I discovered a rootkit on my brother in laws laptop. I've never had to deal with rootkits before and I'm mining for the best utility to deal with them. Avast discovered the rootkit generator but this is probably just the tip of the iceberg.
I discovered a rootkit on my brother in laws laptop. I've never had to deal with rootkits before and I'm mining for the best utility to deal with them. Avast discovered the rootkit generator but this is probably just the tip of the iceberg.
It's okay, I'm a limo driver
Back up the important data and re-install, you'll never know exactly what was installed or changed.
so why back-up it now, when data could have been already altered/destroyed?
format a disk, install a new operating system, restore important data from back-ups done before security was compromised.
ah, i suspect- since you know it's rootkit, you have an idea (or two) how it get into a system (was it up-to-date? maybe some "codecs" were installed? etc etc)
Last edited by szymon_g; December 8th, 2010 at 04:01 AM. Reason: grammar
Nice false positive you got there...
Both detections came back with negative google responses. Oddest part is they were strings of random numbers and letters. Nasty behavior when active, the usual, deactivate AV but the applet said it was active and working. msconfig disabled as well as task manager. I'll probably give the bad news to brother in law tomorrow after I dig a little deeper to see what else is happening.
To answer some of the responses, I have general time line of infection( possibly 2days ago) No idea what was being done when infected, (sister and brother in law very computer illiterate),and definite there was/is an infection, not a false positive. I'll double check personal data and wipe drive and restore.
Last edited by MooPi; December 8th, 2010 at 04:32 AM. Reason: add info
It's okay, I'm a limo driver
MooPi
What OS?
If you believe everything you read, you better not read. ~ Japanese Proverb
If you don't read the newspaper, you're uninformed. If you read the newspaper, you're mis-informed. - Mark Twain
Thinking about becoming an Ubuntu Member?
Bookmarks