Tweaking.com Support Forums

Main Forum => General Computer Support => Topic started by: Gamezertruth on May 31, 2013, 01:44:24 am

Title: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on May 31, 2013, 01:44:24 am
How to fix my own thing after rootkit infection?Note that there is something strange in the Start menu

This is the suspicious message, which is found in the Start menu.

Code: [Select]
removes your laptop or notebook computer from a docking station
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Shane on May 31, 2013, 04:46:15 pm
Never heard of a rootkit putting that int he start menu.

Did you run the malwarebytes anti rootkit tool yet?

Shane
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on May 31, 2013, 08:08:46 pm
Never heard of a rootkit putting that int he start menu.

Did you run the malwarebytes anti rootkit tool yet?

Shane

No,  should run this thing?  :cheesy:
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Shane on June 02, 2013, 02:42:45 pm
Wont hurt :-)

http://www.malwarebytes.org/products/mbar/

Shane
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 05, 2013, 03:19:05 am
Wont hurt :-)

http://www.malwarebytes.org/products/mbar/

Shane

no malware Found  :smiley: so what i can do?
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Shane on June 05, 2013, 10:28:02 pm
Sounds like your fine then bud.

Windows does have docking station support, it is possible Windows put that shortcut there.

Shane
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 06, 2013, 06:24:10 am
Sounds like your fine then bud.

Windows does have docking station support, it is possible Windows put that shortcut there.

Shane

Good, but this is the first time that I see such a thing!But Firefox has a problem with Hotspot Shield program and every time I turn my Hotspot Shield on Then get a pop-up Web pages and seems like a malicious pages and I also noted the web asks me to enter my information in order to unlock my computer?

This is weird. :shocked:

http://www.youtube.com/watch?v=wuSIKzDLnbg (http://www.youtube.com/watch?v=wuSIKzDLnbg)
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 06, 2013, 10:33:14 am
Does it happen when your logged in as Adm?

Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 06, 2013, 01:51:27 pm
Does it happen when your logged in as Adm?

same thing
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 06, 2013, 09:59:30 pm
could you try this? forget the fact it says for XP, get inside ok

http://support.microsoft.com/kb/308577

Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 08, 2013, 01:18:34 am
How to access Administrator rights In normal mode?
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 08, 2013, 05:31:24 am
net user administrator /active:yes

Warning; Hackers Should be careful!

Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 15, 2013, 10:16:13 pm
could you try this? forget the fact it says for XP, get inside ok

http://support.microsoft.com/kb/308577

No need for it!Because this was due to a rootkit virus  :smiley:
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 16, 2013, 02:07:55 pm
Never heard of a rootkit putting that int he start menu.

Did you run the malwarebytes anti rootkit tool yet?

Shane

Now I'm sure this was due to a rootkit virus!So what do you think?  :smiley: http://support.emsisoft.com/topic/11563-explorerexe-virus/?p=77886
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 17, 2013, 07:36:43 am
Have you tried running "hijack this" and autoruns?

see what it finds? be sure run in adminstrator mode
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 17, 2013, 07:51:02 am
This is what I do always like I run these tools!Clicking on the analysis and kill all the startup items  :cheesy:
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 21, 2013, 11:45:43 pm
I found that autoexterminator is useful too;

has that had any impact.

did you identfiy what rootkit virus you had?
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 23, 2013, 03:36:19 pm
I have asked one of the experts, but he does not know what kind of rootkit virus that I'm infected with!
So what can I do now?
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Shane on June 24, 2013, 09:12:28 pm
If you have a rootkit that is brand new and no scanners can detect it yet then your stuck doing a reinstall to get rid of it bud.

This is just one of the many reasons I cant stand rootkits.

Shane
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 25, 2013, 10:29:45 am
first off, you mention that it put some nonsense in the start menu?

The name of that file?

Where does it reside in your system?
Looked at the registry key to confirm it does or does not link to any other areas?

searched hidden files for the name of the file in the start menu?
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 26, 2013, 03:35:26 am
first off, you mention that it put some nonsense in the start menu?

The name of that file?

Where does it reside in your system?
Looked at the registry key to confirm it does or does not link to any other areas?

searched hidden files for the name of the file in the start menu?

yeah, That's right!, This is what appears to me when I put the mouse on the icon.

http://www.tweaking.com/forums/index.php/topic,1184.msg7899.html#msg7899

see my video. and icon name is undock computer

http://www.tweaking.com/forums/index.php/topic,1184.msg8000.html#msg8000


undock computer Elements found in the Registry
Did not find any items in hidden files
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 26, 2013, 04:17:13 am
If you have a rootkit that is brand new and no scanners can detect it yet then your stuck doing a reinstall to get rid of it bud.

This is just one of the many reasons I cant stand rootkits.

Shane

I will do so in the next few days  :smiley:

Thanks for the advice :wink:
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 26, 2013, 05:44:25 am
Ok, you know where the bad stuff is in the registry; A new install, I wouldn't go that far just yet...

I would, export each registry key to a folder on my desktop, then I would consult with shane abdelete each key...
out deleting each key and restart the computer to see the results.

I would also verify each function of the links in the registry and also delete each file it points too
if you have or they point to other areas in your registry using this as an example but filled with code like {0000-0000-0000000-0000000} then go to that key and se where it points to and export it also and then delete it.

I can not see that video because I am here in china and youtube just isn't avaiable here. if you can capture some key screen elements and post them back here?

Also, it will be interesting to see the key strings, I think even shane will want to know what they are too..

their is another program on ubunta called rootkitty, have you heard of? try to download and run it using the method they suggests.. it seems viable option to finding any root kit problems... "I have never used it so I am afraid I can not comment except that in your case, I WOULD TRY IT!

 A new install, I wouldn't go that far just yet...
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Rick on June 26, 2013, 05:46:20 am
does this work? try it
Title: Re: How to fix my own thing after infection with a rootkit
Post by: Gamezertruth on June 26, 2013, 01:54:12 pm
here my file.. check it!