ROOTKIT virus found - question

How do I know how deep this rootkit is? Do I need to toss my PC now or what? HELP! :cry:

https://forum.avast.com/index.php?topic=53253.0

I am working on these! Please don’t think I am not. Just that I have had issues with my other online accounts too. This thing was nasty! I’ll post the logs as I get them. Thanks!

Take the time you need.
Better slow than fast and sorry :wink:

OK, I think I have them all. I was unable to access the forum for a day, so I couldn’t see the list but I had a printout that was mostly complete. Here you go!

more…

I have not made any ‘fixes’. Like with Rogue Killer. Thought I would wait until you reviewed the items.

Fix this one with RK

¤¤¤ Scheduled tasks : 1 ¤¤¤
[Suspicious.Path] \4736 – wscript.exe (C:\Users\owner\AppData\Local\Temp\launchie.vbs //B) → FOUND

What was Avast reporting i.e. file name and location

I have attached a screen cap of the Avast boot scan results. Hope that helps!

OK that is easy to fix as it is in the temporary folder

Clear Cache/Temp Files
Download TFC by OldTimer to your desktop

[*] Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
[*]It will close all programs when run, so make sure you have saved all your work before you begin.
[*]Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
[*]Once it’s finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

OK I ran that. Froze up when it was supposed to reboot, so I had to hard reboot. Otherwise, working great.

Has Avast ceased alerting now ?

No more alerts no. But I have another issue on my laptop. We share a network. Can the virus spread this way? Because I have had a BSOD 5 time for different reasons, I get locked out of websites. Plus, I was trying to upload a file to fileover.net so someone on another forum could help me and it wouldn’t let me register and when it uploaded both things gave security errors. A boot scan showed some corrupted files in temp. I was going to run the same program (OT) that you had me run on my desktop. Could this be virus related? What about the 5 BSODs? Just getting freaked out I guess!

What stop code do you get on the BSOD

How do I find out the stop code?

Could you zip the latest 3 files in C:\windows\minidump and upload them to a file sharing site for me to look at

Well, everytime I try to use fileover.net I get security errors. Do you have another one I can use?

Try mediafire https://www.mediafire.com/

Hopefully I did this right, but I think I only got the last 3.

https://www.mediafire.com/?6rb94kgwzfk9uoo

OK that is related to a video card memory error

Could you check you card supplier for an updated driver nvlddmkm.sys