Author Topic: Help needed: rootkits detected, can't get rid of them, logs corrupted  (Read 2399 times)

0 Members and 1 Guest are viewing this topic.

Ladyssnake

  • Guest
Recently, I have been getting ghost devices on my computer. An icon shows up in the notification area for a split second at a time showing a removable drive when there is no device attached. I detected and deleted several viruses in the last week using a nightly scheduled full system scan. The last 2 detected 3 rootkits, but I received error messages when attempting to repair, move to chest, or delete them.

Running Windows Vista 32 bit.

My system event log has been corrupted and shows nothing after 2009.

My task scheduler also gives an error message saying my task image is corrupt or has been tampered with.

Screenshots are attached. Please tell me how to get rid of these things. Thanks.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help needed: rootkits detected, can't get rid of them, logs corrupted
« Reply #1 on: October 23, 2012, 07:08:21 PM »
The bottom image is related to the McAfee update, so you still have that running on your system

Download and run the removal tool http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe

Then see if you still get the same problems

Then run the logs as shown here http://forum.avast.com/index.php?topic=53253.0

Ladyssnake

  • Guest
Re: Help needed: rootkits detected, can't get rid of them, logs corrupted
« Reply #2 on: October 24, 2012, 07:45:40 AM »
Tried to follow your instructions, got the attached error.  Ghost drive is very active this evening,  shows as disk drive in location zero when I catch it.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help needed: rootkits detected, can't get rid of them, logs corrupted
« Reply #3 on: October 24, 2012, 03:16:52 PM »
If you could run OTL I will use that to remove the job

true indian

  • Guest
Re: Help needed: rootkits detected, can't get rid of them, logs corrupted
« Reply #4 on: October 24, 2012, 06:41:57 PM »
I think avast is finding something running in its sandbox...could clear the contents of avast sandbox and see what are results