Subscribe to How-To Geek

Welcome to the How-To Geek Forums

We encourage you to register on our forums and post any questions you might have. The How-To Geeks monitor this forum and will respond to your question quickly.

How-To Geek Forums » Windows Vista

Remove Rootkits

(23 posts)
  • Started 1 month ago by COMPIDIOT
  • Latest reply from COMPIDIOT
  • Topic Viewed 464 times


COMPIDIOT
Posts: 75

After my weekly scan by AVG Two Rootkits were found:

C:\Windows\System32\Drivers\axk3uljd.SYS

C:\Windows\system32\Drivers\mchInjDrv.sys

AVG says both are hidden drivers(?)and when I try to remove them through AVG a pop up says :
Some files cannot be healed

Access is denied

I then try to go to the folder but I cant find them because they are hidden :\

Well I tried google for some removal tools but the two I did try didnt do the job and I dont know if they were even legit apps.
So Im hoping someone here can help me find a good preferably free app to help me out.

Thanks in advance.

Posted 1 month ago #
 
Lighthouse
Lighthouse
Posts: 5198

Could you check the spelling of "axk3uljd.SYS" please. I cannot find a mention of it on the web!

Posted 1 month ago #
 
whs
whs
Posts: 4907

Well, there is RootAlyser from the people of Spybot http://forums.spybot.info/showthread.php?t=24185 and then also RootkitRevealer from MS http://technet.microsoft.com/e.....97445.aspx - Maybe you want to try those.

Posted 1 month ago #
 
Lighthouse
Lighthouse
Posts: 5198

And here
http://www.resplendence.com/hookanalyzer

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

@ Lighthouse thats the way its spelled on my AVG scan results.

@ whs and Lighthouse thanks for the links. Will try and get back with results.(Probably later on tonight though(its already 6:16 A.M. here)

Thanks again.

Posted 1 month ago #
 
ScottW
ScottW
Posts: 1682

The name "axk3uljd" is just a random string of letters and numbers generated by the malware. This prevents you from googling on it, but it also means it is almost certainly bad. Lots of new malware uses these jumbled names, so always keep an eye out for them. We have seen this many times before.

Compidiot: did you try deleting the files in safe mode? Have you set the Folder Options to display hidden files and folders?

Posted 1 month ago #
 
raphoenix
raphoenix
Posts: 943

All,

When using Root Kit Revealer, it will sometimes hang a machine while scanning the registry WPA Signing Hash entry. There is a minor bug in the code if I remember correctly.

Regards,
Rick P.

Posted 1 month ago #
 
Lighthouse
Lighthouse
Posts: 5198

Thanks for that Rick :)

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

Okay I tried all 3 suggestions:

The spybot one didnt find any rootkits

The Hook Analyzer came with this error:
Cannot communicate with device.The operation completed successfully
I then press ok and the screen pops up and I psh scan but this pops up:
Wrong version of RSPSC32.sys installed. You may need to reinstall or reboot.

The Root Kit Revealer kept rebooting my system and listed a bunch of HKLM\yada yada yada\(Im guessing registry things(?)
but nothing that I could see of any rootkits :(
I finally had to turn off my computer to stop that because it just kept taking me to the log in screen and after I logged in it would continue the same cycle.

Any other suggestions?

Thanks in advance.

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

@ ScottW

I cant find the files even in safe mode because they are hidden(?) and I dont know what you mean by the folder options.

Please explain

Thanks in advance.

Posted 1 month ago #
 
ScottW
ScottW
Posts: 1682

Sure, sorry I was vague. Go to Control Panel -> Folder Options -> View tab. In the Advanced Settings area, find the Hidden Files and Folders section and choose "Show hidden files and folders". You may also want to temporarily uncheck the box next to "Hide system files and folders" because some malware will disguise itself as system files. When you have deleted the bad files, check that option again.

You can get to Folder Options in safe mode as well. The benefit of safe mode is that it is less likely that the malware can protect itself from erasure or generate a new jumbled letters filename and copy itself there. Some of these can be very tenacious.

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

@ ScottW
Okay I changed those settings but I still cant find those files up there ^^^^^^ in my first post.

BTW Im in safe mode.
I had made a post about safe mode too but I dont know what happened to it(maybe it was in the wrong place?)

Thanks for the input.

Posted 1 month ago #
 
ScottW
ScottW
Posts: 1682

If the files aren't there, maybe they were quarantined by AVG. Does AVG have a quarantine that you can look at? How about checking AVG's activity log to see what it did with the files. If they are gone, that's great. How about this -- initiate a manual scan and see if it comes up clean or still identifies those same files.

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

Well when I try to remove using AVG it says access is denied.

Will scan right now will post results shortly.

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

OK I did a scan and no rootkits were found......but then I remembered I had changed that folder thing so I changed them back to the way they were(do not show hidden files and folders;hide protected operating system files[recommended])and ran another scan and now this:

C:\Windows\system32\Drivers\mchInjDrv.sys
and
C:\Windows\System32\Drivers\a90thxv.SYS
both hidden drivers.:(

Dont know how but that second changed I guess.

Any suggestions?

Thanks for all the help.

Posted 1 month ago #
 
ScottW
ScottW
Posts: 1682

Does your user account have admin authority? AVG should not care whether you have hidden files enabled or disabled. That's just for you the user to see or not see them in File Explorer.

Are you still running in Safe Mode? It looks like what I said has happened -- the malware created a new jumbled letter filename and copied itself again. What did AVG do with the files? Heal, quarantine, or delete?

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

When I try to Remove all unhealed infections the same pop up comes up saying access is denied.

Currently Im not in safe mode(When I try to run the AVG scan in safe mode it starts some line command scan or something like that)that I dont understand.

Yes I am the admin on this computer.

How did it change numbers like that?

Thanks.

Posted 1 month ago #
 
jraparrish
Posts: 75

Since this is a Vista computer, it may be a good idea to enable the Administrator Account and use it to perform the tasks you are suggesting. I have found where only the Administrator account itself has total control over the machine, even when the user account the person is using is a member of the Administrators.

Posted 1 month ago #
 
whs
whs
Posts: 4907

AVG may not do the job. Maybe you want to try the programs we linked earlier. Those are specialized on Rootkits.

Posted 1 month ago #
 
COMPIDIOT
Posts: 75

@ jraparrish I will try that Administrator Account thing and see what happens.

@ whs I tried all three of those apps with no luck :( is there any other apps you can think of?

Thanks for the help

Posted 1 month ago #
 

RSS feed for this topic

Reply »

You must log in to post.

Sponsored Links
Getting Started
About How-To Geek
Popular Articles

Copyright © 2006-2008 HowToGeek.com. All Rights Reserved.