| | |
Hacktool.rootkit - aftermath
![]() |
•
•
Join Date: Jul 2004
Posts: 2,964
Reputation:
Solved Threads: 210
Have the file scanned at http://virusscan.jotti.org/
(Upload the file and click Submit to have it scanned); let us know the results.
(Upload the file and click Submit to have it scanned); let us know the results.
Links to help you help yourself :
Protect Your PC & Avoid Infections -- http://www.daniweb.com/techtalkforums/thread27519.html
Cleanup Procedures & Tools -- http://www.daniweb.com/techtalkforums/thread27570.html
Infection Removal & HijackThis Use -- http://www.daniweb.com/techtalkforums/thread28196.html
Protect Your PC & Avoid Infections -- http://www.daniweb.com/techtalkforums/thread27519.html
Cleanup Procedures & Tools -- http://www.daniweb.com/techtalkforums/thread27570.html
Infection Removal & HijackThis Use -- http://www.daniweb.com/techtalkforums/thread28196.html
Hi,
Open NotePad and copy the contents of the below "Quote" box:-
Then go to File Menu > Save As and type the filename as runlist.BAT and save it. Exit from NotePad.
Double-click on the runlist.bat file, a DOS type window should open and close immediately. After this, there would be a file called Info.txt in the same location where the batch file is present. Open this Info.txt file and post its contents here.
Open NotePad and copy the contents of the below "Quote" box:-
•
•
•
•
regedit /e test1.txt "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run"
regedit /e test2.txt "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce"
regedit /e test3.txt "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices"
regedit /e test4.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run"
regedit /e test5.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce"
regedit /e test6.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices"
copy test1.txt + test2.txt + test3.txt + test4.txt + test5.txt + test6.txt = Info.txt
del test1.txt
del test2.txt
del test3.txt
del test4.txt
del test5.txt
del test6.txt
Double-click on the runlist.bat file, a DOS type window should open and close immediately. After this, there would be a file called Info.txt in the same location where the batch file is present. Open this Info.txt file and post its contents here.
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
-Albert Einstein.
-Albert Einstein.
•
•
Join Date: Aug 2005
Posts: 7
Reputation:
Solved Threads: 0
•
•
•
•
Originally Posted by swatkat
Hi,
Open NotePad and copy the contents of the below "Quote" box:-
Then go to File Menu > Save As and type the filename as runlist.BAT and save it. Exit from NotePad.
Double-click on the runlist.bat file, a DOS type window should open and close immediately. After this, there would be a file called Info.txt in the same location where the batch file is present. Open this Info.txt file and post its contents here.
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe"
"IntelWireless"="C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe /tf Intel PROSet/Wireless"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"MMTray"="C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mm_tray.exe"
"mmtask"="C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mmtask.exe"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"vptray"="C:\\Program Files\\NavNT\\vptray.exe"
"gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""
"GoToMyPC"="C:\\Program Files\\Citrix\\GoToMyPC\\g2svc.exe -logon"
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce]
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
Hi,
Go to Start > Run and type regsvr32 /u ADMDLL.DLL and press ENTER. Reboot the Sytsem and check whether you recieve the error or not, and post back the results.
(Note that there is a SPACE after regsvr32 and /)
Go to Start > Run and type regsvr32 /u ADMDLL.DLL and press ENTER. Reboot the Sytsem and check whether you recieve the error or not, and post back the results.
(Note that there is a SPACE after regsvr32 and /)
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
-Albert Einstein.
-Albert Einstein.
•
•
Join Date: Aug 2005
Posts: 7
Reputation:
Solved Threads: 0
•
•
•
•
Originally Posted by swatkat
Hi,
Go to Start > Run and type regsvr32 /u ADMDLL.DLL and press ENTER. Reboot the Sytsem and check whether you recieve the error or not, and post back the results.
(Note that there is a SPACE after regsvr32 and /)
Loadlibrary ("ADMDLL.DLL") failed. The specific module could not be found
I rebooted and the same error came up again.
Hi,
Download RegCleaner and install it. Run it, go to Tools Menu > Registry CleanUp > Do them all. This starts the Registry cleaning. When the scan is complete, select all the junk entry it may find and click "Remove Selected".
Download RegCleaner and install it. Run it, go to Tools Menu > Registry CleanUp > Do them all. This starts the Registry cleaning. When the scan is complete, select all the junk entry it may find and click "Remove Selected".
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
-Albert Einstein.
-Albert Einstein.
![]() |
Similar Threads
- Hacktool.rootkit -how do get rid of it (Viruses, Spyware and other Nasties)
- Hacktool.rootkit virus in WinXP (Viruses, Spyware and other Nasties)
- Unable to get rid of Hacktool.rootkit virus(/Trojan) (Viruses, Spyware and other Nasties)
- Need help with "trojan.hacktool.rootkit" PLEASE!!! (Viruses, Spyware and other Nasties)
- Unable to completely remove HackTool.Rootkit virus (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: IE Explorer & Messenger 7.0 is dead
- Next Thread: Error # 317 & IE Hijacked by Terra.es HELP
Views: 2789 | Replies: 8
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
adobe adware anti-malware anti-virussitesaccessissue antivirus attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china combofix commercial commercials conficker connect control crosssitescripting cyber cybercrime ddos domains e-mafia education email europe exam exploit explorer facebook fake fancheckvirus firefox gaming gumblar hijack hosting internet kaspersky legal logfiles mail malware mcafee mega-d messagelabs microsoft mobile news norton obama panel parents patch pc phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus rootkit scareware school search security seopoisoning software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system threat trojan unwanted update usa virus viruses vista volume warning web windows worm zero-day






