Hi guys,
It's my first time on this forum so I'm sorry if I'm posting on the wrong forum.
I'm a programmer so I know a few things about computers but recently I've encountered a problem that I've never seen before (and don't know how to solve).
My friend's laptop has been infected with a rootkit that is pretty hard to remove.
First, the symptoms:
- registry editing, task manager are disabled (if I re-enable these functions with a .reg file they are overwritten automatically in seconds).
- usb drives are automatically infected with autorun.inf files (that will run a .pif file)
- I cannot boot into safe mode (the computer restarts automatically during boot)
- unhackme (http://greatis.com/unhackme/) finds a rootkit (a random name sys file). I cannot remove it with unhackme (it keeps coming back after reboot).
- gmer (http://www.gmer.net/) will BSOD during scan (so I cannot use it).
I didn't wanted to waste time on this and I formatted (NTFS quick) the C: drive. The laptop has two partitions (D: is used only for data).
So, I've formatted the C: drive and cleaned all the USB sticks (removed autorun.inf) on a Mac computer.
However, the rootkit reappeared instantly after C: format and Windows reinstallation. I have no idea how it persisted because C: was formatted.
Any ideas on what to try next?
Thanks in advance for help,
zmx
It's my first time on this forum so I'm sorry if I'm posting on the wrong forum.
I'm a programmer so I know a few things about computers but recently I've encountered a problem that I've never seen before (and don't know how to solve).
My friend's laptop has been infected with a rootkit that is pretty hard to remove.
First, the symptoms:
- registry editing, task manager are disabled (if I re-enable these functions with a .reg file they are overwritten automatically in seconds).
- usb drives are automatically infected with autorun.inf files (that will run a .pif file)
- I cannot boot into safe mode (the computer restarts automatically during boot)
- unhackme (http://greatis.com/unhackme/) finds a rootkit (a random name sys file). I cannot remove it with unhackme (it keeps coming back after reboot).
- gmer (http://www.gmer.net/) will BSOD during scan (so I cannot use it).
I didn't wanted to waste time on this and I formatted (NTFS quick) the C: drive. The laptop has two partitions (D: is used only for data).
So, I've formatted the C: drive and cleaned all the USB sticks (removed autorun.inf) on a Mac computer.
However, the rootkit reappeared instantly after C: format and Windows reinstallation. I have no idea how it persisted because C: was formatted.
Any ideas on what to try next?
Thanks in advance for help,
zmx

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top









