The Mudcat Café TM
Thread #126812   Message #2824474
Posted By: Bernard
29-Jan-10 - 09:01 AM
Thread Name: Tech: Re my: Help! Serious Virus Plea.
Subject: RE: Tech: Re my: Help! Serious Virus Plea.
Let's be clear about this... a 'rootkit' is not a fix, it is a particularly pernicious form of malware that replaces the system drive's boot sector. It is therefore capable of circumventing any attempt to remove it, even in Safe Mode.

The only sure way to get rid is by booting from another device (usually CDRom) and replacing the boot sector with a clean version. This could also be achieved by connecting the drive as a slave or external drive on another machine which is adequately nailed down.

I repeat - disable autorun (autoplay) to prevent infected drives from installing their rootkit payload. If you have a network, they will spread like wildfire to any machine that has mapped drives with autoplay enabled.

I've been there...