Skip to main content
I have a rootkit virus on my HP, running Windows light7. I bought WR Secure Anywhere to get rid of this, but it did not work bcs it is def still in the system. Any suggestions? I tried to chat with support and could not seem to get a person with a pulse. I have had this "protection" for 166 days now. What good is it if the rootkit isn't gone like the software claims it will clean it up? And lastly, can I get my money back ?
Hello hiskingdominme,

 

Welcome to the Community Forum,

 

Would you try to put your computer in safe mode with Networking and do a scan with Webroot again? Usually you hit F8.

EDITED:

http://www5.nohold.net/Webroot/Loginr.aspx?pid=10&login=1&domain=887&usertext=safe%20mode%20with%20networking or go here

http://windows.microsoft.com/en-us/windows/start-computer-safe-mode#start-computer-safe-mode=windows-7

 

If this doesn't help then please issue a Support Ticket free of charge. And they will glady check this out for you!

 

 

Best Regards,
Hi hiskingdominme

 

Welcome to the Community Forums.

 

Would you be able to tell us how you know you have a rootkit, and if you know what the designation of it is...that would helps. Would also be useful to know what Support advised/recommended.

 

That would be a start to trying to get you some help re. this issue.

 

Regards, Baldrick

 
Hi, I put my computer in safe mode with networking, ran a scan and Webroot found no threats. I know I have a rootkit because my computer crashed recently and the person who reinstalled my os and drivers said I had one. I don't know exactly where it is attached, but this is how it works. ..... When I shutdown my computer I will get a message saying don't power down until windows finishes installing updates. Evidently this is how the rootkit reinstalls or refreshes itself. This particular rootkit takes bits of other programs and adds it to itself, so this makes it harder to find and remove the virus, and seems to change the name and or path of the virus too. At least that is what my more computer savvy friend told me after working on my netbook for @ 6 hours.

I know the virus is still there because I get the message about windows installing updates even when I have been working offline. Windows can't check for and download/install updates when offline, at least that is what I thought. Thanks for all of your help with this problem. I bought Webroot because I was told it was better than Kaspersky and Webroot is supposed to take care of rootkits.
Can you please Submit a Support Ticket and they will let you know if you have a Rootkit! There's not much we can do on the Community so it's best to contact support. And yes Webroot SecureAnywhere is very good and all the work is done in the Cloud and not on your system: http://www.brightcloud.com/platform/webroot-intelligence-network.php

 

Thanks,

 

Daniel ;)

 



 

 
Hi hiskingdominme

 

Thanks for coming back and updating us...I have to say though that with such specific behaviour as you have described I am surprised that your tech savvy friend is unable to find out/given this 'rootkit' a name (BTW...I am not suggesting that your friend does not know what he/she is doing...I do not know them, of course).  As for a PC saying that it wants to install Windows updates I have to say that I have had both occurrences of what you describe and I am absolutely certain that my systems are not infected by a rootkit.

 

Now whilst most security apps are good at preventing infection not many are as good at cleaning an already infected PC. So what I would do is to Open the Support Ticket previously suggested, and in that provide the Support Team withthe link to this thread so that they can pick upi your description of what you have epxerienced, and hopefully the professional Threat Researchers on the Team can identify and deal with the rootkit for you.

 

That would be my recommendation.

 

Please do keep us posted on how you get on either way.

 

Regards, Baldrick

Reply