We'd like to remind Forumites to please avoid political debate on the Forum. This is to keep it a safe and useful space for MoneySaving discussions. Threads that are - or become - political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

Rootkit detected but can't remove

I have XP and I have found a rootkit with AVG in C:\Windows\System 32\Drivers

It tell me to remove it I must restart the computer, but when I do it is still there, although the name has changed. My son has got the same problem on Vista. AVG gives a message on his that it can't be removed and doesn't give him the option of a restart. I have used Spyware Doctor and Malawarebytes, but without success. Is there anything else I can do? Thanks.
«1

Comments

  • posted_2
    posted_2 Posts: 514 Forumite
    Assuming it's not a false positive, use a boot cd

    http://www.free-av.com/en/products/12/avira_antivir_rescue_system.html
  • compmad1
    compmad1 Posts: 995 Forumite
    Part of the Furniture
    posted wrote: »
    Assuming it's not a false positive, use a boot cd

    http://www.free-av.com/en/products/12/avira_antivir_rescue_system.html


    Thanks. I'm not very computer literate and don't know what would be involved in doing this. Actually I find this sort of thing a bit scarey. Could I just ignore the rootkit?
  • posted_2
    posted_2 Posts: 514 Forumite
    Not really.

    If you download the file and run it, with a blank CD in your writer, it will create a CD which is bootable - when you boot from it, it will scan for viruses. Rootkits hide themselves from windows, which makes them hard to remove while windows is running
  • compmad1
    compmad1 Posts: 995 Forumite
    Part of the Furniture
    posted wrote: »
    Not really.

    If you download the file and run it, with a blank CD in your writer, it will create a CD which is bootable - when you boot from it, it will scan for viruses. Rootkits hide themselves from windows, which makes them hard to remove while windows is running

    I can understand this a bit more now. How would I boot from the CD?
  • posted_2
    posted_2 Posts: 514 Forumite
    Depends on the pc, some will boot from cd automatically, some require you to press F12 to get a boot menu, the rest, you just need to set the boot order in the bios so that the CD drive boots before the hard disk
  • Browntoa
    Browntoa Posts: 49,545 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    edited 10 May 2009 pm31 12:03PM
    post the malware bytes log for me

    what did it find ??
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    Ex forum ambassador

    Long term forum member
  • compmad1
    compmad1 Posts: 995 Forumite
    Part of the Furniture
    posted wrote: »
    Depends on the pc, some will boot from cd automatically, some require you to press F12 to get a boot menu, the rest, you just need to set the boot order in the bios so that the CD drive boots before the hard disk

    Thanks for your help. I'll look at doing this.
  • compmad1
    compmad1 Posts: 995 Forumite
    Part of the Furniture
    Browntoa wrote: »
    post the malware bytes log for me

    what did it find ??
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.

    Thanks.

    Malwarebytes' Anti-Malware 1.36
    Database version: 2104
    Windows 5.1.2600 Service Pack 2

    10/05/2009 12:50:04
    mbam-log-2009-05-10 (12-50-04).txt

    Scan type: Quick Scan
    Objects scanned: 118782
    Time elapsed: 21 minute(s), 16 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
  • Browntoa
    Browntoa Posts: 49,545 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    looks clean , reckon its a false positive (not a real infection)
    Ex forum ambassador

    Long term forum member
  • Hazzanet
    Hazzanet Posts: 1,720 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Just give it a check with F-Secure Blacklight (a free rootkit remover):

    http://www.f-secure.com/en_EMEA/security/security-lab/tools-and-services/blacklight/

    see what it comes up with.
    4358
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 348.3K Banking & Borrowing
  • 252.1K Reduce Debt & Boost Income
  • 452.4K Spending & Discounts
  • 240.9K Work, Benefits & Business
  • 617.1K Mortgages, Homes & Bills
  • 175.6K Life & Family
  • 254.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.