win32/rustock trojan thread

Discussion in 'ESET Smart Security' started by btedi10, Mar 30, 2010.

Thread Status:
Not open for further replies.
  1. btedi10

    btedi10 Registered Member

    Joined:
    Mar 30, 2010
    Posts:
    3
    Hello.
    ESET SMART SECURITY ALERT CAN NOT CLEAN THE WIN32/RUSTOCK TROJAN FROM THE OPERATING MEMORY.
    HOW CAN I REMOVE IT FROM MY COMPUTER.
    THANK'S.
    Tedi.
     
  2. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
  3. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,833
    Unbelievable, unless this a brand new variant ? the Rustock series should be no problem now for any AV etc.

    If it's only in the OPERATING MEMORY that's the problem, as you don't mention anything else, then rebooting should clear it. Try it and see if ESET now gets a first chance of catching it whilst booting. If not MBAM is a good suggestion to try http://www.malwarebytes.org/mbam.php

    Do you know how/where you got infected ?
     
  4. CogitoTesting

    CogitoTesting Registered Member

    Joined:
    Jul 4, 2009
    Posts:
    901
    Location:
    Sea of Tranquility, Luna
    Run Dr Web CureIt in safe mode.

    Thanks.
     
  5. siljaline

    siljaline Former Poster

    Joined:
    Jun 29, 2003
    Posts:
    6,619
  6. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,011
    Location:
    Ontario, Canada
    It's probably a new variant and I doubt the Malicious Software Removal Tool will remove it!

    The best thing would be to send the ESET SysInspector log to samples@eset.com! Or read the post a seek some professional help as Cudni suggested!
    HTH,

    TH
     
    Last edited: Mar 30, 2010
  7. btedi10

    btedi10 Registered Member

    Joined:
    Mar 30, 2010
    Posts:
    3
    Thank you for a quick reply.
    The message appeared last night.I don't know how/where i got it
    I run spyware doctor who found other threads but not this one
    Also some other antivirus programs did not found this thread
    Rebooting not helping.
    Eset alert appeares again only in operating memory.
    may be it's a fake alert?
     
  8. ESS3

    ESS3 Registered Member

    Joined:
    Dec 11, 2007
    Posts:
    112
    ESET SysRescue DVD/CD/ISO/USB scan PC delete rustock ;) :)
     
  9. Nick0

    Nick0 Registered Member

    Joined:
    Feb 18, 2010
    Posts:
    32
    Just seen this same infection on another machine.

    Startup scanner detects Win32/Rustock in operating memory on each boot.

    MalwareBytes does not remove infection.
     
  10. btedi10

    btedi10 Registered Member

    Joined:
    Mar 30, 2010
    Posts:
    3
    I managed to remove the trojan with Eset Sys-Rescue cd .
    Thank's you all for helping me with your advices.
    Special thank's to ESS3
     
  11. Nick0

    Nick0 Registered Member

    Joined:
    Feb 18, 2010
    Posts:
    32
    GMER was capable of removing this threat.
    Simply desabling then deleting the service that was picked up was enough to remove.
     
Thread Status:
Not open for further replies.