MSFN Forum: Rootkit - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Rootkit Rate Topic: -----

#1 User is offline   Highlygifted 

  • Newbie
  • Group: Members
  • Posts: 10
  • Joined: 20-March 09

Posted 28 March 2009 - 10:37 AM

I've been tasked with fixing a sibling's computer which contracted Rootkit, and so far it has been an annoying ordeal. When it logs on, it flashes the desktop, then logs off automatically, and leads me to the user selection screen. I was able to determine the problem was Rootkit before, but during my absence a past weekend, my father tried to fix it and did something which he can't remember and I've been left unable to access safe mode. Thanks in advance for the help.

Running Windows XP on her computer, btw.

This post has been edited by Highlygifted: 29 March 2009 - 09:48 AM



#2 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 10,934
  • Joined: 09-September 01
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 28 March 2009 - 12:35 PM

Moving.

#3 User is offline   DigeratiPrime 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,490
  • Joined: 18-August 04
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 28 March 2009 - 05:50 PM

What version of Windows are you running?
What options do you have on the Advanced Boot Options menu (F8)?
Do you have a Windows Vista setup disc? That includes WinRE which could be used to modify the registry "offline".

#4 User is offline   Tarun 

  • Area 5 Investigator
  • Group: Super Moderator
  • Posts: 2,991
  • Joined: 27-January 04
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 31 March 2009 - 11:36 AM

Please download my Anti-Malware Toolkit and get the Professional package. Then follow the directions in the PC Cleanup guide. After that, please post a HijackThis log.

#5 User is offline   Highlygifted 

  • Newbie
  • Group: Members
  • Posts: 10
  • Joined: 20-March 09

Posted 31 March 2009 - 07:25 PM

First of all, I have to find a way to replace userinit.exe, the missing part which is causing this problem apparently. Can I get some help replacing this file with instructions? Thanks.

#6 User is offline   IcemanND 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,239
  • Joined: 24-September 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 31 March 2009 - 07:30 PM

is the file actually missing from c:\windows\system32?

Ir is it the registry value that loads it that is missing?

#7 User is offline   Highlygifted 

  • Newbie
  • Group: Members
  • Posts: 10
  • Joined: 20-March 09

Posted 31 March 2009 - 07:57 PM

That I don't know.

#8 User is offline   IcemanND 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,239
  • Joined: 24-September 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 31 March 2009 - 07:58 PM

do you have a way to make a bartpe cd (preferred) or connect the infected drive to another machine?

#9 User is offline   tguy 

  • Senior Member
  • PipPipPipPip
  • Group: Members
  • Posts: 698
  • Joined: 19-May 04

Posted 31 March 2009 - 09:08 PM

I ran across a rootkit infected computer today as well. I downloaded unhackme.zip, installed and cleaned it up. May want to try that too.

#10 User is offline   IcemanND 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,239
  • Joined: 24-September 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 31 March 2009 - 09:13 PM

if it's missing userint.exe or the associated registry key he can't log into the machine, even in safe mode. He'll need to boot from other media or in another machine to fix that issue before you can do anything else, or perform a repair, may work but is a little extreme.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy