joshdnelson Posted July 29, 2013 ID:708611 Share Posted July 29, 2013 I discovered a rootkit on my system a few days. I just this new system and had yet to set up anti-virus software. I ran several anti-rootkit programs. These included Malwarebytes Anti-Rootkit, Windows Malicious Software Removal Tool July 2013, Sophos Anti-Rootkit, Norton Power Eraser and GMER. All programs identified somewhat different entries and all were able to remove what they found except for Sophos. At this point Sophos is the only sweep that comes up with positive hits. I sent in a log and I received some analysis which I attached to this post along with the log that they recevied from me. To be more specific my current problem is that while Sophos recognizes the infected files, it is not able to remove them. Once the scan is finished it prompts a restart in order to complete the removal. Though when I reboot Sophos after the restart I receive another prompt saying that the same items were not removed and that Sophos requires another restart. I tried this several times, but also with the same result - another request for a reboot. Sorry if this post is a lengthy. Thank you for your time. Sophos analysis.txtsarscan.log Link to post Share on other sites More sharing options...
Firefox Posted July 29, 2013 ID:708613 Share Posted July 29, 2013 Hello and Welcome to Malwarebytes Being that you are probably infected, feel free to follow the instructions below to receive free, one-on-one expert assistance in checking your system and clearing out any infections and correcting any damage done by the malware. Please see the following pinned topic which has information on how to get help with this: Available Assistance for Possibly Infected Computers Thank you Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now