can`t get rid of a nasty rootkit win32:Rootkin-gen and another virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by depechebambina, Dec 16, 2008.

  1. depechebambina

    depechebambina Private E-2

    Hi there, about two months ago i did my avast scan and it told me i had a few viruses, i just put them (or so i thought)in the virus chest.i have performed a few other scans, which always found other viruses, but i didn`t realize they were the same.my computer started playing up a while ago, from simple freezing, my screen going crazy and bleeping and last week after i started it i got a message "replacing bad clusters". the computer crashes or freezes quite frequently.after looking closer in the avast logs, i realized i had a rootkit - win32:Rootkit-Gen and also another virus called HTML:CUE-2004-1050 my avast can`t do anything about it, they can`t be moved to the virus chest or anything.i tend to browse a lot of academic sites as i am student and i thought getting such nasty virus wouldn`t really happed but i guess that`s just me being naive!:-o
    I did Read and Run first, also the Vista clean up and Combofix didn`t help either (thought i couldn`t do Vista recovery Environment before running it, Acer never gave me an installation CD thought i read somewhere in the forum in here that this is not a major problem).i have attached MGlog,Combofix log and avast log and will send the others in another thread.please help me because i am getting desperate!thanx a lot.slavka
     

    Attached Files:

  2. depechebambina

    depechebambina Private E-2

    hi guys, just attaching the other two logs.thanx :)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You ignored very important first instructions in the READ & RUN ME. You have Avast and Norton Internet Security installed. You must uninstall one of these immediately before you bother doing anything else on this PC.

    I also stronly recommend that you immediately cleanup your Desktop. Remove ALL executable files (except combofix.exe which we still need to be there) and leave only links. It is a bad Idea to keep saving and storing all of these downloads on your Desktop. It creates easy hiding places for malware, they could get easily deleted by malware which you may not want to happen, and it can slow your PC down because refreshes can cause rescanning by protection software.


    More than likely you have hardware problems or Windows problems. These are not malware problems.

    Give as a log from Avast so we can see exactly what is being found as your logs are clean.

    Actually you tend to use way too many P2P and Torrent downloading programs which are not safe. I'm surprised your school is not blocking your PC from even getting a connection into their network. I see all of the below:

    swapper
    BitTorrent_DNA
    bittorrent
    limewire
    Kontiki <-- not a torrent downloaded but it is a background downloader and is not recommended.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 5
    Spybot - Search & Destroy 1.5.2.20

    Then reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    "C:\Windows\Temp
    C:\Users\depechebambina\AppData\Local\Temp


    Now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 19, 2008
  4. depechebambina

    depechebambina Private E-2

    hi there, thanx for getting back to me and sorry it took me ages to reply back thought i am sure you are pretty busy!whilst i was waiting for you reply, out of desperation, i tried to deal with the rootkit.my avast couldn`t deal with it, and as bitdefender claimed that their program can be successful for removing rootkits, i installed bitdefender instead only to find out that that trojan renamed itself to Trojan.Qhost.AKR but remained stubbornly in my computer, in the same location (and bitdefender`s advice on how to get rid of was pretty useless).however, as you wanted a scan log from me i had to uninstall bitdefender (i found out later that this is one big disadtvantage with bitdefender, it doesn`t produce scan logs or reports)in order to give you a scan log, so i am back to avast again.anyways, a few things. i deleted temporary files as you asked me to, though i can`t access temporary internet files as it tells me my access is denied, not sure if this is important.

    i have attached MG tools file and also avast report.as you can see, avast shows 2 infected files.they can`t be moved to the chest as it always tells me that they are an archive file but it gives me an option to rename the files.i read somewhere that rootkits can be removed simply by renaming them, do you reckon it could work? also, i have used un-hack me a few times, it always finds 100% dangerous file (enethook.dll) though when it comes to removing it, it can`t be done as i get a message saying that the file doesn`t exist or it has been hiddent by a rootkit.not sure what to do.also, i enables user control, is that ok?
    i don`t really know what to do and how to get rid of the rootkit, do you think that my only option might be reinstalling windows?thanx again.slavka
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only infected file in your logs are the illegal crack/kegens you are downloading. Just delete them and stop downloading things like this. Also if you have installed any of these, uninstall them. You do not have any rootkits, you just have illegal kegens software. Examples, delete the below folders

    C:\Users\depechebambina\Documents\Downloads\BitDefender Pro Total Security 2008 (Antivirus & Antispyware) + Key

    C:\Users\depechebambina\Documents\Downloads\Microsoft Office 2003 + Serial.rar


    You still did not follow my previous instructions and still have multiple antivirus programs installed. This was one of the first instructions in the READ & RUN ME and was the first thing I asked you to do in my last message. If you want our help then you need to follow our instructions; otherwise we are finished.
     
  6. depechebambina

    depechebambina Private E-2

    You still did not follow my previous instructions and still have multiple antivirus programs installed. This was one of the first instructions in the READ & RUN ME and was the first thing I asked you to do in my last message. If you want our help then you need to follow our instructions; otherwise we are finished.[/QUOTE]

    hi again, sorry,please don`t gent angry with me.I tried to uninstall Norton Internet Security and I thought I did but this proved more difficult,as for whatever reason it stayed on my system, so tried to remove it again and it should be gone now.also, i uninstalled spyware terminator which i used to use for scanning the malware.so hopefully, now I have avast as the only antivirus program on my pc. thanx for the advice, i removed the suggested files (which i was scared to do before as i thought my computer would stop running).did a scan and it came clean, very happy.:) un-hack me keeps sending me a message that there is a Vanquish Rootkit there, but I trust your judgment since you viewed the logs and said that no rootkit is there.I appreciate your help, i hope everything will run normally now! (thought i backed up all my files just in case i have to reinstall for whatever reason).thanx again.:wave
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To be sure that all of Norton is gone, please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Where is it finding this? Attach a log that shows what and where.

    Did you delete the below? If not you need to do so to avoid further infections.
    C:\Users\depechebambina\Documents\Downloads\BitDefender Pro Total Security 2008 (Antivirus & Antispyware) + Key
    C:\Users\depechebambina\Documents\Downloads\Microsoft Office 2003 + Serial.rar



    Also do goto this link Using MGtools and download the new version of MGtools.exe using the black bold print link in the first sentence.



    Run MGtools.exe then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds