Thetownend.com

80% => Computer & Technology => Topic started by: juddie on Monday, February 15, 2010, 23:50:41



Title: rootkit
Post by: juddie on Monday, February 15, 2010, 23:50:41
keep getting this notice that I have a rootkit in my system and that I should delete it. Thing is, it won't let me delete it. Is it a virus and if so, how can I get rid of it?


Title: Re: rootkit
Post by: jonny72 on Tuesday, February 16, 2010, 00:17:08
What is issuing the notice? Anti-virus software? Or something else?

I'm no expert but I rootkits can be really bad shit, reinstall Windows kind of bad shit.


Title: Re: rootkit
Post by: jayohaitchenn on Tuesday, February 16, 2010, 02:37:01
Jonny is right. It takes a proper expert days of work to get rid of a rootkit. Better off starting from scratch.


Title: Re: rootkit
Post by: Simon Pieman on Tuesday, February 16, 2010, 08:45:57
Before you do anything rash, let us know the program causing the alert. As jonny alluded to, a lot of dodgy messages appear from suspect third party apps just to get you to buy their software. There may actually be no rootkit at all, although if you're getting dodgy messages you at least have some form of malware present.


Title: Re: rootkit
Post by: stfcinbmth on Tuesday, February 16, 2010, 09:10:09
Worth a try

Code:
http://www.malwarebytes.org/


Title: Re: rootkit
Post by: Peter Venkman on Tuesday, February 16, 2010, 09:57:52
This is the best antirootkit on the market and its free, just sign up to it with a fake name and address, no real registration needed as it just chucks up the download link as soon as you click on next.

http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html


Title: Re: rootkit
Post by: juddie on Tuesday, February 16, 2010, 09:58:15
I'll take a look tonight. cheers for the advice.


Title: Re: rootkit
Post by: juddie on Tuesday, February 16, 2010, 23:06:45
right, I'm getting this:

C:\Windows\System32\Drivers\vjmxh.sys
hidden services
Win32:Rootkit-gen [Rtk]


Title: Re: rootkit
Post by: caveman on Wednesday, February 17, 2010, 11:33:07
Jonny is right. It takes a proper expert days of work to get rid of a rootkit. Better off starting from scratch.

days of work is a bit of an exaggeration, its not rocket science


Title: Re: rootkit
Post by: Simon Pieman on Wednesday, February 17, 2010, 14:05:39
right, I'm getting this:

C:\Windows\System32\Drivers\vjmxh.sys
hidden services
Win32:Rootkit-gen [Rtk]


I'll come online later this evening probably about 9pm and will help you out. I think we should be able to remove this tonight, I don't reckon it's more than an evening's work, hopefully only an hour or two to confirm your computer is clean.


Title: Re: rootkit
Post by: juddie on Wednesday, February 17, 2010, 14:23:47
top man. I'll see you then...


Title: Re: rootkit
Post by: jonny72 on Wednesday, February 17, 2010, 16:47:49
I'll come online later this evening probably about 9pm.

Another chat roulette fan.


Title: Re: rootkit
Post by: Simon Pieman on Monday, February 22, 2010, 23:54:08
This was a pain in the backside to remove. In the end I used a great tool which identifies rootkits and allows you to kill the hidden process before deleting. Nothing else would work, took many attempts but sorted it out using remote assistance.

Code:
http://www.gmer.net/

I'd only use it if you have a decent knowledge of computers, don't want anyone to fuck their pc up.


Title: Re: rootkit
Post by: jayohaitchenn on Tuesday, February 23, 2010, 08:47:17
How long did it take?


Title: Re: rootkit
Post by: juddie on Tuesday, February 23, 2010, 10:48:30
three/four nights of Si's time, for which I am eternally grateful. Cheers Si!


Title: Re: rootkit
Post by: Simon Pieman on Tuesday, February 23, 2010, 10:56:41
Quite a few hours, spread over several days. It would have been easier and a lot quicker if the computer was physically in front of me. We wasted much time just getting the remote desktop to work.

Having said that, had I used the gmer tool to start with it would have taken a fraction of the time, even remotely, so it really does come highly recommended.

The tools I used were as follows:

Avast anti-virus
Malwarebytes Anti-Malware
Trend Micro HijackThis
Gmer.exe
Windows System Integrity Scans in the command line
Remove the offending file manually
Tried to remove the offending file using the command line as well and it wasn't having any of it
I think Juddie had also run online scans and Spyware Doctor

In the end I disabled system restore, unlocked and stopped the hidden process with gmer.exe, scanned and removed the offending file using malwarebytes (after I had confirmed it was a completely bogus sys file). Run a system integrity check to make sure there were no issues and then re-enabled system restore once all scans were coming up clean. Probably one of the most persistent things I've come across.

That probably means you have grounds to quote someone above and use your catchphrase :)


Title: Re: rootkit
Post by: jayohaitchenn on Tuesday, February 23, 2010, 11:29:20
Thought so, Cheers Si.


Title: Re: rootkit
Post by: jayohaitchenn on Tuesday, February 23, 2010, 11:34:05
I've never seen that gmer thing before. It's pretty good, even just for info on running processes and threads. Could really help with manual fine-tuning of a Windows OS (if you're into that sort of thing :)).


Title: Re: rootkit
Post by: Simon Pieman on Tuesday, February 23, 2010, 13:48:42
Yeah I'd never heard of or seen it before the other night when I was getting very pissed off.

Apparently the website got loads of attacks because it was meant to be that good.


Title: Re: rootkit
Post by: Barry Scott on Tuesday, February 23, 2010, 14:36:49
On a remote desktop related thing, have you tried Teamviewer, it's free (if it's not for commercial purposes) and it's fucking ace. I used to use it and really recommend it for remote accessy rubbish, as it only takes seconds to get up and running, supplemented with phone or AIM of course.


Title: Re: rootkit
Post by: Simon Pieman on Wednesday, February 24, 2010, 20:26:41
Cool, I'll remember that


Title: Re: rootkit
Post by: jayohaitchenn on Thursday, February 25, 2010, 09:51:32
Add it to the free software list you lazy welsh git.


Title: Re: rootkit
Post by: Simon Pieman on Thursday, February 25, 2010, 13:48:23
I need to update a lot, not just that list. Not had the time recently.



Title: Re: rootkit
Post by: jayohaitchenn on Thursday, February 25, 2010, 13:55:11
Get on it then.


Title: Re: rootkit
Post by: land_of_bo on Thursday, February 25, 2010, 14:02:09
Yeah, Si, you can't take these things on and then be half-arsed.


Title: Re: rootkit
Post by: Simon Pieman on Thursday, February 25, 2010, 21:09:59
Oh believe me, I can :)