• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Rootkits

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #11
    Just spotted another thing to try - ComboFix
    How did this happen? Who's to blame? Well certainly there are those more responsible than others, and they will be held accountable, but again truth be told, if you're looking for the guilty, you need only look into a mirror.

    Follow me on Twitter - LinkedIn Profile - The HAB blog - New Blog: Mad Cameron
    Xeno points: +5 - Asperger rating: 36 - Paranoid Schizophrenic rating: 44%

    "We hang the petty thieves and appoint the great ones to high office" - Aesop

    Comment


      #12
      Might be useful too.
      Public Service Posting by the BBC - Bloggs Bulls**t Corp.
      Officially CUK certified - Thick as f**k.

      Comment


        #13
        My dear old 75 Year old mum has just had one of these work from home pc defenders come to her aid.

        She complained that her machine was slow
        so he investigated. Said her Norton was out of date, uninstalled it and stuck on Bitdefender. He then took a couple of apps off and said she needed additional memory. So he's upgraded that. Not expensive but £80.

        She's on the phone saying it's getting really hot and now cutting out.

        Frankly the guy who did it is a ******* idiot.

        The reason. The laptop is at least around 10-12 years old. She's recently added skype and the spec is
        low. Adding extra memory has pushed it over the edge.

        I would have got her to buy a new laptop, because now
        she's spent 80 and is heading back tomorrow. He won't get it fixed.

        That's the problem with these stay at home PC vigilantes, they'll keep on struggling to fix stuff, charging away when in truth the best option would be to
        flog them a new laptop and make cash that way.
        What happens in General, stays in General.
        You know what they say about assumptions!

        Comment


          #14
          Hi,
          take the disk out of said machine or boot from a live disk distribution of linux with avgfree added. Now you are protected from the crap that has owned the box, and you can scan the disk to your hearts content knowing no wintel code can run. The story I hear from a number of guys is that most of the good stuff these days will own your AV software in order to hide itself. So once the machine is owned anything loaded to try and sort it out is compromised before it loads. spyware guard and spyware blaster are also very good

          good luck

          Comment


            #15
            Originally posted by MarillionFan View Post
            Adding extra memory has pushed it over the edge.
            eh? How can adding extra memory 'push it over the edge' ?

            Are you saying it can't power the new memory?

            Comment


              #16
              Originally posted by suityou01 View Post
              Not really sure. Seeing as you have no clue to the gamut of scans and approaches I have used you are not making an informed decision, rather an ill informed decision while not being in charge of the facts. I have a 100% success rate in removing malware where others have said the machine is a lost cause.

              I do hope at work you make informed decisions rather than just wobbling around aimlessly scraping code samples from google and trying to gerry rig something together against a deadline.

              Tosspot.
              That's a very dangerous claim to make...

              (Unless of course we're talking full wipes etc, and even then...)
              B00med!

              Comment


                #17
                Them rootkits look horrid. What is stop any viruses using same techniques to hide processes, change bootstrap, sit in bios etc?
                bloggoth

                If everything isn't black and white, I say, 'Why the hell not?'
                John Wayne (My guru, not to be confused with my beloved prophet Jeremy Clarkson)

                Comment


                  #18
                  Fixed. Came close to reinstalling the OS, but persevered.
                  I used the latest Ultimate Boot CD with XP slipstreamed into it to give a lightweight OS to allow me to run the tools. The machine itself has one of those annoying NVidia all in one chipsets so windows did not pick up the network. I switched to a laptop and put Clients HDD in an IcyBox (well Maplins equivalent)

                  I ran superantispyware and cleaned up all the crap. Then I let malware bytes and avg free take a peek. Also sophos anti rootkit and blacklight.

                  All clean.

                  I rebooted the machine, and the same problem occured.

                  I checked again the browser addons, all disabled.
                  I ran process explorer and there was a google updater service running (part of the google toolbar I had disabled)

                  I uninstalled google toolbar, then blitzed the machine again in the icybox.
                  Then rebooted. Problem has gone away, and after some heavy surfing it is still all good.

                  I then patched it, defragged it and fixed the DVD codec issues.

                  What a flaming palaver.
                  Knock first as I might be balancing my chakras.

                  Comment


                    #19
                    Originally posted by suityou01 View Post
                    Fixed. Came close to reinstalling the OS, but persevered.
                    I used the latest Ultimate Boot CD with XP slipstreamed into it to give a lightweight OS to allow me to run the tools. The machine itself has one of those annoying NVidia all in one chipsets so windows did not pick up the network. I switched to a laptop and put Clients HDD in an IcyBox (well Maplins equivalent)

                    I ran superantispyware and cleaned up all the crap. Then I let malware bytes and avg free take a peek. Also sophos anti rootkit and blacklight.

                    All clean.

                    I rebooted the machine, and the same problem occured.

                    I checked again the browser addons, all disabled.
                    I ran process explorer and there was a google updater service running (part of the google toolbar I had disabled)

                    I uninstalled google toolbar, then blitzed the machine again in the icybox.

                    I then patched it, defragged it and fixed the DVD codec issues.

                    Then rebooted. Problem has gone away, and after some heavy surfing it is still all good.



                    What a flaming palaver.
                    Fixed it for you...
                    B00med!

                    Comment


                      #20
                      Originally posted by suityou01 View Post
                      Fixed.

                      What a flaming palaver.
                      May I ask, how much did you charge local customer for this?

                      I find these sorts of jobs very time-consuming, so charging even £25 per hour can make for a hefty bill.

                      Comment

                      Working...
                      X