Rootkit problem

General software, Operating Systems, and Programming discussion.
Everything from software questions, OSes, simple HTML to scripting languages, Perl, PHP, Python, MySQL, VB, C++ etc.
Post Reply
User avatar
Epyon
Regular Member
Posts: 345
Joined: Tue Sep 04, 2001 4:42 am
Location: Pittsburgh, PA

Rootkit problem

Post by Epyon »

Well it's that time of the year again, the holidays... I had my sister come visit me from college and as always I tune her PC up every time. I usually clean the same old stuff off, cannon fodder spyware and adware, occasionally a virus or trojan; Nothing the scanners can't pick up.

This time I've run into the proverbial brick wall. A Rootkit, or what sure as hell seems to be one. I first started trying to clean her pc up by removing all the useless programs from loading on startup. This had little to no effect on the horrendously long time to boot windows(probably around 5-10 min!).

I pretty much figured there was a deeper problem, not one solved so easily. Rootkit was the first thing which sprung to mind. Thus I downloaded a Rootkit reveal app and the problem was even more grand then I could have ever expected.

I think the picture will speak for itself.
Image

So right now I'm in between a rock and a hard place and looking for any help which could be provided. I hadn't even began to study this sort of thing in my IT class so I'm sorry I can't give very much input.

Another program I used was Filemon to see all the kernel calls(I suppose that's what they are). I've seen quite a bit of suspicious activity from the "C:\Windows\Downloaded Program Files" folder. Upon finding this folder and searching through it, I didn't see any of the files or folders I saw calls to from the API. The folders were named something along the lines of "Conflict.1, Conflict.2, and Conflict.3". And one of the files names I noted was OSD1316.OSD.

Upon trying to browse to the file via command prompt, I got the message that the Downloaded Program Files folder didn't exist!

Please, any input would be valued! Thanks for taking the time to read this,


(EDIT: Sorry! Forgot the system specs of my sis's laptop. Windows XP Pro, Pentium 4 2.2 ghz or so, 256 or 512 DDR memory. I can't get the exact specs at the moment, this is just offhand.)

~Matt Davis
EP45-UD3R | E8500 | ZALMAN 9700 NT | 8800GT OC | G.SKILL 8GB DDR2 1066 | Antec 900 | Barracuda 1TB | Win7 Ult x64
User avatar
ScottE
Posts: 16860
Joined: Fri Dec 07, 2001 12:00 pm

Post by ScottE »

Well personally I'd just copy anything your sister wants to save of that HDD. Then Pop in the "Dooms Day Disk" the recovery CD that should have come with the machine to set it back to factory defaults. Then set up a good AV and Antispyware program on it. And tell her to watch what CD's she puts in it to play.
Respect it.
User avatar
Paft
SG Elite
Posts: 5785
Joined: Tue Feb 20, 2001 12:00 am
Location: Richmond VA

Post by Paft »

So trade that typical for something colorful, and if it's crazy live a little crazy!
User avatar
Epyon
Regular Member
Posts: 345
Joined: Tue Sep 04, 2001 4:42 am
Location: Pittsburgh, PA

Post by Epyon »

Yeah, I'm thinking a full format and reinstall. But I was hoping it wouldn't come to that.

One think I want to make clear is: This is not the Sony DRM Rootkit, I've already did the test by naming a file with opening and closing strings($test$), and the file did not disappear.

Thanks for the feedback though.
EP45-UD3R | E8500 | ZALMAN 9700 NT | 8800GT OC | G.SKILL 8GB DDR2 1066 | Antec 900 | Barracuda 1TB | Win7 Ult x64
Scott
Senior Member
Posts: 3846
Joined: Thu Feb 14, 2002 12:00 pm

Post by Scott »

http://www.sysinternals.com/forum/forum_topics.asp?FID=15&PN=1

Perhaps you'll want to start there before re-installing.
Post Reply