Swatkat's rants

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 28 August 2006

Removing Mailbot.AZ (aka Rustok.A) Rootkit

Posted on 10:22 by Unknown
Mailbot.AZ (also known as PE386 or Rustock.A) is a kernel mode rootkit backdoor virus. It contains only one file-its driver-and it is stored as a hidden Alternate Data Stream (ADS) of System32 folder in NTFS systems. ADS itself isn't scanned by most of the security software and moreover the Mailbot.AZ driver ADS is hidden using kernel mode rootkit techniques. This makes the detection more difficult. More information about the Mailbot.AZ can be obtained at F-Secure Rootkit Information Pages or Symantec Security Weblog.


The new AVG Anti-Rootkit Beta detects and removes the Mailbot.AZ rootkit. Lets see how we can do it. Download and install the AVG Anti-Rootkit Beta.


Run the AVG Anti-Rootkit Beta, and click "Perform in-depth search". Allow AVG to complete the scan. It will display the hidden Mailbot.AZ rootkit driver. This is shown in the below screenshot.



Select the rootkit driver by placing a checkmark against it and click "Remove selected items". Next, agree for the terms and conditions that is displayed by AVG and click "OK" to reboot the PC. An example is shown in the below screenshot.


AVG Anti-Rootkit Beta renames the Mailbot.AZ rootkit driver so that the driver will not be loaded at the next reboot. But, it doesn't remove the actual rootkit ADS and its Registry entries. These can be removed by using ADS Spy (or HijackThis) and RegEdit respectively.


Download ADS Spy, a freeware which can be used to detect and remove ADS in NTFS systems. Run ADS Spy, select the "Full scan (all NTFS drives)" and click "Scan the system for alternate data streams". Once the scan is complete, select the rootkit driver ADS from the scan result, and click "Remove selected streams". An example is shown in the below screenshot.

(Note that the driver is renamed to lzx32.sy_)


Next, go to Start Menu > Run, and type Regedit and press Enter key. Here, navigate to the key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386 (or HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msguard). Right-click on this key (i.e. on pe386 or msguard) and select "Delete". Exit from Registry Editor. This is shown in the below screenshot.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Ax Video Plugin
    Ax Video Plugin is one of the latest fake codec/plugin in the block. The site http://axvideodownload.com/ uses the same old fake "Vide...
  • Javacool EULAlyzer!
    Have you ever read those ultra-long EULA (End User License Agreement) pages while you are installing any software? I think no one will read ...
  • Zlob brings back fake MP3s!
    Last August, I had blogged about Zlob gang using fake MP3 download sites to push their malware (link here ). Afterwards, we started to see m...
  • twitcurl - C++ twitter API library
    twitcurl is an open-source pure C++ library for twitter REST APIs. Currently, it has support for most of the twitter APIs and it will be upd...
  • ThinkPoint rogue antivirus
    ThinkPoint is a new addition to the long list of rogue antivirus programs. ThinkPoint uses fake codec download tricks for its distribution. ...
  • Rootkit detection, removal and prevention!
    Here's a Wiki definition for Rootkit: A Rootkit is a set of software tools frequently used by a third party (usually an intruder) after...
  • Antivirus 360 featured in top PC magazines and antivirus certification labs!
    No, we are not talking about Norton 360 , which is a genuine security software. This is about Antivirus 360 , one of the latest rogue securi...
  • yelpcurl - C++ Yelp API library
    yelpcurl is an open-source, pure C++ wrapper for Yelp's RESTful APIs . The library currently supports all the APIs provided by Yelp. yel...
  • Windows Filtering Platform (WFP) user mode examples
    So far, in Windows 2000/XP/2003 operating systems the packet filtering APIs ( PfXxx APIs) were used to implement TCP/IP packet filtering a...

Categories

  • a.exe
  • Autohotkey
  • C++
  • fake mp3 downloads
  • gop.exe
  • NewMediaCodec
  • OAuth
  • Orkut hating virus
  • Privacy Protector
  • rootkit
  • SysProt AntiRootkit
  • TDSServ rootkit removal
  • twitCurl
  • twitter
  • Udefender
  • Ultimate Cleaner
  • vdo_
  • Zlob
  • Zlob rootkit

Blog Archive

  • ►  2013 (1)
    • ►  June (1)
  • ►  2010 (6)
    • ►  October (2)
    • ►  September (2)
    • ►  July (1)
    • ►  April (1)
  • ►  2009 (12)
    • ►  September (1)
    • ►  May (1)
    • ►  April (1)
    • ►  March (4)
    • ►  January (5)
  • ►  2008 (44)
    • ►  December (6)
    • ►  November (6)
    • ►  October (4)
    • ►  September (15)
    • ►  August (2)
    • ►  June (2)
    • ►  May (1)
    • ►  April (1)
    • ►  March (6)
    • ►  January (1)
  • ►  2007 (38)
    • ►  December (1)
    • ►  November (2)
    • ►  October (9)
    • ►  September (2)
    • ►  August (8)
    • ►  July (11)
    • ►  June (3)
    • ►  March (2)
  • ▼  2006 (6)
    • ►  September (1)
    • ▼  August (2)
      • Removing Mailbot.AZ (aka Rustok.A) Rootkit
      • BitDefender RootkitUncover
    • ►  May (1)
    • ►  February (2)
  • ►  2005 (30)
    • ►  December (2)
    • ►  November (2)
    • ►  October (4)
    • ►  September (5)
    • ►  August (11)
    • ►  July (6)
Powered by Blogger.

About Me

Unknown
View my complete profile