View Single Post
Old 06-19-2006, 09:41 AM   #84 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,463
OS: N/A


Congratulations. Looks like you have successfully deleted the rootkit service.

Let's go after the hidden file. It may still be present

Start HijackThis & Go to Config> Misc Tools > Open ADS Spy
  1. Checkmark/tick - "Ignore Safe System Info Streams"
  2. Click the "Scan" button
  3. When it has finished scanning, checkmark/tick all that it found
  4. Click the "remove selected" button

PS..the entry looks like this

C:\WINDOWS\System32:18467
__________________

Question - what have you done for the community today?
sUBs is offline