Saved Bookmarks
| 1. |
Solve : worms in my computer? |
|
Answer» Re-running ComboFix to remove infections:
SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your DESKTOP.
MZ? ÿÿ ? @ P º ?Í!?LÍ!This program cannot be run in DOS mode. The main body of this log was deleted by myself, Dave. It´s all Greek to me........ the SysProt ran fine ( I think) did I miss something? Quote MZ? ÿÿ ? @ P º ? Í!?LÍ!This program cannot be run in DOS mode. $ Did you follow the instructions? It states that you cannot run this in DOS mode. I did not run it in DOS, I am not nearly that smart, I ran it like I was instructed. Here is something I found on the desktop at the end of the day. # Archive C:\Documents and Settings\gne\Escritorio\SysProt.zip 2009-03-15 23:11 Folder Folder SysProt 2009-03-15 20:18 145408 139772 SysProt\SysProt.exe 2009-03-15 23:10 268146 214248 SysProt\SysProt_AntiRootkit_Help.pdf # # TOTAL Size Packed Files # 413554 354020 3 Ok. Let's just forget about this scanner and we'll TRY another. * Download the following TOOL: RootRepeal - Rootkit Detector * Direct download link is here: RootRepeal.zip * Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan. * Click this link to see a list of such programs and how to disable them. * Extract the program file to a new folder such as C:\RootRepeal * Run the program RootRepeal.exe and go to the REPORT tab and click on the Scan button. * Select ALL of the checkboxes and then click OK and it will start scanning your system. * If you have multiple drives you only need to check the C: drive or the one Windows is installed on. * When done, click on Save Report * Save it to the same location where you ran it from, such as C:RootRepeal * Save it as rootrepeal.txt * Then open that log and select all and copy/paste it BACK on your next reply please. * Close RootRepeal. |
|