juddie
Offline
Posts: 2978
|
|
« on: Monday, February 15, 2010, 23:50:41 » |
|
keep getting this notice that I have a rootkit in my system and that I should delete it. Thing is, it won't let me delete it. Is it a virus and if so, how can I get rid of it?
|
|
|
Logged
|
|
|
|
jonny72
Offline
Posts: 5554
|
|
« Reply #1 on: Tuesday, February 16, 2010, 00:17:08 » |
|
What is issuing the notice? Anti-virus software? Or something else?
I'm no expert but I rootkits can be really bad shit, reinstall Windows kind of bad shit.
|
|
|
Logged
|
|
|
|
jayohaitchenn
Wielder of the BANHAMMER
Offline
Posts: 12519
|
|
« Reply #2 on: Tuesday, February 16, 2010, 02:37:01 » |
|
Jonny is right. It takes a proper expert days of work to get rid of a rootkit. Better off starting from scratch.
|
|
|
Logged
|
|
|
|
Simon Pieman
Original Wanker
Offline
Posts: 36318
|
|
« Reply #3 on: Tuesday, February 16, 2010, 08:45:57 » |
|
Before you do anything rash, let us know the program causing the alert. As jonny alluded to, a lot of dodgy messages appear from suspect third party apps just to get you to buy their software. There may actually be no rootkit at all, although if you're getting dodgy messages you at least have some form of malware present.
|
|
|
Logged
|
|
|
|
stfcinbmth
|
|
« Reply #4 on: Tuesday, February 16, 2010, 09:10:09 » |
|
Worth a try http://www.malwarebytes.org/
|
|
|
Logged
|
|
|
|
Peter Venkman
We don't need no stinking badges.
Offline
Posts: 59357
Things can only get better
|
|
« Reply #5 on: Tuesday, February 16, 2010, 09:57:52 » |
|
This is the best antirootkit on the market and its free, just sign up to it with a fake name and address, no real registration needed as it just chucks up the download link as soon as you click on next. http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html
|
|
|
Logged
|
Only a fool does not know when to hold his tongue.
|
|
|
juddie
Offline
Posts: 2978
|
|
« Reply #6 on: Tuesday, February 16, 2010, 09:58:15 » |
|
I'll take a look tonight. cheers for the advice.
|
|
|
Logged
|
|
|
|
juddie
Offline
Posts: 2978
|
|
« Reply #7 on: Tuesday, February 16, 2010, 23:06:45 » |
|
right, I'm getting this:
C:\Windows\System32\Drivers\vjmxh.sys hidden services Win32:Rootkit-gen [Rtk]
|
|
|
Logged
|
|
|
|
caveman
Offline
Posts: 186
|
|
« Reply #8 on: Wednesday, February 17, 2010, 11:33:07 » |
|
Jonny is right. It takes a proper expert days of work to get rid of a rootkit. Better off starting from scratch.
days of work is a bit of an exaggeration, its not rocket science
|
|
|
Logged
|
|
|
|
Simon Pieman
Original Wanker
Offline
Posts: 36318
|
|
« Reply #9 on: Wednesday, February 17, 2010, 14:05:39 » |
|
right, I'm getting this:
C:\Windows\System32\Drivers\vjmxh.sys hidden services Win32:Rootkit-gen [Rtk]
I'll come online later this evening probably about 9pm and will help you out. I think we should be able to remove this tonight, I don't reckon it's more than an evening's work, hopefully only an hour or two to confirm your computer is clean.
|
|
|
Logged
|
|
|
|
juddie
Offline
Posts: 2978
|
|
« Reply #10 on: Wednesday, February 17, 2010, 14:23:47 » |
|
top man. I'll see you then...
|
|
|
Logged
|
|
|
|
jonny72
Offline
Posts: 5554
|
|
« Reply #11 on: Wednesday, February 17, 2010, 16:47:49 » |
|
I'll come online later this evening probably about 9pm.
Another chat roulette fan.
|
|
|
Logged
|
|
|
|
Simon Pieman
Original Wanker
Offline
Posts: 36318
|
|
« Reply #12 on: Monday, February 22, 2010, 23:54:08 » |
|
This was a pain in the backside to remove. In the end I used a great tool which identifies rootkits and allows you to kill the hidden process before deleting. Nothing else would work, took many attempts but sorted it out using remote assistance. I'd only use it if you have a decent knowledge of computers, don't want anyone to fuck their pc up.
|
|
|
Logged
|
|
|
|
jayohaitchenn
Wielder of the BANHAMMER
Offline
Posts: 12519
|
|
« Reply #13 on: Tuesday, February 23, 2010, 08:47:17 » |
|
How long did it take?
|
|
|
Logged
|
|
|
|
juddie
Offline
Posts: 2978
|
|
« Reply #14 on: Tuesday, February 23, 2010, 10:48:30 » |
|
three/four nights of Si's time, for which I am eternally grateful. Cheers Si!
|
|
|
Logged
|
|
|
|
|