Re: win32Rootkit-gen



Donald Eagle wrote:
I run XP home, SP3 updated to today with Zone Alarm free, Avast 4 Home,
Malwarebytes, and SuperAntiSpyware.
This afternoon Avast told me it had detected Win32Rootkit-gen in
Windows\system32\svchost.exe, but could not quarantine it, Windows
Defender, MalwareBytes and SuperAntiSpyware found nothing. A boot scan
from Avast also found it, but I did not attempt a repair because it is a
Windows file. Scanforfree.com root kit remover did not find it, but
Sophos Anti-Rootkit did, but gave the following message:

Area: Local hard drives
Description: Unknown hidden file
Location: C:\WINDOWS\system32\svchost.exe
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

What do I do now? Can I tell Sophos to remove it and regenerate the
file? Can I repair it from an Avast boot scan? If I do either of these,
will I still be able to boot to Windows?

Suggestions for a solution greatly appreciated.

Hello Donald:

Upload your suspected C:\WINDOWS\system32\svchost.exe to:

<https://www.virustotal.com/>

After VT has analyzed, post the URL for the analysis here as a follow
up. Please don't reproduce the report here.

Regards,

Pete
--
1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]
.



Relevant Pages

  • Re: Computer Virus?
    ... with Spywareblaster, SuperAntiSpware, Malwarebytes, Avast, Windows Defender and Windows firewall. ... the Java icon moved to the system tray to the right and disappeared. ...
    (microsoft.public.windowsxp.general)
  • RE: automatic updates wont stay enabled
    ... This SUPERAntiSpyware scan tried to load three malicious programs. ... Windows version, edition and service pack level, and perhaps what other ... A very good antimalware app is SUPERAntiSpyware and Malwarebytes ... Reboot ...
    (microsoft.public.windowsupdate)
  • RE: Windows Automatic Update
    ... Do a full scan with MalwareBytes and SUPERAntiSpyware. ... How to Automate the Disk Cleanup Tool in Windows XP ... Automatic Updates", it gives me the following message: ...
    (microsoft.public.windowsupdate)
  • Re: Computer Virus?
    ... with Spywareblaster, SuperAntiSpware, Malwarebytes, Avast, Windows Defender and Windows firewall. ... System type: 64-bit operating system ...
    (microsoft.public.windowsxp.general)
  • Re: win32Rootkit-gen
    ... MalwareBytes and SuperAntiSpyware found nothing. ... scan from Avast also found it, but I did not attempt a repair because ... it is a Windows file. ...
    (microsoft.public.security.virus)