Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Blacklight "MOVED"

  • Please log in to reply
1 reply to this topic

#1 bimmerbill


  • Members
  • 2 posts
  • Local time:07:31 AM

Posted 14 February 2009 - 02:40 PM

Forgive me if this isn't posted in the right place, I'm a newbie on this forum.

One of my machines has a rootkit issue. I have alot of experience ridding viruses and malware, and am familiar with the use of Hijack This, and Combofix.

Once I realized something had hit the machine, I went to run Combofix, but it wouldn't run. I saw the post about re-naming it, and got past that. Now when I run it, it tells me that rootkit acticity has been detected, and it needs to reboot, which of course, it won't.

I downloaded Blacklight, and it finds a Master Boot record Hidden Item. Since the only thing I can do is Rename it, I was looking for some assurances.

I'm assuming that once it is renamed, a re-boot is called for. If I rename it, what happens then? Where does it get the new boot record?

Can't find any documentation on what to expect next, so I figured I'd ask before I destroyed the boot record.



BC AdBot (Login to Remove)


#2 usasma


    Still visually handicapped (avatar is memory developed by my Dad

  • BSOD Kernel Dump Expert
  • 25,091 posts
  • Gender:Male
  • Location:Southeastern CT, USA
  • Local time:09:31 AM

Posted 15 February 2009 - 04:36 PM

My browser caused a flood of traffic, sio my IP address was banned. Hope to fix it soon. Will get back to posting as soon as Im able.

- John  (my website: http://www.carrona.org/ )**If you need a more detailed explanation, please ask for it. I have the Knack. **  If I haven't replied in 48 hours, please send me a message. My eye problems have recently increased and I'm having difficult reading posts. (23 Nov 2017)FYI - I am completely blind in the right eye and ~30% blind in the left eye.<p>If the eye problems get worse suddenly, I may not be able to respond.If that's the case and help is needed, please PM a staff member for assistance.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users