R
Ron Reaugh
Jim Byrd said:Hi Ron - No, if you've already let A2 clean things (except c:\null?), then
that's OK, although I'd at least run it again and be sure it's still clean
in Safe or Clean Boot, then again after a normal boot (if you didn't already
do this). These things can often re-infect themselves.
As to rootkitresponder - it would be good IMO to increase your confidence
that this (a rootkit) hasn't happened, given the atypical circumstances of
your infection. But of course running this and using the HiJackThis
approach are entirely your choice. Those were just my recommendations,
since in my experience multiple tools can give more complete confidence in a
clean system, particularly when starting from an unknown infection point.
(For well know infections there often exist specific tools which are very
efficient in clean up that specifc malware.)
I understand completely and agree with your thinking....BILLY PLEASE SAVE US
AGAIN.
http://www.majorgeeks.com/downloadg...86d536d57b5f65b6e40c55365e;act=ST;f=27;t=6949Ron Reaugh said:Jim Byrd said:OK, Ron - If you got that from A2 then I would believe a real
infection which, when you're ready, you can have A2 try and clean.
Well I thought it was already cleaned...well. It wanted to delete
c:\null but I said no for now. I did let it delete all the other
stuff. Is there some whole other step that I'm missing? I will say
that after the A2 run and deletions that something is
different....BETTER. Does it do more than advertised?
I would recommend
two additional steps at this point if you wish to continue to
investigate.
OH SHIT, you're trying to send me on a whole new career path. I was
pleased as punch when Gates saved the world from NetRoom and Stacker
hell....I did that career path fully. Please Billy save us all and
start including a robust equivalent set of tools/fixes in SP3 or
maybe that new service that's coming! This is going out of control.
How can the average PC user hope to survive? Billy needs to save em
all again. In the mean time the Geek Squad can't hope to handle such
so they'll just have to keep payin folks like me $100/hr. to keep
there PCs running. Most don't. Most don't keep running....they just
buy a new PC.....I wonder if mikey is financing the malware
industry said:First, download and run Mark Russinovich's rootkitrevealer from
www.sysinternals.com.
I DON'T WANNA! But the I really didn't wanna screw with A2 either
and look what happened. I have fastidiously avoided HiJackThis for
several years now. I don't wanna go here. I want something to just
handle it all...damnit.
Then, I would also download and run HiJackThis and post your results
to one of the forums. There are experts there who can help you
considerably with this:
Download HijackThis, free, here:
http://209.133.47.200/~merijn/files/HijackThis.exe (Always download
a new fresh copy of HijackThis [and CWShredder also] - It's UPDATED
frequently.)
You may also get it here if that link is blocked: