how to stop a driver from running - it self protected and rootkit hidden

Posted by Aristos on Super User See other posts from Super User or by Aristos
Published on 2010-04-18T11:11:09Z Indexed on 2010/04/18 11:14 UTC
Read the original article Hit count: 245

Filed under:
|

I have this serous problem

For the first time I can not stop a program from running.

Something is on one laptop computer that is run as system legacy driver, and self protected and hidden on service as rootkit.

Anything I try to remove fails.

When a program or anti toolkit try to remove the hidden registry setting for make it stop I get this error : "a device attached to the system is not functioning"

So any idea that can help me stop it from running, or even delete it on start up ?

My one limitation is that the hard drive is on a laptop and I can not remove it and attact it to somewhere else.

This program not let me, touch the registry, do not let me touch the file, do not let me touch the file, The move on boot fail to delete it, the rootrepeal fail to delete it, the rootkiet reveal from sysinternals fail to reveal it ! everything fails.

Do how have any experience on this, or do you have any suggestion how to stop this driver from run ?

© Super User or respective owner

Related posts about rootkit

Related posts about virus