We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

AVAST detected a rootkit, help please

Options
Hi all :)

Last night i logged into my AOL browser to read my emails and i got a pop up saying AVAST had detected a Rootkit, i hadnt even started to browse the internet. (i didnt write down what it was as i panicked when i saw the word rootkit) and it said the recommended action was to delete it, which i promtly did.
It then said i should do a bootscan which i did too but at 30% in the whole thing froze (whilst chekcking c:\ windows file repository) and that was it. I got a blank screen and it took about an hour to be able to get back onto my computer.

I have run a quick AVAST scan and a quick malwarebytes scan which have come back ok but I really don't know what to do? do you think my computer is safe to use or should i really take it somewhere to be looked at properly? When i deleted the Rootkit is that it gone? or could it be lurking somewhere?

Thanks
«1345

Comments

  • andygb
    andygb Posts: 14,652 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    edited 8 March 2011 at 9:02AM
    poppie123 wrote: »
    Hi all :)

    Last night i logged into my AOL browser to read my emails and i got a pop up saying AVAST had detected a Rootkit, i hadnt even started to browse the internet. (i didnt write down what it was as i panicked when i saw the word rootkit) and it said the recommended action was to delete it, which i promtly did.
    It then said i should do a bootscan which i did too but at 30% in the whole thing froze (whilst chekcking c:\ windows file repository) and that was it. I got a blank screen and it took about an hour to be able to get back onto my computer.

    I have run a quick AVAST scan and a quick malwarebytes scan which have come back ok but I really don't know what to do? do you think my computer is safe to use or should i really take it somewhere to be looked at properly? When i deleted the Rootkit is that it gone? or could it be lurking somewhere?

    Thanks


    Hi Poppie, I hope that someone does answer this, because I have been getting this message for the past two weeks, and despite doing scans and submitting the results to the Avast Lab, they still persist. I do a Malwarebytes scan (after getting the updates) every morning, and it is mostly clear. The Avast scan takes a long time to complete, and you sometimes need to joggle the mouse a bit, to stop the thing going into hibernation mode.
    Looking back at your previous posts, you have been having much the same problems as myself - IE, Windows Updates, and you run Vista as well.
    Call me cynical, but is it just possible that MS is behind all of this, trying to get people to upgrade their OS to Windows 7?
  • poppie123
    poppie123 Posts: 957 Forumite
    Part of the Furniture Combo Breaker
    andygb wrote: »
    Hi Poppie, I hope that someone does answer this, because I have been getting this message for the past two weeks, and despite doing scans and submitting the results to the Avast Lab, they still persist. I do a Malwarebytes scan (after getting the updates) every morning, and it is mostly clear. The Avast scan takes a long time to complete, and you sometimes need to joggle the mouse a bit, to stop the thing going into hibernation mode.
    Looking back at your previous posts, you have been having much the same problems as myself - IE, Windows Updates, and you run Vista as well.
    Call me cynical, but is it just possible that MS is behind all of this, trying to get people to upgrade their OS to Windows 7?

    It's so worrying, especially as i do online banking.:(
    This morning i completely forgot about the problems i had last night and logged into my Barclaycard account to check to see if my payment had credited. Of course now i am terrified that someone is going to take over my barclaycard account and change all the details. I would normally have checked my Barclays and my Alliance and Leicester accounts this morning too but today i checked by phone.

    I think i am starting to get just a little bit paranoid.:o

    I have just done a full AVAST scan and it came back clear, i am too scared to try another boot scan in case it freezes again. It took me a good hour to get my computer up and running again last night and at one point i thought that was it, it has had it.
  • giraffe69
    giraffe69 Posts: 3,603 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    Call me cynical, but is it just possible that MS is behind all of this, trying to get people to upgrade their OS to Windows 7?

    Paranoid rather than cynical I would think.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Is malwarebytes up to date?

    Run TDSKiller

    http://support.kaspersky.com/viruses/solutions?qid=208280684
    :idea:
  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Personally, if a rootkit was detected on my PC, I would format the OS partition and reinstall from scratch...
  • fwor
    fwor Posts: 6,862 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    esuhl wrote: »
    Personally, if a rootkit was detected on my PC, I would format the OS partition and reinstall from scratch...

    For the really paranoid, don't forget to re-write the MBR! Some rootkits can (in theory at least) survive a partition re-format by hiding there...
  • RussJK
    RussJK Posts: 2,359 Forumite
    fwor wrote: »
    For the really paranoid, don't forget to re-write the MBR! Some rootkits can (in theory at least) survive a partition re-format by hiding there...

    More creepy, rootkits that can infect the firmware of keyboards and other peripherals!
  • fwor
    fwor Posts: 6,862 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    RussJK wrote: »
    More creepy, rootkits that can infect the firmware of keyboards and other peripherals!

    Really? I'd not heard of that. Are these just proof of concept (like I think most of the MBR-infecting ones are), or actually out there in the real world?

    I try to take proof of concept viruses with a pinch of salt, as many of them seem to be developed by the big antivirus firms to scare us into buying their products. When you look at them in detail they often don't actually have a credible means of propagating...
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    fwor wrote: »
    Really? I'd not heard of that. Are these just proof of concept (like I think most of the MBR-infecting ones are), or actually out there in the real world?

    I try to take proof of concept viruses with a pinch of salt, as many of them seem to be developed by the big antivirus firms to scare us into buying their products. When you look at them in detail they often don't actually have a credible means of propagating...

    Exactly

    Ive heard of rootkits staying in formatted hard drives, but never actually seen any evidence of this anywhere online
    :idea:
  • poppie123
    poppie123 Posts: 957 Forumite
    Part of the Furniture Combo Breaker
    OMG, what should i do then? i have no idea with computers. Should i take it somewhere and explain and let them sort it out for me.
    I don't want to do any online banking etc now as this has worried me.:(

    I have posted a hijackthis logfile in another post, please could someone take a look for me.

    Thanks
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.8K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.