How to Manually Remove a Rootkit Infection
- 1). Click on the "Start" menu and select "Run."
- 2). Type "msconfig" into the open box and click "OK."
- 3). Click on the "Boot" tab and check the box next to "Boot Log."
- 4). Click "Apply" and then restart your computer.
- 1). Click on the "Start" menu, then "Search Files and Folders."
- 2). Search for any files that start with the following names. Write down the full name (i.e. rot.exe or rot.sys) of every file that you find.
"rot"
"gas"
"gaopdx"
"seneka"
"win32k.sys"
"uacd"
"tdss"
"tdss"
"kungsf"
"gxvxc"
"ovsfth"
"msqp"
"ndisp"
"msivx"
"skynet" - 3). Close the "Search Files and Folders" window.
- 1). Click on the "Start" menu and then click "Run."
- 2). Type "cmd" into the open box and click "OK." The Command Prompt window will open.
- 3). Type "cacls C:WINDOWSsystem32drivers [filename] /d everyone" into the Command Prompt window and press "ENTER." Note that [filename] should be replaced with the file name that you wrote down in Section 2, Step 2. For example, "cacls C:WINDOWSsystem32drivers rot.sys /d everyone" Do this for every file you wrote down.
- 4). Restart your computer.
- 1). Click on the "Start" menu.
- 2). Click on "Search Files and Folders."
- 3). Search for every file that you wrote down and delete them. To delete a file, simply right-click on it and select "Delete."