs I asked and your not posting logs from the scan results.

Step 1

[Image: aswMBR-icon.png] Run Scan with aswMBR


Please download [Image: aswMBR-icon.png] aswMBR and save it to your desktop.
Please temporary 
disable your Anti-Virus and Anti-Malware software.

·         Right-click [Image: aswMBR-icon.png] aswMBR.exe and Run as Administrator.

·         Click Yes to Allow Virtualisation.

·         Click Yes to download the latest anti-virus definitions for aswMBR from avast.

·         Click Scan.

·         Once completion, you will see Scan finished successfully. Click Save log.

·         Please copy log and post on your next reply

Step 2

[Image: antirootkit.png] Malwarebytes Anti-Rootkit (MBAR)

  • Please download Malwarebytes Anti-Rootkit and save the file to your desktop.
  • Double-click MBAR.exe to run the installer.
  • Select a convenient location to extract the contents and click OK.Navigate to the location you selected.
  • Double-click MBAR.exe to run the programme.
  • Follow the prompts to update the programme and scan your computer.
  • Upon completion, click Cleanup*and reboot your computer.
  • After the reboot, rerun the programme to verify no threats remain. If threats are still detected, click the Cleanup button once more.
  • Upon completion, two logs (mbar-log.txt and system-log.txt) will be created.*Copy the contents of both logs and paste in your next reply.
  • Note: Both logs can be found in the MBAR folder.

<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#10
Hi Britec :

you said: Please follow instructions carefully, your not running all the programs I asked and your not posting logs from the scan results.


Is because I am scared , don't know how to desable AVG and Malwarebytes . I'll ask my husband to desable them.

Is Malwarebytes antirootkit the same as Malwarebytes ? If so I have it sinds october 2014 .

The picture is what I have , if it the same ? Will I loose the  premium licensie if I dowload again ?

I'll try the aswMBR and mail you the result.

Thank you for your patiente .

Gr Bea .


Attached Files Thumbnail(s)
       
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

Powered By MyBB, © 2002-2024 Melroy van den Berg.