Jump to content

Malwarebytes

XRT_ malware


8 replies to this topic

#1
StudioT

    New Member

  • Members
  • Pip
  • 23 posts
  • Location:SomersetUK
Hello, new to Malwarebytes and this forum.

Have been testing a (paid for) copy of MB on a pc with no problems for last couple of months.

In last 2 days have had XRT_rmib.exe (45k) in lodged limited user account.

MB scans do not reveal this or several registry entries in Internet Explorer keys.

have found two references

http://forums.active...php?t-7744.html

and

http://www.awportals...ticle.php?a=215

#2
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 5,524 posts
  • Gender:Male
  • Location:Fortville, IN
Chances are, someone is going to want to see a HijackThis log, so you might want to go ahead and post one.

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...

#3
JeanInMontana

    Delete this account!!

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,867 posts
  • Interests:would love to see some honesty around this site.
Yes you should probably follow the instructions here and start your own topic in that forum.

#4
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Please also submit the files of the infection to http://uploads.malwarebytes.org
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#5
StudioT

    New Member

  • Members
  • Pip
  • 23 posts
  • Location:SomersetUK
Still getting the hang of this forum.

Yes I can upload the file. I can see the upload page, but cant see anywhere to add notes.

Renaming the beast seems to neutralise it, but I would change the extension to .txt for safety.

I will try to find the registry keys again, but have already deleted the offenders, wothout noting the entries, sorry.

Unless someone really wants to look at a HJ log I don't feel the need to obtain one.

#6
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male

Quote

Yes I can upload the file. I can see the upload page, but cant see anywhere to add notes.

Feel free to upload a zip file with a text document describing the malware.

Quote

Renaming the beast seems to neutralise it, but I would change the extension to .txt for safety.

Please keep the extension intact and just upload it zipped up.

Quote

Unless someone really wants to look at a HJ log I don't feel the need to obtain one.

This is to make sure everything was removed correctly. I would recommend you post one.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#7
StudioT

    New Member

  • Members
  • Pip
  • 23 posts
  • Location:SomersetUK
Zip uploaded as requested.

#8
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
My next update will address this .

Thanks for the sample .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
StudioT

    New Member

  • Members
  • Pip
  • 23 posts
  • Location:SomersetUK
Glad to help.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us