Re: Ran Windows Update today and after it finished got a virus from it

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Jupiter Jones [MVP] wrote:
> Travis;
> It is extremely unlikely you got this from Windows Update.
> More likely, you already had it and something made it show itself.
>
> Reboot to Safe Mode and scan for viruses:
> Reboot tapping F8 each second.
> Select Safe Mode at the menu.
>
> Did you look here:
> http://securityresponse.symantec.com/avcenter/venc/data/hacktool.rootkit.html
> But, it is recommended you wait until issue is resolved before disabling
> System Restore.
> If you disable Windows during the repair, even an infected Restore Point may
> be better than no Restore Point.
> Then, once the computer is clean, disable System Restore to remove the
> Restore Points with their corruption.
>

Standard antivirus software packages such as Norton and McAfee are
unable to find many types of rootkit, because of the way rootkits work.

Rootkit revealer works differently to these antivirus packages and is
much more likely to find this type of malware. Its freeware and is one
of the only tools that can detect the types of rootkits which standard
antivirus software cannot.

It may be worth running rootkit revealer before trying to fix the
problem, just to check whether your antivirus software has missed
anything. Here's the link:

http://www.sysinternals.com/Utilities/RootkitRevealer.html


.



Relevant Pages

  • Re: Need help removing malware
    ... The free version is only a on-demand scanner. ... Rootkit Revealer but you need to know how it works and it doesn't do ... The output you show from BitDefender is not very explanatory. ... System Restore which clears out all old restore point files, ...
    (alt.comp.anti-virus)
  • RE: strange telnet behavior
    ... change much itself but the attacker who used the rootkit can change ... Make complete backup of all system files, drives, etc. for analysis of the ... Otherwise restore backups to ... system made prior to the compromise is another option. ...
    (Incidents)
  • Re: Brand New Computer Continually Reboots
    ... Not that it can't be hardware, but I actually have seen antivirus software cause this problem many times before. ... choose the option to Repair Your Computer and try running System Restore to before you installed CA. ... Safe Mode - By pressing F8 during boot you may also get the choice to boot into Safe Mode. ... I get the BSOD with an arrow. ...
    (microsoft.public.windows.vista.general)
  • Re: Need help removing malware
    ... The free version is only a on-demand scanner. ... Rootkit Revealer but you need to know how it works and it doesn't do ... Are they remnant registry entries (so the file may not even exist ... System Restore which clears out all old restore point files, ...
    (alt.comp.anti-virus)
  • Re: Wierd happenings
    ... I guess I should have mentioned that it is only funny when I log in, ... "Shenan Stanley" wrote: ... and all of a sudden its all changed and cannot restore it back. ... What AntiVirus software do you have? ...
    (microsoft.public.windowsxp.help_and_support)