BlackLight has found at least one hidden rootkit though it is possible there are/were two.
11/27/07 22:44:43 [Info]: Hidden file: c:\WINDOWS\SYSTEM32\DRIVERS\runtime2.sys
11/27/07 22:44:43 [Info]: Hidden file: c:\WINDOWS\SYSTEM32\DRIVERS\runtime2.sy_
Now it looks as though combofix has removed at least one of these...
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\drivers\runtime2.sys
What I would like you to do is run BlackLight again to make sure that item is gone and see if the other listings remain. Let's not worry about those 2 hidden C:\Program Files\Internet Explorer\iexplore.exe and
Hidden process: C:\Program Files\Internet Explorer\IEXPLORE.EXE for the moment.
Post the log here.
I also would like to see a new Kaspersky scan too.


Reply With Quote