General Question

trypaw's avatar

Computer Trojan/Rootkit virus problem please help me?

Asked by trypaw (327 points ) August 16th, 2012

So my laptop acquired some Trojans and root-kits (Malware Bytes scan revealed) I am getting these popups from “thetaoofbadass.com” while roaming web pages it just pops up with some web page. Also my windows security essentials and firewall are turned off and disabled. I get some error code and I cannot turn them on, it does not let me. Can anyone help me figure out how to delete these viruses and why is it messing with my computers security? I have tried Spybot (found nothing) and MalwareBytes had found 6 now Its running in safe mode and I’ve found 3 more. What can I do?

Observing members: 0 Composing members: 0

23 Answers

Brian1946's avatar

Have you deleted what MalwareBytes found?

trypaw's avatar

still running the scan that has currently found 3, but yes I deleted the other 6 things it found and computer was still acting up so that’s why I’m scanning again now in safe mode.

Brian1946's avatar

For the time being, let the scan finish and then delete the rest.

trypaw's avatar

Alright it only found 3. Deleted them restarted back in safe mode again. Security essentials is still turned off and the error code that pops up when it says I cannot turn it on is. 0×80070424 it says the service doesn’t not exist? Firewall says similar?

trypaw's avatar

I know some of the rootkits it found are called Rootkit.0Acess and then Trojans.droppe

Brian1946's avatar

Try holding down the Ctrl and Alt keys, and then pressing and releasing your Delete key. That should open the Windows Task Manager.

trypaw's avatar

alright then what should I do from task manager?

Brian1946's avatar

Click on the Processes tab.

trypaw's avatar

yes I have checked and there doesn’t seem to be any odd programs running?

Brian1946's avatar

How many processes do you have running?

Brian1946's avatar

Click on the Image Name to arrange them in alphabetical order.

trypaw's avatar

ok I did

Brian1946's avatar

What are the processes beginning with the letter R (r)?

trypaw's avatar

Rundll32.exe is the only thing running with R

Brian1946's avatar

What’s the user name associated with it?

Brian1946's avatar

I think that’s the process that needs to be ended.

I know this could be a lot of work, but just to play it safe, please list the other processes that are running.

gambitking's avatar

The types of trojans and root kits like this can leave back doors open in your system, and you still don’t know what has been compromised prior to removing the malware, even if you did. Even after removing the programs causing harm, your PC could still be a security risk, and still remain at risk to further attacks.

For this reason, it is highly suggested you format your system (backup your stuff beforehand, of course) and reinstall a fresh OS.

trypaw's avatar

Well I somehow deleted them, there isnt’ anything important on my computer anyways. I’ll just watch over it for awhile. Thank you!

Brian1946's avatar

Is Rundll32.exe still active?

njnyjobs's avatar

Reboot your system and start it up in safemode with networking.
Connect to the internet and go to download.com to get HitMan Pro 36.
Run HitMan Pro to detect the problem files and fix them.
Good luck and report back.

trypaw's avatar

@brian1946 It is but I dont think it is infected anymore

Answer this question

Login

or

Join

to answer.

This question is in the General Section. Responses must be helpful and on-topic.

Your answer will be saved while you login or join.

Have a question? Ask Fluther!

What do you know more about?
or
Knowledge Networking @ Fluther