Author Topic: Sophos Anti-Rootkit. Rootkit Detected [Solved]  (Read 12012 times)

0 Members and 1 Guest are viewing this topic.

Probzzie

  • Guest
Sophos Anti-Rootkit. Rootkit Detected [Solved]
« on: November 27, 2010, 05:09:26 AM »
Ok there are a number rootkits detected but before proceeding any farther I must know what I should do
I need to also know if these are real or just false positives.

C:\Users\Kyle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content IE. 5\T3XMIYOH and then a huge url, this is found like 30 times

Also SPTD.sys in the system32 folder is also noted on here as a rootkit. Is this program legit? Should I be worried or listening to this?
« Last Edit: November 27, 2010, 04:34:58 PM by Bigbear_0488 »

Probzzie

  • Guest
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #1 on: November 27, 2010, 05:14:55 AM »
This is the log so far

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #2 on: November 27, 2010, 08:38:23 AM »
Ok there are a number rootkits detected but before proceeding any farther I must know what I should do
I need to also know if these are real or just false positives.

You should ask this question to the Sophos guys... ;)
Everything in 'Temporary Internet Files' can be deleted.
Best is to run CCleaner. http://www.piriform.com/
You can recheck the other files at http://www.virustotal.com/
asyn

W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

SafeSurf

  • Guest
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #3 on: November 27, 2010, 09:06:59 AM »
Best is to run CCleaner. http://www.piriform.com/
In addition to running CCleaner, you can also do the following for deleting temp. internet files related to malware:

Download TFC by OldTimer to your desktop.

http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/
·   Please double-click TFC.exe to run it.  (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
·   It will close all programs when running, so make sure you have saved all your work before you begin.
·   Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.  Let it run uninterrupted to completion.
·   Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

In addition, you can also run an Avast Boot-time scan since you have a 32-bit machine.  Any infected items put in the Virus Chest where they will be safe.  You can upload them to Avast for analysis during the next update of definitions.  But follow the above posted suggestion first of uploading them to Virus Total (VT) prior to sending to Avast.  Thank you.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #4 on: November 27, 2010, 03:15:52 PM »
@ Bigbear_0488
Why did you feel the need to run this program, it isn't something you run on a regular basis, but for a specific purpose ?

You do know avast does a rootkit scan 8 minutes after boot don't you ?

Were you or had you been on-line playing a game recently as given the reference to Game in the path, emo=D;u=gen-game when you ran this ?

Not to mention the listing isn't saying this is a rootkit, but an Unknown Hidden File, there is a big difference.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Probzzie

  • Guest
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #5 on: November 27, 2010, 03:34:37 PM »
Ok no I was unawre that Avast scanned for rootkits.... The only thing i found a little weird is when I tried to look the folder up (Temporary Internet Files) It didn't even exist.
I must plead the fifth as I randomly scanned this myself. I thought Rootkit scans could be excerised as part of my regular security check.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #6 on: November 27, 2010, 03:36:57 PM »
Sptd.sys is part of your CD emulator and is legit


Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #7 on: November 27, 2010, 03:42:58 PM »
Ok no I was unawre that Avast scanned for rootkits.... The only thing i found a little weird is when I tried to look the folder up (Temporary Internet Files) It didn't even exist.
I must plead the fifth as I randomly scanned this myself. I thought Rootkit scans could be excerised as part of my regular security check.

When you start digging deep, looking for honey, don't be surprised when you find bees ;D

Or rather use tools that may dig up something which you don't understand as if you take a wrong decision it could do serious harm to your system, as in what essexboy mentioned.

If you are going to run these type of scans, it may be best to clear out temp files with ccleaner, etc. before running the scan.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Probzzie

  • Guest
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #8 on: November 27, 2010, 03:48:10 PM »
I understand. CCleaner was just ran, the folder these temp files are in doesn't exist. I tried going to the directory but it wasnt available. How did it find these files in a folder non existing?
I like that line

When you start digging deep, looking for honey, don't be surprised when you find bees ;D


[/quote]
Beautiful way of putting it~

« Last Edit: November 27, 2010, 04:00:57 PM by Bigbear_0488 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #9 on: November 27, 2010, 03:55:11 PM »
1. Ok no I was unawre that Avast scanned for rootkits....
2. The only thing i found a little weird is when I tried to look the folder up (Temporary Internet Files) It didn't even exist.

1. Now you know. ;) Btw, the rootkit scan done at every startup is a fast one, a complete rootkit scan can be done, if you add it to a custom scan with avast.
2. It exists, but you can't see it, if your settings are on default for your system. ;)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #10 on: November 27, 2010, 03:58:49 PM »
Beautiful way of putting it~

+1
Dave can get rather poetic, sometimes...! :)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Probzzie

  • Guest
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #11 on: November 27, 2010, 04:02:04 PM »
No they are not default setting though. I have Show hidden files and folders checked off.

Probzzie

  • Guest
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #12 on: November 27, 2010, 04:07:34 PM »
Thank you for the information on the SPTD.sys essexboy.

Probzzie

  • Guest
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #13 on: November 27, 2010, 04:21:14 PM »
So before running the temp file remover can I just use sopho's to delete the temp files it found?
One other thing, when or how would I or anyone know when is the time to run an anti-rootkit program? Since I made a boo boo I can learn from it :)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Sophos Anti-Rootkit. Rootkit Detected
« Reply #14 on: November 27, 2010, 04:29:44 PM »
TFC will clear all your temp files - so no need to use sophos to kill them

A rootkit scan is a last resort when the system slows down or just generally misbehaves  ;D