Here is a sample of warning messages that the Symantec AV tamper protection pops up... Also, below that I have something interesting that shows up when I do a full system scan.. it starts scanning with \\.\c:\WINTNT ... wtf? I don't think that is what it normally starts with which has me worried.

Target: C:\Program Files\Symantec AntiVirus\DoScan.exe
Event Info: Open Process
Action Taken: Blocked
Actor Process: C:\WINNT\system32\rundll32.exe (PID 1720)
Time: Wednesday, September 14, 2005
11:19:20 AM

SYMANTEC TAMPER PROTECTION ALERT

Target: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
Event Info: Open Process
Action Taken: Blocked
Actor Process: C:\WINNT\system32\rundll32.exe (PID 1720)
Time: Wednesday, September 14, 2005 11:19:22 AM

SYMANTEC TAMPER PROTECTION ALERT

Target: C:\PROGRA~1\SYMANT~1\VPTray.exe
Event Info: Open Process
Action Taken: Blocked
Actor Process: C:\WINNT\system32\rundll32.exe (PID 1720)
Time: Wednesday, September 14, 2005 11:19:22 AM

===

rundll32.exe is also a process which is registered as the W32.Miroot.Worm

====


Symantec Starts full scan with:

\\.\C:\WINNT\Temp

Dani AI

Generated

Tamper-protection alerts mean some process tried to open or interact with the AV engine. Because reported rundll32.exe being involved, that behavior can be either a legitimate Windows helper being used by an app or an indicator that a DLL was launched by a malicious host. Tamper protection blocking the access is a protective sign. 's suggestion to run online scanners and clean temp files is useful as a first pass, but deeper verification is prudent before assuming the system is clean.

Recommended diagnostic and remediation steps:

  1. Verify the rundll32 instance. Confirm the full file path and the digital signature shown in file Properties. A system-signed rundll32 in the OS system32 folder is normal; any copy elsewhere or without a Microsoft signature is suspicious.
  2. Inspect the running process. Use a tool that shows full command line, parent process, loaded DLLs and handles. Look for rundll32 command lines that load DLLs from Temp, user profiles or other unusual locations.
  3. Check persistence points. Search Startup items, Run keys, scheduled tasks and shell extensions for rundll32 invocations that reference odd DLL names or locations. An autorun/registry audit will often reveal the injector.
  4. Run offline or Safe Mode scans. Perform AV scans from Safe Mode or a vendor rescue environment so active malware cannot hide or lock files. Quarantine findings and clear System Restore snapshots after cleaning.
  5. Repair or reinstall the AV if tamper alerts persist after removal of the offending component. If the original system rundll32 was altered, use a trusted source to restore system files rather than deleting them.

Note on device-style paths: an entry shown with a device prefix (for example a path beginning with the low-level NT device namespace) is how some programs open volumes and is not proof of a rootkit by itself. Focus on who opened the AV processes, the exact file location and digital signature, and any rundll32 command lines that reference nonstandard DLL locations. Avoid deleting or replacing system files unless their legitimacy is clearly proven; persistent or unclear infections often require vendor removal tools or a clean OS reinstall.

Hi,
I would suggest you to run Online virus scan at Panda ActiveScan (with "Disinfection" option enabled) and Trend Micro HouseCall (with "Auto Clean" option enabled).

Also, download CCleaner and install it. Run it, click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. Finally click "Run Cleaner" and click "OK" to continue cleaning.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.