![]() |
![]() | Virus that uses rootkit | ![]() |
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
it would help if you were a bit more specific than "detected something". You can always scan a file online at https://www.virustotal.com and see what different AV vendors detect
|
|||||||||||
|
![]() |
![]() | ClamWin Versus Rootkits | ![]() |
GuitarBob
![]() |
![]() |
As Alch said, you need to be more specific. There are several rootkit viruses around, and some antivirus programs are not set up to detect them or will only detect a few. ClamWin uses the Clam signature database. A search of the ativirus signature database at the ClamAV web site using the term "rootkit" turned up one name: Trojan.Rootkit-6. This is Clam's name for it--other antivirus software will have their own name for it. There are some free rootkit removal tools available on the Web--especially for the Sony Rootkit.
Regards, |
|||||||||||
|
![]() |
![]() | ![]() |
sherpya
![]() |
![]() |
use this tool https://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx https://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx
and look for files hidden to the api please note you can get false positives if you are doing something in background so temp file and internet cache can be ignored you need to focus on .sys or .dll that are hidden to api often you have a .sys driver that starts and hides the malware executable. I was happy to notice that clamwin can detect some of rookit hidden files because of using unc paths ![]() |
|||||||||||
|
![]() |
![]() | Virus that uses rootkit | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.