S sonobang Posts: 9 +0 Aug 7, 2010 #1 I was researching this for last couple days..with limited internet cause my internet provider kept banning me. I desperately need help! Attachments mbam-log-2010-08-07 (18-07-03).txt 927 bytes · Views: 1 hijackthis.log 8.9 KB · Views: 0 ComboFix.txt 21.1 KB · Views: 0
I was researching this for last couple days..with limited internet cause my internet provider kept banning me. I desperately need help!
C crunchie Posts: 728 +0 Aug 7, 2010 #2 Hi and welcome to TechSpot . Combofix should not be run without direction, as it is not meant as an everyday scanner. It is a powerful tool that can render your pc useless . == Please follow the directions given here https://www.techspot.com/community/...lware-removal-preliminary-instructions.58138/ and post the requested logs.
Hi and welcome to TechSpot . Combofix should not be run without direction, as it is not meant as an everyday scanner. It is a powerful tool that can render your pc useless . == Please follow the directions given here https://www.techspot.com/community/...lware-removal-preliminary-instructions.58138/ and post the requested logs.
C crunchie Posts: 728 +0 Aug 7, 2010 #4 If it is still running now, it will be fine . I was just letting you know for future reference.
S sonobang Posts: 9 +0 Aug 7, 2010 #5 phew..thanks..but how about the rootkit.agent?..what is it exactly doing to my laptop and how can I get rid of it?
phew..thanks..but how about the rootkit.agent?..what is it exactly doing to my laptop and how can I get rid of it?
S sonobang Posts: 9 +0 Aug 8, 2010 #7 I did what you told me to do. Hopefully I did everything right. Attachments gmer.log 29.7 KB · Views: 2 DDS.txt 22.2 KB · Views: 1 mbam-log-2010-08-07 (22-56-34).txt 950 bytes · Views: 0
C crunchie Posts: 728 +0 Aug 8, 2010 #9 Please go to Jotti's or to virustotal and have this file scanned. Post the results back here. C:\pgddypoc.sys
Please go to Jotti's or to virustotal and have this file scanned. Post the results back here. C:\pgddypoc.sys
C crunchie Posts: 728 +0 Aug 8, 2010 #11 Please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2 Double-click SystemLook.exe to run it. Copy the content of the following codebox into the main textfield: Code: :file C:\pgddypoc.sys Click the Look button to start the scan. When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. Note: The log can also be found on your Desktop entitled SystemLook.txt
Please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2 Double-click SystemLook.exe to run it. Copy the content of the following codebox into the main textfield: Code: :file C:\pgddypoc.sys Click the Look button to start the scan. When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. Note: The log can also be found on your Desktop entitled SystemLook.txt
C crunchie Posts: 728 +0 Aug 8, 2010 #13 Thats ok. It belongs to Gmer. It creates a random file name when it runs. How do things appear now? Are you still having problems?
Thats ok. It belongs to Gmer. It creates a random file name when it runs. How do things appear now? Are you still having problems?
S sonobang Posts: 9 +0 Aug 8, 2010 #14 well I was not really experiencing any problem, but according to my internet provider my laptop is continuously spamming through my internet. So they keep banning me whenever I use my internet..
well I was not really experiencing any problem, but according to my internet provider my laptop is continuously spamming through my internet. So they keep banning me whenever I use my internet..
S sonobang Posts: 9 +0 Aug 8, 2010 #15 ooo I just ran my malwarebytes and the rootkit.agent is finally gone! am I good to go now?
C crunchie Posts: 728 +0 Aug 8, 2010 #16 Should be if MBA-M came up clean . Let's get rid of Combofix now that we are finished with it. Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.
Should be if MBA-M came up clean . Let's get rid of Combofix now that we are finished with it. Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.