Rootkit halp pl0x menu

User Tag List

Results 1 to 8 of 8
  1. #1
    2dgreengiant's Avatar ★ Elder ★


    Reputation
    1192
    Join Date
    Feb 2007
    Posts
    7,129
    Thanks G/R
    1/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Rootkit halp pl0x

    lolololololololololololol.


    2d being 2d was messing around with some crypters and managed to get my pc ifnected me thinks.

    Now my Anti Virus picks up a hidden driver as a root kit and it removes it but after every restart the rootkit comes back in the same place:

    Windows\System32\Drivers

    But under diferent names. Currently its called ahd1rewd.SYS

    Tried going into safe mode but it keeps renaming itself. Any ideas what i can do APART FROM FORMAT!!

    +11 for any help.

    ~2d~
    If you need me you have my skype, if you don't have my skype then you don't need me.

    Rootkit halp pl0x
  2. #2
    Ground Zero's Avatar ★ Elder ★
    Reputation
    1132
    Join Date
    Aug 2008
    Posts
    3,504
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Format your computer?

  3. #3
    Gastricpenguin's Avatar Legendary
    Reputation
    980
    Join Date
    Feb 2007
    Posts
    2,236
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    not a format, a REformat c:

  4. #4
    JD's Avatar Fedora Potato Johnson V
    Reputation
    1113
    Join Date
    Jan 2008
    Posts
    3,129
    Thanks G/R
    12/89
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Oi, you should've waited for me to get you my crypter slacker xP Now you have to Reformat C...




  5. #5
    The-Eradicator's Avatar Contributor

    Reputation
    149
    Join Date
    May 2007
    Posts
    829
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    The first thing i'd try in this situation is MRT. Without more specific details to find out what the virus is there's not much you can do besides scans. If at any step you find something post it up here.

    1. Download and run this. Select Full Scan.

    Note: This can take up to twelve hours. Just leave it running during the night.

    2. Open up Windows Explorer and look at C:\WINDOWS\system32. Sort by date. Look for anything (specifically, DLLs) added in the past few days (since the day before you noticed the virus). If you find anything and don't know what it is post it here.

    3. Run a scan with Malwarebytes' Anti-Malware.

    4. Run a scan with the AVG Rootkit Scanner.


    If none of that works you're either going to reformat or start getting fancy. While I wouldn't recommend it unless all else fails, you can start by running SDFix, Combofix, and posting a HijackThis log.
    Last edited by The-Eradicator; 09-04-2009 at 11:15 AM.

  6. #6
    2dgreengiant's Avatar ★ Elder ★


    Reputation
    1192
    Join Date
    Feb 2007
    Posts
    7,129
    Thanks G/R
    1/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by The-Eradicator View Post
    The first thing i'd try in this situation is MRT. Without more specific details to find out what the virus is there's not much you can do besides scans. If at any step you find something post it up here.

    1. Download and run this. Select Full Scan.

    Note: This can take up to twelve hours. Just leave it running during the night.

    2. Open up Windows Explorer and look at C:\WINDOWS\system32. Sort by date. Look for anything (specifically, DLLs) added in the past few days (since the day before you noticed the virus). If you find anything and don't know what it is post it here.

    3. Run a scan with Malwarebytes' Anti-Malware.

    4. Run a scan with the AVG Rootkit Scanner.


    If none of that works you're either going to reformat or start getting fancy. While I wouldn't recommend it unless all else fails, you can start by running SDFix, Combofix, and posting a HijackThis log.

    Finally thank you a good and helpful asnwer thats not realted to ****ing formatting
    If you need me you have my skype, if you don't have my skype then you don't need me.

  7. #7
    [Ban Hammer]'s Avatar Banned
    Reputation
    394
    Join Date
    Dec 2007
    Posts
    728
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    You owe him some rep don't you my dear 2d?

  8. #8
    2dgreengiant's Avatar ★ Elder ★


    Reputation
    1192
    Join Date
    Feb 2007
    Posts
    7,129
    Thanks G/R
    1/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    ******* :P i cant as i already did it recently fgt.

    /closed as issue solved
    If you need me you have my skype, if you don't have my skype then you don't need me.

Similar Threads

  1. Halp? 1.12 Script packs pl0x?
    By Mr. Missletits in forum WoW EMU Guides & Tutorials
    Replies: 3
    Last Post: 03-03-2009, 02:06 PM
  2. Hacking WoW-An exercise in advanced rootkit design
    By Dude_in_the_dark in forum World of Warcraft Bots and Programs
    Replies: 6
    Last Post: 01-02-2007, 03:50 AM
  3. Sony Rootkit
    By Farore in forum World of Warcraft General
    Replies: 0
    Last Post: 10-06-2006, 07:11 PM
  4. FU Rootkit Frontend
    By raunchy in forum Community Chat
    Replies: 3
    Last Post: 08-22-2006, 08:42 AM
All times are GMT -5. The time now is 11:48 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search