Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Virus or Rootkit

Virus or Rootkit

Scheduled Pinned Locked Moved The Lounge
helpphpcomannouncement
21 Posts 8 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R Rod Kemp

    I would try RootkitRevealer[^] first, at least it should show you if there is something there.

    B Offline
    B Offline
    Bassam Abdul Baki
    wrote on last edited by
    #11

    Thanks! I tried another one that found nothing. I'll try this one too since SysInternals was always good at what it does.

    1 Reply Last reply
    0
    • B Bassam Abdul Baki

      I've already lost that laptop. Every anti-virus and malware software out there can't seem to find it. I have nothing to lose at this moment. I just want to see what happens after I install it. I'll probably end up formatting it eventually.

      M Offline
      M Offline
      Mark_Wallace
      wrote on last edited by
      #12

      Well, just make sure that you never connect to a network - any network - with the machine after installing such a monster. They have killed your machine, but installing the "update" will allow them to own it; you will be voluntarily giving them the opportunity to make any changes they want.

      I wanna be a eunuchs developer! Pass me a bread knife!

      B P 2 Replies Last reply
      0
      • M Mark_Wallace

        Well, just make sure that you never connect to a network - any network - with the machine after installing such a monster. They have killed your machine, but installing the "update" will allow them to own it; you will be voluntarily giving them the opportunity to make any changes they want.

        I wanna be a eunuchs developer! Pass me a bread knife!

        B Offline
        B Offline
        Bassam Abdul Baki
        wrote on last edited by
        #13

        That's assuming that the rootkit remover isn't what they're claiming it is. :)

        1 Reply Last reply
        0
        • B Bassam Abdul Baki

          Unagi!

          OriginalGriffO Offline
          OriginalGriffO Offline
          OriginalGriff
          wrote on last edited by
          #14

          Bassam Abdul-Baki wrote:

          Unagi!

          Fresh water eels?[^] :wtf:

          You should never use standby on an elephant. It always crashes when you lift the ears. - Mark Wallace

          "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
          "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt

          B 1 Reply Last reply
          0
          • OriginalGriffO OriginalGriff

            Bassam Abdul-Baki wrote:

            Unagi!

            Fresh water eels?[^] :wtf:

            You should never use standby on an elephant. It always crashes when you lift the ears. - Mark Wallace

            B Offline
            B Offline
            Bassam Abdul Baki
            wrote on last edited by
            #15

            Unagi[^]

            D 1 Reply Last reply
            0
            • B Bassam Abdul Baki

              Unagi[^]

              D Offline
              D Offline
              dan_fish
              wrote on last edited by
              #16

              That's cleared that up then! Go on - explain (I do like a freshwater eel - I had some nice ones in Portugal last year, but I'm struggling to get the connection here).

              B 1 Reply Last reply
              0
              • D dan_fish

                That's cleared that up then! Go on - explain (I do like a freshwater eel - I had some nice ones in Portugal last year, but I'm struggling to get the connection here).

                B Offline
                B Offline
                Bassam Abdul Baki
                wrote on last edited by
                #17

                It's from Friends - a US TV show.

                1 Reply Last reply
                0
                • M Mark_Wallace

                  By installing something that is written by people who want to invade your computer? Better to format or scrap the drive, flash the BIOS, do anything rather than trust such sterling examples of gentlepeople.

                  I wanna be a eunuchs developer! Pass me a bread knife!

                  L Offline
                  L Offline
                  Lilith C
                  wrote on last edited by
                  #18

                  Reformatting the drive doesn't help with this virus. It installs in sector zero and manipulates things so you can't touch that sector under Windows. My roommate found you could access it from Linux and squash it.

                  I'm not a programmer but I play one at the office

                  T 1 Reply Last reply
                  0
                  • M Mark_Wallace

                    Well, just make sure that you never connect to a network - any network - with the machine after installing such a monster. They have killed your machine, but installing the "update" will allow them to own it; you will be voluntarily giving them the opportunity to make any changes they want.

                    I wanna be a eunuchs developer! Pass me a bread knife!

                    P Offline
                    P Offline
                    patbob
                    wrote on last edited by
                    #19

                    Mark Wallace wrote:

                    installing the "update" will allow them to own it; you will be voluntarily giving them the opportunity to make any changes they want.

                    Like what.. they need your permission? If their rootkit is already there, there's absolutely nothing you can do that will give them more control over your system than they already have. The worst that can happen is that their "fix" will hide their stuff even deeper. The best that it will do what it says it will do. Chances are, they'll just make the systme more unstable. He'll have to write zeros over every sector on the drive to remove every last vestige of their stuff then reinstall, which is what he's fsing right now anyway.

                    patbob

                    1 Reply Last reply
                    0
                    • L Lilith C

                      Reformatting the drive doesn't help with this virus. It installs in sector zero and manipulates things so you can't touch that sector under Windows. My roommate found you could access it from Linux and squash it.

                      I'm not a programmer but I play one at the office

                      T Offline
                      T Offline
                      ThePotty1
                      wrote on last edited by
                      #20

                      Well when I 'format' a drive, I first delete the partition and re-create it. Is that enough or should I delete the partition, shut down and remove power for a couple of seconds, and then start again? Then I might as well kill the partition with a bootable linux cd, then boot and install windows.

                      L 1 Reply Last reply
                      0
                      • T ThePotty1

                        Well when I 'format' a drive, I first delete the partition and re-create it. Is that enough or should I delete the partition, shut down and remove power for a couple of seconds, and then start again? Then I might as well kill the partition with a bootable linux cd, then boot and install windows.

                        L Offline
                        L Offline
                        Lilith C
                        wrote on last edited by
                        #21

                        According to my roommate, who's the one who's fighting this at his workplace, deleting the partition isn't enough.

                        I'm not a programmer but I play one at the office

                        1 Reply Last reply
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups