Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Aug 28th, 2008, 2:00pm
   Mischel Internet Security Forum
   TrojanHunter
   TrojanHunter Scanner
(Moderators: Helena, Gavin_Coe, Magnus)
   41665abd.sys
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: 41665abd.sys  (Read 116 times)
loopax
Newbie
*





   


Posts: 2
41665abd.sys
« on: Jul 2nd, 2008, 10:13am »
Quote Quote  Modify Modify

Hi,
 
Recently I scanned my pc and found this file in my C:\WINDOWS\system32\drivers\41665abd.sys which is not detected by TH. My ZoneAlarmAntivirus find it as Rootkit and after the file is removed next second is created again. I submited the file to VirusTotal can see the results http://www.virustotal.com/analisis/244da6d8ea437c3a8e79a7fa1f1c65a5.  
 
Is this a legit file or is indeed rootkit, if so can someone help get it out?
 
Thanks
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5594
Re: 41665abd.sys
« Reply #1 on: Jul 2nd, 2008, 3:10pm »
Quote Quote  Modify Modify

This definitely looks like a malicious driver.  
 
I am making a basic assumption that you are running either Windows XP or Windows Vista.
 
Please do the following:
 
1.  Make all your files and folders visible as per the procedure in the link below:
 
http://www.misec.net/forum/board/FAQ/1139610900
 
2.  Please submit the file for analysis by Mischel Internet Security.  This link below describes how to submit files for analysis that are probably malicious.
 
http://www.misec.net/forum/board/FAQ/1139308293
 
Then please do this:
 
1.  Download/install program Hijackthis per the instructions in the link below.  
  
http://www.misec.net/forum/board/FAQ/1163329424  
  
2.  Go to the link below and download program Combofix.exe and save it on your desktop.  
  
http://download.bleepingcomputer.com/sUBs/ComboFix.exe  
  
3.  Temporarily de-activate all your security programs EXCEPT your software firewall.  
  
4.  Close down as many programs as you can (programs in the Notification Tray-  next to the clock).  
  
5.  Close your browser.  
  
6.  Double click on Combofix.exe to execute it and follow the instructions.  
 
Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
  
-  When Combofix.exe is finished, it will save a log on your system.    
  
7.  Post the Combofix log back here    
  
8.  Run Hijackthis and post a HiJackthis scan log back here.  DO NOT fix anything with HJT...just post the scan log.
« Last Edit: Jul 2nd, 2008, 4:10pm by siliconman01 » IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register