Jump to content

Malware.RPL.gen.bot infection


Recommended Posts

I am infected by Malware.RPL.gen.bot.   It has disabled Malwarebytes scans so now Malwarebytes skips groups of files and and finishes in 35 seconds. Finds nothing.   Am running windows 10 home on a I5 thinkpad with Kaspersky internet security.  Have run, quickheal, Rkill, TDS killer, Malwarebyes, 9 Labs, superantispyware, Hitman Pro and Zemema.  This malware disables a full reset in Window 10 including complete removal of files so I used the full factory reinstall disks, did a secure erase of the SSD, reinstalled everything and it's back.   The real scary part is it has modified Malwarebytes and 9-labs to skip whole sections of files.  It came from a driveby download of a senior housing website I was looking at three weeks ago. I saw a very small window open on one of my screens and 10 files downloaded in 3 seconds and the screen closed.  I have deleted all extensions in Chrome, deleted all cookies in Chrome settings, reset the router.  It also killed two Windows XP machines on the home network, disabled all exe files.  And infected a second Windows 10 laptop that I will also factory reinstall and secure erase.

Addition_18-03-2017 10.27.21.txt

FRST_18-03-2017 10.27.21.txt

Shortcut_18-03-2017 10.27.21.txt

Link to post
Share on other sites

Update,   Have gotten Malwarebytes Premium to reinstall and stop skipping files, ran MB Chameleon because Malwarebytes Version 3 Premium would not install, only version 2.  Then it installed but Exploit would only show starting and also Ransom ware protection has been intermittent on startup.   So reinstalled again, released a 64 bit driver that was hung up using FBAR fix feature, now appears OK for the moment.  Scans are clean although 9-labs keeps changing the amount signatures from a million plus down to 800 thousand on a repeat scan.  Don't think this is over by any means yet.   

Link to post
Share on other sites

Now morphed into Malware.MPL.Heur.se.       Shuts off Malwarebytes web protection.   Have removed now twice with 9-labs, keeps coming back.   Also modified MB Chameleon service to become a rootkit per GMER.   I have been at this for over a week now.  Anybody got any solutions please?

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.