TechSpot

Contracted Remon.sys (hacktool.rootkit) from AIM, Help please

By arccabri
Dec 26, 2005
Topic Status:
Not open for further replies.
  1. I recently received a virus from a link sent by a buddy. Immediately after clicking on it, norton popped up saying I have a hacktool.rootkit virus, remon.sys. I've looked through the stickies on this page, ive tried the removing hacktool.rootkit method posted but none of the specific files mentioned by that thread was found. When i run Housecall scan online, i get no problems and now, it seems that i am unwillingly passing on the link to others through aim aswell. Hopefully someone can help me. Attached is my HJT log. Thanks

    Attached Files:

  2. Spike

    Spike TS Rookie Posts: 2,371

  3. arccabri

    arccabri TS Rookie Topic Starter

    Thanks for the quick response spike, I looked at that tread and non of the suspect processes or files show up when I run in safe mode. If there is any additional information needed, I will be happy to oblige.
  4. RealBlackStuff

    RealBlackStuff TS Rookie Posts: 8,165

    See the Read: How to.. rootkit post in this forum.
  5. arccabri

    arccabri TS Rookie Topic Starter

    Ive followed the directions on the How to...Rootkit post in the forums and it doesnt seem to apply to my specific circumstance as none of the files, javapanel/taskcenter/xpjava, or processes show up. Any additional support will be appreciated. Thanks
  6. RealBlackStuff

    RealBlackStuff TS Rookie Posts: 8,165

    Did you even bother to get your PC scanned by TM?
  7. arccabri

    arccabri TS Rookie Topic Starter

    yeah, the first time i got it checked by TM, there were some questionable files but none relating to this rootkit virus, i then used the fix utility on the scans and then followed the rootkit removal process. While the rootkit is still there, my next TM housecall scan came up clean.
  8. RealBlackStuff

    RealBlackStuff TS Rookie Posts: 8,165

  9. Niksolo

    Niksolo TS Rookie

    So basically that thread will take care of a good majority of nasties? My fiancee's laptop got the remon.sys (hacktool.rootkit) as well. So I will try that and see if it works, for I had the same problem as arccabri on her laptop.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.