gonczi 0 Posted March 16, 2020 Report Share Posted March 16, 2020 Hi there! My computer is infected. I have rootkit Wdf34078.sys Please help me. I can't delete it. What can I do? My name Gönczi László from Humgary. Thank you, have a good day. Link to post Share on other sites
Kevin Zoll 309 Posted March 16, 2020 Report Share Posted March 16, 2020 Hello @gonczi, Welcome to the Emsisoft Support Forums. All files are to be attached to all replies. Do not copy & paste any log to your replies, unless specifically told to do so. Copy the below code to Notepad; Save As fixlist.txt to your Desktop. HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION GroupPolicyScripts: Restriction <==== ATTENTION FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION "{45487F67-EC9F-4449-A6F2-2D0970F9B80B}" => service could not be unlocked. <==== ATTENTION HKLM\SYSTEM\ControlSet001\Services\{45487F67-EC9F-4449-A6F2-2D0970F9B80B} => C:\Windows\System32\drivers\Wdf34078.sys [1485200 2019-12-21] (Access Denied) [File not signed] <==== ATTENTION (Rootkit!/Locked Service) 2020-03-15 20:16 - 2019-12-21 19:35 - 000000000 ____D C:\Users\Laci\AppData\Roaming\mhj4f1cksmd 2020-03-15 20:16 - 2019-12-21 19:25 - 000000000 ____D C:\Users\Laci\AppData\Roaming\akrv5m5dnyx 2020-03-14 18:31 - 2019-12-20 21:02 - 000000000 ____D C:\Users\Laci\AppData\Roaming\3gzekt4l5wb 2019-12-21 19:25 C:\Windows\system32\Drivers\Wdf34078.sys ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File AlternateDataStreams: C:\kerelem-adatlap_szolgalati_ido_kiszamitasahoz.pdf:xdg.origin.url [309] AlternateDataStreams: C:\ProgramData\TEMP:80337C03 [124] FirewallRules: [{896062B9-D51E-4454-8B5F-610CABD2D730}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe No File FirewallRules: [{185A96E0-0EB2-4ABB-A059-616FDCBFD868}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe No File FirewallRules: [TCP Query User{DF20EDEA-1894-41DC-B280-0D087751F553}F:\win_hdd\telepitők\potplayer live\potplayer live.exe] => (Allow) F:\win_hdd\telepitők\potplayer live\potplayer live.exe No File FirewallRules: [UDP Query User{B74357D1-7B81-4393-8DDC-30127B7738A9}F:\win_hdd\telepitők\potplayer live\potplayer live.exe] => (Allow) F:\win_hdd\telepitők\potplayer live\potplayer live.exe No File FirewallRules: [{72451496-30F3-426A-BC0F-0F5298BB7A08}] => (Allow) C:\sajat pot\PotPlayer\PotPlayerMini.exe No File Close Notepad. NOTE: It's important that both files, FRST, and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system IMPORTANT: Save all of your work, as the next step may reboot your computer. Run FRST and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Attach it to your reply. NOTE: If the tool warns you about an outdated version please download and run the updated version. Also, let me know how the machine is running now, and what remaining issues you've noticed. Link to post Share on other sites
Kevin Zoll 309 Posted March 20, 2020 Report Share Posted March 20, 2020 Thread Closed Reason: Lack of Response PM either Kevin, or Arthur to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on a system, other than the one they were written for, could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE if you don't we are just going to send you back to this thread Link to post Share on other sites
Recommended Posts