Hacktool.rootkit

Status
Not open for further replies.

Eagleowl

Posts: 6   +0
Hi,
I have a problem with my PC. My Symantec Antivirus report this message:

Der lokale Antivirus (Echtzeitschutz) meldet:
Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Hacktool.Rootkit
File: C:\WINNT\services.dll
Location: Quarantine
Computer: LAP3100-002
User: lb49049
Action taken: Quarantine succeeded : Access denied
Date found: Sonntag, 25. Februar 2007 10:19:52

Can anybody help me, please?
 
Hello and welcome to Techspot.

A rootkit is potentially very serious, depending on what other infections may be present on your system.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Download the AVG Antirootkit programme. Disconnect from the net and install the programme, then restart your computer.

Run the programme and click the click "Perform in-depth search." Allow AVG to complete the scan. The AVG scanner will give the "Rootkit path"
* Select the Rootkit Driver by placing a checkmark against it and click "Remove selected items." Next, agree for the terms and conditions that is displayed by AVG and click "OK" to reboot the PC. Reconnect to the net.

Download and run the Blacklight programme. Follow all the instructions carefully.


Then, go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above. Let me know the results of the rootkit scans.

Regards Howard :wave: :wave:

This thread is for the use of Eagleowl only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Hi,
I made all scans and the problem is the same.

Der lokale Antivirus (Echtzeitschutz) meldet:
Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Hacktool.Rootkit
File: C:\WINNT\services.dll
Location: Quarantine
Computer: LAP3100-002
User: lb49049
Action taken: Quarantine succeeded : Access denied
Date found: Dienstag, 27. Februar 2007 07:59:27
 
1. Please download The Avenger by Swandog46 from HERE. Save it to your Desktop and extract it.

2. Download the attached avengerscript.txt and save it to your desktop

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, start The Avenger program by double clicking on its icon on your desktop.

Under "Script file to execute" choose "Load script from file".
Now click on the folder icon which will open a new window titled "open Script File"
navigate to the file you have just downloaded, click on it and press open
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.


You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

Delete all files in AVG Antispyware quarantine.

Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

ieupdater (Microsoft IE Updater)<Disbale the service name and/or the name in brackets.

Close the services window.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

~tmp0374.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

F2 - REG:system.ini: UserInit=userinit.exe,,C:\WINNT\SERVICES.EXE

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = win.edag.de

O17 - HKLM\Software\..\Telephony: DomainName = win.edag.de

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = win.edag.de

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = win.edag.de

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = win.edag.de

O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = win.edag.de

Only fix the above 017 entries, if you don`t recognise the domain.

O20 - Winlogon Notify: partnershipreg - C:\Dokumente und Einstellungen\All Users\Dokumente\Settings\partnership.dll (file missing)

O20 - Winlogon Notify: Uninstall - C:\WINNT\

O23 - Service: ieupdater (Microsoft IE Updater) - Unknown owner - C:\Dokumente und Einstellungen\lb49049.LAP3100-002\~tmp0374.exe (file missing)

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\Dokumente und Einstellungen\lb49049.LAP3100-002\~tmp0374.exe
C:\WINNT\SERVICES.EXE
C:\windows\system32\blank.htm
C:\WINNT\system32\wuavusd.dll

Reboot into normal mode and rehide your protected OS files.

Post a fresh HJT log as well as the c:\avenger.txt and let me know how your system is running.

Regards Howard :)

This thread is for the use of Eagleowl only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Hi Howard,
thanks for your help, but it seems I need your help no more...
I made a mistake and the system doesn´t run. I must format my disk
and install my PC from the start.

Thanks once more
Eagleowl
:eek:
 
Status
Not open for further replies.
Back