Closed Thread

Join Date: Dec 2006
Posts: 1
Reputation: marian2004 is an unknown quantity at this point 
Solved Threads: 0
marian2004 marian2004 is offline Offline
Newbie Poster

rootkit removal

 
0
  #1
Dec 11th, 2006
Hello all!

I am fairly sure that there is a rootkit installed on this laptop, in fact I am certain that there is. I have run loads of different software to try to find out more and I cannot find anything that will remove it with ease or even seem to detect it appart from "rookit reveilver" which throws up the following (I turned AV and firewalls etc off while doing the test):

www.humbled.com/rootkit.jpg

Does anyone with any experiance reading these reports know what next step I should take or can anyone help me to identify these objects?

Thanks
Quick reply to this message  
Join Date: Apr 2005
Posts: 16,249
Reputation: jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all 
Solved Threads: 540
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: rootkit removal

 
0
  #2
Dec 11th, 2006
do a google forr chrootkit. this is a linux tool but i belive there is a windows version

you could also get AVG avntivirus and AVG antispyware and do a full scan and see what it picks up. Also get "hijkackthis" and post the log file here so we can see whats going on
If i am helpful, please give me reputation points.
Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: rootkit removal

 
0
  #3
Dec 13th, 2006
Sysinternals say that the SAC* and SAI* responses are normal.
Do you have Daemon tools on board? alcohol 120%? cos i notice an sptd entry....? It's okay.
The first entry.... try deleting your MRU list and see what happens with a fresh scan. Use CCleaner to do that.
Fifth entry- i think your sys played online while scan ran. To doublecheck that, disconnect from net and repeat scan.
The second entry? I cannot see it all.. Repeat the scan and google the entry to see what reult it picks up - try the sysinternals.. ok microsoft site for more info on that one. But i think it is part of an Explorer log, and i suspect that you did something while the scan ran, which was duly recorded and so put up a discrepancy.
So check/do what i have mentioned, and re-run the scan. But believe them when they say do NOT use the puter while scan runs - that way you avoid false positives. Feel free to repost another log.
Last edited by gerbil; Dec 13th, 2006 at 1:18 am.
Quick reply to this message  
Join Date: Jan 2009
Posts: 1
Reputation: rosie1956 is an unknown quantity at this point 
Solved Threads: 0
rosie1956 rosie1956 is offline Offline
Newbie Poster

Re: rootkit removal

 
0
  #4
Jan 20th, 2009
Had this problem with my pc i used superantispy you can down load it free this seemed to remove the problem

http://www.superantispyware.com/download.html
Quick reply to this message  
Closed Thread

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC