Question

Hacktool.rootkit & Packed.Generic.200 virus

Asked by: swilma

Dell XP laptop w/symantec corporate 10.1 received virus warning today. Surfed the above referenced name and see rootkit revealer recommendation.
Here is the text after I scaned w/revealer:

HKLM\SECURITY\Policy\Secrets\SAC*      2/12/2009 1:24 PM      0 bytes      Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI*      2/12/2009 1:24 PM      0 bytes      Key name contains embedded nulls (*)
HKLM\SOFTWARE\INTEL\DLLUsage\VP6\C:\Program Files\Symantec AntiVirus\Cliproxy.dll      3/24/2009 12:07 PM      18 bytes      Hidden from Windows API.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CD1A110AD1F78AE4DB11C0F579814E82\Usage\SAVUI      3/24/2009 11:41 AM      4 bytes      Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Directory      3/24/2009 12:07 PM      182 bytes      Windows API length not consistent with raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CachePath      3/24/2009 12:07 PM      196 bytes      Windows API length not consistent with raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CachePath      3/24/2009 12:07 PM      196 bytes      Windows API length not consistent with raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CachePath      3/24/2009 12:07 PM      196 bytes      Windows API length not consistent with raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CachePath      3/24/2009 12:07 PM      196 bytes      Windows API length not consistent with raw hive data.
HKLM\SOFTWARE\UAC      3/24/2009 12:04 PM      0 bytes      Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\UACd.sys      3/24/2009 12:06 PM      0 bytes      Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Services\UACd.sys      3/24/2009 12:06 PM      0 bytes      Hidden from Windows API.
C:             0 bytes      Error mounting volume

Can you instruct me what to do now?
Thanks

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-03-24 at 10:40:29ID24260180
Tags

Virus

Topic

Anti-Virus

Participating Experts
2
Points
250
Comments
34

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. removing reg keys found by rootkit revealer
    I just ran Rootkit Revealer and it found 2 reg keys hidden from Windows API.Could someone please explain how to get rid of these or what to do next? Im running XP Home. Thanks in advance Val HKLM\S-1-5-21-1547161642-1960408961-725345543-1006\Software\Microsoft\Windows\Curre...
  2. Is this a rootkit?
    Doing some scans on a pc. Ran Rootkit Revealer and received only this result: HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 80 bytes Data mismatch between windows API and raw hive data Is this one of the false/positives or a rootkit?
  3. rootkit remover
    rootkit revealer indicates that i've two rootkits in registry. what is the best rootkit remover software out there. freeware?
  4. rootkit?
    AM I Rooted? os=windows xp pro service pack 2 used two tools from http://invisiblethings.org/tools.html system virginity tester modgreper What do the results indicate C:\svv>svv check Important module ntoskrnl.exe not found ntdll.dll (7c900000 - 7c9b0000)... suspected...
  5. rootkit suspect
    I've a pc (not mine) that I'm trying to clean up. It had at least two rootkit (lzx32.sys, pe386), several trojans (igfxtray, hkcmd, mstds, mswsck32.dll) and other malware. I used Rootkit Unhooker to detect lzx32 and pe386 (removed from the fs and registry using a linux livecd...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: warturtlePosted on 2009-03-24 at 12:24:57ID: 23972161

Download ComboFix and save it with some other name and run it in safe mode. Don't use mouse or keyboard while its running. Then use MalwareBytes Anti-Malware and SuperAntiSpyware to finish things off. disable your current AV when they are running.

 

by: warturtlePosted on 2009-03-24 at 12:30:27ID: 23972221

After all these tools are done with, then scan with Norton and it will have enough control over the system to remove all other threats.

 

by: rpggamergirlPosted on 2009-03-25 at 04:06:12ID: 23977921

Just run combofix and show us the log.

Here's the link to Combofix if you like, please attach the combofix log.

Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: rpggamergirlPosted on 2009-03-25 at 04:11:49ID: 23977948

HKLM\SOFTWARE\UAC      3/24/2009 12:04 PM      0 bytes      Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\UACd.sys      3/24/2009 12:06 PM      0 bytes      Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Services\UACd.sys      3/24/2009 12:06 PM      0 bytes      Hidden from Windows API.

the above registry entries are bad, running Combofix should removed its related bad files.

 

by: swilmaPosted on 2009-03-25 at 04:45:02ID: 23978194

I just ran combofix. Here's the log. I am not able to boot windows normally. Only safe mode. So I can't install SuperantiSpyware to run.
Can you tell why windows won't start?

 

by: warturtlePosted on 2009-03-25 at 05:35:43ID: 23978650

Sorry for my late reply, I just got back. ComboFix has removed a lot of bad things from your computer for sure. Hmm.. you have interesting things in this log, the TDSS RootKit has added the below entries in registry to disable your antivirus notifications:

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

My suggestion is to first of delete all files from c:\documents and settings\ADMINIstrator\LOCALSettings\Temp. Secondly, run MalwareBytes Anti-Malware (MBAM) while still in safe mode and let us know, what you find. If you are unable to run or install MBAM, then I suggest that you do an online scan with AVG antivirus.

http://www.ewido.net/en/onlinescan/

Then, download ZoneAlarm free firewall and install it. It might not install in the safe mode, but download it and keep it nonetheless to install in normal mode.

Try that and let us know, what you get.

 

by: warturtlePosted on 2009-03-25 at 05:45:20ID: 23978747

If you are able to delete the temporary files without any problems, then its good, if not download ATF Cleaner and run it from (it is designed to delete all temporary files from areas which can harbour any viruses within):

http://www.atribune.org/public-beta/ATF-Cleaner.exe

 

by: warturtlePosted on 2009-03-25 at 06:53:31ID: 23979397

You can also try renaming the MalwareBytes or SuperAntiSpyware files to allow installation, the virus might be checking for filenames to prevent detection or removal. You can download them again and save them with a completely different name like - jabbathehut.exe or idontlikevirus.exe or something like that.

 

by: swilmaPosted on 2009-03-25 at 07:45:10ID: 23980003

Thanks - I'm doing a Malwarebytes scan right now.
I'll let you know what it finds.

I'm curious about the registry items that you saw:
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

Should I edit these? Or will Malware correct them?

 

by: warturtlePosted on 2009-03-25 at 07:50:43ID: 23980077

MalwareBytes will take care of the big fries, then you will have to scan your PC with your own antivirus to take care of small fries. MalwareBytes will restore the control back to your own antivirus. Don't forget to install the firewall though, its essential.

 

by: warturtlePosted on 2009-03-25 at 08:00:04ID: 23980197

And don't worry about those registry entries, they will be taken care of.

 

by: swilmaPosted on 2009-03-25 at 08:15:58ID: 23980440

Malwarebyes finished - found NOTHING!
Went to install Zone Alarm firewall . Won't let me "The system administrator has set policies to prevent this installation"
Reboot - won't let me boot windows
Can boot safe mode
Should I rename SuperAntiSpyware and try to install that?
Something has still got a hold.
"The system administrator has set policies to prevent this installation"

 

by: warturtlePosted on 2009-03-25 at 09:34:23ID: 23981582

Yes, please try the SuperAntiSpyware installation as well. And send us a HijackThis report as well.

 

by: swilmaPosted on 2009-03-25 at 10:02:13ID: 23981943

Here's the Hijack This log.
I still can't install Super AntiSpyware so I'm dead in the water until I hear something new
Thanks

 

by: warturtlePosted on 2009-03-25 at 10:29:51ID: 23982274

PART I: TDss RootKit removal

Step 1: Disable TDSSserv trojan driver.
Right click the My computer icon. If you are using the non classic Start menu, then right click My computer icon on your Start button menu.
Click Properties.
Click Hardware Tab.
Click Device Manager.
In the top menu, click View and click Show Hidden Drivers.
Scroll down to non Plug and Play drivers.
Click + at left.
In the list of drivers right click TDSSserv.sys or UACd.sys (Whichever is present). (If you do not find these, then skip to Step 2)
Click Disable.
Click YES for confirm.
Close all windows and reboot your computer.

PART 2:

Then execute regedit and goto the location: HKEY_LOCAL_MACHINE\SOFTWARE and delete the folder called UAC. Then reboot

PART 3:

Please copy the below into a notepad window and save it as CFScript.txt in the same folder as ComboFix.exe file (or the renamed file). Then drag this file on top of ComboFix executable and send us the log.

KILLALL::
File::
c:\windows\system32\uactmp.db
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=-
"UpdatesDisableNotify"=-

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=-

This should take care of most the things that are creating problems as well as awaken your Symantec antivirus. Try that and let us know what you get. Do not click on ComboFix window while its running or it might stop.

 

by: warturtlePosted on 2009-03-25 at 10:36:08ID: 23982363

I had to add another process to kill, here it is. Please read the instructions from above to find how to execute it:

KILLALL::
File::
c:\windows\system32\uactmp.db
c:\docume~1\ADMINI~1\LOCALS~1\Temp\WEC.exe
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=-
"UpdatesDisableNotify"=-

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=-


Now it looks perfect!

 

by: swilmaPosted on 2009-03-25 at 10:50:10ID: 23982506

WarTurtle
Thanks for all of your attention today. I started following your instructions prior to your last post.
#1 & #2 unbelievably were not listed! I checked & re-checked.
I then performed the CF before your new edition. I will re-do. Then send you the log
Thank you again

 

by: swilmaPosted on 2009-03-25 at 11:11:06ID: 23982769

Here are the logs

 

by: warturtlePosted on 2009-03-25 at 12:26:01ID: 23983566

Hmm.. the log looks normal to me except for one strange process which is still standing...c:\docume~1\ADMINI~1\LOCALS~1\Temp\WEC.exe, do you know this file?

If not, then I suggest using FileAssasin from within MalwareBytes Anti-Malware to kill this file permanently from your system. You can access FileAssasin by opening MalwareBytes interface and going to 'More Tools' interface. Then click on 'Run Tool' and browse to this file. Or copy and paste the file's address from above.

Do that reboot your system in normal mode. Then scan with your own Symantec antivirus and all problems should be history.

 

by: warturtlePosted on 2009-03-25 at 13:27:20ID: 23984301

If your computer can start in normal mode now, then its good. Otherwise, we can check another bit of registry as well, because this TDSS rootkit had installed itself as a device driver, so we need to kill those entries from within registry which point to it.

HKLM\SOFTWARE\UAC - you've checked this one and its not present... GOOD
HKLM\SYSTEM\ControlSet001\Services\UACd.sys - need to check this and remove it
HKLM\SYSTEM\ControlSet003\Services\UACd.sys - need to check this and remove it as well.

Windows will not boot in normal mode, if it doesn't find a driver for all its installed devices(http://support.microsoft.com/kb/555996) and if we remove references to the drivers, we can sort out the problem. Sorry for so much work, TDSS is quite a nasty piece of work and needs some effort to get rid of.

Hacktool rootkit is normally found on a system where hackers may have had full control over the system (http://www.symantec.com/security_response/writeup.jsp?docid=2002-011710-0057-99). As soon as we boot into the normal mode, please install the firewall and set the security slider to highest or stealth mode for internet zone. A firewall is your first line of defence and will prevent hackers from gaining direct access to your system as well as viruses from coming into your PC. As always, let me know what your observations are.

 

by: swilmaPosted on 2009-03-26 at 04:40:47ID: 23989187

I booted up the computer using ERD disk
HKLM\SYSTEM\ControlSet001\Services\UACd.sys - This is not listed
HKLM\SYSTEM\ControlSet003\Services\UACd.sys - This WON'T delete! "Cannot delete UACd.sys: Error while deleting key."
c:\docume~1\ADMINI~1\LOCALS~1\Temp\WEC.exe is not showing anywhere either

I will run the file assasin now

 

by: warturtlePosted on 2009-03-26 at 04:53:03ID: 23989278

Download Avenger (http://swandog46.geekstogo.com/avenger.zip) and unzip to your desktop.
Run Avenger, copy & paste the following text in Input script Box:

Drivers to delete:
UACd.sys

Click on Execute, followed by yes on other and reboot. This will delete the driver file which is the rootkit and after that we should delete the registry key: HKLM\SYSTEM\ControlSet003\Services\UACd.sys

And reboot. Let me know, how it goes.

 

by: swilmaPosted on 2009-03-26 at 05:09:32ID: 23989408

WOW!
I followed your instructions Exactly - then went to HKLM\SYSTEM\ControlSet003\Services\UACd.sys and I still can't delete the key!
I'm getting worn down.

 

by: warturtlePosted on 2009-03-26 at 05:11:29ID: 23989420

Don't worry, the infection I feel is almost finished. Have you tried to reboot in normal mode?

 

by: swilmaPosted on 2009-03-26 at 05:31:30ID: 23989555

Yes, I have tried to boot normal. It just continues in a loop until I choose Safe mode.
I'm glad you are confident that the infection is almost done.
What's next?

 

by: warturtlePosted on 2009-03-26 at 05:36:36ID: 23989598

OK, we need to use Registry Assasin now to kill the unwanted registry entries:

Download it from: http://www.malwarebytes.org/RegASSASSIN.exe and copy and paste the below 2 keys to be deleted from system:

HKEY_LOCAL_MACHINE\SOFTWARE\UAC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys

Then try to reboot. If it still goes to Safe Mode, then please run ComboFix again and send us the log. Please let me know, what you get.

 

by: swilmaPosted on 2009-03-26 at 06:04:20ID: 23989849

HKEY_LOCAL_MACHINE\SOFTWARE\UAC - was not found
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys - This is GONE - Yeah

I still can't boot normally
Here's the CF log
I see that this c:\docume~1\ADMINI~1\LOCALS~1\Temp\WEC.exe is still listed but I can't find it

I can't thank you enough for all of your attention.
SW

 

by: warturtlePosted on 2009-03-26 at 06:27:09ID: 23990060

Hmm.. I would suggest taking this machine off network, some basic things to do now:

1. Run MalwareBytes scan again.

2. When your computer reboots, select 'Last Known, Good Configuration' to start it off. See if it is working normally and at the first chance that it works normally, install the firewall.

3. Open msconfig and disable everything except for Windows and Antivirus to start at bootup. Saving the setting would ask you to reboot your computer, do that and let us know, if you can bootup in normal mode or not.

4. Go back to safe mode go to start->run and type msconfig. Goto boot.ini tab and make sure that "/safeboot" option is cleared.if not clear it and restart.

Try those things and let us know, what you get.

 

by: swilmaPosted on 2009-03-26 at 06:46:31ID: 23990264

I immediately took the laptop off network a couple of days ago when the bug was detected. I am using a clean computer to contact you and download tools. Then transfer to the sick laptop with a flash drive.
I have tried Last Known, Good Configuration many times. Will this work if system restore has been shut off? This was one of the only suggestions Symantec had/has for dealing w/bugs.
I cleared everything in msconfig
/safeboot" option is cleared

I'm running MalwareBytes now

 

by: warturtlePosted on 2009-03-26 at 08:00:13ID: 23991147

Good! The 'Last Known, Good Configuration' might not work if system restore has been shut down. It might try to pickup settings from when it was actually on.

There is a System Repair install, which is non-destructive and would restore the computer back to normal again, I don't usually advise this unless the system has been left in a difficult state by viruses:

http://www.informationweek.com/news/windows/showArticle.jhtml?articleID=189400897&cid=ref-true

As per the ComboFix logs, I can't see anything harmful on your computer except for some strange entries:

- AegisI5Installer.exe
- Internet Connection Wizard,ShellNext = hxxp://www.fulldotfind.com/pubac/ac.php?aid=62&sid=clean
- c:\docume~1\ADMINI~1\LOCALS~1\Temp\WEC.exe

Let me know, what you get from MalwareBytes scan. CCleaner can also be used to clean all unneeded things from registry and temporary folders. That might also help.

 

by: swilmaPosted on 2009-03-26 at 09:45:08ID: 23992431

warturtle
I went ahead and did a windows repair. I can now boot normally. I was also able to install Super AntiSpyware and I'm doing a scan with it now. I haven't yet attached to my network or internet. I'm still afraid of residual poop.

 

by: warturtlePosted on 2009-03-26 at 10:08:14ID: 23992725

Good to see that the machine is normal again. I don't know what it might have been used for before with the HackTool rootkit, but it would also be worth checking a couple of other machine in your network for any possible worm infection or presence of a botnet. TrendMicro have recently released a tool for this called RUBotted, but it is still in Beta phase, so don't know about the reliability of it.  Its available from:

http://www.trendsecure.com/portal/en-US/tools/security_tools/rubotted/overview

I read about it through another thread on Experts Exchange.

 

by: swilmaPosted on 2009-03-26 at 12:10:56ID: 31562031

warturtle is awesome

 

by: warturtlePosted on 2009-03-26 at 12:14:05ID: 23994059

Good to see that the problem is sorted and thanks for the points. I actually owe a big thank you to rpggamergirl, she was the one who introduced me to ComboFix. I had never heard of it before and always used MalwareBytes to resolve any problems and sometimes manually as well. After reading few of her posts, I learnt about this tool.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...