CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[IN PROGRESS]help please!

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
sian08

Guest
IP: 203.167.*.*






PostPosted: Sat Aug 18, 2007 10:30 pm    Post subject: help please!
Reply with quote

I've downloaded avg rootkit after downloading it. I run the application and it found this c:\Windows\system32\kdkv.exe is this a virus? or just part of my system 32 ? can i delete it? Rolling Eyes

Back to top
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sun Aug 19, 2007 6:08 am    Post subject:
Reply with quote

Hi,
It would be helpful if you upload the file. Please download IceSword and extract the archive. Run IceSword.exe and click the "File" tab present in the left-side pane of IceSword's window. Here, navigate to C:\Windows\system32\ folder. Now, the right-side window pane in IceSword should show files present in System32 folder. Locate kdkv.exe, right-click on it and choose "Copy To". Give a different filename such as suspect.ex_ and save it.

Once you get the file, ZIP it and upload it to this forum, by creating a new thread:
CastleCops Link/f81-Unknown_Files.html

Note: While zipping the file, don't forget to password protect the archive.


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
sian08

Guest
IP: 203.167.*.*






PostPosted: Fri Aug 24, 2007 7:34 am    Post subject:
Reply with quote

ok thanks!!! ill post the result later. Laughing

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer