Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: jdm

Sorry I haven’t been on since my post. I’ve been installing an email server and migrating the mail, settings, and contacts, from 3 windows boxes to it.

I’ll be on most of the night.


25 posted on 10/22/2007 6:44:03 PM PDT by papasmurf (sudo apt - get install FRed Thompson)
[ Post Reply | Private Reply | To 24 | View Replies ]


To: papasmurf; Still Thinking; Turbopilot

Looks like the problem is a nasty rootkit infection. I now can’t even get online through dial-up (using someone else’s PC right now).

There is a process called /S /C {7007-ACC7-3202-1101-AAO2-20805FC1270E / I {10DF43C8-11D3-8B-34-006097DF58-D43 / X 0x401 ...

...running here and there on my machine.

It shows up for a few minutes, then disappears, only to reappear later, sometimes up to nine instances of it running simultaneously.

A file, a registry key? Both?

I am going to try removing it using AVG Anti-Rootkit and/or Icesword.

When I try to terminate these malicious processes, I get an “access denied” error, so I’m pretty much stonewalled.

HiJackThis and every other utility I’ve run doesn’t even show this process running.

Only thing that has showed it running is a software called Spyware Process Terminator.

When I do a Start > run > cmd > ipconfig I get a response such as: “a media is disconnected,” even though the network card is enabled and working fine (in fact, I updated the drivers last night). Plus, the Ethernet cable is plugged in and I’m 100% positive the problem isn’t with the cable.

Anyone have any experience removing rootkits? I hear they can be pretty hard to get rid.

Thanks again very much for your suggestions and help.


26 posted on 10/23/2007 3:38:46 PM PDT by jdm
[ Post Reply | Private Reply | To 25 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson