Solved! Kernal Rootkit Removal/Identification?

kangodafi_1

Prominent
Aug 3, 2017
2
0
510
I have a root kit installed on my computer, I haven’t got a clue how to find it or remove it. My fear is that it is a kernel root kit and I’m pretty done for atm. If anyone can offer help then thanks.


I managed to find a very suspicious file if anyone knows what it is. It’s called 4127879B, it runs as a .sys file.
Here’s a picture: https://imgur.com/a/himM4OE
 
By "Didn't work" you mean the file was not deleted or removed?

May be a false positive.

Look in Startup. Do you see anything being launched that you do not or cannot recognize?

Consider TDSSKiller (Kaspersky Lab):

https://www.bleepingcomputer.com/download/tdsskiller/


 

shknawe

Commendable
Oct 22, 2016
84
0
1,610
Read this-----https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=2ahUKEwi34fqpqePfAhUNZd8KHfp8Bf0QFjABegQIBxAE&url=https%3A%2F%2Fwww.file.net%2Fprocess%2Fmbamchameleon.sys.html&usg=AOvVaw1j832xyddGdy2ZT12tGZBH
 

rgd1101

Don't
Moderator


What software is that that find the file?