Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I have a rootkit on account of installing audio freeware, help


  • This topic is locked This topic is locked
3 replies to this topic

#1 alcopop

alcopop

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 06 August 2017 - 10:25 PM

I'm on Windows 10. I downladed SUPER (http://www.erightsoft.com/Superdc.html) and installed it, immediate regret. I can no longer run some executables instead I am shown a message that says "The Requested Resource is in use." Since it was brought to my attention I disconnected from the internet and am now typing from a different machine. It also deleted my system restore points, and doesn't allow me to turn on the task manager for more than a split second. Some executables run, just not sure why some are allowed and some aren't. It is worth noting that I installed the SUPER software and I manually excluded all the extra bloatware I could in the menus.

Attached Files


Edited by alcopop, 07 August 2017 - 01:32 AM.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,215 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:29 AM

Posted 07 August 2017 - 07:19 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

This is a bad infection. Run this tool in normal mode.

Malwarebytes Anti-Rootkit

Please download Anti-Rootkit BETA and save it to your Desktop.
  • Right-click on the icon and select Run as administrator to start the extraction of the program;
  • Click Yes to accept the security warning that may appear;
  • Click OK to extract it to your Desktop (MBAR will be launched shortly after the extraction);
  • Click on Next, and then on the Update button to let it update its database. Once the database has been successfully updated, click on Next;
  • Make sure all the checkboxes are checked, then click on the Scan button, and let it completes its scan (this can take a while);
  • Once the scan is done, if threats are found, make sure that every item is checked, and click on the Cleanup button (a reboot might be required);
  • After that (and the reboot, if one was required), go back in the mbar folder and look for a text file called mbar-log-TODAY'S-DATE.txt;
  • Please copy and paste the entire content of that log in your next reply;
If you have any problems running either one come back and let me know.
===

If this scan is completed successfully please run the Farbar tool again and post fresh FRST and Addition.txt logs for my review.
Make sure that the box to created a new Addition.txt log is marked.

Let me know what problem persists.

Edited by nasdaq, 07 August 2017 - 07:31 AM.


#3 alcopop

alcopop
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 07 August 2017 - 10:29 PM

Thank you for the attention, I've decided the best course of action would be to wipe the whole drive. I should to that relatively soon, one or two days, so I will inform you if I still have problems that persist through a possible bootkit, IF I can't clean it. If I can, I will tell you. I would have done what you said if my OS let me run executables, it was kinda 50/50 at the very beginning, now nothing that has to do with malware removal will open. Get the same error, The resquested resource is in use. If it's any consolation, those WERE results after mbar had run.


Edited by alcopop, 07 August 2017 - 11:35 PM.


#4 alcopop

alcopop
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 10 August 2017 - 05:19 PM

Been a while but I just ran mbar and the results were clean so I think I'm good.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users