Swatkat's rants

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 28 August 2006

Removing Mailbot.AZ (aka Rustok.A) Rootkit

Posted on 10:22 by Unknown
Mailbot.AZ (also known as PE386 or Rustock.A) is a kernel mode rootkit backdoor virus. It contains only one file-its driver-and it is stored as a hidden Alternate Data Stream (ADS) of System32 folder in NTFS systems. ADS itself isn't scanned by most of the security software and moreover the Mailbot.AZ driver ADS is hidden using kernel mode rootkit techniques. This makes the detection more difficult. More information about the Mailbot.AZ can be obtained at F-Secure Rootkit Information Pages or Symantec Security Weblog.


The new AVG Anti-Rootkit Beta detects and removes the Mailbot.AZ rootkit. Lets see how we can do it. Download and install the AVG Anti-Rootkit Beta.


Run the AVG Anti-Rootkit Beta, and click "Perform in-depth search". Allow AVG to complete the scan. It will display the hidden Mailbot.AZ rootkit driver. This is shown in the below screenshot.



Select the rootkit driver by placing a checkmark against it and click "Remove selected items". Next, agree for the terms and conditions that is displayed by AVG and click "OK" to reboot the PC. An example is shown in the below screenshot.


AVG Anti-Rootkit Beta renames the Mailbot.AZ rootkit driver so that the driver will not be loaded at the next reboot. But, it doesn't remove the actual rootkit ADS and its Registry entries. These can be removed by using ADS Spy (or HijackThis) and RegEdit respectively.


Download ADS Spy, a freeware which can be used to detect and remove ADS in NTFS systems. Run ADS Spy, select the "Full scan (all NTFS drives)" and click "Scan the system for alternate data streams". Once the scan is complete, select the rootkit driver ADS from the scan result, and click "Remove selected streams". An example is shown in the below screenshot.

(Note that the driver is renamed to lzx32.sy_)


Next, go to Start Menu > Run, and type Regedit and press Enter key. Here, navigate to the key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386 (or HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msguard). Right-click on this key (i.e. on pe386 or msguard) and select "Delete". Exit from Registry Editor. This is shown in the below screenshot.
Read More
Posted in | No comments

Tuesday, 8 August 2006

BitDefender RootkitUncover

Posted on 07:49 by Unknown
Softwin has released a rootkit removal tool, called BitDefender RootkitUncover. Its still in beta stage, but it looks very promising. RootkitUncover is very easy to use, and interface is similar to that of F-Secure’s BlackLight. Its very heartening to see that more and more Antivirus firms are considering rootkit threats seriously. Download it here or here.
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Ax Video Plugin
    Ax Video Plugin is one of the latest fake codec/plugin in the block. The site http://axvideodownload.com/ uses the same old fake "Vide...
  • Spyware Guard 2008
    Spyware Guard 2008 is a new rogue application. Does that name sound familiar? Well, yes, there is a legitimate application named SpywareGuar...
  • Javacool EULAlyzer!
    Have you ever read those ultra-long EULA (End User License Agreement) pages while you are installing any software? I think no one will read ...
  • Zlob brings back fake MP3s!
    Last August, I had blogged about Zlob gang using fake MP3 download sites to push their malware (link here ). Afterwards, we started to see m...
  • Myphonegames.co.uk hacked?!
    It seems that some pages of a mobile-phone games website www.myphonegames.co.uk have been hacked to execute malicious looking Javascript. A...
  • twitcurl - C++ twitter API library
    twitcurl is an open-source pure C++ library for twitter REST APIs. Currently, it has support for most of the twitter APIs and it will be upd...
  • DomPlayer - Rogue Multimedia Player
    DomPlayer is a new rogue multimedia player on the loose. The gang behind DomPlayer is making use of fake video files (available as torrents)...
  • Some new malware - a.exe, gop.exe etc
    We have some "new" malware this time, ranging from trojans to rootkits. One of them is a trojan which detected by some of the AVs ...
  • ThinkPoint rogue antivirus
    ThinkPoint is a new addition to the long list of rogue antivirus programs. ThinkPoint uses fake codec download tricks for its distribution. ...
  • Removing Mailbot.AZ (aka Rustok.A) Rootkit
    Mailbot.AZ (also known as PE386 or Rustock.A) is a kernel mode rootkit backdoor virus. It contains only one file-its driver-and it is stored...

Categories

  • a.exe
  • Autohotkey
  • C++
  • fake mp3 downloads
  • gop.exe
  • NewMediaCodec
  • OAuth
  • Orkut hating virus
  • Privacy Protector
  • rootkit
  • SysProt AntiRootkit
  • TDSServ rootkit removal
  • twitCurl
  • twitter
  • Udefender
  • Ultimate Cleaner
  • vdo_
  • Zlob
  • Zlob rootkit

Blog Archive

  • ►  2013 (1)
    • ►  June (1)
  • ►  2010 (6)
    • ►  October (2)
    • ►  September (2)
    • ►  July (1)
    • ►  April (1)
  • ►  2009 (12)
    • ►  September (1)
    • ►  May (1)
    • ►  April (1)
    • ►  March (4)
    • ►  January (5)
  • ►  2008 (44)
    • ►  December (6)
    • ►  November (6)
    • ►  October (4)
    • ►  September (15)
    • ►  August (2)
    • ►  June (2)
    • ►  May (1)
    • ►  April (1)
    • ►  March (6)
    • ►  January (1)
  • ►  2007 (38)
    • ►  December (1)
    • ►  November (2)
    • ►  October (9)
    • ►  September (2)
    • ►  August (8)
    • ►  July (11)
    • ►  June (3)
    • ►  March (2)
  • ▼  2006 (6)
    • ►  September (1)
    • ▼  August (2)
      • Removing Mailbot.AZ (aka Rustok.A) Rootkit
      • BitDefender RootkitUncover
    • ►  May (1)
    • ►  February (2)
  • ►  2005 (30)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (5)
    • ►  August (11)
    • ►  July (6)
Powered by Blogger.

About Me

Unknown
View my complete profile