ChkRootKit Worm Removal Guide – Immediately Clean Up ChkRootKit Worm

Posted by Tinain Blog Worm on October 31st, 2011 | 5 Comments

ChkRootKit Worm is malicious program designed by hacker who want to get remote access to your computer. When executed, it copies itself in system folder and writes its information to the registry. It is able to propagate itself without user knowledge about its presence. Are you a victim of ChkRootKit Worm and don’t know how to address the annoying problem yourself? It is obligatory to learn some skills of removing this worm effectively. This article may be taken as a guide.

If you are infected with a ChkRootKit Worm, you may encounter the following problems:
Receive additional email messages containing copies of the worm.
Firewall is not running or is missing altogether.
Your desktop background changes or is disabled every time your computer starts.
System stops working or locks up.
Suffers from constant error messages fails to perform.
Unknown software is installed on your computer without your knowledge or permission.
If you believe that your computer is infected, you should take immediate steps to remove the offending worm.

General Method to Remove ChkRootKit Worm

1. Start Windows in Safe Mode. While in Safe Mode, only specific programs and files needed to run the operating system are loaded. This allows us to remove some spyware, adware, viruses and such that cannot be removed in Normal Mode. Follow the instructions below to Start Safe Mode:
Reboot your computer;
Start tapping the F8 key;
When the Windows Advanced Options Menu appears, select the Safe mode option;
Press Enter to start in Safe mode.

2. Use search tool to find all the files which are created or infected by this worm:
worm.ChkRootKit.exe
ChkRootKit.exe
syshosts.exe
wmso.exe
worm.CRsetup.e.exe

3. ChkRootKit Worm adds itself to the system registry to ensure it will be activated when the system is rebooted. Click Start > Run>Type regedit>Click OK. Enter registry editor, find and delete the keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ ChkRootKit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\amir_civil
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\directx
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA1910DE-AA86-4ED0-874B-2924E38BAD99}

If you have enough time and expertise, you can search your computer for ChkRootKit Worm manually. However, it might take hours to find out all associated files of Worms, and it is possible that the threat will appear after rebooting, for its hidden files and registry entries may still be there. That’s why it is required to remove worm with a worm removal tool.

The advanced method to kill this worm once and for all is using a qualified anti-spyware program. PC Safe Doctor is proved to be able to remove ChkRootKit within minutes. Your 100% guaranteed solution to clean up worm infection is download and install PC Safe Doctor on your computer. Do not hesitate now. Take good care of your computer with the professional anti-spyware tool.

5 Responses to ChkRootKit Worm Removal Guide – Immediately Clean Up ChkRootKit Worm

  1. Hanks Somecotton -  November 1, 2011 at 5:21 pm

    I will never download the Spyware Doctor if I know that is not a real anti-spyware program. Thanks for your advice.

    ...

  2. Christopher Granger -  November 2, 2011 at 1:59 am

    I’ve read this. Thanks for your useful and workable suggestions.

    ...

  3. Arnold Ivey -  November 2, 2011 at 5:25 pm

    I simply could not depart your web site prior to suggesting that I extremely enjoyed the usual info an individual provide on your guests? Is going to be back regularly to check out new posts

    ...

  4. Robert Steinhall -  November 3, 2011 at 1:47 am

    Hi, Neat post. There is an issue with my PC with WIN 7 operating system, may check this?

    ...

  5. Rob Thomas -  November 4, 2011 at 1:36 am

    Google led me to this blog post, and it is everything that I was looking for.

    ...

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>