Pages: [1] 2   Go Down
Print
Author Topic: rootkit  (Read 6715 times)
juddie

Offline Offline

Posts: 2978





Ignore
« on: Monday, February 15, 2010, 23:50:41 »

keep getting this notice that I have a rootkit in my system and that I should delete it. Thing is, it won't let me delete it. Is it a virus and if so, how can I get rid of it?
Logged
jonny72

Offline Offline

Posts: 5554





Ignore
« Reply #1 on: Tuesday, February 16, 2010, 00:17:08 »

What is issuing the notice? Anti-virus software? Or something else?

I'm no expert but I rootkits can be really bad shit, reinstall Windows kind of bad shit.
Logged
jayohaitchenn
Wielder of the BANHAMMER

Offline Offline

Posts: 12519




« Reply #2 on: Tuesday, February 16, 2010, 02:37:01 »

Jonny is right. It takes a proper expert days of work to get rid of a rootkit. Better off starting from scratch.
Logged
Simon Pieman
Original Wanker

Offline Offline

Posts: 36318




« Reply #3 on: Tuesday, February 16, 2010, 08:45:57 »

Before you do anything rash, let us know the program causing the alert. As jonny alluded to, a lot of dodgy messages appear from suspect third party apps just to get you to buy their software. There may actually be no rootkit at all, although if you're getting dodgy messages you at least have some form of malware present.
Logged
stfcinbmth

« Reply #4 on: Tuesday, February 16, 2010, 09:10:09 »

Worth a try

Code:
http://www.malwarebytes.org/
Logged
Peter Venkman
We don't need no stinking badges.

Offline Offline

Posts: 59357


Things can only get better



« Reply #5 on: Tuesday, February 16, 2010, 09:57:52 »

This is the best antirootkit on the market and its free, just sign up to it with a fake name and address, no real registration needed as it just chucks up the download link as soon as you click on next.

http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html
Logged

Only a fool does not know when to hold his tongue.
juddie

Offline Offline

Posts: 2978





Ignore
« Reply #6 on: Tuesday, February 16, 2010, 09:58:15 »

I'll take a look tonight. cheers for the advice.
Logged
juddie

Offline Offline

Posts: 2978





Ignore
« Reply #7 on: Tuesday, February 16, 2010, 23:06:45 »

right, I'm getting this:

C:\Windows\System32\Drivers\vjmxh.sys
hidden services
Win32:Rootkit-gen [Rtk]
Logged
caveman

Offline Offline

Posts: 186




Ignore
« Reply #8 on: Wednesday, February 17, 2010, 11:33:07 »

Jonny is right. It takes a proper expert days of work to get rid of a rootkit. Better off starting from scratch.

days of work is a bit of an exaggeration, its not rocket science
Logged
Simon Pieman
Original Wanker

Offline Offline

Posts: 36318




« Reply #9 on: Wednesday, February 17, 2010, 14:05:39 »

right, I'm getting this:

C:\Windows\System32\Drivers\vjmxh.sys
hidden services
Win32:Rootkit-gen [Rtk]


I'll come online later this evening probably about 9pm and will help you out. I think we should be able to remove this tonight, I don't reckon it's more than an evening's work, hopefully only an hour or two to confirm your computer is clean.
Logged
juddie

Offline Offline

Posts: 2978





Ignore
« Reply #10 on: Wednesday, February 17, 2010, 14:23:47 »

top man. I'll see you then...
Logged
jonny72

Offline Offline

Posts: 5554





Ignore
« Reply #11 on: Wednesday, February 17, 2010, 16:47:49 »

I'll come online later this evening probably about 9pm.

Another chat roulette fan.
Logged
Simon Pieman
Original Wanker

Offline Offline

Posts: 36318




« Reply #12 on: Monday, February 22, 2010, 23:54:08 »

This was a pain in the backside to remove. In the end I used a great tool which identifies rootkits and allows you to kill the hidden process before deleting. Nothing else would work, took many attempts but sorted it out using remote assistance.

Code:
http://www.gmer.net/

I'd only use it if you have a decent knowledge of computers, don't want anyone to fuck their pc up.
Logged
jayohaitchenn
Wielder of the BANHAMMER

Offline Offline

Posts: 12519




« Reply #13 on: Tuesday, February 23, 2010, 08:47:17 »

How long did it take?
Logged
juddie

Offline Offline

Posts: 2978





Ignore
« Reply #14 on: Tuesday, February 23, 2010, 10:48:30 »

three/four nights of Si's time, for which I am eternally grateful. Cheers Si!
Logged
Pages: [1] 2   Go Up
Print
Jump to: