Free PC Performance Scan

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » Anti-Virus » can't remove TR/Rootkit.L

Anti-Virus - can't remove TR/Rootkit.L posted in the Security & Safety forums; everytime i start windows and sometimes during running windows i get an alert that reads: C:\SYSTEM VOLUME INFORMATION\_RESTORE{159D80CF-7EDF-409A-A914-9E2489DA75D3}\RP16\A0012238.SYS Is the Trojan horse TR/Rootkit.L i choose to delete the trojan but ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 08-01-2005
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default can't remove TR/Rootkit.L

everytime i start windows and sometimes during running windows i get an alert that reads:

C:\SYSTEM VOLUME INFORMATION\_RESTORE{159D80CF-7EDF-409A-A914-9E2489DA75D3}\RP16\A0012238.SYS

Is the Trojan horse TR/Rootkit.L

i choose to delete the trojan but it keeps on popping back up, can anyone shed some light on this please?


  #2  
Old 08-01-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: can't remove TR/Rootkit.L


Thats pointing to system restore.
Temporary disable system restore , delete old restore points if needed and delete it again.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 08-02-2005
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default Re: can't remove TR/Rootkit.L

here are some more that keep on popping up


C:\WINDOWS\SYSTEM32\RDRIV.SYS

Is the Trojan horse TR/Rootkit.L


C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\H9SB3VWX\CLEARLOGS[1].RAR

Is the Trojan horse TR/Dldr.Agent.JN.2


this one pops up EVERY time i start windows

C:\CLEARLOGS.EXE

Is the Trojan horse TR/Dldr.Agent.JN.2


  #4  
Old 08-02-2005
Friend of PCHF
 
Join Date: Sep 2004
Location: Right here !
Posts: 2,149
Zimbo - See this Members User comments on their Profile page
Default Re: can't remove TR/Rootkit.L

What antivirus software are you running?

Click on "handy tools" in my signature and you can find a lot of useful tools like "Stinger" ; "AVG" ; and Microsoft malicious removal tool.
(Download and run in safemode)

Try those and also delete everything from your "TEMP" and "Temporary Internet Folder"


  #5  
Old 08-02-2005
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default Re: can't remove TR/Rootkit.L

i usually run mcafee internet shield, the full works. but since my recent xp install i have for some reason started using zone alarm for the firewall and antvir, dont ask why. i intend on re-installing mcafee at some point though.


  #6  
Old 08-06-2005
Bronze Member
 
Join Date: Aug 2005
Posts: 1
alazat521 - See this Members User comments on their Profile page
Default Re: can't remove TR/Rootkit.L

um, i believe i'm experiencing the same..except what i keep getting is this:

C:\WINDOWS\SYSTEM32\RDRIV.SYS

Is the Trojan horse TR/Rootkit.L

...constantly. and i just can't get rid of it. suggestions maybe?


  #7  
Old 08-06-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,616
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default Re: can't remove TR/Rootkit.L

Download ewdio in my signature boot into safe mode and run it.. Let it delete everything it finds.. See if it cant get rid of it.


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:08 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top