ROOTKITS

All your computer hardware and software questions in here please.

Moderator: Moderators

Post Reply
pistonbroke1957
Senior Member
Posts: 156
Joined: Tue Apr 13, 2010 5:55 pm
Location: Kent
Has thanked: 29 times
Been thanked: 4 times

ROOTKITS

Post by pistonbroke1957 »

Morning Campers.
Need some advice on how to get rid of ROOTKITS
AVG picked 6 of them up on a scan but can't 'heal' them.
They show on the results as 'hidden' and when i try to
remove them the results say they are 'inaccessible'.
They are all 'CORRUPTED SECTION WIN32K.SYS(TEXT)'
I ran RKILL and MALWAREBYTES prior to AVG but these didn't detect
any issues.
Am running WINDOWS 7 HOME PREMIUM.
Cheers
User avatar
BillyGoat
Troll Headbutter
Posts: 8071
Joined: Sat Jan 01, 2011 8:20 pm
Location: On top of a mountain, in the long grass.
Has thanked: 386 times
Been thanked: 796 times

Re: ROOTKITS

Post by BillyGoat »

Wipe/re-install.

My thinking: if there are 6 that are detected, what else has been left. ADS streams, hidden locations, altered system files, keyloggers, download agents - whatever else!!!

Protect yourself and your data - wipe, re-install and be wary of where you download files from and what you accept from people.

With so many free alternatives for software, I still see people saying "got it from bit torrent - readme says it's a real copy". Yeah. OK. Course it is.....

I've met the foresnsic guys at a major software company - you would be amazed what gets changed in shared files. Scary stuff.

BG
Arguing with a woman is like reading a Software Licence Agreement.
In the end, you ignore everything and click "I agree".
User avatar
RichieP
UHM Super Moderator
Posts: 679
Joined: Thu Sep 08, 2005 8:45 am
Location: Wolverhampton
Has thanked: 4 times
Been thanked: 12 times

Re: ROOTKITS

Post by RichieP »

TDSS Killer and GMER
Change the filenames before running them.
pistonbroke1957
Senior Member
Posts: 156
Joined: Tue Apr 13, 2010 5:55 pm
Location: Kent
Has thanked: 29 times
Been thanked: 4 times

Re: ROOTKITS

Post by pistonbroke1957 »

Cheers guys
User avatar
Megaross
Senior Member
Posts: 1766
Joined: Tue Jul 19, 2011 10:59 pm
Location: Swindon
Has thanked: 28 times
Been thanked: 110 times

Re: ROOTKITS

Post by Megaross »

Kapersky rescuedisk, yet to come accross a rootkit it won't kick out. Great bit of software.
User avatar
SteveOC
Newly registered Member
Posts: 87
Joined: Sat Apr 28, 2012 8:44 am
Location: Nr Trowbridge, Wiltshire
Has thanked: 10 times
Been thanked: 4 times

Re: ROOTKITS

Post by SteveOC »

I used to run something, I seem to recall it was Blacklight.

Anyhow, I ran the two programs that RichieP posted links to just out of curiosity.

TDSS Killer ran no problem.

GMER either hangs my Netbook or seems to run forever, then if left unattended crashes and forces a Reboot.

I might look at the Kapersky option.

Steve O.
Post Reply

Return to “Computers”