Poll

What is the best thing to do next, after 14 rootkits attacked W7?

Factory reset to OEM state.
0 (0%)
Let Avast use its might against these rooty ninjas.
1 (100%)
System restore to a week ago (rootkit invasion was today).
0 (0%)
Change HDD, get a new one, and I dunno… get Windows or something.
0 (0%)
Do nothing, absolutely nothing.
0 (0%)

Total Members Voted: 0

Author Topic: 14 Rootkits, Removal Help Needed  (Read 3063 times)

0 Members and 1 Guest are viewing this topic.

Berxerker

  • Guest
14 Rootkits, Removal Help Needed
« on: May 09, 2012, 02:27:28 AM »
Ok so, to start this, I have an ASUS K53SV-B1 Laptop, whose specs. are these:

Intel Core i7 2630QM
Nvidia GT540M
6GB RAM
5'400RPM HDD, 640GB
15.6" Inch Screen
Microsoft Windows 7 Home Premium 64-bit

The problem is, today I felt curious, and ran a scan with Avast! Free Antivirus to detect 14 rootkits in my "winsx" folder. Me, being paranoid over my laptop (because of what it costed) run a boot-time scan, and here I am, waiting at 96% for results.

What happened? Well, yesterday my Microsoft Office trial decided to give up on me, and my dad decided he'd buy today the full student version. I put the laptop away, knowing it won't be exactly safe…

After school, I receive the laptop with a "I tried to get Microsoft Office free, but couldn't. Will try tomorrow". I immediately think *So he may have had used unsafe websites and stuff? Damn…*

I boot the laptop, run a scan immediately to stop at 24% because it "had found 14 rootkits"… I panicked. As Avast said, I am running a boot-time scan to eliminate the rootkits now, and well, I haven't found a single one of them. Not even ONE. A few corrupted ZIP files I always find in there, but nothing. No malware.

Now, I am going even more paranoid with this. Is there anything I can do?

1.) Will System Restore go back to a week before, when laptop was normally operating?
2.) If system restore fails, shall a Factory Reset be?
3.) As my paranoia has taken me this far already, I have no idea what to do. Really, I don't.  Could you help, please?


I have run scans with Windows Defender and Avast, to no help. I have updated Avast's malware definitions and updated the program and nothing yet. I am currently running my SECOND boot-time scan, as I'm paranoid. By the way, before I restarted to use the Avast boot scan, I tried deleting all of the rootkits, which led to a "[5] Access Denied", and whenever I tried to move to safe chest, it would tell me that option wasn't available or something similar… :(

Gargamel360

  • Guest
Re: 14 Rootkits, Removal Help Needed
« Reply #1 on: May 09, 2012, 02:33:40 AM »
No system restore, that can do more harm than good sometimes.

Head here and read>>http://forum.avast.com/index.php?topic=53253.0 , then when you have the logs, post them back in this topic as attachments, someone qualified will review them and tell you what to do next. 

Berxerker

  • Guest
Re: 14 Rootkits, Removal Help Needed
« Reply #2 on: May 09, 2012, 02:46:52 AM »
Sure? I mean, what about factory reset? Is that invincible to rootkits, or am I screwed forever to carrying the worry of not being able to get rid of a ton of rootkits?

I know it's a little bit drastic but, I don't have really important stuff installed.

What do I have in my PC that I care a lot of? Not really anything, I care about the laptop, not what it has, as I haven't placed important information in it.

Yet I have things like:

iTunes
Steam +6/7 Games
2 Games from Amazon.com
Avast
Fraps
Fraps Videos
Some school assignments, still available online, and probably also in my iPad.
Etc…

Gargamel360

  • Guest
Re: 14 Rootkits, Removal Help Needed
« Reply #3 on: May 09, 2012, 02:52:28 AM »
I'm not the expert, but pretty sure there are rootkits that can survive a factory reset by hiding in the MBR (master boot record). 

Berxerker

  • Guest
Re: 14 Rootkits, Removal Help Needed
« Reply #4 on: May 09, 2012, 02:57:36 AM »
Oh god…

Gargamel360

  • Guest
Re: 14 Rootkits, Removal Help Needed
« Reply #5 on: May 09, 2012, 03:33:00 AM »
Well, that is what the thread I pointed you to is for.   The diagnostics will determine what you are infected with and they are more than capable of finding what is wrong and killing it.  Just browse this section of the forum for many examples.   So you are not looking at a bricked PC or anything,  it is just that rootkits can require more than a simple reset to fix.