Ask the Expert

Troubleshooting a Trojan rootkit

I have Windows XP Professional SP1. Trojan.rootkit.h keeps coming back after rebooting even though I have deleted its infected files from the drive and registry several times. I've used every adware and spyware removal tool possible, so I'm quite clean now. Symptoms besides physical presence include inability to run msconfig, regedit and taskmanager, as well as having the Windows Installer stop on me. This makes it impossible to update it to version three, since that also uses the MSI utility. Do you have any thoughts on this? Thanks in advance!
You may want to try Ewido. Otherwise, as drastic as this may sound, my suggestion would be to back up your data files and reload the system -- Windows and all your apps. This will likely take less time than trying to troubleshoot this further, and you'll have a clean system to boot (pun intended).

Also check out our Prevention Guide on detecting and removing rootkits in Windows.

This was first published in May 2005

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: