Author Topic: How to fix my own thing after infection with a rootkit  (Read 21678 times)

0 Members and 1 Guest are viewing this topic.

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
How to fix my own thing after infection with a rootkit
« on: May 31, 2013, 01:44:24 am »
How to fix my own thing after rootkit infection?Note that there is something strange in the Start menu

This is the suspicious message, which is found in the Start menu.

Code: [Select]
removes your laptop or notebook computer from a docking station

Offline Shane

  • Administrator
  • Hero Member
  • *****
  • Join Date: Sep 2011
  • Posts: 9281
  • Location: USA
  • Karma: 137
  • "Knowledge should be shared not hidden."
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #1 on: May 31, 2013, 04:46:15 pm »
Never heard of a rootkit putting that int he start menu.

Did you run the malwarebytes anti rootkit tool yet?

Shane

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #2 on: May 31, 2013, 08:08:46 pm »
Never heard of a rootkit putting that int he start menu.

Did you run the malwarebytes anti rootkit tool yet?

Shane

No,  should run this thing?  :cheesy:

Offline Shane

  • Administrator
  • Hero Member
  • *****
  • Join Date: Sep 2011
  • Posts: 9281
  • Location: USA
  • Karma: 137
  • "Knowledge should be shared not hidden."
    • View Profile

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #4 on: June 05, 2013, 03:19:05 am »

Offline Shane

  • Administrator
  • Hero Member
  • *****
  • Join Date: Sep 2011
  • Posts: 9281
  • Location: USA
  • Karma: 137
  • "Knowledge should be shared not hidden."
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #5 on: June 05, 2013, 10:28:02 pm »
Sounds like your fine then bud.

Windows does have docking station support, it is possible Windows put that shortcut there.

Shane

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #6 on: June 06, 2013, 06:24:10 am »
Sounds like your fine then bud.

Windows does have docking station support, it is possible Windows put that shortcut there.

Shane

Good, but this is the first time that I see such a thing!But Firefox has a problem with Hotspot Shield program and every time I turn my Hotspot Shield on Then get a pop-up Web pages and seems like a malicious pages and I also noted the web asks me to enter my information in order to unlock my computer?

This is weird. :shocked:

http://www.youtube.com/watch?v=wuSIKzDLnbg
« Last Edit: June 06, 2013, 06:26:30 am by G-hot »

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #7 on: June 06, 2013, 10:33:14 am »
Does it happen when your logged in as Adm?


Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #8 on: June 06, 2013, 01:51:27 pm »
Does it happen when your logged in as Adm?

same thing

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #9 on: June 06, 2013, 09:59:30 pm »
could you try this? forget the fact it says for XP, get inside ok

http://support.microsoft.com/kb/308577


Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #10 on: June 08, 2013, 01:18:34 am »
How to access Administrator rights In normal mode?

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #11 on: June 08, 2013, 05:31:24 am »
net user administrator /active:yes

Warning; Hackers Should be careful!


Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #12 on: June 15, 2013, 10:16:13 pm »
could you try this? forget the fact it says for XP, get inside ok

http://support.microsoft.com/kb/308577

No need for it!Because this was due to a rootkit virus  :smiley:

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #13 on: June 16, 2013, 02:07:55 pm »
Never heard of a rootkit putting that int he start menu.

Did you run the malwarebytes anti rootkit tool yet?

Shane

Now I'm sure this was due to a rootkit virus!So what do you think?  :smiley: http://support.emsisoft.com/topic/11563-explorerexe-virus/?p=77886
« Last Edit: June 16, 2013, 02:09:27 pm by G-hot »

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #14 on: June 17, 2013, 07:36:43 am »
Have you tried running "hijack this" and autoruns?

see what it finds? be sure run in adminstrator mode

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #15 on: June 17, 2013, 07:51:02 am »
This is what I do always like I run these tools!Clicking on the analysis and kill all the startup items  :cheesy:

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #16 on: June 21, 2013, 11:45:43 pm »
I found that autoexterminator is useful too;

has that had any impact.

did you identfiy what rootkit virus you had?

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #17 on: June 23, 2013, 03:36:19 pm »
I have asked one of the experts, but he does not know what kind of rootkit virus that I'm infected with!
So what can I do now?

Offline Shane

  • Administrator
  • Hero Member
  • *****
  • Join Date: Sep 2011
  • Posts: 9281
  • Location: USA
  • Karma: 137
  • "Knowledge should be shared not hidden."
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #18 on: June 24, 2013, 09:12:28 pm »
If you have a rootkit that is brand new and no scanners can detect it yet then your stuck doing a reinstall to get rid of it bud.

This is just one of the many reasons I cant stand rootkits.

Shane

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #19 on: June 25, 2013, 10:29:45 am »
first off, you mention that it put some nonsense in the start menu?

The name of that file?

Where does it reside in your system?
Looked at the registry key to confirm it does or does not link to any other areas?

searched hidden files for the name of the file in the start menu?

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #20 on: June 26, 2013, 03:35:26 am »
first off, you mention that it put some nonsense in the start menu?

The name of that file?

Where does it reside in your system?
Looked at the registry key to confirm it does or does not link to any other areas?

searched hidden files for the name of the file in the start menu?

yeah, That's right!, This is what appears to me when I put the mouse on the icon.

http://www.tweaking.com/forums/index.php/topic,1184.msg7899.html#msg7899

see my video. and icon name is undock computer

http://www.tweaking.com/forums/index.php/topic,1184.msg8000.html#msg8000


undock computer Elements found in the Registry
Did not find any items in hidden files

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #21 on: June 26, 2013, 04:17:13 am »
If you have a rootkit that is brand new and no scanners can detect it yet then your stuck doing a reinstall to get rid of it bud.

This is just one of the many reasons I cant stand rootkits.

Shane

I will do so in the next few days  :smiley:

Thanks for the advice :wink:

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #22 on: June 26, 2013, 05:44:25 am »
Ok, you know where the bad stuff is in the registry; A new install, I wouldn't go that far just yet...

I would, export each registry key to a folder on my desktop, then I would consult with shane abdelete each key...
out deleting each key and restart the computer to see the results.

I would also verify each function of the links in the registry and also delete each file it points too
if you have or they point to other areas in your registry using this as an example but filled with code like {0000-0000-0000000-0000000} then go to that key and se where it points to and export it also and then delete it.

I can not see that video because I am here in china and youtube just isn't avaiable here. if you can capture some key screen elements and post them back here?

Also, it will be interesting to see the key strings, I think even shane will want to know what they are too..

their is another program on ubunta called rootkitty, have you heard of? try to download and run it using the method they suggests.. it seems viable option to finding any root kit problems... "I have never used it so I am afraid I can not comment except that in your case, I WOULD TRY IT!

 A new install, I wouldn't go that far just yet...
« Last Edit: June 26, 2013, 07:02:27 am by Rick »

Offline Rick

  • Hero Member
  • *****
  • Join Date: May 2013
  • Posts: 829
  • Karma: 2
    • View Profile
Re: How to fix my own thing after infection with a rootkit
« Reply #23 on: June 26, 2013, 05:46:20 am »
does this work? try it
« Last Edit: June 26, 2013, 06:06:08 am by Rick »

Offline Gamezertruth

  • Hero Member
  • *****
  • Join Date: Aug 2012
  • Posts: 1143
  • Karma: 4
    • View Profile
    • Gamezertruth
Re: How to fix my own thing after infection with a rootkit
« Reply #24 on: June 26, 2013, 01:54:12 pm »
here my file.. check it!