PDA

View Full Version : online scanner misses infection found by v4.2.64.12


Mister Natural
November 10th, 2010, 02:02 PM
I was given a laptop to work on and had a hard time getting any type of anti-malware to run on the system. Anything I tried would start to run, then stop, then give access denied errors when trying to re-run.

I tried the eset online scanner and it was the only thing that would run, but found nothing. So I pulled the hard drive and scanned it from another pc running 4.2.64.12. cngaudit.dll was detected as infected and removed. Malwarebytes reported it as trojan.sirefef. Even after all that I still couldn't prevent it from coming back. I wound up re-partitioning, format and re-installed the OS.

Just thought I'd pass along.

Marcos
November 10th, 2010, 02:53 PM
That sounds like a rootkit being normally active but inactive when the system booted from a clean drive.

Mister Natural
November 10th, 2010, 03:57 PM
Yep that's what I figured too. As much as I like playing around trying to fix something like this, eventually I have to move on and stop wasting time with it.