1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

need some help with rootkit infection

Discussion in 'Malware and Virus Removal Archive' started by BillB, 2006/01/10.

  1. 2006/01/10
    BillB Lifetime Subscription

    BillB Well-Known Member Thread Starter

    Joined:
    2003/03/18
    Messages:
    750
    Likes Received:
    0
    AVG has been popping up a window on my son's PC for a week or so indicating an infected file avpe32.dll, but I could not find the file anywhere. I did some searching on the AVG forums and found that this file is an indication of a rootkit infection. I did some searching here and found some other threads that suggested downloading and running rootkit revealer. I ran the program and saved the log so that I could post it here in hopes that I can get some help in getting rid of this pest. Any help would be greatly appreciated. Here is the log from rootkit revealer;

    C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf 1/10/2006 7:43 PM 13.97 KB Hidden from Windows API.
    C:\WINDOWS\SYSTEM32\AVPE32.DLL 8/23/2001 12:00 PM 39.10 KB Hidden from Windows API.
    C:\WINDOWS\SYSTEM32\AVPE64.SYS 8/23/2001 12:00 PM 21.30 KB Hidden from Windows API.
    C:\WINDOWS\SYSTEM32\klgcptini.dat 12/6/2005 11:35 AM 0 bytes Hidden from Windows API.
    C:\WINDOWS\SYSTEM32\QZ.DLL 8/23/2001 12:00 PM 39.10 KB Hidden from Windows API.
    C:\WINDOWS\SYSTEM32\QZ.SYS 8/23/2001 12:00 PM 21.30 KB Hidden from Windows API.
    C:\WINDOWS\SYSTEM32\STT82.INI 12/6/2005 11:35 AM 320 bytes Hidden from Windows API.
     
  2. 2006/01/11
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0

  3. to hide this advert.

  4. 2006/01/11
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
  5. 2006/01/11
    BillB Lifetime Subscription

    BillB Well-Known Member Thread Starter

    Joined:
    2003/03/18
    Messages:
    750
    Likes Received:
    0
    Thanks for the replies, I opened a thread in the sysinternals forum and have been provided some suggestions there. I'm going to finish going through them tonight. One thing though, one of the cleanup steps is to turn off system restore. When I try to do this I get the message that system restore has encountered an error trying to enable/disable restore points, reboot the machine and try again. Rebooting doesn't do any good, nor does it work in Safe Mode. Does anyone have any ideas what would cause this?

    I'll post back with steps taken to rid the PC of this pest when I'm done.
     
  6. 2006/01/11
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Bill,

    This is the first time I've seen this, might very well be one of the effects of the infection - thanks for the heads up on that.

    This might be of help:

    How to reinstall SR
    http://bertk.mvps.org/html/tips.html#ReinstallSR

    Also keep in mind that the infection in SR's RP's are inert, and as long as no restore done, they'll not have any affect on the system even though they are reported on. So I would concentrate on cleaning the "live" files first and then go about fixing/cleaning out SR's RP's.

    Regards - Charles
     
    Last edited: 2006/01/11
  7. 2006/01/12
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Arie,
    #6
  8. 2006/01/12
    BillB Lifetime Subscription

    BillB Well-Known Member Thread Starter

    Joined:
    2003/03/18
    Messages:
    750
    Likes Received:
    0
    Thanks Arie, I'll follow up on that one.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.