how do i get rid of ntoskrnl-hook [Closed] |
![]() ![]() |
how do i get rid of ntoskrnl-hook [Closed] |
Aug 26 2009, 01:11 PM
Post
#1
|
|
|
New Member ![]() Posts: 2 OS: windows xp |
My pc appears to be infected with ntoskrnl-hook, how do i deal with this.
McAfee finds it and says its been removed only for it to be found again. Max secure spyware remover finds a Generic rootkit and quarantines it only for it to reappear next time. McAfee also now finds the following C:\WINDOWS\SYSTEM32\KBIWKMGRKCTNDY.DLL Trojan Rescan after restart C:\WINDOWS\SYSTEM32\KBIWKMTBQMDXFB.DLL Trojan Rescan after restart C:\WINDOWS\SYSTEM32\DRIVERS\KBIWKMXXDEVNLV.SYS Trojan Quarantined all of these files are still there no matter what some ones help would be much appreciated, i understand the ntoskrnl-hook i quite common but asap would be good. This post has been edited by jxp1000: Aug 26 2009, 02:31 PM |
|
|
Aug 26 2009, 05:17 PM
Post
#2
|
|
![]() Malware Removal Staff Posts: 633 OS: Windows XP |
Hello and welcome to the forum!
Let's continue with two more scans. Download and run DDS We need to see some information about what is happening in your machine. Please perform the following scan:
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE Download and Run Scan with GMER We will use GMER to scan for rootkits.
If GMER doesn't work in Normal Mode try running it in Safe Mode Note: Do Not run any program while GMER is running *Note*: Rootkit scans often produce false positives. Do NOT take any actions on "<--- ROOKIT" entries Post back with those logs in your next reply and provide a description of any remaining problems or symptoms you may still have please. With Regards, Extremeboy |
|
|
Aug 29 2009, 04:40 AM
Post
#3
|
|
|
New Member ![]() Posts: 2 OS: windows xp |
Well, I ran both those programs, GMER crashed the computer everytime (blue screen - dumping physical memory) and with DDS all I got was the attached .txt file.
Attached File(s)
|
|
|
Aug 30 2009, 11:42 AM
Post
#4
|
|
![]() Malware Removal Staff Posts: 633 OS: Windows XP |
Hello.
I can't read that DDS log file. Please run RootRepeal. Then afterwards, re-run DDS again. Download and run RootRepeal CR Please download RootRepeal from the following location and save it to your desktop.
~Extremeboy |
|
|
Sep 5 2009, 06:24 PM
Post
#5
|
|
![]() Malware Removal Staff Posts: 633 OS: Windows XP |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
4 / 590 | 16th December 2005 - 08:39 AM freeflyer37 started - last by didom |
|||||
![]() |
10 / 930 | 10th December 2008 - 06:48 AM kaos0930 started - last by fenzodahl512 |
|||||
![]() |
2 / 548 | 3rd February 2009 - 07:10 PM alfred2 started - last by handhfan |
|||||
![]() |
47 / 3,492 | 2nd August 2009 - 10:09 PM Master Spade started - last by heir |
|||||
|
Time is now: 21st November 2009 - 12:16 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising