PDA

View Full Version : pc root-ed


p0p3y31
08-15-07, 10:29 AM
a friend of mine some how has hosed her pc these were the symptons when i got to her house boot up time appr. 20 min no internet nothing would open errors left and right you could tell the internet was in use by the icons i tried a couple things in safe mode and was able to get online in safe mode but at that point it was hopeless, so here is what i did:

1:detached hard drive and slaved to my computer
2:scanned with all of the below

>bitdefender av plus v10
>kaspersky online scanner
>trendmicro house call
>panda activescan
>spysweeper v5
>xcleaner
>super antispyware
>spybot
>sysclean (trend micro)

3:removed drive and hooked back up to her pc
it ran a little better so i did a sfc /scannow
but, my problem now is that it's still i little wiggy ran some more scans in safe mode but this is where i'm at my end i'm 90% positive that the pc is still rooted(rootkit) every root kit remover i use when i run them kills immediatly"f-secure blacklight,smitrem,smitfraud"the only one that finished was mcafee rootkit detective that said no problems but, i've never realy trusted rootkit detective. i have icesword but, not sure how to use and apihookcheck but i think that was a corrupted download because when i run that it just pops up for half a second then closes any suggestions would be appreciated by the way i'm at work but the first three of the rootkit removers the error i would get was something threw an exception i'll try to get the full error message

thanx in advance for any help

mnosteele52
08-15-07, 03:49 PM
Please try and use proper punctuation and grammar it is very hard to read your post.;)

Try the following:

Prior to doing anything XP users MUST disable System Restore!!! You can re enable it after you are clean.

1. Download, install and run CrapCleaner (http://www.ccleaner.com) to remove any temporary and junk files.

2. Download Ad-Aware SE 1.06 (http://www.majorgeeks.com/download506.html) and set it up as shown HERE (http://www.drtweak.com/index.php?topic=40.0).

3. Download SpyBot Search & Destroy 1.4 (http://www.safer-networking.org/index.php?page=download) and set it up as shown HERE (http://www.drtweak.com/index.php?topic=41.0).

4. Download SUPERAntiSpyware (http://www.superantispyware.com), update and do a full system scan.

5. Download AVG Anti-Spyware 7.5 (http://www.ewido.net/en/download), update and do a full system scan.

6. Download and run CWShredder (http://www.trendmicro.com/cwshredder).

7. Do a FREE online virus scan from BitDefender Online Scan (http://www.bitdefender.com/) and remove all that it finds.

8. It is a good idea to use Sysinternal's Autoruns (http://www.sysinternals.com/Utilities/Autoruns.html) to make sure you have removed all of the malware.

9. It it also a good idea to run the Winsock Fix (http://www.snapfiles.com/get/winsockxpfix.html) to repair your TCP/IP stack. (you will have to redo any tweaks for your connection if this is used)

10. If after doing ALL of the above and you are still having problems please scan with HijackThis 1.99.1 (http://www.majorgeeks.com/download3155.html) as shown HERE (http://www.drtweak.com/index.php?topic=58.0) and post a log here in this forum for us to look at.

11. Download SpywareBlaster 3.5.1 (http://www.javacoolsoftware.com/spywareblaster.html) and set it up as shown HERE (http://www.drtweak.com/index.php?topic=42.0) to help stay spyware free.

13. Make sure you have ALL of the latest Windows Updates.

:D

p0p3y31
08-15-07, 05:56 PM
eat me, is that proper

mnosteele52
08-15-07, 07:50 PM
eat me, is that proper

That's really polite, I wasn't trying to be a jerk, just being honest, so go find help elsewhere.

:thumb:

burple
08-15-07, 08:25 PM
Damn somebody trying to make my local area look bad.

Pettos
08-15-07, 08:47 PM
Damn somebody trying to make my local area look bad.

Don't worry, everyone has their own village idiot.