Need help with Rootkit problem?

Yankie007

New member
Power User
Local time
8:47 PM
Messages
87
Location
New-Brunswick, Canada
Hi,
I recently download a software (Sophos anti-rootkit) to get rid of Rootkits so I made a scan with it and the program was showing like 50 issues but I didn't deleted these files because I could not tell if they were infected files or just good files that could mess up my computer if they were removed.

Now, is there a way to know for sure if I have rootkit and how to get rid of them?

Any helps, I would really appreciate,

Yannik
 

My Computer

OS
Windows 7 Home Premium 64bit.
CPU
Intel Core i7 CPU
Motherboard
Gigabyte X58A-UD3R
Memory
6.00 GB RAM
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
Creative Sb-X-Fi
Monitor(s) Displays
Acer 24 inch
Screen Resolution
1400 X 1050
Hard Drives
1 Tb
Case
NZXT Mid Tower
Mouse
Kensington Expert Mouse
Internet Speed
Cable
were you using the pc whilst scanning?

Known problems
If a scan is run whilst the computer is being used, false positives may appear in the scan results. This is caused by files or registry entries being deleted during the scan, such as temporary files being deleted automatically when an application is closed.

To work around this problem, close all non-essential applications, and then run the scan again.

source

you may want to disable realtime a/v scanning too - especially if you use mse
 

My Computer

Computer Manufacturer/Model Number
mickey megabyte 1234
OS
ultimate 64 sp1
CPU
i5 2500K [email protected]
Motherboard
MSI P67A-GD53
Memory
8 gigs GSkill Ripjaws 1600
Graphics Card(s)
amd hd6950
Sound Card
creative x-fi gamer
Monitor(s) Displays
samsung 24"
Screen Resolution
1920x1080
Hard Drives
ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext
PSU
antec 550
Case
antec three hundred
Cooling
i'm a cooling fan
Keyboard
saitek eclipse ii
Mouse
logitech g3
Internet Speed
about 4 Mbps
Other Info
i love win7
Disconnect from the network if you disable your Anti-virus program. You really should disconnect, anyway.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
+1

i should have said that :o
 

My Computer

Computer Manufacturer/Model Number
mickey megabyte 1234
OS
ultimate 64 sp1
CPU
i5 2500K [email protected]
Motherboard
MSI P67A-GD53
Memory
8 gigs GSkill Ripjaws 1600
Graphics Card(s)
amd hd6950
Sound Card
creative x-fi gamer
Monitor(s) Displays
samsung 24"
Screen Resolution
1920x1080
Hard Drives
ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext
PSU
antec 550
Case
antec three hundred
Cooling
i'm a cooling fan
Keyboard
saitek eclipse ii
Mouse
logitech g3
Internet Speed
about 4 Mbps
Other Info
i love win7
Hi again,
My anti-virus is Microsoft Security Essentials and I also have Malwarebytes. My problem is these two software can not find hidden Rootkits and it is making me nervous because I buy quite a bit online and these Rootkits are dangerous for that, picking up sensituive information so do you guys happen to know a good software that will scan & remove these Rootkits on my Pc without deleting the good files which is why I need help because I don't know which files are potentially harmful and which files that can't be deleted because they are needed so the Pc can function properly?

Can you please let me know if you have a solution?

Thanks,

Yannik
 

My Computer

OS
Windows 7 Home Premium 64bit.
CPU
Intel Core i7 CPU
Motherboard
Gigabyte X58A-UD3R
Memory
6.00 GB RAM
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
Creative Sb-X-Fi
Monitor(s) Displays
Acer 24 inch
Screen Resolution
1400 X 1050
Hard Drives
1 Tb
Case
NZXT Mid Tower
Mouse
Kensington Expert Mouse
Internet Speed
Cable
If I had Rootkit on one of my computers, I'd wipe and do a "Clean" install.
There are circumstances that require a fresh install, such as when a system becomes infected with a rootkit. Rootkits can infiltrate the operating system in such a way as to make removal problematic if not impossible. The only way to be sure of eradicating a rootkit is to reformat the drive, destroying all data. Once the drive has been reformatted you can reinstall Microsoft® Windows™ using the compact disc that came with the machine, or a purchased retail version.

However, have a read here What is a Rootkit?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi and thank you Fletch for your help! I did ran a scan with a free tdskiller by Kaspersky and it actually removed a nasty rootkits that was making Google redirect all website I wanted to view. After that, I did download another Anti-Rootkits (Sophos anti-rootkits) that was supposed to kill all kind of rootkits so I did a scan but at the result it was showing like 50 rootkit problems but I didn't do anything because I did not want to delete the wrong file that could of mess up my computer. On the other hand, I kind of nervous that there is still a rootkits so I want to make sure there's nothing.

Thanks,

Yannik

Ps: If I save a scan and post it here on the site, could someone let me know if I'm infected or not?
 

My Computer

OS
Windows 7 Home Premium 64bit.
CPU
Intel Core i7 CPU
Motherboard
Gigabyte X58A-UD3R
Memory
6.00 GB RAM
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
Creative Sb-X-Fi
Monitor(s) Displays
Acer 24 inch
Screen Resolution
1400 X 1050
Hard Drives
1 Tb
Case
NZXT Mid Tower
Mouse
Kensington Expert Mouse
Internet Speed
Cable
Yes Yankie007, I can read the saved logs and let you know. Please copy and paste them in your next reply.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I'm glad your sorted Yannik and it will be interesting in seeing the logs
 

My Computer

OS
Windows 7 Home Premium 32bit.
Sorry guys, I've never could figure out the problem (couldn't copy log files) with the software I was using (Sophos Anti-rootkits) but I got rid of one Rootkit that was messing up my Pc so that's good news.

Annyway, 1 million thanks guys for taking your precious time to help me out!

Peace
 

My Computer

OS
Windows 7 Home Premium 64bit.
CPU
Intel Core i7 CPU
Motherboard
Gigabyte X58A-UD3R
Memory
6.00 GB RAM
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
Creative Sb-X-Fi
Monitor(s) Displays
Acer 24 inch
Screen Resolution
1400 X 1050
Hard Drives
1 Tb
Case
NZXT Mid Tower
Mouse
Kensington Expert Mouse
Internet Speed
Cable
You could try Emsisoft Antimalware free for a usb stick and scan you computer with having to install a program. It has approximately over 5 million signatures and finds all kinds of other stuff as well.

Emsisoft Free Emergency Kit
 

My Computer

Computer Manufacturer/Model Number
Custom built be me
OS
Windows 7 Ultimate x64
CPU
Amd dual-core 4400 Socket 979
Motherboard
Asus A8N-SLI
Memory
Kingston 3gb ddr 3200
Graphics Card(s)
Radeon Sapphire HD5670 1gb GDDR5 Artic cooling
Sound Card
Standard Motherboards Realtec
Monitor(s) Displays
IC Power
Screen Resolution
1280 x 1024
Hard Drives
Seagate Barracuda 500gb Sata 16mb Cache 7200 rpm Primary Drive
300gb Maxtor IDE
Seagate 500gb usb freeagent backup drive
PSU
600 watt power star
Case
Lian-Li Aluminum
Cooling
MassCool Socket 979
Keyboard
Microsoft Comfort Curve
Mouse
Microsoft Basic Optical Mouse 2.0
Internet Speed
5mb
Other Info
The system as of now is about a year old and the OS was installed on 11/30/2010..
Awesome thanks Krokusnat!
 

My Computer

OS
Windows 7 Home Premium 64bit.
CPU
Intel Core i7 CPU
Motherboard
Gigabyte X58A-UD3R
Memory
6.00 GB RAM
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
Creative Sb-X-Fi
Monitor(s) Displays
Acer 24 inch
Screen Resolution
1400 X 1050
Hard Drives
1 Tb
Case
NZXT Mid Tower
Mouse
Kensington Expert Mouse
Internet Speed
Cable
Sophos should do the job best so I'd run it until it shows clean.

Someone in the Security forum here should be able to tell you how to upload its log file.

For now you can use the Snipping Tool in the Start Menu to take a screenshot(s) of its maximized results window. Post back using paper clip in reply box.
 
Back
Top