1. IMPORTANT - NEW & EXISTING MEMBERS

    E-MAIL SERVER ISSUES

    We are currently experiencing issues with our outgoing email server, therefore EXISTING members will not be getting any alert emails, and NEW/PROSPECTIVE members will not receive the email they need to confirm their account. This matter has been escalated, however the technician responsible is currently on annual leave.For assistance, in the first instance, please PM any/all of the admin team (if you can), alternatively please send an email to:

    [email protected]

    We will endeavour to help as quickly as we can.
    Dismiss Notice

Rootkits

Discussion in 'Computer Corner' started by pete, Jul 7, 2012.

  1. pete

    pete Growing a bit of this and a bit of that....

    Joined:
    Jan 9, 2005
    Messages:
    48,116
    Gender:
    Male
    Occupation:
    Retired
    Location:
    Mid Kent
    Ratings:
    +85,642
    Could someone tell me what a rootkit is.
    Just done a scan and it came up with 5 it says they are hidden????:scratch:

    So how did it find them and are they likely to be dangerous?
     
  2. clueless1

    clueless1 member... yep, that's what I am:)

    Joined:
    Jan 8, 2008
    Messages:
    17,778
    Gender:
    Male
    Location:
    Here
    Ratings:
    +19,595
    They modify the very core, or the root if you like, of your operating system. This makes them very dangerous in terms of the integrity of your computer and the data on it. They used to be virtually impossible to remove too, but nowadays they're not that 'ard compared to the most up to date anti-malware programs, hence your detecting them, as they used to be virtually impossible to detect.
     
  3. pete

    pete Growing a bit of this and a bit of that....

    Joined:
    Jan 9, 2005
    Messages:
    48,116
    Gender:
    Male
    Occupation:
    Retired
    Location:
    Mid Kent
    Ratings:
    +85,642
    Thanks clueless, it says 6 are hidden in windows/system32/drivers.

    But if I remove them will I also remove the file?
    Its not removed them as a matter of course and wants me to highlight the affected file and the click remove.
     
  4. pete

    pete Growing a bit of this and a bit of that....

    Joined:
    Jan 9, 2005
    Messages:
    48,116
    Gender:
    Male
    Occupation:
    Retired
    Location:
    Mid Kent
    Ratings:
    +85,642
    OK, I'm now thinking that was a stupid question.

    I've found I can remove them but need to do a restart.
     
  5. clueless1

    clueless1 member... yep, that's what I am:)

    Joined:
    Jan 8, 2008
    Messages:
    17,778
    Gender:
    Male
    Location:
    Here
    Ratings:
    +19,595
    Sounds like a bit of a pain. Was there an option to quarantine the affected files?

    If not, then it may be necessary to run the Windows repair utility.
     
  6. clueless1

    clueless1 member... yep, that's what I am:)

    Joined:
    Jan 8, 2008
    Messages:
    17,778
    Gender:
    Male
    Location:
    Here
    Ratings:
    +19,595
    If you've removed them, you'll have to restart your machine for the changes to take effect, but, depending on what the files were, you may find some stuff doesn't work quite right. You may have to reinstall some device drivers, or run the Windows repair utility. Lets hope that neither is necessary because it can be a bit of a pain.
     
  7. pete

    pete Growing a bit of this and a bit of that....

    Joined:
    Jan 9, 2005
    Messages:
    48,116
    Gender:
    Male
    Occupation:
    Retired
    Location:
    Mid Kent
    Ratings:
    +85,642
    Yeah, I hope not.
    That sounds a bit complicated.
     
  8. pete

    pete Growing a bit of this and a bit of that....

    Joined:
    Jan 9, 2005
    Messages:
    48,116
    Gender:
    Male
    Occupation:
    Retired
    Location:
    Mid Kent
    Ratings:
    +85,642
    On the two I have tried it says moved to virus vault
     
  9. watergarden

    watergarden have left the forum because...i'm a sad case

    Joined:
    Jan 14, 2007
    Messages:
    946
    Ratings:
    +549
    AVG has a "virus vault" I forgot all about it till you mentioned it. Just emptied mine, so thanks for that.
     
  10. pete

    pete Growing a bit of this and a bit of that....

    Joined:
    Jan 9, 2005
    Messages:
    48,116
    Gender:
    Male
    Occupation:
    Retired
    Location:
    Mid Kent
    Ratings:
    +85,642
    It is AVG watergarden that I'm using.
     
    • Like Like x 1
    • clueless1

      clueless1 member... yep, that's what I am:)

      Joined:
      Jan 8, 2008
      Messages:
      17,778
      Gender:
      Male
      Location:
      Here
      Ratings:
      +19,595
      I take it that all is well now? I'm basing that assumption on the fact that you were still able to get onto the internet, so the PC is still working, but of course you might be on another machine.
       
    • pete

      pete Growing a bit of this and a bit of that....

      Joined:
      Jan 9, 2005
      Messages:
      48,116
      Gender:
      Male
      Occupation:
      Retired
      Location:
      Mid Kent
      Ratings:
      +85,642
      Well not quite sure really clueless.
      It moved two into the virus vault,it doesn't seem to want to do the same with the other four.
       
    • clueless1

      clueless1 member... yep, that's what I am:)

      Joined:
      Jan 8, 2008
      Messages:
      17,778
      Gender:
      Male
      Location:
      Here
      Ratings:
      +19,595
      Just see how it goes I guess.
       
    • pete

      pete Growing a bit of this and a bit of that....

      Joined:
      Jan 9, 2005
      Messages:
      48,116
      Gender:
      Male
      Occupation:
      Retired
      Location:
      Mid Kent
      Ratings:
      +85,642
      Yeah as long as the PC still works I'm not really bothered, but it did have me wondering.

      Thanks for your help.
       
      • Like Like x 1

      Share This Page

      1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
        By continuing to use this site, you are consenting to our use of cookies.
        Dismiss Notice