Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 07:34:38 PM

Login with username, password and session length

663838 Posts
70590 Topics
145231 Members

Latest Member: destanee13

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  AntiVirus Help - CIS
| | | | |-+  Rootkit query
« previous next »
Pages: [1] Go Down Print
Author Topic: Rootkit query  (Read 1203 times)
7Leagues
Comodo Family Member
***
Offline Offline

Posts: 94



WWW
« on: January 06, 2012, 04:19:40 AM »

Following a full scan, one or more rootkits have been found but when I try to clean them CIS tells me it is not possible to clean or quarantine them. Can anyone advise what the procedure is for rootkit removal please?
Logged

Who else wants to defy gravity by wearing a pair of 7 Leagueboots?
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13182


Volunteer Moderator


« Reply #1 on: January 06, 2012, 03:56:35 PM »

Can you please post a screenshot of those 'rootkit' detections?

Rookit verification must be done on an 'offline' system, I'd advise to download Hiren's boot CD here
Boot from it and use explorer or registry editor to verify the existence of the detected 'Rootkits'.
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
7Leagues
Comodo Family Member
***
Offline Offline

Posts: 94



WWW
« Reply #2 on: January 06, 2012, 05:08:38 PM »

I will have to come back to you Ronny. I didn't take a screenshot so it will require a full scan again. I can't do that at this time as the machine is too busy running other tasks. I can tell you that all rootkits were found in the registry and related to Microsoft applications which seemed a bit strange to me. I was kind of wondering whether they may be false positives?
Logged

Who else wants to defy gravity by wearing a pair of 7 Leagueboots?
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13182


Volunteer Moderator


« Reply #3 on: January 06, 2012, 05:19:41 PM »

Could be some anomaly was found during scanning, let's see what turns up.
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
Tags: Rootkit  rootkits  rootkit removal 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.038 seconds with 23 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com