-
Spoke too soon. Somehow the shortcut changed from opening the .exe to opening the .scr. Spybot still won't open when I click the resident tray icon.
-
Hello,
yes, please feel free to send the cab to this adress so we can have a look on it
Best regards,
Markus
-
RootAlyzer .cab file
Hello Markus,
I have done the deep scan using the RootAlyzer.
I am not able to attach the .can file
Please find below the contect of the can file.
// info: Rootkit removal help file
// copyright: (c) 2008 Safer Networking Ltd. All rights reserved.
:: RootAlyzer Results
File:"Invisible to Win32","C:\Documents and Settings\gigig\Start Menu\Programs\Startup\majjljip.exe"
File:"Invisible to Win32","C:\Documents and Settings\gigig\Local Settings\Application Data\etrwbgcc\majjljip.exe"
File:"No admin in ACL","C:\Documents and Settings\All Users\Application Data\36A9432208.sys"
File:"No admin in ACL","C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys"
Directory:"Invisible to Win32","C:\Documents and Settings\gigig\Local Settings\Application Data\etrwbgcc"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\","NOS"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\NOS\","{459E93B6-150E-45d5-8D4B-45C66FC035FE}"
Looking forward to hear from you.
Thanks and regards
Gigi
-
Hello,
You seem to be infected:
C:\Documents and Settings\gigig\Start Menu\Programs\Startup\majjljip.exe
C:\Documents and Settings\gigig\Local Settings\Application Data\etrwbgcc\majjljip.exe
Please follow the procedure in this link: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)
Start your own thread in the Malware Removal Forum where a helper will advise you as soon as available.
Best regards
Sandra
Team Spybot
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules