Plz NEED HELP with Win32/Rustock.gen!C I have no clue what to do

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by needhelpplzplzplz, May 17, 2007.

  1. needhelpplzplzplz

    needhelpplzplzplz Private E-2

    OK I need help with a Win32/Rustock.gen!C virus. The Microsoft Website told me to run their antivirus but it didnt help. This problem is very annoying and help would be appreciated.
    Thanks
     
  2. needhelpplzplzplz

    needhelpplzplzplz Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. needhelpplzplzplz

    needhelpplzplzplz Private E-2

    Here are the logs

    This one was called pelog
    ************************* Rustock.b-fix -- By ejvindh *************************
    Sat 05/19/2007 15:36:32.59

    ******************* Pre-run Status of system *******************

    Rootkit driver huy32 is found. Starting the unload-procedure....

    Rustock.b-ADS attached to the System32-folder:
    :huy32.sys 79094
    Total size: 79094 bytes.
    Attempting to remove ADS...
    system32: deleted 79094 bytes in 1 streams.

    Looking for Rustock.b-files in the System32-folder:
    No Rustock.b-files found in system32


    ******************* Post-run Status of system *******************

    Rustock.b-driver on the system: NONE!

    Rustock.b-ADS attached to the System32-folder:
    No System32-ADS found.

    Looking for Rustock.b-files in the System32-folder:
    No Rustock.b-files found in system32


    ******************************* End of Logfile ********************************


    Next one was called avenger
    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\elyagshj

    *******************

    Script file located at: \??\C:\Program Files\dowopass.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Driver huy32 unloaded successfully.
    Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.

    Completed script processing.

    *******************

    Finished! Terminate.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember to follow directions. No logs should be posted in line. They must always be attachments. If you don't know what this means, see HOW TO: Attach Items To Your Post which is referenced many times in our sticky threads which are supposed to be read before posting.

    Looks like you Rustock infection was found and removed. Are you having any other malware problems? If so, run the READ & RUN ME sticky procedure and attach the 6 requested logs.
     
  6. needhelpplzplzplz

    needhelpplzplzplz Private E-2

    Ok thanks and sorry about the post
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Since you did not answer my question, I'll just assume you are not having any other problems.

    It is time to do our final steps:
    1. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    2. After doing the above, you should work thru the below link:
     
  8. needhelpplzplzplz

    needhelpplzplzplz Private E-2

    Alright thanks for everything.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds