Go Premium for a chance to win a PS4. Enter to Win


Rootkit Agent found with Malwarebytes.  How do I remove it?

Posted on 2009-05-09
Medium Priority
Last Modified: 2013-11-22
Running the latest version of Malwarebytes, it found a file that it identified as a Rootkit.Agent.  It looked like it was successfully removed; however, upon reboot, it was still there.  It is c:/windows/temp/gnijhagv.dat.  When you try to delete the file by itself it gives an access denied error.  I have run several freeware programs against it, as well as Symantec anti-virus.  Can anyone help me get rid of it?  

Following is the malwarebytes log:
Malwarebytes' Anti-Malware 1.36
Database version: 2101
Windows 5.1.2600 Service Pack 3
5/9/2009 8:58:09 PM
mbam-log-2009-05-09 (20-58-09).txt
Scan type: Quick Scan
Objects scanned: 84960
Time elapsed: 6 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\Temp\gnijhagv.dat (Rootkit.Agent) -> Delete on reboot.
Question by:schowning
  • 7
  • 3
  • 2
  • +2

Author Comment

ID: 24346817
I have already tried this.  I ran it in safe mode and it looked like it was deleting, but it didn't.  I've also run dial-a-fix, smsitfraudfix, ccleaner, and combofix.  Any other suggestions?

Expert Comment

ID: 24346858
Have you tried safe mode command prompt or even creating a dos boot disk and browsing to that directory in dos and deleting the file that way?   Does it delete and then recreate itself?


Author Comment

ID: 24346875
I have tried deleting from a command prompt in safe mode.  I can't tell if it really deletes from Malwarebytes.  It looks like it does.  From the command prompt, it says "Access is denied".  I will try to create a dos boot disk and see what happens.
Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

LVL 47

Expert Comment

ID: 24346922
Use combofix and if it won't remove during its first run, we should be able to remove it using its script function, just show us the logfile.

Please download ComboFix by sUBs:

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:

Author Comment

ID: 24347038
I ran combofix earlier and it couldn't find any problems.  I couldn't get it to run in safe mode so I ran it from a normal startup.  Attached is the log files.   Thanks for your help.

Author Comment

ID: 24348738

Upon running unlocker, I get a message that says "the object could not be deleted.  Do you want to perform the requested command at next reboot?"  When I choose yes and reboot, the file is still there.

Expert Comment

ID: 24348830
so try after reboot.. what about other softwares???

Author Comment

ID: 24348888

i did reboot and the file is still there.  actually i rebooted several times.  as stated above, I've also run dial-a-fix, smsitfraudfix, ccleaner, and combofix.

Expert Comment

ID: 24349174
so do than temp install xp in other partition and then remove if u dont want to format ur c drive...

or reinstall ur pc

Author Comment

ID: 24349246
thanks, althakar.  but i'm trying to avoid a reinstall.  perhaps someone else can offer a suggestion?
LVL 16

Expert Comment

ID: 24355686
Have you tried using FileAssassin from within MalwareBytes?? Try to use that to delete the file. Just browse to where the file is and it will attempt to delete it.

Secondly, I am going to suggest that you scan with Kaspersky Online Scanner based at: http://www.kaspersky.co.uk/virusscanner . Let us know, what you find in this scan. This virus scanner will not remove viruses but will let us know of what is in there.
LVL 47

Accepted Solution

rpggamergirl earned 2000 total points
ID: 24383813
Combofix should be able to delete those baddies.

Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:



3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
Please attach the result of the Combofix run.

Author Closing Comment

ID: 31579862
Thanks!  This worked.

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

An introduction to the wonderful sport of Scam Baiting.  Learn how to help fight scammers by beating them at their own game. This great pass time helps the world, while providing an endless source of entertainment. Enjoy!
If you are like me and like multiple layers of protection, read on!
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

927 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question