Log in

View Full Version : This is regarding the windows\system32\drivers\cwsbda.sys


hainesjean
Nov 29, 2010, 05:57 AM
I keep getting this message every time I turn my computer on "A Rootkit was found, then it show the following: c:\windows\system32\cwsbda.sys although the words are so close I can't decide if it's cwstxla.sys. It also states the following: Type: Hidden Services
Malware Name: Win32:Qandr(Rtk). I have gone into my C drive trying to locate this file and can't seem to. I have the Avast AntiVirus system and it can't seem to delete this file. Can you please give me any suggestions? Thank you

Drakcol
Dec 29, 2010, 11:33 PM
For rootkits the easiest way to remove them would be to try Combofix (found here http://majorgeeks.com/Combofix_d6402.html) or Hijackthis (found here http://free.antivirus.com/hijackthis/) Both are free and they specialize in removing rootkits.