<?xml version="1.0"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>How-To Geek Forums Topic: Remove Rootkits</title>
<link>http://www.howtogeek.com/forum/</link>
<description>How-To Geek Forums Topic: Remove Rootkits</description>
<language>en</language>
<pubDate>Tue, 02 Dec 2008 12:54:02 +0000</pubDate>

<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits/page/2#post-38717</link>
<pubDate>Thu, 31 Jul 2008 04:54:48 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">38717@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Okay I followed the instructions to delete the malware but it just kept switching names.&#60;/p&#62;
&#60;p&#62;So I ran AVG in Admin Mode and deleted both.&#60;/p&#62;
&#60;p&#62;After that I completely un-installed AVG and it gave me an option to also delete any viruses or anything that was in the vault so I did.&#60;/p&#62;
&#60;p&#62;I read up a little on different security and decided to go with BitDefender Total Security 2008.&#60;br /&#62;
In a few tests of products it came out number 1 and AVG didnt fare so well.&#60;br /&#62;
Now Ive run scans and come up clean :)&#60;/p&#62;
&#60;p&#62;I also have SUPERAntispyware installed &#38;lt; great program.&#60;/p&#62;
&#60;p&#62;Just wanted to post and say thanks for all the help.&#60;/p&#62;
&#60;p&#62;Sorry for the lag between responses,all the help is greatly appreciated!
&#60;/p&#62;</description>
</item>
<item>
<title>ScottW on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits/page/2#post-36228</link>
<pubDate>Mon, 21 Jul 2008 01:07:05 +0000</pubDate>
<dc:creator>ScottW</dc:creator>
<guid isPermaLink="false">36228@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Well, a search on mchInjDrv.sys shows exactly what I suspected.  This malware is hiding and regenerating when removed.  Here are instructions from Symantec on removal:&#60;br /&#62;
&#60;a href='http://www.symantec.com/security_response/writeup.jsp?docid=2003-111816-3817-99&#38;#38;tabid=1'&#62;http://www.symantec.com/security_response/writeup.jsp?docid=2003-111816-3817-99&#38;#38;tabid=1&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;Note this line: &#34;Loads the following driver, when stealth mode is activated, and uses it to hide its process and service: mchinjdrv.sys&#34;.  The idea of hiding itself and recreating the random letter filename is why this is being called a rootkit by AVG.
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits/page/2#post-36224</link>
<pubDate>Mon, 21 Jul 2008 00:17:49 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">36224@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Okay I managed to delete :&#60;br /&#62;
C:\Windows\system32\Drivers\mchInjDrv.sys&#60;br /&#62;
and&#60;br /&#62;
C:\Windows\System32\Drivers\a90thxv.SYS&#60;br /&#62;
using Admin Account.&#60;/p&#62;
&#60;p&#62;So Im running another scan and now its :&#60;br /&#62;
C:\Windows\System32\Drivers\ayx8md7x.SYS&#60;/p&#62;
&#60;p&#62;Any thoughts on how to get rid of this?&#60;/p&#62;
&#60;p&#62;Thanks for all the help.
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36209</link>
<pubDate>Sun, 20 Jul 2008 22:27:56 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">36209@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;@ jraparrish I will try that Administrator Account thing and see what happens.&#60;/p&#62;
&#60;p&#62;@ whs I tried all three of those apps with no luck :( is there any other apps you can think of?&#60;/p&#62;
&#60;p&#62;Thanks for the help
&#60;/p&#62;</description>
</item>
<item>
<title>whs on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36183</link>
<pubDate>Sun, 20 Jul 2008 20:48:42 +0000</pubDate>
<dc:creator>whs</dc:creator>
<guid isPermaLink="false">36183@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;AVG may not do the job. Maybe you want to try the programs we linked earlier. Those are specialized on Rootkits.
&#60;/p&#62;</description>
</item>
<item>
<title>jraparrish on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36178</link>
<pubDate>Sun, 20 Jul 2008 20:43:37 +0000</pubDate>
<dc:creator>jraparrish</dc:creator>
<guid isPermaLink="false">36178@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Since this is a Vista computer, it may be a good idea to enable the Administrator Account and use it to perform the tasks you are suggesting. I have found where only the Administrator account itself has total control over the machine, even when the user account the person is using is a member of the Administrators.
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36159</link>
<pubDate>Sun, 20 Jul 2008 19:52:39 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">36159@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;When I try to Remove all unhealed infections the same pop up comes up saying access is denied.&#60;/p&#62;
&#60;p&#62;Currently Im not in safe mode(When I try to run the AVG scan in safe mode it starts some line command scan or something like that)that I dont understand.  &#60;/p&#62;
&#60;p&#62;Yes I am the admin on this computer.&#60;/p&#62;
&#60;p&#62;How did it change numbers like that?&#60;/p&#62;
&#60;p&#62;Thanks.
&#60;/p&#62;</description>
</item>
<item>
<title>ScottW on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36156</link>
<pubDate>Sun, 20 Jul 2008 19:43:21 +0000</pubDate>
<dc:creator>ScottW</dc:creator>
<guid isPermaLink="false">36156@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Does your user account have admin authority?  AVG should not care whether you have hidden files enabled or disabled.  That's just for you the user to see or not see them in File Explorer.&#60;/p&#62;
&#60;p&#62;Are  you still running in Safe Mode?  It looks like what I said has happened -- the malware created a new jumbled letter filename and copied itself again.  What did AVG do with the files?  Heal, quarantine, or delete?
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36152</link>
<pubDate>Sun, 20 Jul 2008 19:20:49 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">36152@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;OK I did a scan and no rootkits were found......but then I remembered I had changed that folder thing so I changed them back to the way they were(do not show hidden files and folders;hide protected operating system files[recommended])and ran another scan and now this:&#60;/p&#62;
&#60;p&#62;C:\Windows\system32\Drivers\mchInjDrv.sys&#60;br /&#62;
and&#60;br /&#62;
C:\Windows\System32\Drivers\a90thxv.SYS&#60;br /&#62;
both hidden drivers.:(&#60;/p&#62;
&#60;p&#62;Dont know how but that second changed I guess.&#60;/p&#62;
&#60;p&#62;Any suggestions?&#60;/p&#62;
&#60;p&#62;Thanks for all the help.
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36023</link>
<pubDate>Sun, 20 Jul 2008 07:58:19 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">36023@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Well when I try to remove using AVG it says access is denied.&#60;/p&#62;
&#60;p&#62;Will scan right now will post results shortly.
&#60;/p&#62;</description>
</item>
<item>
<title>ScottW on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36013</link>
<pubDate>Sun, 20 Jul 2008 06:23:22 +0000</pubDate>
<dc:creator>ScottW</dc:creator>
<guid isPermaLink="false">36013@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;If the files aren't there, maybe they were quarantined by AVG.  Does AVG have a quarantine that you can look at?  How about checking AVG's activity log to see what it did with the files.  If they are gone, that's great.  How about this -- initiate a manual scan and see if it comes up clean or still identifies those same files.
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36004</link>
<pubDate>Sun, 20 Jul 2008 03:53:00 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">36004@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;@ ScottW&#60;br /&#62;
Okay I changed those settings but I still cant find those files up there ^^^^^^ in my first post.&#60;/p&#62;
&#60;p&#62;BTW Im in safe mode.&#60;br /&#62;
I had made a post about safe mode too but I dont know what happened to it(maybe it was in the wrong place?)&#60;/p&#62;
&#60;p&#62;Thanks for the input.
&#60;/p&#62;</description>
</item>
<item>
<title>ScottW on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-36000</link>
<pubDate>Sun, 20 Jul 2008 03:33:07 +0000</pubDate>
<dc:creator>ScottW</dc:creator>
<guid isPermaLink="false">36000@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Sure, sorry I was vague.  Go to Control Panel -&#38;gt; Folder Options -&#38;gt; View tab.  In the Advanced Settings area, find the Hidden Files and Folders section and choose &#34;Show hidden files and folders&#34;.  You may also want to temporarily uncheck the box next to &#34;Hide system files and folders&#34; because some malware will disguise itself as system files.  When you have deleted the bad files, check that option again.&#60;/p&#62;
&#60;p&#62;You can get to Folder Options in safe mode as well.  The benefit of safe mode is that it is less likely that the malware can protect itself from erasure or generate a new jumbled letters filename and copy itself there.  Some of these can be very tenacious.
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-35994</link>
<pubDate>Sun, 20 Jul 2008 02:46:09 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">35994@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;@ ScottW&#60;/p&#62;
&#60;p&#62;I cant find the files even in safe mode because they are hidden(?) and I dont know what you mean by the folder options.&#60;/p&#62;
&#60;p&#62;Please explain &#60;/p&#62;
&#60;p&#62;Thanks in advance.
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-35993</link>
<pubDate>Sun, 20 Jul 2008 02:44:00 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">35993@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Okay I tried all 3 suggestions:&#60;/p&#62;
&#60;p&#62;The spybot one didnt find any rootkits&#60;/p&#62;
&#60;p&#62;The Hook Analyzer came with this error:&#60;br /&#62;
  Cannot communicate with device.The operation completed successfully&#60;br /&#62;
  I then press ok and the screen pops up and I psh scan but this pops up:&#60;br /&#62;
  Wrong version of RSPSC32.sys installed. You may need to reinstall or reboot.&#60;/p&#62;
&#60;p&#62;The Root Kit Revealer kept rebooting my system and listed a bunch of HKLM\yada yada yada\(Im guessing registry things(?)&#60;br /&#62;
but nothing that I could see of any rootkits :(&#60;br /&#62;
I finally had to turn off my computer to stop that because it just kept taking me to the log in screen and after I logged in it would continue the same cycle.&#60;/p&#62;
&#60;p&#62;Any other suggestions?&#60;/p&#62;
&#60;p&#62;Thanks in advance.
&#60;/p&#62;</description>
</item>
<item>
<title>Lighthouse on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-35870</link>
<pubDate>Sat, 19 Jul 2008 16:56:36 +0000</pubDate>
<dc:creator>Lighthouse</dc:creator>
<guid isPermaLink="false">35870@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;Thanks for that Rick :)
&#60;/p&#62;</description>
</item>
<item>
<title>raphoenix on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-35869</link>
<pubDate>Sat, 19 Jul 2008 16:54:53 +0000</pubDate>
<dc:creator>raphoenix</dc:creator>
<guid isPermaLink="false">35869@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;All,&#60;/p&#62;
&#60;p&#62;When using Root Kit Revealer, it will sometimes hang a machine while scanning the registry WPA Signing Hash entry. There is a minor bug in the code if I remember correctly.&#60;/p&#62;
&#60;p&#62;Regards,&#60;br /&#62;
Rick P.
&#60;/p&#62;</description>
</item>
<item>
<title>ScottW on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-35829</link>
<pubDate>Sat, 19 Jul 2008 12:41:58 +0000</pubDate>
<dc:creator>ScottW</dc:creator>
<guid isPermaLink="false">35829@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;The name &#34;axk3uljd&#34; is just a random string of letters and numbers generated by the malware.  This prevents you from googling on it, but it also means it is almost certainly bad.  Lots of new malware uses these jumbled names, so always keep an eye out for them.  We have seen this many times before.&#60;/p&#62;
&#60;p&#62;Compidiot: did you try deleting the files in safe mode?  Have you set the Folder Options to display hidden files and folders?
&#60;/p&#62;</description>
</item>
<item>
<title>COMPIDIOT on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-35813</link>
<pubDate>Sat, 19 Jul 2008 11:17:04 +0000</pubDate>
<dc:creator>COMPIDIOT</dc:creator>
<guid isPermaLink="false">35813@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;@ Lighthouse thats the way its spelled on my AVG scan results.&#60;/p&#62;
&#60;p&#62;@ whs and Lighthouse thanks for the links. Will try and get back with results.(Probably later on tonight though(its already 6:16 A.M. here)&#60;/p&#62;
&#60;p&#62;Thanks again.
&#60;/p&#62;</description>
</item>
<item>
<title>Lighthouse on "Remove Rootkits"</title>
<link>http://www.howtogeek.com/forum/topic/remove-rootkits#post-35809</link>
<pubDate>Sat, 19 Jul 2008 10:54:03 +0000</pubDate>
<dc:creator>Lighthouse</dc:creator>
<guid isPermaLink="false">35809@http://www.howtogeek.com/forum/</guid>
<description>&#60;p&#62;And here&#60;br /&#62;
&#60;a href='http://www.resplendence.com/hookanalyzer'&#62;http://www.resplendence.com/hookanalyzer&#60;/a&#62;
&#60;/p&#62;</description>
</item>

</channel>
</rss>
