How to Manually Remove a Rootkit Infection

104 11

    Enable Boot Log

    • 1). Click on the "Start" menu and select "Run."

    • 2). Type "msconfig" into the open box and click "OK."

    • 3). Click on the "Boot" tab and check the box next to "Boot Log."

    • 4). Click "Apply" and then restart your computer.

    Locate Infected Files

    • 1). Click on the "Start" menu, then "Search Files and Folders."

    • 2). Search for any files that start with the following names. Write down the full name (i.e. rot.exe or rot.sys) of every file that you find.

      "rot"
      "gas"
      "gaopdx"
      "seneka"
      "win32k.sys"
      "uacd"
      "tdss"
      "tdss"
      "kungsf"
      "gxvxc"
      "ovsfth"
      "msqp"
      "ndisp"
      "msivx"
      "skynet"

    • 3). Close the "Search Files and Folders" window.

    Disable File Permission

    • 1). Click on the "Start" menu and then click "Run."

    • 2). Type "cmd" into the open box and click "OK." The Command Prompt window will open.

    • 3). Type "cacls C:WINDOWSsystem32drivers [filename] /d everyone" into the Command Prompt window and press "ENTER." Note that [filename] should be replaced with the file name that you wrote down in Section 2, Step 2. For example, "cacls C:WINDOWSsystem32drivers rot.sys /d everyone" Do this for every file you wrote down.

    • 4). Restart your computer.

    Delete Infected Files

    • 1). Click on the "Start" menu.

    • 2). Click on "Search Files and Folders."

    • 3). Search for every file that you wrote down and delete them. To delete a file, simply right-click on it and select "Delete."

Subscribe to our newsletter
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
You can unsubscribe at any time

Leave A Reply

Your email address will not be published.