Rootkit, anybody?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Other forums
- :
- Tech Help - Software/Hardware etc
- :
- Rootkit, anybody?
Rootkit, anybody?
01-11-2014 6:15 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
So are rootkits always malicious? If so, can they be manually removed safely - and if so how, please?
Cheers!
Re: Rootkit, anybody?
01-11-2014 6:45 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Any thoughts please?
Re: Rootkit, anybody?
01-11-2014 6:48 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Rootkit, anybody?
01-11-2014 8:35 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I generally scan with something like tdsskiller - give it a go and see if it picks up anything ?
http://support.kaspersky.co.uk/viruses/disinfection/5350
I've had one machine that was so riddled with stuff after contracting a rootkit that it took a clean boot with Hirens, a disinfect then some serious repair work afterwards - three days to rebuild that machine

Re: Rootkit, anybody?
01-11-2014 9:34 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Rootkit, anybody?
01-11-2014 9:50 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
GMER is safe enough to use but I never seemed to get anywhere much with it - worth having a play with though but make sure you back up any vital data etc before trying to fix anything.
I remember the rootkit I removed for a customer had rendered their system almost unusable and by the time I'd removed it had really screwed things up.
Re: Rootkit, anybody?
02-11-2014 10:20 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Rather nervously took a look at GMER, which appeared to identify something called TDL4@MBR.
Didn't go any further with GMER.
Googling TDL4@MBR turned up a 2012 thread on the Malwarebytes forum.
One post suggested using RogueKiller

With some trepidation I went into that, but to this noddy it could have been written in Reverse Polish.
Experience has taught me that setting off something complex that I don't understand often does me more harm than good!
Re: Rootkit, anybody?
02-11-2014 1:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator

I'd love to try and help you out more but that isn't a rootkit I'm familiar with

Re: Rootkit, anybody?
02-11-2014 3:08 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
http://windowstechies.com/-/en/spyware/?t=1&k=tdl4%20rootkit&m=b&u=&c=53624069550&gclid=COrf8pqZ3MEC...
It may help you.
York.
Re: Rootkit, anybody?
03-11-2014 8:20 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Quote from: DomS Always wise to quit when you are ahead
Unfortunately ArthurDent is behind rather than ahead! And the link by NedLudd is just a 'sales pitch' for a program called SpyHunter.
Edit: There's an interesting commentary on 'Spyhunter' at the bottom of this thread http://www.bleepingcomputer.com/forums/t/517033/spyhunter-cannot-remove-infections/
2nd Edit; MBR stands for Master Boot Record. If your Master Boot Record has been modified then even resetting your computer to its 'factory state' would probably leave the infected boot record intact. Did you actually try tdsskiller, ArhturDent? That has worked for me in similar situations.
Re: Rootkit, anybody?
03-11-2014 1:55 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
The only real reason I started this thread was that when running a PlusnetProtect/McAfee scan (even a quick one) it continuously displays what it is scanning.I happened to notice it flagging up that it was scanning rootkit. That seemed to take some time before moving on to scan something else. Having seen this I have looked out for it and seen it since.
Yep, RR, I did run TDSKILLER but after galloping quickly through 524 objects it didn't identify any cause for concern.
Also ran SPYHUNTER, which came up with a load of warnings - yellow flags, not red so I'm not sure about the seriousness of them:
15 x adware (all LuckyLeap)
5 x assorted tracking cookies
2 x PUP (both MyPC Backup)
2 x spyware cookies (both xiti)
Was going to register until I saw the price tag ($47.99).
Obviously this would be on top of Malwarebytes, for which I'm already paying. So?
I note, however, that there's a Malwarebytes beta of a rootkit app. Any experience/comments from you guys would be appreciated.
Cheers!
Re: Rootkit, anybody?
03-11-2014 2:50 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator

York.

Re: Rootkit, anybody?
03-11-2014 2:52 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I have this and mine too came up clean:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 03/11/2014
Scan Time: 14:40:56
Logfile: malware.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.03.06
Rootkit Database: v2014.11.01.02
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 313598
Time Elapsed: 3 min, 5 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Warn
PUM: Warn
Processes: 0 (No malicious items detected)
Modules: 0 (No malicious items detected)
Registry Keys: 0 (No malicious items detected)
Registry Values: 0 (No malicious items detected)
Registry Data: 0 (No malicious items detected)
Folders: 0 (No malicious items detected)
Files: 0 (No malicious items detected)
Physical Sectors: 0 (No malicious items detected)
(end)
Re: Rootkit, anybody?
04-11-2014 1:42 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
It turned out that the problem (lots of pop-up adverts when browsing the web) was down to past malware changing the DNS settings. I'm not sure if I simply missed that at first look or if It had been 'cloaked' and I managed to reveal it.
Re: Rootkit, anybody?
04-11-2014 4:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page