Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: I'm pretty sure I have a root kit, but I can't get rid of it.  (Read 2893 times)

0 Members and 1 Guest are viewing this topic.

Kaworu517

  • Guest
I'm pretty sure I have a root kit, but I can't get rid of it.
« on: September 15, 2009, 09:39:25 PM »
About a week and a half ago, I clicked on a link on another forum that gave me a bunch of viruses and spyware(it was a tinyurl link, which I know I shouldn't have clicked on...).  I've managed to get almost all of it out, but there's one thing I can't get rid of.  It's a file called "88e25094" and it's located in F:\WINDOWS\system32\drivers.

Avast! will detect it, say it's a root kit, but I can't perform any actions on it.  Webroot Antivirus with Antispyware will detect it and have me reboot so it can delete it early, but it'll say that the file is missing.  Malwarebytes' Anti-Malware detects it and says it'll delete the file on reboot, but the file is still there.  If I try to delete it myself, I get this error: "Cannot delete 88e25094: cannot find the specified file."

My computer started acting real sluggish when I originally got the viruses and spyware and considerably improved since then, but it's still not running anywhere near as well as before.


I've followed everything in the sticky and attached the logs for SuperAntispyware, Malwarebytes' Anti-Malware, and HijackThis.


Thanks to anyone who can help.  If you need any more information about anything, I'll be checking this thread often, so I'll get you whatever you need asap.

[attachment deleted by admin]

digvijay

  • Guest
Re: I'm pretty sure I have a root kit, but I can't get rid of it.
« Reply #1 on: September 15, 2009, 10:00:54 PM »
just try the avast boottime scan and i am sure u can delete or modify it...................



if u dont know how to run boot time scan read avast FAQ.... :)









CBMatt

  • Mod & Malware Specialist


  • Prodigy

  • Sad and lonely...and loving every minute of it.
  • Thanked: 167
    • Yes
  • Experience: Experienced
  • OS: Windows 7
Re: I'm pretty sure I have a root kit, but I can't get rid of it.
« Reply #2 on: September 16, 2009, 10:33:55 PM »
The first thing you need to do is boot into Safe Mode and try scanning that way.  Most infections lay dormant in Safe Mode, which makes them easier to detect and remove.  So, while in Safe Mode, scan with MBAM, SAS, and Avast, one at a time.  When you're done, post the logs and here and let us know if the file is still returning.
Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey