Author Topic: Win32:Rootkit-gen[Rtk]  (Read 3680 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Win32:Rootkit-gen[Rtk]
« on: May 18, 2017, 11:04:13 AM »
So avast detects it everytime I startup windows the files are located in C:\users\Myname avast keeps blocking it and the virus seems to recreate itself Please i need help.

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #1 on: May 18, 2017, 11:06:20 AM »
everytime i run malwarebytes and it freezes and it causes my pc to slow down

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #2 on: May 18, 2017, 11:07:16 AM »
theres is also a weird program running on background powershell.exe

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #3 on: May 18, 2017, 11:09:44 AM »
heres the log

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #4 on: May 18, 2017, 11:19:08 AM »
also in msconfig startup theres a startup called "X" and the file is x.vbs

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #5 on: May 18, 2017, 11:28:34 AM »
so after I restarted my pc the powershell.exe seems gone but avast threat blocked is still giving alerts that there is a new  Win32:Rootkit-gen[Rtk]

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #6 on: May 18, 2017, 11:37:28 AM »
NEW VIRUS FOUND IDP.ARES.GENERIC

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #7 on: May 18, 2017, 11:39:16 AM »
heres all the threats

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #8 on: May 18, 2017, 12:37:17 PM »
new virus is still IDP.ARES.Generic

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37574
  • Not a avast user
Re: Win32:Rootkit-gen[Rtk]
« Reply #9 on: May 18, 2017, 12:56:58 PM »
Have you run Combofix?   

if so why? also attach combofix log

Malware expert is probaly not online before tomorrow



REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #10 on: May 18, 2017, 01:11:27 PM »
I run combo in the morning. But dont worry i fixed it already i used the malwarebytes rootkit tool and it deleted the vbs script which is the reason why it keeps creating the virus if connected to the internet. You can close this now thanks btw :)

REDACTED

  • Guest
Re: Win32:Rootkit-gen[Rtk]
« Reply #11 on: May 18, 2017, 01:13:39 PM »
thats also the reason why it runs the powershell thingy on startup