How to know if the rootkit is really gone from my system?

I recetly got the (what I think was) the TDL3 rootkit/virus (a few random popups, CONSTANT redirecting from google links and computer lag) and avg never even noticed that the computer was infected. My dad usedthe CD that came with the computer to reload windows (he did not wipethe hard drive) he dis some sort of recovery. Our computer is showing. Dramtic difference. No popups whatsoever, great speed, not a single page redirection. I’m still very suspicious that a rootkit, that only two known antivirus programs can detect, can so easily be gotten rid of with just that one CD.

So main question: without downloading any sort of anything, how can I tell that the rootkit is REALLY gone?

Answer #1

my AVG has a rootkit scanner… I use the paid for AVG antivirus + firewall… it also come with anti-spyware and other stuff I dont install.. but I’ve never been infected while AVG is installed and using firefox…

firefox alone would have stopped you going to an infected site with the option ‘get me the hell out of here!’

I cant comment on what other browsers will do as I dont use them..

if youve just done a full format and I mean a full format, not a quick format it will be gone.. a quick format doesnt 100% format the drive… so as you said, he didnt format the whole drive yes its possible its still there just waiting to be rewoke..

if your comfatable editing your own registry… start - run - type ‘regedit’ (as jeremy said) but without the qoutes and have a look in the HCU and HLM for anything that doesnt look right…

after I’ve installed something and I have the option to add a yahoo toolbar, I untic to allow install but the bugger always ends up in my registry so I always go in and delete it manualy…

windows will give you the option ‘are you sure you want to permanently delete this key?’ just make sure its not a windows file otherwise youll have to format again..

Answer #2

Regedit…look there for anything non standard or suspicious.

Also:

  1. upgrade windows (they do new security fixes every week or so)
  2. Never ever surf with IE only FF or Safari or Chrome
  3. Update AVG / spybot and make sure they are current, and run them every week at least.
More Like This
Ask an advisor one-on-one!
Advisor

ATI Systems

Mass Communication Systems, Emergency Notification Systems, Public Safety Solutions

Advisor

CSM South Business Phone Syst...

Telecommunications Services, Structured Cabling Services

Advisor

Eject System

Industrial Equipment Supplier, Vacuum Pump Manufacturer, Engineering Services

Advisor

Vivint Smart Home Security Sy...

Home Automation, Security Systems, Smart Home Technology

Advisor

Network Digital Office Systems

Office Equipment, Business Solutions, Printing Services