Thursday, December 17, 2009

Virus installed as legacy driver

The free version of Malwarebytes found the file hjyqojs.sys as a rootkit:agent, but can't remove it because it is installed as a legacy driver. To resolve this, go to Device Manage, click View - Show hidden devices. Under legacy drivers, you will find the device with the same name. Disable it, restart, delete the file and then uninstall the device. I think the name of the infected file can differ.

I found another rootkit, just like the one described earlier, but it uses the file ptdyc.sys