All day I keep getting this and Have no idea how to stop it, it appears to keep coming up over and over, when I check the system nothing else shows up, and also have checked for spy ware with nothing else appears except in AVAST nad it keeps poping up and I send it to the chest.
Any ideas?
After the listing of the sign I have also attached the hijack I just did. Can anyone tell me what I have or what to do to stop it?
4/9/2008 7:54:32 AM 1207742072 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\SYSTEM32\SHAI.DLL” file.
4/9/2008 10:09:48 AM 1207750188 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:13:39 AM 1207750419 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:13:57 AM 1207750437 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:14:01 AM 1207750441 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:14:24 AM 1207750464 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:14:48 AM 1207750488 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:15:13 AM 1207750513 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:15:30 AM 1207750530 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:18:55 AM 1207750735 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:19:17 AM 1207750757 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 10:19:18 AM 1207750758 SYSTEM 212 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\system32\shai.dll” file.
4/9/2008 11:12:44 AM 1207753964 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os6.tmp\AppInit.dll” file.
4/9/2008 11:23:24 AM 1207754604 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os13.tmp\AppInit.dll” file.
4/9/2008 11:33:55 AM 1207755235 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os16.tmp\AppInit.dll” file.
4/9/2008 11:44:26 AM 1207755866 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os18.tmp\AppInit.dll” file.
4/9/2008 11:54:58 AM 1207756498 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os1C.tmp\AppInit.dll” file.
4/9/2008 12:05:27 PM 1207757127 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os20.tmp\AppInit.dll” file.
4/9/2008 12:15:57 PM 1207757757 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os41.tmp\AppInit.dll” file.
4/9/2008 12:26:57 PM 1207758417 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os4E.tmp\AppInit.dll” file.
4/9/2008 12:37:27 PM 1207759047 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os5B.tmp\AppInit.dll” file.
4/9/2008 12:47:58 PM 1207759678 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os60.tmp\AppInit.dll” file.
4/9/2008 12:58:32 PM 1207760312 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os6C.tmp\AppInit.dll” file.
4/9/2008 1:09:04 PM 1207760944 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os78.tmp\AppInit.dll” file.
4/9/2008 1:19:41 PM 1207761581 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os7A.tmp\AppInit.dll” file.
4/9/2008 1:30:20 PM 1207762220 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os7C.tmp\AppInit.dll” file.
4/9/2008 1:41:06 PM 1207762866 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os218.tmp\AppInit.dll” file.
4/9/2008 1:56:54 PM 1207763814 Nicholas 1984 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os523.tmp\AppInit.dll” file.
4/9/2008 9:39:39 PM 1207791579 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os15.tmp\AppInit.dll” file.
4/9/2008 9:51:13 PM 1207792273 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os19.tmp\AppInit.dll” file.
4/9/2008 10:01:58 PM 1207792918 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os1C.tmp\AppInit.dll” file.
4/9/2008 10:12:40 PM 1207793560 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os1E.tmp\AppInit.dll” file.
4/9/2008 10:23:43 PM 1207794223 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os20.tmp\AppInit.dll” file.
4/9/2008 10:35:05 PM 1207794905 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os36.tmp\AppInit.dll” file.
4/9/2008 10:46:38 PM 1207795598 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os38.tmp\AppInit.dll” file.
4/9/2008 10:57:22 PM 1207796242 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os3B.tmp\AppInit.dll” file.
4/9/2008 11:07:59 PM 1207796879 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os3D.tmp\AppInit.dll” file.
4/9/2008 11:18:31 PM 1207797511 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os45.tmp\AppInit.dll” file.
4/9/2008 11:31:20 PM 1207798280 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os5B.tmp\AppInit.dll” file.
4/9/2008 11:41:56 PM 1207798916 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os5D.tmp\AppInit.dll” file.
4/9/2008 11:52:26 PM 1207799546 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os5F.tmp\AppInit.dll” file.
4/10/2008 12:03:00 AM 1207800180 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os61.tmp\AppInit.dll” file.
4/10/2008 12:14:14 AM 1207800854 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os63.tmp\AppInit.dll” file.
4/10/2008 12:24:48 AM 1207801488 SYSTEM 1944 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os65.tmp\AppInit.dll” file.
4/10/2008 1:35:35 AM 1207805735 Nicholas 1908 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os4.tmp\AppInit.dll” file.
4/10/2008 1:46:30 AM 1207806390 Nicholas 1908 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os8.tmp\AppInit.dll” file.
4/10/2008 1:56:58 AM 1207807018 Nicholas 1908 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os11.tmp\AppInit.dll” file.
4/10/2008 2:07:26 AM 1207807646 Nicholas 1908 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os1F.tmp\AppInit.dll” file.
4/10/2008 2:17:54 AM 1207808274 Nicholas 1908 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os22.tmp\AppInit.dll” file.
4/10/2008 2:31:08 AM 1207809068 Nicholas 1980 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~osB.tmp\AppInit.dll” file.
4/10/2008 2:35:04 AM 1207809304 Nicholas 1980 Sign of “Win32:Trat-D [Drp]” has been found in “C:\Documents and Settings\Nicholas\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.BIN” file.
4/10/2008 2:41:48 AM 1207809708 Nicholas 1980 Sign of “Win32:Rootkit-gen [Rtk]” has been found in “C:\WINDOWS\TEMP~os1C.tmp\AppInit.dll” file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:53:43 AM, on 4/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
While I am not an expert on reading HJT logs, I have done some research for those who may be able to help you with this infection. Please wait for someone else to give you instructions on what steps to take next.
Thanks, since I know I am a member of shoppershotlinewired and this program is on my computer, I have no problems with it being there now or in the past should I just accept the allerts, and is there a way to turn off the alert. This has just started with the latest update of Avast, and have not seen it before.
From the links I supplied:
(bold inserted by me to highlight the major dangers)
ACTIVITY ANALYSIS OF: SHWIRED.EXE
The following behaviors have been observed for this object:
Installs programs.
Deletes programs.
Invokes dll components.
Creates Run Keys.
[b]Modifies the hostsfile.[/b]
Runs temporary programs.
Runs other programs.
[b]Communicates with web sites using httpout protocols.[/b]
[b]Communicates with other computers across the web.[/b]
[b]Hijacks running processes.[/b]
Has outbound communications.
Creates registry entries.
[b]Creates run keys for known malware.[/b]
[b]Creates known malware.[/b]
Creates copies of itself.
PRLS.DLL has been the subject of the following behavior(s):
Registered as a Dynamic Link Library File The process is hooked into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
Created as a process on disk
Deleted as a process from disk
The choice is your, of course, but you can not be surprised if you get rootkits, spyware, keygens, or other malware if you continue to use such programs.
Quote from nicholas2:
This has just started with the latest update of Avast, and have not seen it before.
This is because the new version of avast 4.8 includes a rootkit detector where as previous versions of avast did not have this capability.
Thanks for the information, and I did read the various comments, however I have had the program on the computer for over a year and have not had any problems of the possibilites described, as it came from a reputable source to my knowledge, and to be sure contacted the technical people at the site for information.
Is there a way to allow the program to run, without the alerts for this program, but will alert me it something else arrives?
Would someone else like to comment here? I have done what I can to help nicholas2 understand what is wrong but I seem to have failed … or maybe I am missing something.