TechSpot

Hacktool.rootkit

By Eagleowl
Feb 25, 2007
  1. Hi,
    I have a problem with my PC. My Symantec Antivirus report this message:

    Der lokale Antivirus (Echtzeitschutz) meldet:
    Scan type: Realtime Protection Scan
    Event: Virus Found!
    Virus name: Hacktool.Rootkit
    File: C:\WINNT\services.dll
    Location: Quarantine
    Computer: LAP3100-002
    User: lb49049
    Action taken: Quarantine succeeded : Access denied
    Date found: Sonntag, 25. Februar 2007 10:19:52

    Can anybody help me, please?
     
  2. Eagleowl

    Eagleowl TS Rookie Topic Starter

    Thanks, I now, but I feel better whitout it o:)
     
  3. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    A rootkit is potentially very serious, depending on what other infections may be present on your system.

    Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

    If after reading the above, you wish to clean your system, do the following.

    Download the AVG Antirootkit programme. Disconnect from the net and install the programme, then restart your computer.

    Run the programme and click the click "Perform in-depth search." Allow AVG to complete the scan. The AVG scanner will give the "Rootkit path"
    * Select the Rootkit Driver by placing a checkmark against it and click "Remove selected items." Next, agree for the terms and conditions that is displayed by AVG and click "OK" to reboot the PC. Reconnect to the net.

    Download and run the Blacklight programme. Follow all the instructions carefully.


    Then, go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above. Let me know the results of the rootkit scans.

    Regards Howard :wave: :wave:

    This thread is for the use of Eagleowl only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  4. Eagleowl

    Eagleowl TS Rookie Topic Starter

    Hi,
    I made all scans and the problem is the same.

    Der lokale Antivirus (Echtzeitschutz) meldet:
    Scan type: Realtime Protection Scan
    Event: Virus Found!
    Virus name: Hacktool.Rootkit
    File: C:\WINNT\services.dll
    Location: Quarantine
    Computer: LAP3100-002
    User: lb49049
    Action taken: Quarantine succeeded : Access denied
    Date found: Dienstag, 27. Februar 2007 07:59:27
     
  5. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    1. Please download The Avenger by Swandog46 from HERE. Save it to your Desktop and extract it.

    2. Download the attached avengerscript.txt and save it to your desktop

    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by double clicking on its icon on your desktop.

    Under "Script file to execute" choose "Load script from file".
    Now click on the folder icon which will open a new window titled "open Script File"
    navigate to the file you have just downloaded, click on it and press open
    Now click on the Green Light to begin execution of the script
    Answer "Yes" twice when prompted.

    4. The Avenger will automatically do the following:

    It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    On reboot, it will briefly open a black command window on your desktop, this is normal.
    After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.


    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

    Delete all files in AVG Antispyware quarantine.

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    ieupdater (Microsoft IE Updater)<Disbale the service name and/or the name in brackets.

    Close the services window.

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    ~tmp0374.exe

    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

    F2 - REG:system.ini: UserInit=userinit.exe,,C:\WINNT\SERVICES.EXE

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = win.edag.de

    O17 - HKLM\Software\..\Telephony: DomainName = win.edag.de

    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = win.edag.de

    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = win.edag.de

    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = win.edag.de

    O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = win.edag.de

    Only fix the above 017 entries, if you don`t recognise the domain.

    O20 - Winlogon Notify: partnershipreg - C:\Dokumente und Einstellungen\All Users\Dokumente\Settings\partnership.dll (file missing)

    O20 - Winlogon Notify: Uninstall - C:\WINNT\

    O23 - Service: ieupdater (Microsoft IE Updater) - Unknown owner - C:\Dokumente und Einstellungen\lb49049.LAP3100-002\~tmp0374.exe (file missing)

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    C:\Dokumente und Einstellungen\lb49049.LAP3100-002\~tmp0374.exe
    C:\WINNT\SERVICES.EXE
    C:\windows\system32\blank.htm
    C:\WINNT\system32\wuavusd.dll

    Reboot into normal mode and rehide your protected OS files.

    Post a fresh HJT log as well as the c:\avenger.txt and let me know how your system is running.

    Regards Howard :)

    This thread is for the use of Eagleowl only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  6. Eagleowl

    Eagleowl TS Rookie Topic Starter

    Hi Howard,
    thanks for your help, but it seems I need your help no more...
    I made a mistake and the system doesn´t run. I must format my disk
    and install my PC from the start.

    Thanks once more
    Eagleowl
    :eek:
     
  7. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    What mistake did you make?

    Regards Howard :)
     
  8. Eagleowl

    Eagleowl TS Rookie Topic Starter

    I run a program "pcwcleaner" from a PC-World DVD and I lost all *.dll and system
    files. :eek:(
     
  9. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    I`m sorry to hear that.

    Good luck with the reformat.

    Regards Howard :(
     
  10. Eagleowl

    Eagleowl TS Rookie Topic Starter

    Thanks once more for your help and time.

    Eagleowl
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...