How to get rid of this Root kit Virus.

Discussion in 'ESET NOD32 Antivirus' started by Ballan, Mar 25, 2012.

Thread Status:
Not open for further replies.
  1. Ballan

    Ballan Registered Member

    Joined:
    Mar 25, 2012
    Posts:
    1
    Location:
    Sweden
    Eset found that i have 3 virus. It says:

    MBR sector of the 0. physical disk - Win32/Rootkit.Whistler.A trojan .

    But Eset cant get rid of it. I looked throug several other sites that recomended me to take away some files in regedit. But i cant find the files. Anyon who know´where i can get some help?

    I have searched the forums for Whistler.A but cant find anythinbg here on this.
     
  2. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Did Eset quarantine the root kit?
     
  3. SmackyTheFrog

    SmackyTheFrog Registered Member

    Joined:
    Nov 5, 2007
    Posts:
    767
    Location:
    Lansing, Michigan
    If it is a rootkit, you won't be able to clean it up with just a registry key. They inject themselves in to the very start of the OS boot process and use that as an extremely effective means of masking themselves and preventing their removal. There were some instances a few weeks ago of definitions reporting false positives of root kits and if you're lucky it could be that. Either way, I could contact Eset support directly so they can look over a sysinspector log and assist you with the cleanup process. Just be aware that a rootkit places the integrity of the entire system in question, and often times it is better to restore from a backup if available to get back to a known good configuration. If that isn't an option, then you should consider backing up your user data and reformatting.
     
Thread Status:
Not open for further replies.