Hi, I have been having problems trying to get rid of a rootkit only Avast can detect.
The Rootkit file name is SVC: WinRing0_1_2_0 and its showing up in my user>appdata>local>temp folder, but when I go there I can’t see it, only Avast does.
First time Avast found it I followed it’s instructions, Delete Now (recommended) then restarted and it done a boot scan which came up clean but about 2 minutes after my comp booted up, Avast had detected it again.
I then ran Malwarebytes Anti-Rootkit BETA which came up clean.
I don’t know where to go from here, any help would be much appreciated. Thanks.
From what iv’e read on rootkits so far today, they’re not something you can just delete as they freshly install everytime you boot or hit the trigger which ever that trigger may be. Ofcourse I could be wrong, I really don’t know much about this stuff, just what I read. This is getting me worried though, seeing some of the things that can be done with them.
I believe this may be related to Steam or one of the games
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
R3 WinRing0_1_2_0; \??\C:\Users\KR15MCS\AppData\Local\Temp\tmp5198.tmp [X]
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
[*]Click the Look button to start the scan.
[*]When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
I don’t think I’m having problems, I did just have to reconfigure my speaker settings because 2 of them mysteriously stopped working in 5.1 channel, but I’m not sure if that has anything to do with this.
I don’t really understand why Avast is doing this now, is it because this is a new file or has it always been there? And why does it come back after it is deleted?
Although it doesn’t appear to be causing problems I would still like it gone ofcourse, I would feel uncomfortable just to ignore it.
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
My system didn’t reboot, just explorer.exe. Should I reboot it? aswMBR is showing more hidden files after running the ComboFix programme, is that anything to worry about?
No the terminology is hidden, there is a world of difference. Hidden means that it will not show at a cursory glance this is normal for several registry entries
Close any open browsers.
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open notepad and copy/paste the text in the quotebox below into it:
Driver::
WinRing0_1_2_0
Save this as CFScript.txt, in the same location as ComboFix.exe