Win32:Rootkit-gen query

Mathius

New member
This should be in the right place, but move if needed :)

The last few days, my internet has been used on my second machine, and gave me ample time to go through my system and uninstall all the junk I've put on it over the past 12months.....

I ran a deep search scan and my Avast found 5 results:

3x PUP - Potentially UnWanted Programs which were found on my E: and F: drives, but these are trainer programs and are false positives so have discarded these.....and since put them onto a MicroSD card so are off my system. (re-scanned the file locations and came up clean)

The other 2 are the Win32-Rootkit-gen and were found:

C:\Program Files (x86)\x264 Video Codec\Filters\Haali\mmdinfo.dll
C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlay.dll


Now for some reason a simple Move to Chest wasn't working for me, so dug a little deeper and the x264 Video Codec I installed turns out to be un-used and have successfully uninstalled it through Program and Features.

I then went exploring to the Media Tools folder, and inside were 2 more folders.... 'Plugins' and 'Temp' both of which were empty and the MediaIconsOverlay.dll file.

I've Deleted the dll file and did a restart and went back to check to see if the file had reappeared... and no it didn't so, so far so good.

So now my system 'looks' clean.
I've set up Avast to run a Boot-Time Scan on the next time my PC powers up searching only the C:\ as drive E and F were clean.

-------------
Anything else need doing?

EDIT: Malwarebytes scan is clean.
 
Last edited:
Seeing as you have uninstalled old stuff and been deleting it's probably wise to do a registry fix, use CCleaner and perform a reg clean. After that I can't think of much more you need to do.
 
Seeing as you have uninstalled old stuff and been deleting it's probably wise to do a registry fix, use CCleaner and perform a reg clean. After that I can't think of much more you need to do.

if bytes is coming up clean it normally is.

could try hijackthis if you know what you're looking for or post a log and i could take a look, used to fix infections a lot back in the day.
 
update,
Still waiting on the bootscan to finish, its been 2.5 hours and has found a few but I'm aware of what they are in my system and I'm not worried.....yet at least.

Did laugh at Avast Error 42110, I think its being a scaredy cat ..... relates to a decompression bomb.....which it won't read, understandably.... (file is fine as it is in my games installers directory on my removable drive. - basically its a small file that unpacks to a huge one. )
 
If it is a Rootkit then you've got one of the worst infections you can deal with as they operate at the operarating system services level.

If Bytes comes up clean it can mean three things:

1: Bytes doesn't actually know it's signature.
2: The rootkit itself has deployed countermeasures from being detected.
3: You are clean

Hijackthis log would be pretty good :)
 
not overly sure about this file.....
the txt file is zip'd

it looks complete garbage to me :(



Update again...
After running yet another BootScan and Scan through Windows, as well as a Malwarebyte again..the only two found were both decompression bombs, which are Installer exe's for two games I have, I actually have these games installed and a scan of those directories comes out clean.

So unless something is drastically wrong with the HiJackThis.txt, everything is sorted.
 

Attachments

Last edited:
i had a quick look, sorry it's late.

i don't see anything that stands out to me but it's been a while so maybe see if someone else can verify you are clean.
 
Back
Top