BleepingComputer.com: Rootkit has disabled network, system restore and security software

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 5 Pages +
  • « First
  • 3
  • 4
  • 5
  • You cannot start a new topic
  • This topic is locked

Rootkit has disabled network, system restore and security software Need help removing rootkit infection

#61 User is offline   ncbeachcomber 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 37
  • Joined: 14-October 11

Posted 22 November 2011 - 11:11 PM

Say hallelujah! I cracked the network nut (mostly.) Not 100% sure of this, but it looks like a Firewire/IEEE adapter was conflicting with the main ethernet card. Anyhow, I disabled it and my PC is back on the network. So I believe we can declare victory on the subject of the malware infection, with great appreciation for your diligent assistance.

I am still having trouble with DNS. Should I start a new topic on the networking side?

(I'm connected to the Internet, can ping any IP address, and can reach any website by IP address, but can't get to any Internet location by domain name. This is a consistent issue across platforms: IE, Firefox, email applications, FTP, ODBC connection to an SQL server. So the problem lies pretty deep in Windows, apparently.

My TCP/IP and DNS settings are consistent with those on other machines on the network that are connecting normally.

One other question: Your opinion on McAfee as a reliable, robust protection for our network?

#62 User is offline   jedi 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 273
  • Joined: 03-September 04
  • Gender:Male
  • Location:UK

Posted 23 November 2011 - 04:11 PM

Hi again,

That's great news. I'm assuming there are no on-going signs of infection? If that's the case, yes, start a new topic in the XP forum here:
http://www.bleepingcomputer.com/forums/forum56.html
and link back to this topic in case it needs to be referenced. Once you've done that let me know in this topic and I will close it and ask for someone appropriate to look at your new topic.
As for McAfee, yes, they provide a good level of protection. My personal preference would be Kaspersky Corporate Suite, but I wouldn't suggest you change unless you're unhappy with McAfee.

It's been a pleasure working with you. :)

jedi

#63 User is offline   ncbeachcomber 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 37
  • Joined: 14-October 11

Posted 23 November 2011 - 06:15 PM

Jedi,

Many, many thanks again for your assistance.

I'll be reinstalling my McAfee, then. And for the rest of the good news: After researching the DNS problem the last day or so, I re-installed the latest iteration of Service Pack 3 for Win XP, and it cured the last of my ills. I'm fully back online again; have reformatted the iffy back-up drive and scheduled new, clean backups, and am now officially thankful just in time for the Thanksgiving holiday. So there's no need for a new topic; you can declare this one closed and fully resolved.

Best wishes!

#64 User is offline   jedi 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 273
  • Joined: 03-September 04
  • Gender:Male
  • Location:UK

Posted 24 November 2011 - 02:47 PM

You're most welcome. Happy Thanksgiving. :)

jedi

#65 User is offline   jedi 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 273
  • Joined: 03-September 04
  • Gender:Male
  • Location:UK

Posted 25 November 2011 - 12:33 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Share this topic:


  • 5 Pages +
  • « First
  • 3
  • 4
  • 5
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users