Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: nickcarraway

I have a recurring issue on one XP Home laptop. A rootkit is repeatedly infecting atrac.dll; Norton doesn’t seem to even detect it. I got an antivirus from PCTools, and that disables it, but fails to delete or quarantine it. Another computer on the home network is on Symantec and is fine.

Anyone experienced anything similar?


5 posted on 05/07/2009 12:05:13 PM PDT by annalex (http://www.catecheticsonline.com/CatenaAurea.php)
[ Post Reply | Private Reply | To 1 | View Replies ]


To: annalex

I had a nasty memory-resident infection of something similar on my computer once.

Remove your current AV, and install Avast and that Malwarebytes software. Both are free for home use.

Run a scan and see if this helps.


18 posted on 05/07/2009 12:10:42 PM PDT by MyTwoCopperCoins (I don't have a license to kill; I have a learner's permit.)
[ Post Reply | Private Reply | To 5 | View Replies ]

To: annalex
I know rootkits can be pretty nasty to remove. I've never seen this particular one, but I googled it (as I would if you were to bring your computer to me).

I found a thread on forums.techguy.org that has a ridiculously long discussion and troubleshooting session on it.

The most promising part of the thread seems to be a link to a program called gmer.net. It appears that a better known scanner called Avast contains the same anti-rootkit technology.

I'd try to remove it with the free version of Avast.
If that doesn't work, I'd try malwarebytes.
Then, I'd look into this gmer.net rootkit removal tool.
32 posted on 05/07/2009 12:24:52 PM PDT by mmichaels1970
[ Post Reply | Private Reply | To 5 | View Replies ]

To: annalex
Cleaning tools may work, or they may not. Particularly pernicious malware can be programmed to look for and work around said tools. Installing and scanning with various tools can take up a lot of time, and then there's always that nagging doubt as to whether or not it really got it. So as a plan D:

Backup data ONLY. No applications.

Then

Repartition, reformat, reinstall.

"I say we take off and nuke the site from orbit - it's the only way to be sure" - Ripley

43 posted on 05/07/2009 2:01:26 PM PDT by AFreeBird
[ Post Reply | Private Reply | To 5 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson