[Active] Rootkit Agent keeps coming back like a zombie

Status
Not open for further replies.

sonobang

Posts: 9   +0
I was researching this for last couple days..with limited internet cause my internet provider kept banning me.
I desperately need help!
 

Attachments

  • mbam-log-2010-08-07 (18-07-03).txt
    927 bytes · Views: 1
  • hijackthis.log
    8.9 KB · Views: 0
  • ComboFix.txt
    21.1 KB · Views: 0
phew..thanks..but how about the rootkit.agent?..what is it exactly doing to my laptop and how can I get rid of it?
 
I did what you told me to do. Hopefully I did everything right.
 

Attachments

  • gmer.log
    29.7 KB · Views: 2
  • DDS.txt
    22.2 KB · Views: 1
  • mbam-log-2010-08-07 (22-56-34).txt
    950 bytes · Views: 0
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:
    :file
    C:\pgddypoc.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
 
Thats ok. It belongs to Gmer. It creates a random file name when it runs.
How do things appear now? Are you still having problems?
 
well I was not really experiencing any problem, but according to my internet provider my laptop is continuously spamming through my internet. So they keep banning me whenever I use my internet..
 
Should be if MBA-M came up clean :).

Let's get rid of Combofix now that we are finished with it.
  • Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

    ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.

  • CF_cleanup.png
 
Status
Not open for further replies.
Back