Rootkit Found

Page 1 of 3 123 LastLast

  1. Posts : 369
    Windows 7 Ultimate x64 with SP1
       #1

    Rootkit Found


    I have NIS 2010 installed on my PC and I do a couple scans a day with Norton, Malwarebytes, and Hitman Pro 3.5.5. I just did a scan with Hitman Pro and it found a Rootkit in C:\Windows\system32\DRIVERS\

    Isn't Norton supposed to detect and block these kind of malware attacks?????

    Not very happy right now since Rootkits can do many things...
      My Computer


  2. Posts : 4,772
    Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
       #2

    codyw said:
    I have NIS 2010 installed on my PC and I do a couple scans a day with Norton, Malwarebytes, and Hitman Pro 3.5.5. I just did a scan with Hitman Pro and it found a Rootkit in C:\Windows\system32\DRIVERS\

    Isn't Norton supposed to detect and block these kind of malware attacks?????

    Not very happy right now since Rootkits can do many things...
    Hello !!

    What is File name that was detected ?? Maybe it's just a False Positive

    - Captain
      My Computer


  3. Posts : 369
    Windows 7 Ultimate x64 with SP1
    Thread Starter
       #3

    File name is elxstor.sys
    Does Hitman Pro tend to get known good files mixed up?
      My Computer


  4. Posts : 4,772
    Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
       #4

    codyw said:
    File name is elxstor.sys
    Does Hitman Pro tend to get known good files mixed up?
    It's not a virus look this webiste Elxstor.sys Analysis Report If you're wanting to individually scan this file for a virus, use VirusTotal and upload elxstor.sys to have it scanned with dozens of different anti-virus scanners at once.

    Hope this helps,
    Captain
      My Computer


  5. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #5

    Capt.Jack Sparrow said:
    codyw said:
    File name is elxstor.sys
    Does Hitman Pro tend to get known good files mixed up?
    It's not a virus look this webiste Elxstor.sys Analysis Report If you're wanting to individually scan this file for a virus, use VirusTotal and upload elxstor.sys to have it scanned with dozens of different anti-virus scanners at once.

    Hope this helps,
    Captain
    Agreed. Also see elxstor.sys - Greatis Software
      My Computer


  6. Posts : 369
    Windows 7 Ultimate x64 with SP1
    Thread Starter
       #6

    After viewing that website, I have 2 questions:
    1. Does Hitman Pro conflict with virus protection?
    2. Why did Hitman clissify this as malware when it's a perfectly good file?


    Symantec is telling me that Hitman Pro will conflict.
      My Computer


  7. Posts : 369
    Windows 7 Ultimate x64 with SP1
    Thread Starter
       #7

    I went to the DRIVERS folder under the C drive and manually scanned the folder with Norton and it said everything was fine.
      My Computer


  8. Posts : 369
    Windows 7 Ultimate x64 with SP1
    Thread Starter
       #8

    What would happen if I told Hitman Pro to quarantine/delete the infection and this WAS a false positive. I have Symantec Support saying it's an infection. What would happen if I was to delete the said file?
      My Computer


  9. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #9

    codyw said:
    After viewing that website, I have 2 questions:
    1. Does Hitman Pro conflict with virus protection?
    2. Why did Hitman clissify this as malware when it's a perfectly good file?


    Symantec is telling me that Hitman Pro will conflict.

    1. Hitman Pro is an malware scanner and should not conflict with Symantec.
    2. It is not unusual for false/positives to occur. Thus, the need to pay attention to what is happening on your computer.


    codyw said:
    I went to the DRIVERS folder under the C drive and manually scanned the folder with Norton and it said everything was fine.
    codyw said:
    What would happen if I told Hitman Pro to quarantine/delete the infection and this WAS a false positive. I have Symantec Support saying it's an infection. What would happen if I was to delete the said file?
    Your two posts have conflicting information. One indicates that NAV said the Drivers folder is fine and the second indicates Symantec Supports indicates an infection. Which is it?

    Did you scan the specific file at VirusTotal as suggested by Capt.Jack Sparrow?

    As to what would happen if you delete the driver, you would no longer have a driver for LightPulse Host Bus Adapters (HBAs).
      My Computer


  10. Posts : 369
    Windows 7 Ultimate x64 with SP1
    Thread Starter
       #10

    No, I did not go to VirusTotal. But I still have my Kaspersky 2010 license. What I'm going to do is put it on after wiping Norton. If it finds the infection, then I'll know it was bad. Because Hitman Pro is cloud based leads me to thinking it has to be some kind of infection. I was reading up on Rootkits too since I never really had experience with them. Exactly, how do they act as malware? Do they come through your firewall or how do they get in?
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 07:56.
Find Us