Hello,
I've recently been seeing Roguekiller detect a lot of userland rootkits on quite a few machines that come through our repair shop. I was wondering how exactly to proceed in removing them besides just reloading. I've tried a lot of rootkit scanners, asw, mbar, tdsskiller, but nothing seems to help. What would the procedure be to actually remove the detected rootkits? I've done some research and it seems to be some coding that has to be implemented in order to unhide services but this is a little over my head. Can someone provide newbie steps on how to do this?
Thanks!
I've recently been seeing Roguekiller detect a lot of userland rootkits on quite a few machines that come through our repair shop. I was wondering how exactly to proceed in removing them besides just reloading. I've tried a lot of rootkit scanners, asw, mbar, tdsskiller, but nothing seems to help. What would the procedure be to actually remove the detected rootkits? I've done some research and it seems to be some coding that has to be implemented in order to unhide services but this is a little over my head. Can someone provide newbie steps on how to do this?
Thanks!