Ask Experts Questions for FREE Help!
  Advanced
Register  |  Log in  
   Ask    
 Answer  
  Help  

Ask QuestionsprogressAnswer QuestionsprogressBuild ReputationprogressBecome an Expert
 
Free Answers in 3 Easy Steps

Register Now
3 Steps

At Ask Me Help Desk you can ask questions in any topic and have them answered for free by our experts. To ask questions or participate in answering them you must register for a free account. By registering you will be able to:
  • Get free answers from experts in any of our 300+ topics.
  • Accept money for answers that you provide.
  • Communicate privately with other members (PM).
  • See fewer ads.

Home > Computers & Technology > Security > Spyware, Viruses, etc.   »   Hidden driver, rootkit? C:\WINDOWS\System32\Drivers\adojzhcu.SYS

 
Question Tools Search this Question Display Modes
Question
 
 
#1  
Old May 22, 2008, 09:54 AM
Hartlieb
New Member
Hartlieb is offline
 
Join Date: May 2008
Posts: 4
Hartlieb See this member's comment history on his/her Profile page.
Hidden driver, rootkit? C:\WINDOWS\System32\Drivers\adojzhcu.SYS

This was missed with Kaspersky Anti-Virus 7.0 (version 7.0.1.321) and Trojanhunter 5.0. I found it; if it is a rootkit; running AVG Anti-Rootkit Free. After it was found and erased the first time when the computer was restarted it was there again only with a different ending to the file. It did the same the third time it was erased. My guess is there is something in there re-installing it on startup everytime and it changes itself to be missed? Here is the starting name of the file with the change at the end everytime I erased it. It would also change the ending if the computer is just restarted. It's called a Hidden Driver File by AVG Anti-Rootkit Free. All of the capitals and lower cases are how it was listed.

C:\WINDOWS\System32\Drivers\adojzhcu.SYS
C:\WINDOWS\System32\Drivers\amujjg5a.SYS
C:\WINDOWS\System32\Drivers\aianq1zc.SYS

If I check it again, I am guessing it will still be there just with a different ending. I can send you a Hijackthis scan file or anything else that you need. You build a great AV system and I hope this helps you make it better as well as helping me get rid of it, if it is bad.

Thanks for your time

Matt

Reply With Quote
 
     

Answers
 
 
Old May 23, 2008, 10:46 AM   #2  
invisibleman_productions
Junior Member
invisibleman_productions is offline
 
Join Date: Jul 2006
Posts: 196
invisibleman_productions See this member's comment history on his/her Profile page.
Send a message via Yahoo to invisibleman_productions
Please run all the 5 steps listed here
especially a complete scan with dr web
  Reply With Quote
 
     
 
 
Old May 23, 2008, 08:47 PM   #3  
Hartlieb
New Member
Hartlieb is offline
 
Join Date: May 2008
Posts: 4
Hartlieb See this member's comment history on his/her Profile page.
I did the scans with all 5. There were a few spy and ad files found and deleted that I have seen before. A complete scan of Dr. Web came up with these. They were unable to be cured and were put in quarantine. I did not put the Q file in a certain place so I will have to find it if need be.

A0075695.exe;C:\System Volume Information\_restore{80DED19E-4EB2-4BBA-94DE-BE7FE31173DD}\RP435;Probably DLOADER.Trojan;;
A0077578.exe;C:\System Volume Information\_restore{80DED19E-4EB2-4BBA-94DE-BE7FE31173DD}\RP455;Probably DLOADER.Trojan;;
A0100831.exe;C:\System Volume Information\_restore{80DED19E-4EB2-4BBA-94DE-BE7FE31173DD}\RP571;Probably BACKDOOR.Trojan;;
A0100832.exe;C:\System Volume Information\_restore{80DED19E-4EB2-4BBA-94DE-BE7FE31173DD}\RP571;Probably BACKDOOR.Trojan;;
A0100905.exe;C:\System Volume Information\_restore{80DED19E-4EB2-4BBA-94DE-BE7FE31173DD}\RP572;Probably DLOADER.Trojan;;
A0102255.bat;C:\System Volume Information\_restore{80DED19E-4EB2-4BBA-94DE-BE7FE31173DD}\RP573;Probably SCRIPT.Virus;;
A0102470.bat;C:\System Volume Information\_restore{80DED19E-4EB2-4BBA-94DE-BE7FE31173DD}\RP575;Probably SCRIPT.Virus;;

One more scan of AVG Anti-Rootkit found this again but changed

C:\WINDOWS\System32\Drivers\aj2g55og.SYS

I will be reading the links on how to prevent this stuff in the future while I await your reply on what to do next.

Thanks for your help
  Reply With Quote
 
     
 
 
Old May 25, 2008, 06:07 AM   #4  
invisibleman_productions
Junior Member
invisibleman_productions is offline
 
Join Date: Jul 2006
Posts: 196
invisibleman_productions See this member's comment history on his/her Profile page.
Send a message via Yahoo to invisibleman_productions
The incurable are stored in your system restore folder >>C:\System Volume Information\_restore

To remove them you need to turn off your system restore and then turn it back on

As you have run all 5 steps you need to Visit the HijackThis Logs and Analysis forum. SWI Forums -> Malware Removal and let the hijackthis experts take a look at whats happening on your computer
  Reply With Quote
 
     
 
 
Old May 25, 2008, 01:26 PM   #5  
Hartlieb
New Member
Hartlieb is offline
 
Join Date: May 2008
Posts: 4
Hartlieb See this member's comment history on his/her Profile page.
Yes, I did that after reading the link you had for prevention and AV scans. I will be contacting the Hijack This forum now. Thanks for the help.
  Reply With Quote
 
     
 
 
Old May 25, 2008, 02:18 PM   #6  
junglenutz123
New Member
junglenutz123 is offline
 
Join Date: May 2008
Posts: 16
junglenutz123 See this member's comment history on his/her Profile page.
Quote:
Originally Posted by Hartlieb
This was missed with Kaspersky Anti-Virus 7.0 (version 7.0.1.321) and Trojanhunter 5.0. I found it; if it is a rootkit; running AVG Anti-Rootkit Free. After it was found and erased the first time when the computer was restarted it was there again only with a different ending to the file. It did the same the third time it was erased. My guess is there is something in there re-installing it on startup everytime and it changes itself to be missed? Here is the starting name of the file with the change at the end everytime I erased it. It would also change the ending if the computer is just restarted. It's called a Hidden Driver File by AVG Anti-Rootkit Free. All of the capitals and lower cases are how it was listed.

C:\WINDOWS\System32\Drivers\adojzhcu.SYS
C:\WINDOWS\System32\Drivers\amujjg5a.SYS
C:\WINDOWS\System32\Drivers\aianq1zc.SYS

If I check it again, I am guessing it will still be there just with a different ending. I can send you a Hijackthis scan file or anything else that you need. You build a great AV system and I hope this helps you make it better as well as helping me get rid of it, if it is bad.

Thanks for your time

Matt
I would just go in and reformat your whole harddrive, if you have the operating system to install onto it. that would be your best bet, without killing too much time
  Reply With Quote
 
     
 
 
Old May 25, 2008, 10:26 PM   #7  
Hartlieb
New Member
Hartlieb is offline
 
Join Date: May 2008
Posts: 4
Hartlieb See this member's comment history on his/her Profile page.
He, he... that was one of the things I was thinking of doing. You have any idea what this stuff could be? Because that is probably what is going to happen...
  Reply With Quote
 
     


Question Tools Search this Question
Search this Question:

Advanced Search
Display Modes

 
Similar Sponsors

Similar Questions
Question Asker Topic Answers Last Post
virus in C:\\WINDOWS\system32\drivers\etc\hosts coachcj Spyware, Viruses, etc. 12 May 5, 2008 08:55 PM
Fix greyware. C:\windows\system32\drivers\etc\hosts ronsall Spyware, Viruses, etc. 8 Apr 9, 2008 07:17 PM
C:\WINDOWS\system32\drivers\etc\host some how its changed! COOKIE MONSTER Windows 4 Mar 25, 2008 03:13 PM
C:\WINDOWS\system32\drivers\etc\hosts murphy55 Windows 1 Oct 29, 2007 12:14 PM
how do I open c:/windows/system32/drivers/etc/hosts mamaloney Windows 2 Jul 21, 2007 01:03 AM




Copyright ©2003 - 2007, Ask Me Help Desk.
All times are GMT -8. The time now is 04:42 PM.

Content Relevant URLs by vBSEO 3.0.0 RC6 © 2006, Crawlability, Inc.