CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Please help me remove my rootkit

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
UnLucky

Guest
IP: 75.39.*.*






PostPosted: Fri Feb 01, 2008 5:21 pm    Post subject: Please help me remove my rootkit
Reply with quote

I am dumb with pc's.. pls add my msn and help me! MSN removed by Moderator. im only 15 and just got a pc! pls help im a desperate girl who wants to play her world of warcraft without FEAR! i hate these damd poopie pop ups. i see how to remove but .. gah HELP PLS. someone with a heart. Shocked

the dam thing is called Rootkit.angent

Back to top
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Feb 01, 2008 6:27 pm    Post subject:
Reply with quote

1. We do not provide any private assistance via IM, email or Private Messaging.

2. How do you know you have "rootkit.angent"? Please post whatever log is telling you that. Do not post the log as an attachment. Open it with Notepad, go to the Format menu and uncheck Word Wrap, then copy and paste it into a post to this topic.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
UnLucky

Guest
IP: 76.250.*.*






PostPosted: Sat Feb 02, 2008 12:57 am    Post subject: ok sorry!
Reply with quote

Well i reinstalled my zone alarm suite, AVG, and some other stuff..

Malwarebytes' Anti-Malware 1.01
Database version: 309

Scan type: Full Scan (A:\|C:\|)
Objects scanned: 27799
Time elapsed: 9 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR (Trojan.DNSChange) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE (Trojan.Downloader) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\drivers\core.cache.dsk (Malware.Trace) -> No action taken.

i think i removed all but "Rootkit.win32.agent" zone alarm keeps poping up saying remove.. then rename.. then remove on reboot. but it wont go away.

please help i am not very good at this stuff. sorry i posted my e-mail! Sad

Back to top
IP: 75.39.*.*

Guest






PostPosted: Sat Feb 02, 2008 7:06 am    Post subject:
Reply with quote

Virus Name: Rootkit.Win32.Agent.to

Date Detected: 16 Jan 2008 05:21:00 +0300

this is only thing left.. it opens IE pages. and nothing i try removes it. Embarassed

Back to top
fatdcuk

MIRT Hunter
Premium Member

Joined: Oct 31, 2006
Posts: 2986
Location: Uk
MIRT Premium

PostPosted: Sat Feb 02, 2008 10:09 am    Post subject:
Reply with quote

Try the free version of the following botkiller as it ha a strong ARK capability Cool

It took out C:\WINDOWS\system32\drivers\core.cache.dsk

for AP on this topic yesterday>>>
http://forums.superantispyware.com/viewtopic.php?t=1181

HTH:)


_________________
Malware hunter....Got Bot ?
http://www.castlecops.com/f269-Malware_Listserv.html
Back to top
View users profile Send private message Visit posters website
UnLucky

Guest
IP: 75.39.*.*






PostPosted: Sat Feb 02, 2008 10:28 am    Post subject:
Reply with quote

Hi fatdcuk i will try it.. but i already got everything off my pc xcept "Rootkit.Win32.Agent.to" or Rootkit.Agrent as spy doctor pro reads it. i think its impossible to remove!! i found it is NOT a keylogger but a mailware so i am glad i can atleast play my world of warcraft without fear! BUT id really like help on how to remove this crappy thing.

Back to top
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Sat Feb 02, 2008 4:33 pm    Post subject:
Reply with quote

You are correct, your system is infected, and with multiple ones at that. This does not need to be dealt with here in this forum, it can be dealt with quite well in our HJT forum. To get started, I recommend that you follow CastleCops' Malware Removal and Prevention procedure, a new system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you. If they determine that you do have a rootkit that requires our assistance, you will then be referred back to this forum for more help. This way, you can have your system comprehensively and systematically cleaned of all malware and rootkits if there are any.

NOTE: You MUST be a member here to receive help in our HJT forum. Please join, it is completely free, before you try to post in the HJT Forum.

You might also want to read this to learn more about rootkits:

http://wiki.castlecops.com/Rooting_Out_the_Dangers:_Rootkit_Removal_for_Beginners


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer