Avast WEBforum

Other => Viruses and worms => Topic started by: xblazingpig on June 20, 2009, 03:29:34 AM

Title: Trojans & Rootkit from System (Drivers) in chest - delete or not?
Post by: xblazingpig on June 20, 2009, 03:29:34 AM
Avast was scanning my memory when it was opening and found a rootkit; trojans were found via boot-time scan Avast. They were immediately put in the virus chest.


(http://i44.tinypic.com/2ldvscz.jpg)

I use Windows XP Home Edition, SP3. RustNT is a rootkit.

So - should I delete the above infected files or not? Or how do I remove them? As I had used GMER to detect the rootkit two weeks ago. I deleted the rootkit service. After that, GMER Rootkit Detector and Remover (gmer.net) didn't find it. But now the same rootkit file is back. How do I delete it for good? Help is much appreciated.

PS: I don't think I have a F: drive. I have local disks C: and E:, and Floppy Drive A: and DVD-RAM Drive D:.
Title: Re: Trojans & Rootkit from System (Drivers) in chest - delete or not?
Post by: DavidR on June 20, 2009, 04:27:24 AM
There is no rush to delete anything from the chest, a protected area where it can do no harm. Anything that you send to the chest you should leave there for a few weeks. If after that time you have suffered no adverse effects from moving these to the chest, scan them again (inside the chest) and if they are still detected as viruses, delete them.

What is your firewall ?
It should be capable of blocking unauthorised outbound Internet Connections. - What is your firewall ?

Whilst the windows XP firewall is usually good at keeping your ports stealthed (hidden) it provides no outbound protection and you should consider a third party firewall.

The F: was probably a USB Flash drive when connected to your system ?
So your flash drive might well be infected and the batch file, 2fiy.bat, could have been what brought in more guests.

If you haven't already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).

 
Don't worry about reported tracking cookies they are a minor issue and not one of securty, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie (http://en.wikipedia.org/wiki/HTTP_cookie).
Title: Re: Trojans & Rootkit from System (Drivers) in chest - delete or not?
Post by: spg SCOTT on June 20, 2009, 03:02:46 PM
{SNIP}
PS: I don't think I have a F: drive. I have local disks C: and E:, and Floppy Drive A: and DVD-RAM Drive D:.

Usually the F: is associated with external media, i.e. a memory stick (F is the drive letter for my memory stick on the PC)
Did you have anything like this plugged in during the boot scan?

You may need to use one of these:
Let your USB drive plugged and run Autorun Eater (http://www.softpedia.com/get/Security/Secure-cleaning/Autorun-Eater.shtml) or Flash Disinfector (http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe), allowing them to clean up all drives. They would create hidden folders named autorun.inf in each partition and every USB drive plugged in when you ran it. These folders protect your drives from future infection. After that, reboot your computer.

-Scott-

EDIT:Sorry, I missed that you'd already answered that part, DavidR