Possible root kit found.  Spysweep, blacklight and Rootkit revealer don't agree.

Posted on 2006-05-27
Last Modified: 2008-02-01
A lot of information to post here

I am working on a WinXP Home PC.  The main problem was that the computer functions normally, except for the odd occasion (once or twice per session) that the CPU utilization goes to 100%, and the spysweeper process is the culprit.

- Webroot spy sweeper detected two files as 'possible masked root kits'.  The files were components of a game that was removed previously.  When I go to the folder where the files are stored, I get an error '...not accessible' and then the message 'Not enough storage is available to process this command'.  I can rename the folder where the files are stored, but after clicking on the folder to view the files inside, I get the same error message.  Attempts to delete 'higher up' return the message 'folder not empty.'
When I click on 'Elevator', I get the error message.
I can rename Elevator (or even CARS or ATARI).
If I click on Atari and go 'Delete', it tells me that 'Elevator' is not empty.

- I can reboot in Safe Mode, Command line only and still get the same results when trying to view/access this folder or attempting to do a Delete *.* command in the folder.

- SysInternals RootKitRevealer returned the results of 25792 discrepancies found.  Along with the two files that exist in the above mentioned directory, there is a mash of files like Adobe reader and all it's support files, hundreds of files from Windows, windows\fonts, windows\inf and Windows\System32.  Thousands of files from c:\Program Files\Common files.  Thousands of files in the _restore folder.  Thousands from c:\program files.

- FProt's Blacklight did not find anything suspicious.

- I have tried downloading some third party file managers to erase the two trouble files listed at the start, and no go.  Always get the 'Not enough storage is available' error.

- Next stop is a rebuild, but I wanted thoughts first.



(PS If you think there is another forum where this should be posted, please let me know)
Question by:tnorman
    LVL 47

    Accepted Solution

    When runnning Rootkit Revealer you need to have an idle pc so the result is not polluted with legit entries (like the mentioned thousands of discrepancies)

    If you want to delete the folder, try using Killbox.
    Download Pocket Killbox.
    *Select the "Delete on Reboot" option.


    Assisted Solution

    I have had similar problems removing Spyware/Viruses/Rootkits.  

    Are there registry entries associated with these files?  Can you remove the registry entries in Safe Mode?  Have you determined what is keeping these files running?

    If the file system is NTFS, I would boot using NTFS Pro (or similar) to delete the files.  This has worked for me in the past.  

    Author Comment

    Thanks everyone for their help on this one.  Something was definitely 'off' here, with the 27000 entries being logged.  There were no corresponding (or any, actually) registry entries.  I can't believe that they were all in use, as that would be impossible to have that many files running at the same time (and the computer still functioning 99% normally).


    It seems sometimes that the simplest solution was the easiest one.  It turns out, after several HD checks, that there was corruption on the HD, specifically where those two files were.

    So that, combined with the 'threat' of a possible root-kit, I just replaced the HD and rebuilt.

    Again, thanks for your input on this.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    What Should I Do With This Threat Intelligence?

    Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

    Can I legally transfer my OEM version of Windows to another PC?  (AKA - Can I put a new systemboard in my OEM PC?) Few of us are both IT and legal experts but we all have our own views of Microsoft's licensing rules and how they apply.  There are…
    Can you find a fax from a vendor you saved a decade ago in seconds? Have you ever cursed your PC under your breath during an audit because you couldn’t find the requested statement or driver history?  If you answered no to the first question or yes …
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now