| Windows 7: Need help with Rootkit problem? |
20 Nov 2010
|
#1 | | Windows 7 Home Premium 64bit. New-Brunswick, Canada |
Need help with Rootkit problem? Hi,
I recently download a software (Sophos anti-rootkit) to get rid of Rootkits so I made a scan with it and the program was showing like 50 issues but I didn't deleted these files because I could not tell if they were infected files or just good files that could mess up my computer if they were removed.
Now, is there a way to know for sure if I have rootkit and how to get rid of them?
Any helps, I would really appreciate,
Yannik | My System Specs |
| OS Windows 7 Home Premium 64bit. CPU Intel Core i7 CPU Motherboard Gigabyte X58A-UD3R Memory 6.00 GB RAM Graphics Card ATI Radeon HD 5700 Series Sound Card Creative Sb-X-Fi Monitor(s) Displays Acer 24 inch Screen Resolution 1400 X 1050 Mouse Kensington Expert Mouse Case NZXT Mid Tower Hard Drives 1 Tb Internet Speed Cable |
20 Nov 2010
|
#2 | | |
were you using the pc whilst scanning? Quote: Known problems
If a scan is run whilst the computer is being used, false positives may appear in the scan results. This is caused by files or registry entries being deleted during the scan, such as temporary files being deleted automatically when an application is closed.
To work around this problem, close all non-essential applications, and then run the scan again. source
you may want to disable realtime a/v scanning too - especially if you use mse | My System Specs | | System Manufacturer/Model Number mickey megabyte 1234 OS ultimate 64 sp1 CPU i5 2500K 3.3@4.2GHz Motherboard MSI P67A-GD53 Memory 8 gigs GSkill Ripjaws 1600 Graphics Card amd hd6950 Sound Card creative x-fi gamer Monitor(s) Displays samsung 24" Screen Resolution 1920x1080 Keyboard saitek eclipse ii Mouse logitech g3 PSU antec 550 Case antec three hundred Cooling i'm a cooling fan Hard Drives ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext Internet Speed about 4 Mbps Other Info i love win7 |
20 Nov 2010
|
#3 | | Windows 7 Ultimate 32bit SP1 |
Disconnect from the network if you disable your Anti-virus program. You really should disconnect, anyway. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
20 Nov 2010
|
#4 | | |
+1
i should have said that | My System Specs | | System Manufacturer/Model Number mickey megabyte 1234 OS ultimate 64 sp1 CPU i5 2500K 3.3@4.2GHz Motherboard MSI P67A-GD53 Memory 8 gigs GSkill Ripjaws 1600 Graphics Card amd hd6950 Sound Card creative x-fi gamer Monitor(s) Displays samsung 24" Screen Resolution 1920x1080 Keyboard saitek eclipse ii Mouse logitech g3 PSU antec 550 Case antec three hundred Cooling i'm a cooling fan Hard Drives ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext Internet Speed about 4 Mbps Other Info i love win7 |
21 Nov 2010
|
#5 | | Windows 7 Home Premium 64bit. New-Brunswick, Canada |
Hi again,
My anti-virus is Microsoft Security Essentials and I also have Malwarebytes. My problem is these two software can not find hidden Rootkits and it is making me nervous because I buy quite a bit online and these Rootkits are dangerous for that, picking up sensituive information so do you guys happen to know a good software that will scan & remove these Rootkits on my Pc without deleting the good files which is why I need help because I don't know which files are potentially harmful and which files that can't be deleted because they are needed so the Pc can function properly?
Can you please let me know if you have a solution?
Thanks,
Yannik | My System Specs | | OS Windows 7 Home Premium 64bit. CPU Intel Core i7 CPU Motherboard Gigabyte X58A-UD3R Memory 6.00 GB RAM Graphics Card ATI Radeon HD 5700 Series Sound Card Creative Sb-X-Fi Monitor(s) Displays Acer 24 inch Screen Resolution 1400 X 1050 Mouse Kensington Expert Mouse Case NZXT Mid Tower Hard Drives 1 Tb Internet Speed Cable |
21 Nov 2010
|
#6 | | Windows 7 Ultimate 32bit SP1 |
If I had Rootkit on one of my computers, I'd wipe and do a "Clean" install. Quote: There are circumstances that require a fresh install, such as when a system becomes infected with a rootkit. Rootkits can infiltrate the operating system in such a way as to make removal problematic if not impossible. The only way to be sure of eradicating a rootkit is to reformat the drive, destroying all data. Once the drive has been reformatted you can reinstall Microsoft® Windows™ using the compact disc that came with the machine, or a purchased retail version. However, have a read here What is a Rootkit? | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
21 Nov 2010
|
#8 | | Windows 7 Home Premium 64bit. New-Brunswick, Canada |
Hi and thank you Fletch for your help! I did ran a scan with a free tdskiller by Kaspersky and it actually removed a nasty rootkits that was making Google redirect all website I wanted to view. After that, I did download another Anti-Rootkits (Sophos anti-rootkits) that was supposed to kill all kind of rootkits so I did a scan but at the result it was showing like 50 rootkit problems but I didn't do anything because I did not want to delete the wrong file that could of mess up my computer. On the other hand, I kind of nervous that there is still a rootkits so I want to make sure there's nothing.
Thanks,
Yannik Ps: If I save a scan and post it here on the site, could someone let me know if I'm infected or not? | My System Specs | | OS Windows 7 Home Premium 64bit. CPU Intel Core i7 CPU Motherboard Gigabyte X58A-UD3R Memory 6.00 GB RAM Graphics Card ATI Radeon HD 5700 Series Sound Card Creative Sb-X-Fi Monitor(s) Displays Acer 24 inch Screen Resolution 1400 X 1050 Mouse Kensington Expert Mouse Case NZXT Mid Tower Hard Drives 1 Tb Internet Speed Cable |
22 Nov 2010
|
#9 | | Windows 7 Ultimate 32bit SP1 |
Yes Yankie007, I can read the saved logs and let you know. Please copy and paste them in your next reply. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
22 Nov 2010
|
#10 | | Windows 7 Home Premium 32bit. UK Midlands |
I'm glad your sorted Yannik and it will be interesting in seeing the logs | My System Specs | | OS Windows 7 Home Premium 32bit. Need help with Rootkit problem? problems? All times are GMT -5. The time now is 08:05 PM. | |