Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need to repair my system files after removing a rootkit


  • Please log in to reply
4 replies to this topic

#1 noob123456

noob123456

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:04:48 PM

Posted 31 July 2012 - 05:48 PM

I tried doing SFC /SCANNOW but its not working :( :( certain programs that I try to run they won't run e.g. cmd.exe, sfc.exe and a few more...if anyone can help me that'd be great

BC AdBot (Login to Remove)

 


#2 deb001

deb001

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:48 PM

Posted 31 July 2012 - 06:21 PM

Hi,

My name is Debbie.

Is your account an administrator account? Try right-clicking on cmd.exe and selecting Run as Administrator. Reply back to me with the answer.
After that Boot into safe mode and run sfc /scannow

If no-go, try another user account - create a new one if you can.

Please reply in case you have any questions.

Edited by Orange Blossom, 04 August 2012 - 08:52 PM.

Thanks & Regards
Debbie_B

#3 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:48 PM

Posted 31 July 2012 - 06:26 PM

What is your exact issue? How did you remove the rootkit? Combofix?

What error do you receive when you launch them

#4 noob123456

noob123456
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:04:48 PM

Posted 31 July 2012 - 08:01 PM

What is your exact issue? How did you remove the rootkit? Combofix?

What error do you receive when you launch them


I removed the rootkit via avast! scanner from my Linux partition i've ran GMER and when I run it shows some registry entries yet I can't delete them because they are nulled also SFC.exe, CMD.exe is not working as well as some other programs

When i try to run ComboFix it gets to Output Folder: C:\328d8sdfsX and it gets stuck...won't go any further...

I've tried in safe-mode and in normal boot

Hi,

My name is Debbie and I work for the Social Media and Community Team at Dell.

Is your account an administrator account? Try right-clicking on cmd.exe and selecting Run as Administrator. Reply back to me with the answer.
After that Boot into safe mode and run sfc /scannow

If no-go, try another user account - create a new one if you can.

Please reply in case you have any questions.


my account IS an administrator account, and in safe-mode i get the same error

#5 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:48 AM

Posted 31 July 2012 - 10:56 PM

Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues and what you have done to resolve them.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users