Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit infection please help [Moved]


  • Please log in to reply
3 replies to this topic

#1 jonlyons

jonlyons

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:27 AM

Posted 30 August 2009 - 03:48 AM

Hi All
I'm new to this site so please go easy on me :thumbsup:

I think that i have been infected with that rootkit that is described on the first page:

'When AntiSpy Protector 2009 is installed on your computer it looks like every other rogue. It shows fake security alerts, displays fake scan alerts, and is a general nuisance. It is only when you try to remove this malware that you notice that your programs no longer work. While testing this program, I noticed that any program I ran to remove this malware was terminated, and then when I tried to run it again, I was told I did not have permission'

I do not have AntiSpy Protector installed but i am getting fake security alerts and when i try to run a program to remove it the program is terminated, so far i have tried:

ccleaner - which completed
and these that get terminated:
superantispyware
malwarebytes
rootrepel
mgtools
combofix
rootrepel
hijackthis

I am running IE7 but i am unable to connect to any website. i used to get a message in the browser (something like page unavailable) but i cannot recreate it now, IE just terminates when after i have typed in the url and pressed enter. I also occasionally get an error messages when i try to run a program (like IE for example) the error refers to a memory error, i have also just had another blue screen.

My computer is a Sony Vaio VGN-SZ61WN running Vista Business SP2. This started the other night, i had a message appear that said i was infected, i got a blue screen and as the laptop rebooted it installed SP2.

I am running Kaspersky Anti-Virus 6.0 for Windows Workstations.

If you need anymore information i will do my best to get it for you. please help

Cheers
Jon

BC AdBot (Login to Remove)

 


#2 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,946 posts
  • ONLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:11:27 PM

Posted 31 August 2009 - 11:50 PM

As no logs have been posted, I am shifting this topic from the specialized HiJack This forum to the Am I Infected forum.

==>PLEASE DO NOT NOW POST LOGS<== unless a log is specifically requested.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#3 jonlyons

jonlyons
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:27 AM

Posted 14 September 2009 - 05:36 AM

please ignore this post, i have reloaded my pc.
Cheers
Jon

#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,394 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:27 PM

Posted 14 September 2009 - 08:18 AM

Sometimes that is the best solution.


Tips to protect yourself against malware and reduce the potential for re-infection:Keep Windows and Internet Explorer current with all critical updates from Microsoft which will patch many of the security holes through which attackers can gain access to your computer. If you're not sure how to do this, see Microsoft Update helps keep your computer current.

Avoid gaming sites, porn sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs (i.e. Limewire, eMule, uTorrent). They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Malicious worms, backdoor Trojans IRCBots, and rootkits spread across P2P file sharing networks, gaming, porn and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans, and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.Keeping Autorun enabled on USB (pen, thumb, jump) and other removable drives has become a significant security risk due to the increasing number of malware variants that can infect them and transfer the infection to your computer. To learn more about this risk, please read:Many security experts recommend you disable Autorun asap as a method of prevention. Microsoft recommends doing the same.

...Disabling Autorun functionality can help protect customers from attack vectors that involve the execution of arbitrary code by Autorun when inserting a CD-ROM device, USB device, network shares, or other media containing a file system with an Autorun.inf file...

Microsoft Security Advisory (967940): Update for Windows Autorun

• Finally, if you need to replace your anti-virus, firewall or need a reliable anti-malware scanner please refer to:
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users