Home Join MIGClub Forums Gallery Videos Classifieds Links Help Desk ©MIGWeb 1997-2008


MIG Performance Vauxhalls

Go Back   MIG Performance Vauxhalls > Community Forums > Off Topic Discussions > Electronics

Electronics Post all about computers, gaming, software, web hosting, hardware, home electronics, mobiles etc here

Reply
 
LinkBack Thread Tools
Old 10-07-2008, 09:48   #1
MIGWeb User
 
Join Date: May 2001
Location: 52.26320° -0.81374°
Drives: 2.0 16v Astra GTE
iTrader: (4)
Posts: 17,704
Can someone recommend a root-kit removal tool

As per title, and needed free and fast! I can download from all the usual top places too.
__________________
"He's a quality driver, very strong and only 16. If he keeps this up I'm sure he will reach F1."
Michael Schumacher in 2001, about Lewis Hamilton, Formula 1 World Champion 2008.
Trevor is offline   Reply With Quote
Old 10-07-2008, 10:23   #2
MIGClub Member
 
KillBill's Avatar
 
Join Date: Jan 2005
Location: Ireland
Drives: Cars you won't like
iTrader: (0)
Posts: 7,015
Re: Can someone recommend a root-kit removal tool

I've found there's no one tool that's completely effective.

However, F-Secure Blacklight is a good place to start, provided the bastarding thing hasn't edited the local policies on the machine to deny even members of the Administrator's group the SeAdminDebug privlege. If that's happened then even it won't work.

My advice, initially, boot from a CD, or mount the drive in another machine, go into \Windows\System32, order by date, and start deleting the dozens of suspiciously named DLLs that will be in there. You can spot them a mile off, recent dates, garbage names, and if you check their properties, they won't have any of the proper version information that all legitimate Windows system files have.
I suspect you'll also find, if you boot the machine outside of the host OS, that the rootkit will have created itself an invisible working directory somewhere, C:\Program Files seems to be favourite for some of the more common ones. Of course this folder is completely transparent when Windows (and the rootkit) are running, because it will be intercepting the output of Explorer.

Get yourself a copy of Process Explorer from MS too, you're going to need it.
I suspect the rootkit has listed itself in the Winlogon autorun sections of the registry, and its probably registered under AppInitDlls too. Some of the ****ers even associate themselves with Autoplay extensions, so they get called again and again when any USB or drive with removable media is accessed, right pain in the hole.
__________________
Feckoff cup!
KillBill is online now   Reply With Quote
Old 10-07-2008, 10:30   #3
MIGClub Member
 
KillBill's Avatar
 
Join Date: Jan 2005
Location: Ireland
Drives: Cars you won't like
iTrader: (0)
Posts: 7,015
Re: Can someone recommend a root-kit removal tool

Something I forgot to add, I've found in the past if there's a persistent malicious dll or .exe running which you can't seem to stop, if you use the Local Security policy in Administrative Tools to create a deny hash for the program in question, it should stop it loading into memory on the next boot, despite of where it may move or change it's name to. (Using the hash method effectively takes a finger print of the file so its identifiable even if it changes).
KillBill is online now   Reply With Quote
Old 10-07-2008, 11:08   #4
MIGClub Member
 
Join Date: Jan 2007
Location: Cheddar
Drives: ACT, 306xnd
iTrader: (4)
Posts: 1,518
Re: Can someone recommend a root-kit removal tool

Bought a sony music CD that's a couple of years old?
kNeo_gHau is offline   Reply With Quote
Old 10-07-2008, 19:59   #5
MIGClub Member
 
KillBill's Avatar
 
Join Date: Jan 2005
Location: Ireland
Drives: Cars you won't like
iTrader: (0)
Posts: 7,015
Re: Can someone recommend a root-kit removal tool

KillBill is online now   Reply With Quote
Old 10-07-2008, 21:25   #6
MIGWeb User
 
Join Date: May 2001
Location: 52.26320° -0.81374°
Drives: 2.0 16v Astra GTE
iTrader: (4)
Posts: 17,704
Re: Can someone recommend a root-kit removal tool

It is not even my box, I have been entrusted to sort it out. So far 193 viruses and 356 malware/spyware/adware hits. Then there is the tracking cookies....
Trevor is offline   Reply With Quote
Old 10-07-2008, 23:34   #7
MIGClub Member
 
KillBill's Avatar
 
Join Date: Jan 2005
Location: Ireland
Drives: Cars you won't like
iTrader: (0)
Posts: 7,015
Re: Can someone recommend a root-kit removal tool

Wouldn't surprise me one bit.
My record is 6,300 viruses on one machine, I'm surprised it worked at all.
KillBill is online now   Reply With Quote
Old 11-07-2008, 00:59   #8
MIGClub Member
 
Join Date: Jan 2007
Location: Cheddar
Drives: ACT, 306xnd
iTrader: (4)
Posts: 1,518
Re: Can someone recommend a root-kit removal tool

Quote:
Originally Posted by KillBill View Post
I wondered if anyone would get the reference

Quote:
Originally Posted by Trevor View Post
It is not even my box, I have been entrusted to sort it out. So far 193 viruses and 356 malware/spyware/adware hits. Then there is the tracking cookies....
Backup anything they want to keep, format, then reinstall windows. Quicker and easier 99% of the time
kNeo_gHau is offline   Reply With Quote
Old 11-07-2008, 07:30   #9
MIGClub Member
 
KillBill's Avatar
 
Join Date: Jan 2005
Location: Ireland
Drives: Cars you won't like
iTrader: (0)
Posts: 7,015
Re: Can someone recommend a root-kit removal tool

Quote:
Originally Posted by kNeo_gHau View Post
I wondered if anyone would get the reference
I'd forgotten all about that **** they tried a few years back, they would have gotten away with it too, if it wasn't for those pesky kids!
KillBill is online now   Reply With Quote
Reply
Sponsored Links


Thread Tools


» Search
To use the advanced search, please log in.
» Forum Stats
Members: 42,319
Threads: 306,986
Posts: 3,456,394
Top Poster: LEE69 (42,828)
Welcome to our newest member, ledge
» Join MIGClub Today
Join online now!

Members receive extra MIGWeb features plus all the benefits of being a MIGClub Member.

It takes just two minutes to join via PayPal and your account will be instantly upgraded.
Powered by vBadvanced CMPS v3.0.1

All times are GMT. The time now is 00:39.


Powered by: vBulletin. Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
- Not Member