954,258 Members — Technology Publication meets Social Media
Username:
Password:
Lost login information?
Have something to say? Contribute New Article Reply to this Article

rootkit removal

Hello all!

I am fairly sure that there is a rootkit installed on this laptop, in fact I am certain that there is. I have run loads of different software to try to find out more and I cannot find anything that will remove it with ease or even seem to detect it appart from "rookit reveilver" which throws up the following (I turned AV and firewalls etc off while doing the test):

www.humbled.com/rootkit.jpg

Does anyone with any experiance reading these reports know what next step I should take or can anyone help me to identify these objects?

Thanks

marian2004
Newbie Poster
1 post since Dec 2006
Reputation Points: 10
Solved Threads: 0
 

do a google forr chrootkit. this is a linux tool but i belive there is a windows version

you could also get AVG avntivirus and AVG antispyware and do a full scan and see what it picks up. Also get "hijkackthis" and post the log file here so we can see whats going on

jbennet
Moderator
Moderator
18,523 posts since Apr 2005
Reputation Points: 1,826
Solved Threads: 600
 

Sysinternals say that the SAC* and SAI* responses are normal.
Do you have Daemon tools on board? alcohol 120%? cos i notice an sptd entry....? It's okay.
The first entry.... try deleting your MRU list and see what happens with a fresh scan. Use CCleaner to do that.
Fifth entry- i think your sys played online while scan ran. To doublecheck that, disconnect from net and repeat scan.
The second entry? I cannot see it all.. Repeat the scan and google the entry to see what reult it picks up - try the sysinternals.. ok microsoft site for more info on that one. But i think it is part of an Explorer log, and i suspect that you did something while the scan ran, which was duly recorded and so put up a discrepancy.
So check/do what i have mentioned, and re-run the scan. But believe them when they say do NOT use the puter while scan runs - that way you avoid false positives. Feel free to repost another log.

gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
 

Had this problem with my pc i used superantispy you can down load it free this seemed to remove the problem

http://www.superantispyware.com/download.html

rosie1956
Newbie Poster
1 post since Jan 2009
Reputation Points: 10
Solved Threads: 0
 

This article has been dead for over three months

Post: Markdown Syntax: Formatting Help
You