Rootkit - please help

T

TW

Hi,

I'm using WindowsXP Pro SP2.
Programs RootkitRevealer and Gmer shown that
c:\Windows\System32\antiak.sys is a rootkit.
How to get rid of it? Should I simply delete the file
from the system or ought I to do anything else?
What are general rules of removing rootkits from
Windows systems?

Regards,
TW
 
S

Squire

Do a search for Rootkit,
you can delete all of them as they are not a part of XP.
 
K

Kerry Brown

TW said:
Hi,

I'm using WindowsXP Pro SP2.
Programs RootkitRevealer and Gmer shown that
c:\Windows\System32\antiak.sys is a rootkit.
How to get rid of it? Should I simply delete the file
from the system or ought I to do anything else?
What are general rules of removing rootkits from
Windows systems?

Regards,
TW

Do you have an anti-keystroke logger installed? Googling for that file name
suggests it may be part of a anti-keystroke logger program. If you have
never installed any of these programs and it is a rootkit the only sure way
to get rid of it is a clean install of Windows. This means formatting your
hard drive so back up your data first.
 
T

TW

Thank you very much for your reply.
Do you have an anti-keystroke logger installed? Googling for that file name
suggests it may be part of a anti-keystroke logger program.
I think I don't have and I didn't ever have any anti-keystroke logger installed
but I'm not absolutely sure.
I'd like to avoid formatting disk and installing Windows again (especially if it's
not necessary) so is there any method to check if I have or had such anti-keylogger installed?

Regards,
TW
 
K

Kerry Brown

TW said:
Thank you very much for your reply.


I think I don't have and I didn't ever have any anti-keystroke logger
installed but I'm not absolutely sure.
I'd like to avoid formatting disk and installing Windows again
(especially if it's not necessary) so is there any method to check if I
have or had such
anti-keylogger installed?
Regards,
TW

Not that I know of. In another newsgroup it was suggested that you try
renaming the file. Have you tried this?
 
T

TW

Thank you very much for your reply.
In another newsgroup it was suggested that you try
renaming the file. Have you tried this?
Yes I have, after trobles with getting the Safe Mode.
Eventually I did it and it seems to be helpful.
At least the Gmer program doesn't show any rootkit
anymore.

Regards,
TW
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top