Home / Software / Computer viruses and spyware / RootKits..
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] 2  All - (Bottom) Print
Author Topic: RootKits..  (Read 1273 times)
Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« on: August 31, 2009, 10:46:57 PM »

I downloaded Rootkitrevealer today from Here, Because I wanted to make sure that there are no rootkits on my computer, because of This, and it showed quiet a lot of stuff. I've attached a screen shot.

I checked my virus vault, It showed this.
PUP Potentially harmful Hack Tool BVP 
C:\System Volume Information\-restore{8718f503-489f-8c04-133208dd68ce}\a0000156.exe



I don't know what to do! I don't have any softwares left, and if I try to download anything it crashes half way most of the time, it's so frustrating!!!Please help me! I've already reformatted this computer twice in 2 days! But I'm ready to reformat the computer again! but I'm afraid by now it's too late cause I've logged in into all my accounts already..(I used On-Screen keyboard for passwords though for the time being).

Please help.

Thank you.

[attachment deleted by admin]
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #1 on: August 31, 2009, 11:07:51 PM »

Succeeded in downloading HJT.

I have attached a log file.

[attachment deleted by admin]
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #2 on: August 31, 2009, 11:28:31 PM »

Hi Ivy,

Follow this link..

http://www.computerhope.com/cgi-bin/process.pl?o=31222613

Follow the cleaning instructions, and run an MBAm scan afterwards.
IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #3 on: August 31, 2009, 11:41:39 PM »

Actually I did that already, it's says I gotta delete some files, I thought you guys might not want me to delete them without consulting you first.

So shall I go ahead and remove those files?
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #4 on: August 31, 2009, 11:52:59 PM »

Also I have downloaded RootKitBuster that Patio mentioned in one of his posts, It showed no hidden files.

+----------------------------------------------------
| Trend Micro RootkitBuster
| Module version: 2.52.0.1013
+----------------------------------------------------


--== Dump Hidden MBR and Hidden File on C:\ ==--
No hidden files found.

--== Dump Hidden Registry Value on HKLM ==--
No hidden registry entries found.


--== Dump Hidden Process ==--
No hidden processes found.

--== Dump Hidden Driver ==--
No hidden drivers found.
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #5 on: September 01, 2009, 06:16:26 AM »

Yup, follow the process tool instructions and fix the entries in HJT.
IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #6 on: September 01, 2009, 06:30:25 AM »

It says
Quote
This file could be a legitimate file. Make sure you're positive this is not a valid file by reading the suggestions in the above chart before deleting it. If you're not comfortable deleting the file just leave it alone.

And I'm not sure if those files are valid or not.

IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #7 on: September 01, 2009, 10:57:50 AM »

Stay away from Rootkit tools unless you are very sure what you are doing.

Quote
I don't know what to do! I don't have any softwares left

What happened exactly? I don't know what that means.
IP logged

Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #8 on: September 01, 2009, 08:12:27 PM »

Did you read the links? I reformatted my comp and all software's gone, I've been downloading  then one by one now, but there were so many that I had.

Please tell me what must I do Evil?
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #9 on: September 01, 2009, 08:13:51 PM »

All you can do is redownload everything you are missing.
IP logged

Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #10 on: September 01, 2009, 08:16:39 PM »

and what about the rootkits and the hacktools? I'm not worried about the software I had, I'm worried about my passwords etc!
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #11 on: September 01, 2009, 08:19:08 PM »

Quote
PUP Potentially harmful Hack Tool BVP
C:\System Volume Information\-restore{8718f503-489f-8c04-133208dd68ce}\a0000156.exe

This is a system restore point and could be anything.

Download  The Avenger by Swandog46

* Unzip/extract it to your desktop.
* Now start The Avenger by double clicking on its icon on your desktop and click OK when to the warning.
* Leave the box for Scan for rootkits checked.
* Then place a check in the box next to Disable any rootkits found
* Now click on Execute to begin the scan.
* You will be asked No script has been entered. Do you want to execute a rootkit scan only?.
* Click Yes.
* You will now be asked 'First step completed ... The Avenger has been successfully set up to run on next boot. Reboot now?'
* Click Yes
* Your PC will now be rebooted.
* After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at
%systemdrive%avenger.txt (typically C:\avenger.txt)

* Please post the Avenger log in your next reply.
IP logged

Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #12 on: September 01, 2009, 08:38:27 PM »

Log

[attachment deleted by admin]
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #13 on: September 01, 2009, 10:01:41 PM »

I can't read that...

Quote
Logfile of The Avenger Version 2.0, (c) by Swandog46
਍栀琀琀瀀㨀⼀⼀猀眀愀渀搀漀最㐀㘀⸀最攀攀欀猀琀漀最漀⸀挀漀洀ഀഀ

਍倀氀愀琀昀漀爀洀㨀  圀椀渀搀漀眀猀 堀倀ഀഀ

਍⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀⨀ഀഀ

਍匀挀爀椀瀀琀 昀椀氀攀 漀瀀攀渀攀搀 猀甀挀挀攀猀猀昀甀氀氀礀⸀ഀഀ
Script file read successfully.
਍ഀഀ
Backups directory opened successfully at C:\Avenger
਍ഀഀ
*******************
਍ഀഀ
Beginning to process script file:
਍ഀഀ
Rootkit scan active.
਍一漀 爀漀漀琀欀椀琀猀 昀漀甀渀搀℀ഀഀ

਍ഀഀ
Completed script processing.
਍ഀഀ
*******************
਍ഀഀ
Finished!  Terminate.
IP logged

Ivy
Topic Starter
CH Queen
Mentor



Thanked: 48
Posts: 1,604


« Reply #14 on: September 01, 2009, 10:05:00 PM »

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Completed script processing.

*******************

Finished!  Terminate.


Why did it look like that???
IP logged

Use what talent you possess.
The woods would be very silent
If no birds sang except those that sang best-
Henry Van Dyke
Pages: [1] 2  All - (Top) Print 
Home / Software / Computer viruses and spyware / RootKits.. « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.103 seconds with 21 queries.