Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Rootkit, network attacks and malware (mebix, ishi/ishigo)


  • Please log in to reply

#1
arifzub

arifzub

    New Member

  • Member
  • Pip
  • 6 posts
Hi,

I have avast installed on my machine and am getting some rootkit warnings from it. I allowed avast to delete these a couple of times but rootkit notices still show up sometimes.

I also noticed some malware (mebix, ishi, svsh0st, antimalware doctor etc) and deleted the respective files from file system besides removing registry entries for these. mebix was somehow being added to startup programs lists even though the file being pointed there had been deleted, but now it seems to be gone.

I have run SuperAntiSpyware and Malwarebytes malware removal on the machine lately. Malwarebytes showed some stuff in quarantine but I decided to delete those.

Current situation (OTL log attached)
-----------------
1. I am continuously getting network shield messages of blocked connections ("Threat has been detected") to or from 95.143.193.138. Any idea what could be causing it ? Is that site attacking from outside or is the connection initiated by some malware on my machine ?

2. Rootkit problem hasn't occured today but not sure if it is completely gone.
3. Some site named ...ishigo... was being accessed from my machine. The connection was being initiated by explorer. I noticed this with fiddler http debugging proxy tool.

Please check logs and inform if there's still something fishy and suggest cures.

Thanks!
Arif

Attached Files

  • Attached File  OTL.Txt   72.62KB   47 downloads

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP