Author Topic: Hatred for rootkit  (Read 1249 times)

0 Members and 1 Guest are viewing this topic.

Plane

  • Hero Member
  • *****
  • Posts: 26993
    • View Profile
Hatred for rootkit
« on: March 09, 2010, 10:12:14 AM »
http://en.wikipedia.org/wiki/Rootkit



I am getting virused every two minutes.

Rootkit has propped a back door open and can't be removed.

Anyone have a suggestion?

BT

  • Administrator
  • Hero Member
  • *****
  • Posts: 16143
    • View Profile
    • DebateGate
Re: Hatred for rootkit
« Reply #1 on: March 09, 2010, 10:34:02 AM »
What virus is being found?

Amianthus

  • Hero Member
  • *****
  • Posts: 7574
  • Bring on the flames...
    • View Profile
    • Mario's Home Page
Re: Hatred for rootkit
« Reply #2 on: March 09, 2010, 10:36:10 AM »
Anyone have a suggestion?

I like running Linux.
Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight. (Benjamin Franklin)

Plane

  • Hero Member
  • *****
  • Posts: 26993
    • View Profile
Re: Hatred for rootkit
« Reply #3 on: March 09, 2010, 11:16:26 AM »
What virus is being found?


Global root\systemroot\system32\4DW4R3:OHtkIpbGe.dl is not a valid windows image

interrutpts almost everything I do

Virus patroll finds cookies and adware ten each time I run it, even if I run it immediately again I still get ten infections found , "successfully removed" and the problem starts over again.

Rootkit detected (rootkittdss) usually so I think that I have a rootkit that arrived with a trojan I diddn't notice. It either props open a backdoor to the same set of adware or it installs it itself right after I clear it.

I might not ever have noticed the rootkit itself ,only the adware that interrupts so often. I wonder if my computer is being used to spread the contagion?

BT

  • Administrator
  • Hero Member
  • *****
  • Posts: 16143
    • View Profile
    • DebateGate
Re: Hatred for rootkit
« Reply #4 on: March 09, 2010, 12:34:51 PM »

Xavier_Onassis

  • Hero Member
  • *****
  • Posts: 27916
    • View Profile
Re: Hatred for rootkit
« Reply #5 on: March 09, 2010, 01:26:00 PM »
I have tried to run Linux, but neither Ubuntu 8.1 nor 9.04, which are supposed to give the options of crating a dual boot, will load properly: the drive is already partitioned, and when it gets to the point where I partition it again, it refuses to go any further.

I would suggest googling the words root kit repair and see what you get.
"Time flies like an arrow; fruit flies like a banana."

Amianthus

  • Hero Member
  • *****
  • Posts: 7574
  • Bring on the flames...
    • View Profile
    • Mario's Home Page
Re: Hatred for rootkit
« Reply #6 on: March 09, 2010, 04:24:08 PM »
I have tried to run Linux, but neither Ubuntu 8.1 nor 9.04, which are supposed to give the options of crating a dual boot, will load properly: the drive is already partitioned, and when it gets to the point where I partition it again, it refuses to go any further.

You have to use a utility to reduce the size of the current partition so that a new one for Linux can be created.

Either that, or use a distribution that boots directly from the Windows file system.
Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight. (Benjamin Franklin)

Xavier_Onassis

  • Hero Member
  • *****
  • Posts: 27916
    • View Profile
Re: Hatred for rootkit
« Reply #7 on: March 09, 2010, 06:16:38 PM »
Either that, or use a distribution that boots directly from the Windows file system.

I used a distro intended to boot from a windows file system. It didn't work, either.
"Time flies like an arrow; fruit flies like a banana."

Amianthus

  • Hero Member
  • *****
  • Posts: 7574
  • Bring on the flames...
    • View Profile
    • Mario's Home Page
Re: Hatred for rootkit
« Reply #8 on: March 09, 2010, 06:27:37 PM »
I used a distro intended to boot from a windows file system. It didn't work, either.

You don't happen to have an old Radio Shack or Bell and Howell computer, do you? They both used lots of non-standard hardware that didn't work well without custom OS builds.
Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight. (Benjamin Franklin)

Xavier_Onassis

  • Hero Member
  • *****
  • Posts: 27916
    • View Profile
Re: Hatred for rootkit
« Reply #9 on: March 09, 2010, 09:02:11 PM »
It is a computer I assembled myself from a barebones kit. I have loaded a dual boot system Windows XP Pro and Ubuntu on it before. It has Phoenix bios LTD 6.00 PG 3/5/2005 and a Celeron 2.40 GHz CPU.

Th e problem could be that I partitioned the drive into two virtual drives before I loaded Windows on the C drive and should have left the partitioning up to the Ubunto program.

Can I repartition the drive into a single drive without losing everything? I have Partition Genius and Spotmau, which both can partition, but can they unpartition?

The Ubuntu requires a small boot partition and a larger one for programs. I forgot this, and partitioned the drive, as I said, probably in error. Now Ubuntu does a partial load and freezes after about 20 minutes.

Originally, I had Windows and Ubuntu on this same computer as a dual boot, but I lost the Ubuntu password and did not register Windows and so before I reloaded them, I erased the drive (a serial 100 Gig WD).

Thanks for any help.
"Time flies like an arrow; fruit flies like a banana."

Amianthus

  • Hero Member
  • *****
  • Posts: 7574
  • Bring on the flames...
    • View Profile
    • Mario's Home Page
Re: Hatred for rootkit
« Reply #10 on: March 09, 2010, 09:16:11 PM »
There is a mini-FAQ for help with setting up a dual boot system: http://www.tldp.org/HOWTO/Install-Strategies/

The software discussed in this mini-FAQ is FIPS, which I've used successfully several times.
Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight. (Benjamin Franklin)

Plane

  • Hero Member
  • *****
  • Posts: 26993
    • View Profile
Re: Hatred for rootkit
« Reply #11 on: March 14, 2010, 07:03:55 PM »
 
  BT your suggestion worked , but it was an epic battle.


    Spyware Doctor was able to diagnose the problem as Rootkit , but was unable to locate or affect it. The site you pointed out led to UnHackMe which really did the same thing but no better. Time  and again I got a warning but no less infected.

  But Wiccipedia had some informtion about the way a Rootkit hides itself that suggested the strategy that finally worked. Thanks Xo that was your suggestion.

       The Rootkit can react to sarches for it by shutting down the functions that the antivirus could use to find it , so I attempted the tequnique suggested and ran two antivirals at once.

      As Spyware Doctor combed the halls of my computers memory banks the Rootkit , the rootkit did as before and ducked out of sight, but this time UnHackMe was also on patroll and spotted Rootkit reactivateing itself and peeping out of its hidey hole. nhackMe sprang into action and grasped the monster by the scruff of its neck and lifting it into plane sight.
  
   It was  Blue , not a pleasant blue  , but a greasy dirty blue , a blue the hue of death. It had bracts and jointed legs which twiched and writhed in grip of  UnHackMe ,it schreeched and chittered and scratched and grasped  to no avail.  I ordered  UnHackMe to destroy it  so with his vorpal blade he went snicker snack destroying it utterly. Oh Fabjurous day.

Spy Ware Doctor found a huge ragged crater in nessacery programming and 66 infections which previously had been hidden by the the Rootkit ,Microsoft obligeingly provided bandagges and updates which replaced the dammaged software
 functioning has returned to the old normal.
« Last Edit: March 14, 2010, 07:08:12 PM by Plane »

Xavier_Onassis

  • Hero Member
  • *****
  • Posts: 27916
    • View Profile
Re: Hatred for rootkit
« Reply #12 on: March 14, 2010, 11:12:51 PM »
Congratulations! I am glad you got rid of this. I have used search engines to remove a lot of nasty stuff before. A recommend Avira and AVG, and both of them together would be a good idea, except they interfere with one another's updates.

Do you have any idea how you got it, or how to prevent it from getting in?
"Time flies like an arrow; fruit flies like a banana."

Plane

  • Hero Member
  • *****
  • Posts: 26993
    • View Profile
Re: Hatred for rootkit
« Reply #13 on: March 15, 2010, 07:51:34 PM »


Do you have any idea how you got it, or how to prevent it from getting in?


I wish I did.

Already another of the same type has had to be removed. I know how now but it is still time consuming.

Do these things leave tracks ?

Can its sorce be spotted?


Probly another innocent who wishes nothing more than to get rid of it also.