Soemthing unusual......!!!

Discussion in 'Software Q&A' started by pr.itdude, Oct 21, 2009.

Thread Status:
Not open for further replies.
  1. pr.itdude

    pr.itdude tHe nEw gEEk......ITian

    Joined:
    Oct 25, 2008
    Messages:
    357
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    New Delhi
    Hi guyz.....
    coming straight to the point, recently my pc got infected by a malware which is detected by KIS and Avast, named synsenddrv.sys and loc is : C:\WINDOWS\system32\Drivers\synsenddrv.sys
    type:Rootkit.Win32.Small.bk

    Although detection, KIS is unable to delete or disinfect it.....i even tried Avast's boot scan.....but of no use !!!

    Every time at startup, KIS prompt for this and i have to disinfect it each time (thrice).....its annoying me now :x

    I think this malware comes with some update of drivers, (as it prompts to load some hidden drivers or so)....but i didn't updated anything...!!

    Guyz help me out as this might be infecting my downloading speed......!!!
     
  2. OP
    OP
    pr.itdude

    pr.itdude tHe nEw gEEk......ITian

    Joined:
    Oct 25, 2008
    Messages:
    357
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    New Delhi
    *bump*
    are yaar koi to kuchh help karo........!!!!
     
  3. Krow

    Krow Crowman

    Joined:
    Mar 6, 2008
    Messages:
    4,330
    Likes Received:
    9
    Trophy Points:
    0
    Location:
    New Delhi
    In all my experience I have found that formatting is the best solution to disinfection. That being said, try Trojan Remover or Spybot S&D or MalwareBytes anti malware and check if something works on the abomination.
     
  4. rhitwick

    rhitwick Democracy is a myth

    Joined:
    Apr 20, 2004
    Messages:
    2,862
    Likes Received:
    47
    Trophy Points:
    48
    Location:
    Kolkata
    If u know the path of the infected file, try deleting it manually.
    Try from safe mode ans scan again.

    I would like to ask u, scan with Remove IT Pro (latest version, free for personal use)
     
  5. Gauravs90

    Gauravs90 geek........

    Joined:
    Sep 24, 2008
    Messages:
    748
    Likes Received:
    7
    Trophy Points:
    18
    Location:
    Thane, India
    guys its rootkit, you can not delete a simple file and get rid of this. what you can do is dowload better trial version av's panda or norton and try to remove if they fails you have to format.
     
  6. RaghuKL

    RaghuKL Swalpa Adjust Maadi

    Joined:
    Sep 14, 2006
    Messages:
    179
    Likes Received:
    0
    Trophy Points:
    16
  7. OP
    OP
    pr.itdude

    pr.itdude tHe nEw gEEk......ITian

    Joined:
    Oct 25, 2008
    Messages:
    357
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    New Delhi
    Problem resolved......!!!

    I had already deleted it manually.....then also the same problem occurred !!!
    Finally i did a complete scan and found some other rootkits n trojans......!!!
    huh.....now its again to good !!!

    Thnx mate 4 ur quick suggestions !!!
     
  8. ramprasad

    ramprasad New Member

    Joined:
    May 7, 2004
    Messages:
    375
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    00-1D-7D-5A-34-2E
    Boot into the system using a LIVE Linux CD (any variant) and try to remove the file
    Just a thought..
    Hope it is worth a try
     
  9. Krow

    Krow Crowman

    Joined:
    Mar 6, 2008
    Messages:
    4,330
    Likes Received:
    9
    Trophy Points:
    0
    Location:
    New Delhi
    Yes, Raghu, Prevx is indeed a good scanner. Its new, so not many people have heard of it. @ pr.itdude Which app did you use to scan?
     
  10. Gauravs90

    Gauravs90 geek........

    Joined:
    Sep 24, 2008
    Messages:
    748
    Likes Received:
    7
    Trophy Points:
    18
    Location:
    Thane, India
    yes prevx is good scanner. It uses in the cloud and behavior based technology. u need to be connected with internet to use its scanner.
     
Thread Status:
Not open for further replies.

Share This Page