rdriv.sys problem !!! Pls help me !!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by kenboiboi, Jun 10, 2006.

  1. kenboiboi

    kenboiboi Private E-2

    Greetings to all...

    Im getting irritated by this pest. My Mcafee keeps popping up c:\windows\system32\rdriv.sys was infected by the NTRootKit-J trojan and has been deleted to complete the Clean process message.

    I have tried many types of scans in safe mode, including Mcafee VScan, Ad-aware, Stinger AVERT, etc, but to no avail.

    I have even tried in safe mode to delete the file manually and delete the "rdriv" service but to no avail too...

    Pls analyze my HJT log file to see what is the problem...and list the steps for me to remove....

    thank you so much
     

    Attached Files:

  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Some research turns up that System Restore could be the culprit. Please disable it, then do your scans. Not going to go much further until you scan from safe mode again with restore off, otherwise anything I have you remove might be fixed on a scan.

    Let me know
     
  3. kenboiboi

    kenboiboi Private E-2

    Hi Maj Att,

    Yea i just did it doesnt work. I offed system restore and got into safe mode. Virus scan did detect the file rdriv.sys again and deleted it but once i got back to normal boot, the same problem is still there. Mcafee is still reporting the NTRootKit-J msg.

    Seems like there is some program that keeps spawning the rdriv.sys file but not sure which is the one....

    any advice from anyone looking at the HJT log file???
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file here.

    Then please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  5. kenboiboi

    kenboiboi Private E-2

    Hi Chaslang,

    I did everything you told me. Well, spybot,bitdefender and panda scan did get something. I have saved the results and will attach the findings.

    After a gruelling afternoon of scans. Everything seems okie. There wasnt any Mcafee msg pop-ups. But i cant be sure. As sometimes this trojans will go dormant for a while. So i have done my HJT log file in normal mode after all the scans.

    Pls assess the files and advise if there is anything else that needs to be done in order to 100% remove the pest.

    THank you.
     

    Attached Files:

  6. kenboiboi

    kenboiboi Private E-2

    Chaslang,

    The Blacklight Log and spybot results are here. Pls view

    Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows Update Manager ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    WUM

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot locate the below files using Windows Explorer and delete them if found.
    C:\WINDOWS\winfire.exe
    C:\Documents and Settings\Kenny\Desktop\tsc\backup\T\60611000.DAT

    Now attach a new HJT log and tell me how things are working.
     
  8. kenboiboi

    kenboiboi Private E-2

    Hi Chaslang,

    THink everything for me has been solved. Thanks for the advice.

    The only think i cant find is the winfire.exe file... seems to be hidden or already delete.

    well here is my new HJT log.

    thanks again
    kenny
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log is clean!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds