cancel
Showing results for 
Search instead for 
Did you mean: 

Rootkit, anybody?

Anonymous
Not applicable

Re: Rootkit, anybody?

You could always try fdisk /mbr from a command line. Either via Safe Mode or a Standard CLI.
picbits
Rising Star
Posts: 3,432
Thanks: 23
Registered: ‎18-01-2013

Re: Rootkit, anybody?

Quote from: ReedRichards
I'm not sure if I simply missed that at first look or if It had been 'cloaked' and I managed to reveal it.

A customer of mine had a similar issue.
AVG / MSE / Avast all came up with no viruses detected. One rootkit removal later and there were five or six hiding away .....
7up
Community Veteran
Posts: 15,830
Thanks: 1,587
Fixes: 17
Registered: ‎01-08-2007

Re: Rootkit, anybody?

I was just about to suggest the same as mook too but the trouble is these days most laptops don't have floppy drives and vista and 7 (and later i assume) don't seem to have a pre-boot dos prompt to use  Roll_eyes
I'm working on a laptop now thats also been hit with a rootkit, the antivirus had expired (free but the owner being a woman didn't know how to renew it - despite the onscreen instructions) and had several other expired similar products too.
Somehow the laptop got hit with a rootkit and all hell has broken loose. It still sees other machines on the network via ping but the browsers cannot access anything via http - even on my intranet so something is clearly screwed up!
Quote from: DomS
I've had one machine that was so riddled with stuff after contracting a rootkit that it took a clean boot with Hirens, a disinfect then some serious repair work afterwards - three days to rebuild that machine Sad

I know that feeling Dom. This same laptop I mention above has been here before last year and was in just as bad state then. To add insult to injury it was also badly overheating and needed a complete backup too and was incredibly noisy  Cry Nasty job that, I ended up dumping it out in the kitchen just to escape the noise and then once I'd VNC'd into it and backed up everything I ended up stripping the damned thing down to parts. The cooling fan being the bit i wanted to get to of course being the very last part to come out of the system buried under everything else.. was completely clogged with a carpet of dust on each set of cooling fans. That also took me a few days to sort out.
I now have it here again and guess what... IT'S THE BLOOMIN SAME! Stuff dismantling it again though, last time I got a "thanks for that.. we didn't get you anything though" so considering the same repair would cost £150+ with most laptop specialists I'm just doing as little as possible this time - rid it of the nasties and give it back. At a push i might reinstall windows if i'm really forced to..
I need a new signature... i'm bored of the old one!
ReedRichards
Seasoned Pro
Posts: 4,927
Thanks: 145
Fixes: 25
Registered: ‎14-07-2009

Re: Rootkit, anybody?

You cannot use fdisk unless your computer runs Windows XP or earlier.  Instead you use the bootrec.exe tool (as I stated in a previous response).
You get to a 'DOS prompt' by pressing F8 as the computer is starting, choosing Repair my Computer.  If the computer starts an automatic repair you may want to cancel that.  Windows 8 computers may boot too fast for the F8 key to work but there is a settings option to restart the computer in the mode you require.
A computer that keeps coming back with the same sort of virus problems possibly isn't being 'cured'.  In the past I have done a factory reset on a computer with a boot sector virus and observed that the virus survived.
Anonymous
Not applicable

Re: Rootkit, anybody?

Thanks RR for pointing out the use of fdisk (or lack of it) but I was under the impression that it was available on 7 sorry for the confusion guys.
I have to be honest and say that it has been a while since I've actually rolled up the sleeves on a machine like this, so a bit behind the times.
7up
Community Veteran
Posts: 15,830
Thanks: 1,587
Fixes: 17
Registered: ‎01-08-2007

Re: Rootkit, anybody?

Quote from: Mook
I have to be honest and say that it has been a while

Same here. My win7 machine has been so reliable i've never needed to bother doing anything with it really. I did reinstall windows once but that was a automated OEM thing so no biggie. Not had to repartition a drive for years yet alone deal with the MBR! Not a task i'd want to do via a linux live cd either.
I need a new signature... i'm bored of the old one!
7up
Community Veteran
Posts: 15,830
Thanks: 1,587
Fixes: 17
Registered: ‎01-08-2007

Re: Rootkit, anybody?

Quote from: ReedRichards
A computer that keeps coming back with the same sort of virus problems possibly isn't being 'cured'.

It doesn't keep coming back, this is the second time i've had it. The last time it was cured and it is this time too (now i've spent ages on it since my last post).
I've not bothered dismantling or reinstalling though, i've just ridded it of everything, run several more scans after (which always turns up stuff that was being hidden by the previous nasties) and eventually got it nice and clean. Internet works again too so she will be pleased.
Can you believe the last time i repaired it (taking it apart, sorting out the cooling fan and fins and applying new thermal paste), i asked them to pay for the thermal paste as i had none left.. and they even took the rest of it with them  Roll_eyes Not that they'd ever use it or know how but they took it simply because in their eyes, they'd paid for it. Stuff the out of work guy repairing it for free (for two employed people) who might be able to use it  Crazy
Some people are so tight their backsides must squeek  Roll_eyes
I need a new signature... i'm bored of the old one!
ReedRichards
Seasoned Pro
Posts: 4,927
Thanks: 145
Fixes: 25
Registered: ‎14-07-2009

Re: Rootkit, anybody?

Quote from: 7up
...the out of work guy repairing it for free (for two employed people) who might be able to use it  Crazy

So why do it?  You're depriving some poor techy of work that he/she might need to feed the family, you get no thanks and you quite possibly encourage a careless attitude towards the computer that lands you with much the same thankless task a year later.
nanotm
Pro
Posts: 5,756
Thanks: 156
Fixes: 2
Registered: ‎11-02-2013

Re: Rootkit, anybody?

I used to help people like that but only for goods in return, I don't mind sorting things out for others so they can continue using them without the £75 evaluation fee charged by pc(ripyouoffshop)world before undertaking to open the machine up and actually repair it....
they pay for the parts though as required and most don't come back too often once the thing is made to work as they want
just because your paranoid doesn't mean they aren't out to get you
7up
Community Veteran
Posts: 15,830
Thanks: 1,587
Fixes: 17
Registered: ‎01-08-2007

Re: Rootkit, anybody?

Quote from: ReedRichards
Quote from: 7up
...the out of work guy repairing it for free (for two employed people) who might be able to use it  Crazy

So why do it?

You know I keep asking myself that. I'm a mug.. I was brought up with the christian attitude of always help others. Clearly that doesn't work in the real world does it.
This is the last time i touch this laptop... i'm not doing it again. I've had enough of freeloaders.. it gets me nowhere.
I need a new signature... i'm bored of the old one!
shylok
Rising Star
Posts: 252
Thanks: 23
Fixes: 1
Registered: ‎29-11-2014

Re: Rootkit, anybody?

Kasperksy TDSSKiller is a free scanner for rootkits