MarkFE
2008-01-10, 22:05
Dear All,
I am having the same annoying rootkit as some others and already looked through the other two topics posted here. But my problem is a little bit more complicated :sad: I am running Windows 2003 Server @home for some testing for work and started to have some Problems with crashing afd.sys.
After renaming this file to .old, the following file came up: srosa.sys ALSO crashing my server with a bluescreen....
I can't boot into safe mode either : blue screen.
SafeBootKeyRepair.exe won't work either.
I booted with a BartPE CD and deleted srosa.sys & hldrrr.exe and the folder C:\windows\system32\drivers\download. After another reboot the files were there again :sick:
I checked for SpyBot and the SpybotSD.exe was gone from C:\program files\Spybot - Search & Destroy
The Problem is probably that I can't get into the registry with BartPE either to check for more files....
I am now running a check with azv4 (after updating it first on a running computer).
Any idea's how to solve this problem ???
regards,
Mark
I am having the same annoying rootkit as some others and already looked through the other two topics posted here. But my problem is a little bit more complicated :sad: I am running Windows 2003 Server @home for some testing for work and started to have some Problems with crashing afd.sys.
After renaming this file to .old, the following file came up: srosa.sys ALSO crashing my server with a bluescreen....
I can't boot into safe mode either : blue screen.
SafeBootKeyRepair.exe won't work either.
I booted with a BartPE CD and deleted srosa.sys & hldrrr.exe and the folder C:\windows\system32\drivers\download. After another reboot the files were there again :sick:
I checked for SpyBot and the SpybotSD.exe was gone from C:\program files\Spybot - Search & Destroy
The Problem is probably that I can't get into the registry with BartPE either to check for more files....
I am now running a check with azv4 (after updating it first on a running computer).
Any idea's how to solve this problem ???
regards,
Mark