Government Security
Network Security Resources

Jump to content

Photo

Rootkit, No Idea What To Do.

- - - - - rootkit windows
  • Please log in to reply
1 reply to this topic

#1 Awaken

Awaken

    Private

  • Members
  • 1 posts

Posted 17 January 2013 - 12:58 AM

So I experienced some intrusions on my PC, after a reformat I discovered with RootKit reveraler that there were numerous folders in the C drive hidden from the API which I assume to be a RootKit.

I don't have an External Drive handy to reformat correctly, I tried reformatting with a USB, and the RootKit spread itself from my backup hard-drive onto the fresh installation..... as the rootkit will automatically spread to new drives.... I tried to create new partitions, and even tried to login from windows repair console after a new partition was created to transfer my backups, and the rootkit had already managed to spread.....

Basically I can't reformat without losing 80GB of backups, and I have no external device handy to save these files, when I reformat, the rootkit automatically spreads to new installations from the backup partition.... I tried deleting from command prompt and repair console, I tried deleting as the system user, among other things..... I tried every rootkit remover out there, I have no idea.

The command prompt gives me the error "access denied" when I try to enter the directores which are hidden in all the drives, even as system user.

Running windows XP pro.

Any solutions? I kind of want to inspect the files in these folders.

#2 Glyph

Glyph

    General of the Army

  • GSO Management
  • 1,603 posts

Posted 18 January 2013 - 12:30 PM

Boot from DVD with something like Helix.





Also tagged with one or more of these keywords: rootkit, windows