I’m new to the forums. Actually I was searching for some solution to my PC’s rootkit problem that’s why I’m here. Any help would be appreciated.
I’ve been using avast for a while now on my laptop PC (running 64-bit Windows 7 Home). And so far I didn’t get any problems. But recently my laptop PC has been having problems. It’s running pretty slowly and having trouble starting up in normal mode. A few days ago it started up normally but now it wouldn’t at all. So now I’m running it in safe mode with networking. I did a full scan with avast and found a DLL file with the status – Threat:Rootkit:hidden file. I tried to delete it with avast but I get the error message: Access is denied (5). Avast also found 7 other things but the status says-- Error: the request could not be performed because of an I/O device error.
Please visit the site located here. Follow the directions
for running OTL, aswMBR.exe and Malwarebytes and then attach the logs that are created to your next reply.
I’ve downloaded OTL and tried to run it as specified (all other windows closed, etc.). But it freezes at some point and it just hangs. I’ve tried to run it twice now and I get the same result. Am I doing something wrong? Should I just wait it out and (cross fingers) it’ll finish the scan eventually?
I’ve also downloaded aswMBR and also tried to run it as specified. But at some point before it’s finished, I just get the blue screen and the computer restarts. So I have no aswMBR scan log either.
[*]Extract it to your desktop
[*]Double click TDSSKiller.exe
[*]When the window opens, click on Change Parameters
[*]Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
[*]click OK
[*]Press Start Scan
[]Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct items.
[]Attach the log in your next reply
[*]A copy of the log will be saved automatically to the root of the drive (typically C:)
Download Combofix from either of the links below, and save it to your desktop. Link 1 Link 2
Note: It is important that it is saved directly to your desktop
If you get a message saying “Illegal operation attempted on a registry key that has been marked for deletion”, please restart your computer.
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
[*]Please post the C:\ComboFix.txt for further review.
Okay, downloaded Combofix and ran it. I disabled (or so I thought) my anti-spyware (Ad-Aware) and antivirus programs (avast) before I ran Combofix, but for some reason, Combofix still said they were running. I ran Combofix anyways and got this log.
By the way, the computer restarted by itself. The computer is still running in Safe Mode with Networking.
I see that you are running both Avast and AdAware Antivirus? Using more than one antivirus program is not a good idea and could lead to more problems and actually less detection. You may also be interested in reading this >> http://www.scmagazine.com/lavasofts-new-owners-operated-misleading-websites/article/209123/ in reference to AdAware. I would suggest you remove one of them completely.
[*]Please open Notepad (Start → Run → type notepad in the Open field → OK) and copy and paste the text present inside the code box below:
[*]Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
[*]Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
[*]ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
[*]When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix’s window while it is running. That may cause it to stall.
I ran into the same problem as last time when disabling avast and Ad-Aware. I disabled avast by right-clicking the avast icon in the system tray and clicking “disable permanently”. And I also disabled Ad-Aware by right-clicking the Ad-Aware icon and clicking “exit”. I even opened the task manager to end all the processes I thought were related to both programs. But when I ran Combofix, it says both programs are running. I haven’t clicked “OK” from the Combofix message box. What do I do to REALLY disable these programs? :-\
Okay, that’s a relief.
But now I have another problem (sorry, it seems the problems never end). The computer was shutdown unexpectedly (power outage… argh) while Combofix was running, and now when I restarted the computer and ran Combofix again, it’s stuck at extracting files to output folder C:\32788R22FWJFW. What do I do?
I’ve done that but it just stalls again. I restarted the computer, even deleted Combofix.exe and re-downloaded it and ran it again but that doesn’t work either. I’ve repeated the process many times but the result’s the same – stalled Combofix. Are there any other options?
To enter System Recovery Options from the Advanced Boot Options:
[*]Restart the computer.
[*]As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
[*]Use the arrow keys to select the Repair your computer menu item.
[*]Select US as the keyboard language settings, and then click Next.
[*]Select the operating system you want to repair, and then click Next.
[*]Select your user account an click Next.
To enter System Recovery Options by using Windows installation disc:
[*]Insert the installation disc.
[*]Restart your computer.
[*]If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
[*]Click Repair your computer.
[*]Select US as the keyboard language settings, and then click Next.
[*]Select the operating system you want to repair, and then click Next.
[*]Select your user account and click Next.
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select Command Prompt
[*]In the command window type in notepad and press Enter.
[*]The notepad opens. Under File menu select Open.
[*]Select “Computer” and find your flash drive letter and close the notepad.
[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.
[*]When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
I downloaded FRST on a flashdrive, plugged the flashdrive in the computer and then restarted. I entered system recovery options through advanced boot options. After I selected “Repair your computer”, it seemed to work (Windows was loading files and the screen changed into that blue/white gradient background with some leaf accents). But after some minutes though I got the message:
System Recovery Options
The installed program cannot start. Click OK to turn off the computer.
So I turned off the computer.
I haven’t got a Windows 7 installation CD since Windows 7 came pre-installed when I bought the laptop. I do have system recovery discs (they’re not exactly the same as the installation discs from what I understand, but what the heck, it was worth a shot) but when I tried those, it didn’t seem to work either. There wasn’t any prompt to start Windows from the CD/DVD drive.
So I’ll go borrow an installation disc or buy one tomorrow. But if there’s yet another option, let me know.
Okay, since that attempt to run FRST didn’t work, I tried running Combofix again. And it worked! I don’t know why but it worked! But I don’t understand why Combofix still says that Ad-Aware is running since I uninstalled it the day before when you said to uninstall either Ad-Aware or avast. And I installed Ad-Aware in the first place as an anti-spyware program. I didn’t even know it was also an antivirus. :-[