hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Remove Hxdef?
Axl
Ok mess around with hxdef, somehow installed service and hides itself. Now i can't seem to get rid of it, i would download the source but it automatically hides itself when i try to download.
hegemonie
there are some tools that can detect and remove several rootkits.
if you're using Win2k have a look at Patchfinder2

hxxp://www.rootkit.com/vault/joanna/patchfinder_w2k_2.11.zip

Or start your PC in safe mode and look for a suspicous service smile.gif
Axl
er no cigar with the safe mode tried already i'm in xp, i was doing some development made a boo boo. laugh.gif
123spawnie123
try net stop hackerdefender084 or whatever name you gave the ServiceName in it's ini

if you run iis/or any other webserver, connect throught the backdoor to ur server and goto the dir ur exe is in and type hxdef084 -:uninstall
you should be able to do that as long as you haven't removed rcmd.exe from the root process

for version 073 there's a rootkit detector wich can stop it
detonator
i use for this handle.exe
this gives you the pid of the hxdef-process
then use kill.exe pid
then you are able to find and delete the service

greetz
GhostCow
handle.exe:
http://www.sysinternals.com/ntw2k/freeware/handle.shtml
ThEWaTcHeR
net stop hackerdefender084
Double-=V=-
Or copy your cmd.ex to rcmd.exe and you can see everything again unless you changed the default file. Then just use the uninstall option.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.