confusedsoul
New member
Hello Security Gurus,
I think I am infected with a rootkit virus. My antivirus McAfee, Spybot, Malewarebytes all wont start. When I try to run them, it gives me a message that
"Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item."
I tried to follow the post as advised by Ken545
http://forums.spybot.info/showthread.php?t=52099
I did the following steps successfully but got stuck eventually. Here are the steps that I followed to the "T".
1) I downloaded RootRepeal, Win32kDiag, TFC, exeHelper, ComboFix (Saved it as another name on the desktop), and the 3 dds files.
2) I ran RootRepeal with the options suggested in the mail viz-a-viz
Drivers
Processes
SSDT
Hidden Services.
and I generated the report. (I shall post all the reports in subsequent posts so that its separated out and easier to read).
3) I ran Win32Diag and generated a report.
4) I did Start, Run and entered "%userprofile%\desktop\win32kdiag.exe" -f -r and ran the report and saved the report.
5) Thereafter I ran exeHelper and saved the report.
6) Then i followed the instructions and turned off the Antivirus programs, AVG and McAfee and shutdown pctools.
7) Here is where I got stuck.
I ran ComboFix and it said that a RootKit has been detected and I need to reboot, so I said Ok, it did reboot my PC but upon starting the ComboFix opens up and gives a message that Grep is invalid command and after that its tries to create a system restore point and then it vanishes.
This is similar to any spyware that when installed it kills the process in about 2 seconds or so.
So I was not able to run combo fix.
I am not able to proceed.
I was hoping that if I followed the instructions to the"T" of any of the security Guru's I might not need to open a new thread and trouble anyone, however, I am stuck and do need assistance.
If someone can help me, I would really appreciate it very much.
I have to go into work for the day and will be back in the evening (EDT) and will pick up from here.
In the subsequent replies to this post I will post all the logs so that one can read them.
Thanks in advance,
Kind Regards.
ConfusedSoul.
I think I am infected with a rootkit virus. My antivirus McAfee, Spybot, Malewarebytes all wont start. When I try to run them, it gives me a message that
"Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item."
I tried to follow the post as advised by Ken545
http://forums.spybot.info/showthread.php?t=52099
I did the following steps successfully but got stuck eventually. Here are the steps that I followed to the "T".
1) I downloaded RootRepeal, Win32kDiag, TFC, exeHelper, ComboFix (Saved it as another name on the desktop), and the 3 dds files.
2) I ran RootRepeal with the options suggested in the mail viz-a-viz
Drivers
Processes
SSDT
Hidden Services.
and I generated the report. (I shall post all the reports in subsequent posts so that its separated out and easier to read).
3) I ran Win32Diag and generated a report.
4) I did Start, Run and entered "%userprofile%\desktop\win32kdiag.exe" -f -r and ran the report and saved the report.
5) Thereafter I ran exeHelper and saved the report.
6) Then i followed the instructions and turned off the Antivirus programs, AVG and McAfee and shutdown pctools.
7) Here is where I got stuck.
I ran ComboFix and it said that a RootKit has been detected and I need to reboot, so I said Ok, it did reboot my PC but upon starting the ComboFix opens up and gives a message that Grep is invalid command and after that its tries to create a system restore point and then it vanishes.
This is similar to any spyware that when installed it kills the process in about 2 seconds or so.
So I was not able to run combo fix.
I am not able to proceed.
I was hoping that if I followed the instructions to the"T" of any of the security Guru's I might not need to open a new thread and trouble anyone, however, I am stuck and do need assistance.
If someone can help me, I would really appreciate it very much.
I have to go into work for the day and will be back in the evening (EDT) and will pick up from here.
In the subsequent replies to this post I will post all the logs so that one can read them.
Thanks in advance,
Kind Regards.
ConfusedSoul.