Jump to content

Removing riot games rootkit

Genius little brother downloaded Valorant, which uses a root kit, on the family computer after being told not to multiple times. Although I don’t know much about computers, I know enough not to willingly download a Chinese virus. I would appreciate it if you guys could give me simplified steps on how to 100% remove it. From what I understand it’s pretty persistent and have anti deleting mechanisms. Luckily it’s a new computer, so I’m willing to nuke the computer if necessary. Thank you for your help

 

edit: I know they Riot Games made an official guide on how to delete it, but I’m taking it with a grain of salt. 

Link to comment
Share on other sites

Link to post
Share on other sites

Didn't they make it easier to get rid of after receiving all that criticism? As in just removing their Vanguard anti-cheat from Programs and Features inside Windows.

Desktop: Intel Core i9-9900K | ASUS Strix Z390-F | G.Skill Trident Z Neo 2x16GB 3200MHz CL14 | EVGA GeForce RTX 2070 SUPER XC Ultra | Corsair RM650x | Fractal Design Define R6

Laptop: 2018 Apple MacBook Pro 13"  --  i5-8259U | 8GB LPDDR3 | 512GB NVMe

Peripherals: Leopold FC660C w/ Topre Silent 45g | Logitech MX Master 3 & Razer Basilisk X HyperSpeed | HIFIMAN HE400se & iFi ZEN DAC | Audio-Technica AT2020USB+

Display: Gigabyte G34WQC

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, VTurer said:

Genius little brother downloaded Valorant, which uses a root kit, on the family computer after being told not to multiple times. Although I don’t know much about computers, I know enough not to willingly download a Chinese virus. I would appreciate it if you guys could give me simplified steps on how to 100% remove it. From what I understand it’s pretty persistent and have anti deleting mechanisms. Luckily it’s a new computer, so I’m willing to nuke the computer if necessary. Thank you for your help

 

They have an official uninstall guide on their website. Whether it leaves traces of the malware behind or not is questionable, so best to perform a clean Windows reinstall if you want to be certain it's removed.

https://support-valorant.riotgames.com/hc/en-us/articles/360044648213-Uninstalling-and-Disabling-Riot-Vanguard

Desktop: KiRaShi-Intel-2022 (i5-12600K, RTX2060) Mobile: OnePlus 5T | Koodo - 75GB Data + Data Rollover for $45/month
Laptop: Dell XPS 15 9560 (the real 15" MacBook Pro that Apple didn't make) Tablet: iPad Mini 5 | Lenovo IdeaPad Duet 10.1
Camera: Canon M6 Mark II | Canon Rebel T1i (500D) | Canon SX280 | Panasonic TS20D Music: Spotify Premium (CIRCA '08)

Link to comment
Share on other sites

Link to post
Share on other sites

27 minutes ago, kirashi said:

They have an official uninstall guide on their website. Whether it leaves traces of the malware behind or not is questionable, so best to perform a clean Windows reinstall if you want to be certain it's removed.

https://support-valorant.riotgames.com/hc/en-us/articles/360044648213-Uninstalling-and-Disabling-Riot-Vanguard

Unfortunately that’s what I’ve been thinking as well.

Link to comment
Share on other sites

Link to post
Share on other sites

It's not really "malware" if we're being honest, but I can see why its undesirable and why you'd want to get rid of it.

 

The "rootkit" component is a kernel driver called vgk.sys located at C:\Program Files\Riot Vanguard\vgk.sys which persists via a Windows service which loads the vanguard application (in turn loading the kernel driver). My suggestion would be:

 

1) Follow the official uninstall guide
2) Restart your system

3) Check for the presence of that kernel driver in the folder path above (I'd also check C:\Windows\system32\drivers just in case)

 

If it's no longer there I would be fairly safe to say you've removed all traces of the application that are likely to have any impact, though without actually installing the thing in a VM, checking what it writes where, and what is removed when the uninstall is run, I can't confirm if anything else is left.

[ P R O J E C T _ M E L L I F E R A ]

[ 5900X @4.7GHz PBO2 | X570S Aorus Pro | 32GB GSkill Trident Z 3600MHz CL16 | EK-Quantum Reflection ]
[ ASUS RTX4080 TUF OC @3000MHz | O11D-XL | HardwareLabs GTS and GTX 360mm | XSPC D5 SATA ]

[ TechN / Phanteks G40 Blocks | Corsair AX750 | ROG Swift PG279Q | Q-Acoustics 2010i | Sabaj A4 ]

 

P R O J E C T | S A N D W A S P

6900K | RTX2080 | 32GB DDR4-3000 | Custom Loop 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×