Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

"Resource In Use" Rootkit has stronghold Malware/Antivirus


  • This topic is locked This topic is locked
4 replies to this topic

#1 SnipMaster

SnipMaster

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:02:22 AM

Posted 28 August 2017 - 05:09 PM

OK Im pretty familiar with PC's being in the industry myself for 10+yrs. However I'm more of break/fix and general virus/spyware removal type of person.  However Ive finally came across one i can't shake and have been reading threads after threads of other people who have experienced this issue. Rootkits and windows 10 is fairly new to me. I can find the virus and processes running, however I cant stop or find where it is replicating from.
 

Heres what hasnt worked thus far:

   Kaspersky TDKSSKiller
   Rkill and RKILL iexplorer.exe
   Malwarebytes (none of their software not even mb chk/rootkit)
   SuperAntiSpy
   ComboFix
   Spyhunter
   No Antivirus software - Norton IPE, Kaspersky, Avast, Avira, ESET, TrendMicro Housecall, Bitdefender, Hitman Pro, Emisoft, Windows Security Defender. All of the above programs result give me the same result "Resource In Use".  
 

 

Now for what I've managed to get working and detect issues but not fully get rid of the problem is:
 

1. Spybot Search and Destroy
(program was able to install, but i had to manually install the updates, because the virus was blocking it from updating.Successful Scans)

 

2. RogueKiller
(It was able to scan and locate the files but not delete nor quarantine them)
 

3. Windows Security Defender Offline
(Ive got to say, this was the most successful program to run, however it found very little (3files) and didnt do much else)
 

 4. Zemana Anti Malware (Portable)
(This program was another successful one on scanning and deleting/quarantine what it found, however after reboot the files come back)
 
    So basically those are my PROs/CONs.  Other things I tried, was booting in to safe mode with just command prompt and executing things.  Safe Mode with networking support.  All resulted in the same "Resource In Use".  I've tried creating a rescue disk with Kaspersky and Avast on a Thumb Drive using different USB format utilities, however it seems to not be creating a successful boot.efi for windows to acknowledge in UEFI during boot up.  Not even Hiren's Boot v15.2 is being recognize. I've even directed BIOS to boot from UEFI, and to no avail.   Speaking of Hiren, Ive also tried utilizing Hiren's utilities, and get same results on most in CMD mood. "Resource In Use"
 
 
So there you have it. Thats about it in a nutshell.  Ive been dealing with this for 4days now, and to no avail, I am unable to remove this or really locate this rootkit. Ive never been so stumped. The processes and files i keep seeing replicate themselves are: masse.exe, ravcpdkz.exe, and another i cant rememember the others. But they are pretty recognizable.
 
I can attach some logs from roguekiller, spybot and Farbar, but I cant find an attachment link on this message. Only photos?

 
 
 
Thanks Roger.



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,760 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:22 AM

Posted 28 August 2017 - 05:14 PM

Hi Roger as mentioned in the other topic, to safely remove this rootkit we need a deeper look and n FRST LOG.

Please follow this Preparation Guide and post in a new topic.
Let me know if all went well..
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,760 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:22 AM

Posted 28 August 2017 - 05:35 PM

Now do step 7 please
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#4 SnipMaster

SnipMaster
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:02:22 AM

Posted 28 August 2017 - 05:57 PM

https://www.bleepingcomputer.com/forums/t/655578/resource-in-use-malwareantivirus-cant-delete-rootkit/#

 

Thanks for your help!!



#5 hamluis

hamluis

    Moderator


  • Moderator
  • 55,260 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:01:22 AM

Posted 28 August 2017 - 06:05 PM

Now that you have properly posted a topic in the MRL forum, please pursue that topic.

 

To avoid confusion, I am closing the topic posted in the Am I Infected forum.

 

Louis






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users