Solved avast: winsxs rootkit detected. help?

IonicRipper

New member
Local time
2:26 PM
Messages
23
Location
Montreal, Canada
The other day my computer started acting very strange, i knew i caught a virus somewhere just not sure where. I decided to go the simple way and just reformat.
After the format and all the updates applied i found my PC ran very poorly. Did a scan with avast! free and found this:

2qitgdt.jpg


Then avast! froze before i could do anything else. Restarted and now it says "access denied"??
What should i do? I was about to format again but decided to ask here before as my comp seems to be running fine for now.
 

My Computer My Computer

Computer Manufacturer/Model Number
Alienware Aurora
OS
Windows 7 Home 64bit
CPU
Intel i7 920 2.67 @ 3.20Ghz
Motherboard
Alienware X58 mATX
Memory
6Gb 1067Mhz DDR3
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Sound Card
Realtek
Monitor(s) Displays
Dell 21.5" HD
Screen Resolution
1920x1080
Hard Drives
500Gb 7200Rpm SATA2
PSU
525 Watts
Case
Alienware
Cooling
Alienware water cooled
Keyboard
Alienware
Mouse
Logitech G500
Internet Speed
30Mb/s

My Computer My Computer

Computer Manufacturer/Model Number
HP Pavillion dv-7 1005 Tx
OS
Win 8 Release candidate 8400
CPU
[email protected]
Memory
4 gigs
Graphics Card(s)
Nvidia 9600M
Sound Card
HD built-in
Monitor(s) Displays
17" Wxga
Screen Resolution
1440x900
Cooling
none
Internet Speed
45Mb down 5Mb up

My Computer My Computer

Computer Manufacturer/Model Number
Homebuilt
OS
Windows 7 Home Premium x64
CPU
Core i7 2600K
Motherboard
Asus P8Z77-V LX
Memory
4GB DDR3 Kingston HyperX
Graphics Card(s)
Gigabyte GTX 670
Sound Card
Realtek HD Audio
Monitor(s) Displays
Delium Monitor
Screen Resolution
1360 x 768
Hard Drives
C: (500GB)
PSU
Corsair 620W
Case
Antec
Cooling
Cooling Master
Keyboard
Logitech
Mouse
Logitech wireless mouse M 505
Internet Speed
60MBPS

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Inspiron 530
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core 2 Duo Processor E8300 @ 2.83GHz
Motherboard
Dell Inc. 0RY007 (Socket 775)
Memory
4.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15)
Graphics Card(s)
Intel(R) G33/G31 Express Chipset Family
Sound Card
Integrated 7.1 Channel Audio
Monitor(s) Displays
Acer G245HQL 23.6" LED(1920x1080@60Hz)
Screen Resolution
1920 x 1080
Hard Drives
Disk 0 HITACHI 1TB OS Installed - Disk 1 HITACHI 1TB For Backups
Keyboard
Dell USB Keyboard
Mouse
Dell Optical USB Mouse
Internet Speed
DSL 10 meg
Antivirus
Symantec(SEP)
Browser
Pale Moon
Well I prefer he first tries my suggestion and the one from zigzag3143
 

My Computer My Computer

Computer Manufacturer/Model Number
Homebuilt
OS
Windows 7 Home Premium x64
CPU
Core i7 2600K
Motherboard
Asus P8Z77-V LX
Memory
4GB DDR3 Kingston HyperX
Graphics Card(s)
Gigabyte GTX 670
Sound Card
Realtek HD Audio
Monitor(s) Displays
Delium Monitor
Screen Resolution
1360 x 768
Hard Drives
C: (500GB)
PSU
Corsair 620W
Case
Antec
Cooling
Cooling Master
Keyboard
Logitech
Mouse
Logitech wireless mouse M 505
Internet Speed
60MBPS

My Computer My Computer

Computer Manufacturer/Model Number
HP Pavillion dv-7 1005 Tx
OS
Win 8 Release candidate 8400
CPU
[email protected]
Memory
4 gigs
Graphics Card(s)
Nvidia 9600M
Sound Card
HD built-in
Monitor(s) Displays
17" Wxga
Screen Resolution
1440x900
Cooling
none
Internet Speed
45Mb down 5Mb up
It seems Malwarebytes didnt find anything


Malwarebytes Anti-Malware 1.60.1.1000
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: v2012.03.02.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
IonicRipper :: MOTHERSHIP [administrator]

02/03/2012 2:55:42 PM
mbam-log-2012-03-02 (14-55-42).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 456884
Time elapsed: 46 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Should i give Hitman a try or will the results be the same?
 

My Computer My Computer

Computer Manufacturer/Model Number
Alienware Aurora
OS
Windows 7 Home 64bit
CPU
Intel i7 920 2.67 @ 3.20Ghz
Motherboard
Alienware X58 mATX
Memory
6Gb 1067Mhz DDR3
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Sound Card
Realtek
Monitor(s) Displays
Dell 21.5" HD
Screen Resolution
1920x1080
Hard Drives
500Gb 7200Rpm SATA2
PSU
525 Watts
Case
Alienware
Cooling
Alienware water cooled
Keyboard
Alienware
Mouse
Logitech G500
Internet Speed
30Mb/s
It seems Malwarebytes didnt find anything


Malwarebytes Anti-Malware 1.60.1.1000
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: v2012.03.02.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
IonicRipper :: MOTHERSHIP [administrator]

02/03/2012 2:55:42 PM
mbam-log-2012-03-02 (14-55-42).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 456884
Time elapsed: 46 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Should i give Hitman a try or will the results be the same?

YESS ! try hitman :p
 

My Computer My Computer

Computer Manufacturer/Model Number
Homebuilt
OS
Windows 7 Home Premium x64
CPU
Core i7 2600K
Motherboard
Asus P8Z77-V LX
Memory
4GB DDR3 Kingston HyperX
Graphics Card(s)
Gigabyte GTX 670
Sound Card
Realtek HD Audio
Monitor(s) Displays
Delium Monitor
Screen Resolution
1360 x 768
Hard Drives
C: (500GB)
PSU
Corsair 620W
Case
Antec
Cooling
Cooling Master
Keyboard
Logitech
Mouse
Logitech wireless mouse M 505
Internet Speed
60MBPS
No luck with Hitman Pro.

I think im gonna do a clean install of Win7 then.
 

My Computer My Computer

Computer Manufacturer/Model Number
Alienware Aurora
OS
Windows 7 Home 64bit
CPU
Intel i7 920 2.67 @ 3.20Ghz
Motherboard
Alienware X58 mATX
Memory
6Gb 1067Mhz DDR3
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Sound Card
Realtek
Monitor(s) Displays
Dell 21.5" HD
Screen Resolution
1920x1080
Hard Drives
500Gb 7200Rpm SATA2
PSU
525 Watts
Case
Alienware
Cooling
Alienware water cooled
Keyboard
Alienware
Mouse
Logitech G500
Internet Speed
30Mb/s

My Computer My Computer

Computer Manufacturer/Model Number
HP Pavillion dv-7 1005 Tx
OS
Win 8 Release candidate 8400
CPU
[email protected]
Memory
4 gigs
Graphics Card(s)
Nvidia 9600M
Sound Card
HD built-in
Monitor(s) Displays
17" Wxga
Screen Resolution
1440x900
Cooling
none
Internet Speed
45Mb down 5Mb up
With that many rootkits I would start new. I would wipe/clean the drive and then do a fresh install. Remember rootkets are mean and at times will hang around.


http://www.sevenforums.com/tutorials/172617-secure-erase-wipe-definition-methods.html
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Thanks for giving a try guys, means a lot to me :)

Did a clean install... Cant get any cleaner then this other then if i bought a new PC lol

Any ideas where i could have got those pesky rootkits? Do you get them like a normal virus or are they caught differently?
 

My Computer My Computer

Computer Manufacturer/Model Number
Alienware Aurora
OS
Windows 7 Home 64bit
CPU
Intel i7 920 2.67 @ 3.20Ghz
Motherboard
Alienware X58 mATX
Memory
6Gb 1067Mhz DDR3
Graphics Card(s)
EVGA GeForce GTX 560 Ti
Sound Card
Realtek
Monitor(s) Displays
Dell 21.5" HD
Screen Resolution
1920x1080
Hard Drives
500Gb 7200Rpm SATA2
PSU
525 Watts
Case
Alienware
Cooling
Alienware water cooled
Keyboard
Alienware
Mouse
Logitech G500
Internet Speed
30Mb/s
before you re-install, try combofix from bleepingcomputer.com DL it on a clean machine to a thumb drive. Rename it, because recent malware knows about it. Also get a utility from that website called rkill. get one of the funky named ones like winlogon.exe, run that, then run combofix (renamed) right off the thumb drive. When done, make sure you scan/clean the thumb drive also...
 

My Computer My Computer

Computer Manufacturer/Model Number
iBuyPower
OS
windows seven
CPU
Phenom II x2 3.1
Motherboard
asus
Memory
4 gigs
Graphics Card(s)
Nvidia GTS 250
Monitor(s) Displays
23in Acre
before you re-install, try combofix from bleepingcomputer.com

   Warning

Do NOT under any circumstances attempt to use ComboFix without specific guidance from a trained malware removal specialist. This software is extremely powerful and you stand a very good chance of easily rendering your system completely unusable.

Every reputable download of ComboFix carries this very explicit warning.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top