Adlice forum

Software feedback => RogueKiller => Topic started by: BrewIT on March 11, 2015, 04:52:18 PM

Title: Unsure of results in report
Post by: BrewIT on March 11, 2015, 04:52:18 PM
I'd like some advice what to do with these findings. Most look like system files to me in the processes but states known malware.
Please see attached report

Thank you
Bob
Title: Re: Unsure of results in report
Post by: Curson on March 11, 2015, 11:19:38 PM
Hi BrewIT,

Welcome to Adlice.com Forum.

The [Proc.Injected] detection could be triggered by two things : 
To determine what's going on, and possibly whitelist the cases where it's a legit injection, please do the following :

1. Process Dump
We will analyse what is really injected, and whitelist if needed.

2. MBR Dump

The MBR on your computer seems nonstandard.
Unknown MBRs are dumped into %programdata%/RogueKiller/debug/.

Please locate this folder and attach it on your next post (you need to zip it first).

3. TDSSKiller
Please post the contents of TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically C:\) in your next reply.

Regards.
Title: Re: Unsure of results in report
Post by: BrewIT on March 12, 2015, 02:31:25 PM
Curson
Thank you for your prompt response. The PC is located at a remote site so I will follow your instructions when I return to that site in a few days. I suspect they are Symantec AV protecting the system as you speculate.

Regards
Bob
Title: Re: Unsure of results in report
Post by: Curson on March 12, 2015, 04:43:07 PM
Hi Bob,

You are welcome.
The analysis of the dump will bring confirmation.

Regards.
Title: Re: Unsure of results in report
Post by: BrewIT on March 27, 2015, 10:04:01 PM
Hello again
Finally back at the remote site again.

SMSS link is https://drive.google.com/file/d/0B4BNZnNZ0SnvTm85c1VkdlVLdUk/view?pli=1

I've attached the MBR debug file but message is too big so attaching in separate post

TDSSKiller results are too big to attach. I have them zipped if I can share them with you or I'll try to attach in another post. FYI nothing was found.

Thank again for your assistance!
Have a great weekend
Bob
Title: Re: Unsure of results in report
Post by: BrewIT on March 27, 2015, 10:06:15 PM
TDSSKiller results in attachment

Bob

Title: Re: Unsure of results in report
Post by: Curson on March 31, 2015, 09:52:43 PM
Hi Bob,

Could you pleae download RogueKiller latest version and try to run the scan again ?
Numerous false positives have been fixed since V10.5.3.0.

Regards.
Title: Re: Unsure of results in report
Post by: BrewIT on March 31, 2015, 10:15:50 PM
Curson
I just did run the latest version prior to your reply. I had already uninstalled and reinstalled Symantec Enterprise Protection before hand and most of the previously found items were no longer there.
Any more problems and I'm rebuilding the machine. Too many users have had their hands in the pie at this point to keep mucking with it.  :P

Thank you for your trouble and diligence!

Bob
Title: Re: Unsure of results in report
Post by: Curson on April 01, 2015, 12:20:40 AM
Hi Bob,

You are very welcome.  :)

Regards.