Results 1 to 3 of 3

Thread: Spyeye Rootkit is alive but AV refuses to detect it

  1. #1
    Network Hub
    Join Date
    Jun 2011
    Posts
    481

    Spyeye Rootkit is alive but AV refuses to detect it

    Edit: Seems to be sorted now, typically I only thought up a solution after posting.

    As of yesterday, Avast has been complaining pretty regularly that C:\jau38uj.bin\50BE4DF0031.exe is attempting to connect to a dodgy url (I'll avoid posting it for obvious safety reasons!). A bit of google-fu shows that this behaviour is linked to the Spyeye rootkit, which probably sneaked in via a bad google result I came across yesterday.

    The problem is that, whilst Avast is seemingly preventing it from actually doing anything, it's also not actually detecting it. I ran a full scan last night and nothing came up, so I installed Ad-Aware and gave that a run, but again got nothing detected. The folder it's in is obviously sneakily hidden, and whilst the command prompt admits it exists when I try and use "del", it fails silently.

    Thoughts on getting rid of it? If nothing else, it's annoying having Avast pop up every 5 minutes.
    Last edited by Danny252; 10-04-2012 at 03:43 PM.

  2. #2
    Network Hub SMiD's Avatar
    Join Date
    Jun 2011
    Location
    Langhorne, PA, USA! USA! USA!
    Posts
    356
    Malwarebytes. Get to it.
    2013 Great Game Challenge Completion: 131/171 - 76.61%

  3. #3
    Network Hub
    Join Date
    Jun 2011
    Posts
    481
    I knew I'd forgotten the obvious second program to try (which, to even further my foolishness, is already installed).

    I think I managed to kick it out manually by booting into safe mode and deleting it from there - will give Malwarebytes a go as well, naturally.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •