Win32:Rootkit-gen. In driver not file.

Discussion in 'Malware Help (A Specialist Will Reply)' started by samir1010, Jan 18, 2010.

  1. samir1010

    samir1010 Private E-2

    All right, here we go. About a week ago I started having problems with Firefox, every time I tried to open it I got a message that it was already open. So, I figured I had a small bug or something. I ran avast and got a message that there was a virus located at:

    C:/windows/system32/drivers/8463b4.sys

    I tried to move to chest and delete numerous times but had no luck. Uninstalled avast and loaded up and ran another virus scanner. Same problem, it was found but not able to fix or delete or move to chest. Researched online for 4 days and tried everything I could but am completely stuck.

    Problems Im having:
    System running extremely slow and lags. When I type, most of the time it just takes forever to type a single word. Also having trouble with all browsers. Will route only after shutting down from task manager after initial launch.

    What I've tried:
    I ran the read me first post and went through each procedure step by step. I found that the avast scanner popped up during Super Anti Spyware and MBAM and gave me the same virus warning with the win32:rootkit-gen at the exact location as above. Still couldn't move to chest or delete.

    What was interesting was when I ran the rootrepeal nothing showed up in the file scan but during the drivers scan the first file which is the same as above showed "hidden from API". So I am assuming that this is where the virus resides. Any help would be appreciated. I am attaching all logs to this and the next post.

    Thanks in advance for any help as I am totally at my wits end and have no idea what else to do. :cry
     

    Attached Files:

  2. samir1010

    samir1010 Private E-2

    Here are the rootrepeal logs.
     

    Attached Files:

  3. samir1010

    samir1010 Private E-2

    Well, just an update I ran a bunch of different anti-rootkit programs and only 1 of them caught it, radix. It said that the file is deleted but still shows up when i do a scan but the file cannot be deleted again. Says that the file is inoperable. System seems to be working better now but still don't know if its a 100%.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me the exact path to the radix file that was reported.

    I am not sure about this file either ( 8463b4.sys ) but let's rename the file and see if you run into problems, so:
    Use windows explorer to find and rename:
    C:/windows/system32/drivers/8463b4.sys ---> C:/windows/system32/drivers/8463b4.sys.old

    Reboot and tell me what issues you have as well as the path to the other file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds