Virus Win32:Rootkit-gen [Rtk]

Solved
lermite222 Posted messages 9042 Status Contributeur -  
momonj Posted messages 978 Status Membre -
Hello,
I have read the 5 messages on the forum about the Win32:Rootkit-gen [Rtk] virus, but none of them could solve the problem.
It happened when visiting the site https://www.ecrandeveille.net/ for reference.

File name: C:\Windows\Temp\ZUMDB0F.tmp\upgrade.exe
Malware name: Win32:Rootkit-gen [Rtk]
Types: Rootkit
VPS version: 080504-0, 04/05/2008

Avast detects the virus and reports it, advising me to quarantine it. I tried deleting it, but nothing works; it comes back periodically.
Has anyone found a solution in the meantime?
Thank you in advance.
Configuration: Windows Vista Internet Explorer 7.0

6 réponses

Redbart Posted messages 21510 Registration date   Status Membre Last intervention   3 377
 
you have free AVG anti-rootkit
--
Be precise and complete in your questions, readers are not mind readers.
Search engines are here to help you.
12
lermite222 Posted messages 9042 Status Contributeur 1 199
 
Thank you, I'm going to try it; on the other topics, he doesn't talk about that one.
-1
Sirliane
 
I confirm, under no circumstances should you quarantine or delete!
I had Avast, I quarantined it but it kept coming back (I continued to quarantine it).
After a few times, an error message appeared saying that for system stability, I had to insert the XP CD to restore files in win32.
I didn't hesitate, thinking, my god, my PC is going to crash.
Hmmm apparently putting the CD in "excited" the virus because suddenly everything froze and virus alert messages started coming in by the dozen!
Then it became impossible to do anything, in desperation I deleted ... the messages kept coming anyway. Everything froze, I had to restart and there ... Well I still have my files but there's no way to back them up, to move them so I've lost everything!
So, don’t make the same mistake I did.

PS: Is there a way to reinstall the lost file? Since my Windows system is on a different partition than all my other files, would just formatting that disk allow me to recover my data?
Thank you
2
momonj Posted messages 978 Status Membre 111
 
and it's not a virus
no you can't reinstall the lost file it doesn't work
however if your windows is on a separate partition you can format just that partition
I didn't format I just launched the windows cd, installed windows, update, and windows reinstalled itself and everything works without having to reinstall the software, drivers, peripherals

and here is the cause with avast, which I received in an email but too late

This message is for AVAST antivirus users only.

Hello momon,

Some AVAST users may have encountered issues while playing the game GEMMZ on Cmonjour.
The AVAST antivirus reports: "A malware has been found!"

This message from Avast is triggered by one of the flash components used on GEMMZ as well as on pages containing flash games, or animations on many websites.
This flash component potentially represents a security vulnerability that is corrected in the latest version of Adobe's flash player.
That said, to claim that you are about to download "malware"... is inaccurate and excessively alarmist!
Moreover, AVAST seems to have fixed this by updating its software.

To resolve this issue, we recommend:

1/ Download the latest version of the Flash player:
- Download this player from Adobe's website by following this link (copy/paste it into your browser):
https://get.adobe.com/flashplayer/
- Download the flash player, and install it by double-clicking on the "install" file you just downloaded and following the installation program's instructions.


2/ Update AVAST as follows:
- in the taskbar (at the bottom right of your screen), right-click on the AVAST logo ("a")
- from the menu that appears, choose "Update" then "Program Update".
- To finalize the update, restart your computer


Once these 2 updates are done, you should be able to access the GEMMZ game again!
We apologize for this inconvenience although it is beyond our control!


Enjoy your game on Cmonjour!
0
Redbart Posted messages 21510 Registration date   Status Membre Last intervention   3 377
 
weird at my place

note: Avira antivirus searches for rootkits but doesn't find them all
--
Be precise and thorough in your questions, readers are not mind readers.
Search engines are there to help you.
1
nouche
 
Hello
since yesterday I have a win32rotkit-gen virus, I have Windows XP SP1 and I can't delete it or put it in quarantine, I am new to computers
thank you for replying
1
momonj Posted messages 978 Status Membre 111
 
If it is detected by Avast, if it alerts you to the file svchost.exe, especially do not delete it or put it in quarantine,
it is not a virus, doing so will crash your Windows and you will need to reinstall everything, it even blocks system restoration.
0
atanalban > momonj Posted messages 978 Status Membre
 
Hello,
it's my case, the rootkit is in svchost.exe

how to remove it, is it dangerous?

should I format?

thanks for the advice

Alban
0
momonj Posted messages 978 Status Membre 111 > atanalban
 
do not delete if it was found by avast
nor in quarantine
leave it for now, avast will have a reaction since many people are affected
0
colos51 > momonj Posted messages 978 Status Membre
 
I have exactly the same problem with Avast and unfortunately I deleted the file flagged as infected. No restoration possible. What can I do besides formatting the computer???
0
lermite222 Posted messages 9042 Status Contributeur 1 199
 
Hi,
It's fine with AVG, at first it did detect the Rootkits (3), I eliminated them and they haven't come back.
Once again, thanks for the info.
See you later
PS: Except the app is only in English and Japanese, it's ok but it's more comfortable in French.
And it messed with IE a bit, but that's another story.
-1
goldendemon Posted messages 185 Status Membre 12
 
I had the same problem but I think it keeps sending the message... and prevents us from working on Windows until we give it a response...

The only thing to do is to disable Avast...

I formatted yesterday and installed Windows XP this morning and updated Avast, so it seems to be working again...
0
colos51
 
same problem, I deleted the pseudo virus and as a result, Windows appearance changed, no internet connection, no actions possible including system restore, in short, a real mess. Am I forced to format the PC and reinstall everything???
0
momonj Posted messages 978 Status Membre 111 > colos51
 
Hi
I didn't format, I just launched the Windows CD, installed Windows, updated it, and Windows reinstalled itself and everything works without having to reinstall the software, drivers, or peripherals.
0