Can't get win32:trojan-gen to stop!

"Win32:Trojan-gen. {Other}" has been found in "C:\WINDOWS\system32\rdriv.sys" file.

Above is the message I’m getting every time I turn my pc on - which is now about every 10 minutes. I have different options, but it won’t repair it, won’t move it, won’t delete it - nothing. I have to ‘x’ out of the alert to get it to close. My Microsoft malicious software program is also consistently finding VirTool:winNT/FUROOTKIT.D - again, with no info on the internet on how to get rid of it.

I don’t have hijack and all that installed. It won’t remove with avast and I can’t find any manual removal routines listed anywhere. It is affecting a lot of my internet files and within 5 to 10 minutes, my internet comes to a halt now. All I can’t is “page can’t be found” and my email won’t send/receive either. I believe it may have also turned off my firewall. MS says “low” threat - but I can’t use my pc, so I consider that pretty high.

Anybody have anything I CAN UNDERSTAND on how to get this out of my pc? I don’t know where it’s hiding, but it keeps resetting itself on pc reboot.

hi :slight_smile: ,

What OS do you have?
If you have NT based system you can do a boot-time scan >You can plan a boot-time scan from the program main menu :wink:

Hi wmtoo,

I suspect you have a variant of the FU rootkit, which is an application used by malware to hide itself. Because the rootkit is not very sophisticated, it does not try to hide itself (which is why avast! and MSAS can see it.) What they cannot see is the malware generating the rootkit.

The rootkit loads as a driver even during a boot time scan.

The presence of a rootkit means your system has been severely compromised: you won’t know what sort of backdoors might have be installed to allow a hacker to control your system.

Your best advice is to backup important data and flatten your system and reinstall your OS.

This is a problem people have had before:

http://forum.avast.com/index.php?topic=14618.0

I haven’t been visiting the forum for a few months: maybe somebody has found a solution?

Hello FreewheelinFrank,

As of now there is a new development in detecting the FU rootkit and others,
Kaspersky’s version 6.0 claims to be better prepared. Read this:
http://www.viruslist.com/en/analysis?pubid=168740859

greets,

polonus

Cool. 8)

When is avast! going to tackle rootkits?

Put those thinking caps on, guys. ???