Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« on: August 31, 2009, 10:46:57 PM » |
|
I downloaded Rootkitrevealer today from Here, Because I wanted to make sure that there are no rootkits on my computer, because of This, and it showed quiet a lot of stuff. I've attached a screen shot. I checked my virus vault, It showed this. PUP Potentially harmful Hack Tool BVP C:\System Volume Information\-restore{8718f503-489f-8c04-133208dd68ce}\a0000156.exeI don't know what to do! I don't have any softwares left, and if I try to download anything it crashes half way most of the time, it's so frustrating!!!Please help me! I've already reformatted this computer twice in 2 days! But I'm ready to reformat the computer again! but I'm afraid by now it's too late cause I've logged in into all my accounts already..(I used On-Screen keyboard for passwords though for the time being). Please help. Thank you. [attachment deleted by admin]
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #1 on: August 31, 2009, 11:07:51 PM » |
|
Succeeded in downloading HJT.
I have attached a log file.
[attachment deleted by admin]
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
Karnac
Thanked: 211 Posts: 1,987
|
 |
« Reply #2 on: August 31, 2009, 11:28:31 PM » |
|
Hi Ivy, Follow this link.. http://www.computerhope.com/cgi-bin/process.pl?o=31222613Follow the cleaning instructions, and run an MBAm scan afterwards.
|
 Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #3 on: August 31, 2009, 11:41:39 PM » |
|
Actually I did that already, it's says I gotta delete some files, I thought you guys might not want me to delete them without consulting you first.
So shall I go ahead and remove those files?
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #4 on: August 31, 2009, 11:52:59 PM » |
|
Also I have downloaded RootKitBuster that Patio mentioned in one of his posts, It showed no hidden files.
+---------------------------------------------------- | Trend Micro RootkitBuster | Module version: 2.52.0.1013 +----------------------------------------------------
--== Dump Hidden MBR and Hidden File on C:\ ==-- No hidden files found.
--== Dump Hidden Registry Value on HKLM ==-- No hidden registry entries found.
--== Dump Hidden Process ==-- No hidden processes found.
--== Dump Hidden Driver ==-- No hidden drivers found.
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
Karnac
Thanked: 211 Posts: 1,987
|
 |
« Reply #5 on: September 01, 2009, 06:16:26 AM » |
|
Yup, follow the process tool instructions and fix the entries in HJT.
|
 Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #6 on: September 01, 2009, 06:30:25 AM » |
|
It says This file could be a legitimate file. Make sure you're positive this is not a valid file by reading the suggestions in the above chart before deleting it. If you're not comfortable deleting the file just leave it alone. And I'm not sure if those files are valid or not.
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #8 on: September 01, 2009, 08:12:27 PM » |
|
Did you read the links? I reformatted my comp and all software's gone, I've been downloading then one by one now, but there were so many that I had.
Please tell me what must I do Evil?
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #10 on: September 01, 2009, 08:16:39 PM » |
|
and what about the rootkits and the hacktools? I'm not worried about the software I had, I'm worried about my passwords etc!
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #11 on: September 01, 2009, 08:19:08 PM » |
|
PUP Potentially harmful Hack Tool BVP C:\System Volume Information\-restore{8718f503-489f-8c04-133208dd68ce}\a0000156.exe This is a system restore point and could be anything. Download The Avenger by Swandog46* Unzip/extract it to your desktop. * Now start The Avenger by double clicking on its icon on your desktop and click OK when to the warning. * Leave the box for Scan for rootkits checked. * Then place a check in the box next to Disable any rootkits found* Now click on Execute to begin the scan. * You will be asked No script has been entered. Do you want to execute a rootkit scan only?. * Click Yes. * You will now be asked 'First step completed ... The Avenger has been successfully set up to run on next boot. Reboot now?' * Click Yes* Your PC will now be rebooted. * After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%avenger.txt (typically C:\avenger.txt) * Please post the Avenger log in your next reply.
|
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #12 on: September 01, 2009, 08:38:27 PM » |
|
Log
[attachment deleted by admin]
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|
|
|
Ivy Topic Starter CH Queen
Thanked: 48 Posts: 1,604
|
 |
« Reply #14 on: September 01, 2009, 10:05:00 PM » |
|
Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.comPlatform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Completed script processing. ******************* Finished! Terminate. Why did it look like that???
|
Use what talent you possess. The woods would be very silent If no birds sang except those that sang best- Henry Van Dyke
|
|
|