kgootkit.sys - Dangerous
kgootkit.sys
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
KGootkit.sys is Trojan/Backdoor.
Kill the file KGootkit.sys and remove KGootkit.sys from Windows startup.
Malware:
C:\sand-box\install.exe
Removed:
C:\WINDOWS\system32\drivers\KGootkit.sys
After first reboot detected by UnHackMe:
Item Name: KGootkit
Author:
Related File: C:\WINDOWS\SYSTEM32\DRIVERS\KGOOTKIT.SYS
Type: Services detected by Partizan
Removal Results: Success
Number of reboot: 1
Classification:Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.04.13 Trojan.PWS.YOE
Kaspersky 7.0.0.125 2010.04.13 Trojan.Win32.Starter.jz
McAfee 5.400.0.1158 2010.04.13 Generic Dropper!cib
Microsoft 1.5605 2010.04.13 TrojanDropper:Win32/Otlard.B
NOD32 5026 2010.04.13 Win32/Wigon
Additional information
File size: 38400 bytes
MD5 : 578a0b39fdc977738843c52d3c36af62
SHA1 : c23f07bbaf40232959dd46622850725b8680f696
SHA256: 2a4bcd2d736a9555e3258ee46c00691d5db1368c1df23648b9bdb2a02cf86a55
http://greatis.com/blog/how-to-remove-ma...