Jump to content

Davexxx

Honorary Members
  • Posts

    32
  • Joined

  • Last visited

Posts posted by Davexxx

  1. 1) Error message post-boot:

     

    RegSvr32
    The module "C:\ProgramData\GoluKfid\OatboSratl.fox" failed to load.
    Make sure the binary is stored at the specified path or debug it to check for problems with the binary or dependent .DLL files.
    The specified module could not be found.

     

    2) Start-up includes:

     

    Yes    HKCU:Run    GoluKfid    Microsoft Corporation    regsvr32.exe "C:\ProgramData\GoluKfid\OatboSratl.fox"

     

    No trace of OatboSratl.fox apart from the two quarantine copies.

     

    Dave.

  2. Malwarebytes Anti-Rootkit: "An error has occurred: Scan failed!" on two attempts (updated successfully) ...

     

    1) Malwarebytes Anti-Rootkit - "Registry Value "AppInit_Dlls" has been found ... Press 'no' button if not sure [selected] ... if tool crashes ... restart and press "yes" ...'

    "This version of Malwarebytes Anti-Rootkit requires ... to completely exit ... [OK selected] - "An error has occurred: Scan failed!" and exit

    2) Launched mbar.exe - "Registry Value "AppInit_Dlls" has been found ... Press 'no' button if not sure ... if tool crashes ... restart and press "yes" [selected] ...'

    "This version of Malwarebytes Anti-Rootkit requires ... to completely exit ..." [OK selected] - "An error has occurred: Scan failed!" and exit
     

    So FRST scan not undertaken.

     

    Dave.

  3. Virustotal reports:

    File name: OatboSratl.fox
    Detection ratio: 5 / 57

    Kaspersky - UDS:DangerousObject.Multi.Generic - 20150213  
    Avira - TR/Crypt.ZPACK.Gen8 - 20150213  
    AVG - Inject2.BOTR - 20150213  
    Bkav - HW32.Packed.C45E - 20150213  
    ESET-NOD32 - a variant of Win32/Kryptik.CYGW - 20150213  
     

    https://www.virustotal.com/en/file/8eb1d073516485ee9e0d079f7e33c17e7d63c68f2eadeb1c8b3138b1867fc21e/analysis/1423861508/

     

    Dave.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.