Jump to content

Got Rootkited

renasance

Hi everyone. I think I got rootkited. It all started when I torrent something fishy (I know it was dumb to trust but I needed it that time, so yeah). Anyways, I noticed my system slowed down. And from time to time hangs on me and go BSOD. 

I tried a few things to get my laptop back to it's former stat.
1.) Doing a full scan with windows defender. (And yeah, windows defender is my only anti virus) but cant finish coz it always hangs up and goes BSOD. Maybe because of the virus.

2.) Doing system restore inside desktop. But cant open the the window for system restore. Waited for an hour after clicking, still didnt run. 

          a.) Cant do it also in safe mode, still cant access system restore.

          b.) Troubleshooting before startup, when I acessed the restore point there too system says I dont have a restore point. But I have 5 restore points, as far as I can remember. Also tried the                       Refresh option. It said it needs a boot up media. Before it doesnt need it right? Correct me if Im wrong.

3.) And I also have dual boot linux. But when I adjust the boot priorities again so that the GRUB will start first, the GRUB doesnt appear. I dont know why. 

 

Side questions: 

Gonna try doctor web live usb scanning, is it advisable? I cant run the installation in my pc. Need another one for this. Maybe again because of the virus. 

 

Heres some processes in my task manager that wasnt there before. 

 

 

thistoo.PNG

idk.PNG

wpm.PNG

Link to comment
Share on other sites

Link to post
Share on other sites

Well you can try right clicking those processes and going to file location. Try ending the process and immediately deleting the folder. If that doesn't work, continue ending processes until it does. If that still does not work (it's likely) download and run Malwarebytes to check for known malware. Reboot. If there's still an issue, look into a professional virus removal service, or wipe and reinstall.

 

Rootkits are very difficult to get rid of, lets just hope you have a simple virus.

"Although there's a problem on the horizon; there's no horizon." - K-2SO

Link to comment
Share on other sites

Link to post
Share on other sites

Run an AV Rescue Disk. Most AV companies provide images you can download then create a bootable USB or DVD. The system boots off the rescue disk so no malware can be running.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, dj_ripcord said:

download and run Malwarebytes to check for known malware.

Amendment, get Malwarebytes Chameleon edition which (I don't think) requires an install and is also the self-protecting version they made.

Join the Appleitionist cause! See spoiler below for answers to common questions that shouldn't be common!

Spoiler

Q: Do I have a virus?!
A: If you didn't click a sketchy email, haven't left your computer physically open to attack, haven't downloaded anything sketchy/free, know that your software hasn't been exploited in a new hack, then the answer is: probably not.

 

Q: What email/VPN should I use?
A: Proton mail and VPN are the best for email and VPNs respectively. (They're free in a good way)

 

Q: How can I stay anonymous on the (deep/dark) webzz???....

A: By learning how to de-anonymize everyone else; if you can do that, then you know what to do for yourself.

 

Q: What Linux distro is best for x y z?

A: Lubuntu for things with little processing power, Ubuntu for normal PCs, and if you need to do anything else then it's best if you do the research yourself.

 

Q: Why is my Linux giving me x y z error?

A: Have you not googled it? Are you sure StackOverflow doesn't have an answer? Does the error tell you what's wrong? If the answer is no to all of those, message me.

 

Link to comment
Share on other sites

Link to post
Share on other sites

I would suggest using a tool like tronscript, its takes a while, but itll clean it.

How do Reavers clean their spears?

|Specs in profile|

The Wheel of Time turns, and Ages come and pass, leaving memories that become legend. Legend fades to myth, and even myth is long forgotten when the Age that gave it birth comes again.

Link to comment
Share on other sites

Link to post
Share on other sites

Run several on-demand scanner (Emsisoft Emergency Kit, Malwarebytes free, HitmanPro, Zemana, etc...) and if it is indeed a rootkit: format and reinstall Windows.

Link to comment
Share on other sites

Link to post
Share on other sites

Hey update. I installed and run Malwarebytes. 

 Heres the text file of the threats found.  

 

Also, quarantined and deleted the detected files. But still cant access my restore point. Laptop runs smoother now. 

update.txt

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Tsuki said:

I would suggest using a tool like tronscript, its takes a while, but itll clean it.

I would like to try it but Im not that good handling CLI. 

Link to comment
Share on other sites

Link to post
Share on other sites

Hey I restarted my laptop I cant run Malwarebytes again. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×