Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to remove a possible rootkit?

Status
Not open for further replies.

pepsiaddict

Technical User
Nov 15, 2005
8
US
My brother seems to have acquired a pretty nasty piece of malware on his PC ... was wondering if someone might have run into this before and could help me solve the problem.

*** Symptoms ***
Constant pop-up ads, every few minutes and immeadiate when some webpages are opened.

*** Troubleshooting ***
Did the usual ... run AdAware and Spybot ... found multiple instances of spyware, cleaned them all ... both utilities now only return normal cookies in their results. However, the pop-ups continued.

Ran a full System Scan using Symantec Anti-Virus using the latest virus definitions. Nothing was found. The pop-ups continued.

Checked all the places in the registry that a process could start from at boot, removed everything that shouldnt be there. Rebooted. The pop-ups continued.

Ran the Microsoft Malware Detector for November, it found nothing. The pop-ups continued.

Ran the "Rootkit Revealer" available from Sysinternals and discovered 3533 files that it claims are hidden from the the Windows API ... including:

These registry keys:
HKLM\SOFTWARE\CtPVnACFLU5D
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_FLTDSVR
HKLM\SYSTEM\ControlSet001\Services\FltdSvr

These files:
C:\Program Files\Vene inc\ace.dll
C:\Program Files\Vene inc\data.bin
C:\Program Files\Vene inc\iersrpcn.exe
C:\Program Files\Vene inc\t2enetpp.exe
C:\Program Files\Vene inc\WinGenerics.dll
C:\Program Files\Vene inc\Cache\*.* (there are 3508 randomly named files hidden in this hidden directory)
C:\Program Files\Vene inc\Cache\dns
C:\Program Files\Vene inc\Cache\index
C:\WINDOWS\system32\drivers\waniaide.sys
C:\WINDOWS\system32\mgmieftp.exe

So basically I know there is a problem with the system and that there is a good chance that a rootkit was installed, but I dont have a clue how to remove it.

To compound the problem the computer is at school with my brother in Pennsylvania (I am in New York) and he isnt very computer savy ... so most of the troubleshooting has to be done through a RealVNC connection.

Anyone have any ideas? I am at a total loss.

Thanks in advance,

~Matt

 
I use AdawareSe free addition in conjunction with Ccleaner and had good luck with it.

Bo

Kentucky phone support-
"Mash the Kentrol key and hit scape."
 
Update:

Ran Microsoft Anti-Spyware ... it found a piece of spyware called "Adware.cmdService" ... something we thought we had already cleaned. Its totally removed now, however the problem is still persisting. The hidden files I found with Rootkit Revealer are still there.

Ran the too bcastner recommended, it didnt find anything.

Ran spybot again, it still didnt find anything.

Did check his anti-virus history and found a trojan (Trojan.ByteVerify) that it found on 11/12 but it claims was "deleted" ... he said 11/12 is the time it started happening. I also found several instances of MHTMLRedir.Exploit at around the same time in the history ... it claims that all but one of those was deleted, but one instance was "Left Alone". I think that might be what did it.

He also apparently hasnt done windows updates since WinXP SP2 was installed ... I am going to fix that issue, but it doesnt solve whats going on now. *shrug*
 
Also this might be worth helping on some files, run sfc from command prompt and while your updating the computer might use this link below to make a sp2 disc.


Also of spyware removers the best ive found in my opinion is spyware doctor, its not free but to see if it would do you any good you can download it and run a test scan and see if it finds anything.



Also a free online scan might even do some good. Run this in safe mode with networking if possible to avoid as many problems as you can.


See if this stuff helps any.
 
Some ad-ware producers do actually provide tools to remove their own stuff, if you ask them. Do a search for "Vene inc" and see whether their website has any removal tools. If it does - and if you trust them! - it may fix the problem for you.

Nelviticus
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top