Rootkit Virus

Saajuk

Member
Apr 15, 2013
45
0
61
There is this program called Rootkit that I have found when scanning my anti virus. During scanning the Word "RootKit" pops up every few seconds. I read that its a type of virus that normal scanners and such wont pick up and will just ignore. Has anyone had this before? How can I get rid of it.
 

mikeymikec

Lifer
May 19, 2011
18,491
11,139
136
It's not so much that anti-virus scanners ignore something, they simply can't detect it (possibly) because the primary aim of a rootkit is to be undetectable.

Screenshot?
 

Saajuk

Member
Apr 15, 2013
45
0
61




and the word Rootkit pops up every few seconds in the first 5-10 minutes. I might need to reimage but how can I do that w/o the installation disk? My laptop never came with one
 
Last edited:

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
From your screenshot, it looks like that is McAfee telling you that it is currently running its rootkit detection part of the scan. It's a progress indicator, not an indication that it has found a rootkit on your system.
 

Saajuk

Member
Apr 15, 2013
45
0
61
I hope thats the case. Ive never seen that being scanned before but the software has updated itself multiple times within the last couple of weeks so it might be new. What exactly are the indicators of having this Rootkit?
 

lxskllr

No Lifer
Nov 30, 2004
57,941
8,198
126
What exactly are the indicators of having this Rootkit?

If it was made well, absolutely nothing. You might find instability in programs that worked fine previously, or unexplained network traffic.
 

mikeymikec

Lifer
May 19, 2011
18,491
11,139
136
An indicator of a rootkit (apart from an outright detection of it by security software) could be any unusual behaviour (but they are designed to not be detectable, so no symptoms would be ideal as far as the designer's intent is concerned). Rootkit tactics (in my experience) involve either a device driver / system service masquerading as something legitimate or something hijacking the boot process (ie. starting with the boot sector and coupling it with a dodgy driver).

Despite my low opinion of McAfee, I would be surprised if it acknowledged that it had scanned a rootkit but then moved on to the next item to scan.

I agree with seepy83, it's just McAfee's poor choice of wording.
 

xgsound

Golden Member
Jan 22, 2002
1,374
8
81
Your screenshot shows that the A/V is searching for a rootkit; not that it has found one. It is good that it is looking and not found anything.

A rootkits goal is not remain undetected, so to be more assured that there is not a rootkit, install and run rkill and tdsskiller (or your preferred anti-rootkit program) from the following link. http://www.bleepingcomputer.com/download/tdsskiller/ These are the two rootkit detectors that I have found to be most effective.

Jim
 

Johnny4

Member
Nov 12, 2013
71
0
0
Oshi Unhooker is a lightweight and portable software application that scans your computer for rootkits and attempts to extract and remove them.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |