Author Topic: Malware " rootkit" in temp file every time I turn on the computer  (Read 6447 times)

0 Members and 4 Guests are viewing this topic.

fdarcy6

  • Guest
 I don't know whats happening, everything was fine with my computer until this morning when I turned on my computer to say that there was a malware called " rootkit" in my temp file, please help on how to get rid of it. It happens every time I turn on the computer. HELP!!!! the malware is called "win32:Rootkit-gen"
The Original file names are mc227,mc230, mc241
all the Original Location is at C:\WINDOW\TEMP
the size of the files are all 2560
and all of the virus description is Win32:Rootkit-gen[R.....
Thanks for all help!!!!
« Last Edit: July 25, 2008, 06:47:26 PM by fdarcy6 »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #1 on: July 25, 2008, 07:04:21 PM »
Could be a false positive, could be infected files...
Check other threads about the mc*.tmp files that are opened to discussion.
For instance: http://forum.avast.com/index.php?topic=37358.msg312854#msg312854 and http://forum.avast.com/index.php?topic=37353.0;topicseen
The best things in life are free.

fdarcy6

  • Guest
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #2 on: July 25, 2008, 07:13:02 PM »
I am sorry but what is a false positive? I am totally clueless as to computers, SORRY!! Thanks for the reply

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #3 on: July 25, 2008, 07:15:57 PM »
I am sorry but what is a false positive?
A clean file that is identified as being infected by the antivirus.
So it's not really infected (positive detection), although the antivirus detect it as so (false detection). Does it make sense now?
The best things in life are free.

fdarcy6

  • Guest
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #4 on: July 25, 2008, 07:19:03 PM »
So what do I do in order to stop it from popping up on my computer every time I turn it on?
and what what file should i upload in virustotal and how do i do it?
« Last Edit: July 25, 2008, 07:32:19 PM by fdarcy6 »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #5 on: July 25, 2008, 09:29:25 PM »
So what do I do in order to stop it from popping up on my computer every time I turn it on?
I'm not sure it's a false positive or not...
I suggest:

1. Disable System Restore and reenable it after step 3.
2. Clean your temporary files.
3. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
4. Use SUPERantispyware, MBAM or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
5. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
6. Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.
7. Immunize your system with SpywareBlaster or Windows Advanced Care.
8. Check if you have insecure applications with Secunia Software Inspector.

and what what file should i upload in virustotal and how do i do it?
Two or three of them, one by one, click in the buttons of the www.virustotal.com page.
The best things in life are free.

fdarcy6

  • Guest
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #6 on: July 25, 2008, 10:42:39 PM »
avast! Antirootkit, version 0.9.6
Scan started: Friday, July 25, 2008 4:25:23 PM


Scan finished: Friday, July 25, 2008 4:32:49 PM
Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0

this is just the antirootkit scan and i have disabled system restore and enabled it back and scanned my whole computer, there is no more warnings telling me about detecting a virus, thanks a lot, but i will post a HJT log here later to be sure,Its been a long time since i've done a HJT log so will you explain the steps. Thanks a whole lot!!!!!

fdarcy6

  • Guest
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #7 on: July 25, 2008, 11:00:54 PM »
Should I download the zip file or the exe file for the Hijackthis log?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #8 on: July 25, 2008, 11:22:01 PM »
Should I download the zip file or the exe file for the Hijackthis log?
Never mind... do you have an unzip tool (like IZarc or 7-zip)?
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89667
  • No support PMs thanks
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #9 on: July 25, 2008, 11:30:08 PM »
If you do a forums search for these file names you will see other topics, e.g. some of the links posted by Tech, in some of these it looks like a VPS update has resolved this.

Do a manual iAVS Update, right click the avast 'a' icon, select, Updating, iAVS Update. Once complete, scan the files again and let us know if they are still detected before doing anything else.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

fdarcy6

  • Guest
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #10 on: July 25, 2008, 11:37:33 PM »
Quote
Never mind... do you have an unzip tool (like IZarc or 7-zip)?
NOPE

fdarcy6

  • Guest
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #11 on: July 25, 2008, 11:40:50 PM »
Quote
Once complete, scan the files again and let us know if they are still detected before doing anything else.
What files?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89667
  • No support PMs thanks
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #12 on: July 26, 2008, 01:16:12 AM »
The ones previously detected as infected of course.
Quote from: fdarcy6
The Original file names are mc227,mc230, mc241

There is little point in continuing with additional tasks if the files are no longer detected as infected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

fdarcy6

  • Guest
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #13 on: July 27, 2008, 03:28:51 AM »
Nope they are no longer detected as infected, and I have scanned my computer for rootkit and found nothing, after disabling and enabling system restore, nothing has been detected by avast scanner of a rootkit, so far so good!!! Thanks.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89667
  • No support PMs thanks
Re: Malware " rootkit" in temp file every time I turn on the computer
« Reply #14 on: July 27, 2008, 02:16:43 PM »
You're welcome, looks like it was a false positive that has been corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security