Win32/Rustock Trojan

Discussion in 'ESET Smart Security' started by Gwafu, Apr 20, 2010.

Thread Status:
Not open for further replies.
  1. Gwafu

    Gwafu Registered Member

    Joined:
    Apr 20, 2010
    Posts:
    3
    I got one D:
    Anyone know how to remove it.
    (It infected my operating memory :/)
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,415
    Have you tried running a full system scan in safe mode or better from a rescue cd since Rustock is a rootkit and is normally hidden?
     
  3. Gwafu

    Gwafu Registered Member

    Joined:
    Apr 20, 2010
    Posts:
    3
    It says Unable to Clean
     
  4. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,415
    When running a scan in safe mode? What about using a rescue cd to remove the infection?
     
  5. Gwafu

    Gwafu Registered Member

    Joined:
    Apr 20, 2010
    Posts:
    3
    In normal mode.
    Whats rescue cd? is it free?
     
  6. BFG

    BFG Registered Member

    Joined:
    Oct 27, 2004
    Posts:
    482
    Location:
    San Diego
    Hello,

    A scan in Safe mode as shown in this kb article won't see the threat. It's in memory and memory isn't being scanned.

    You could create the SysRescue disc or use a third party cleaner. This article shows how to create the SysRescue disc.

    BFG
     
  7. STRYDER

    STRYDER Registered Member

    Joined:
    Aug 21, 2008
    Posts:
    99
    is there any information outlining the steps on how to scan the memory using the Sysrescue CD? Thanks.
     
  8. Searching_ _ _

    Searching_ _ _ Registered Member

    Joined:
    Jan 2, 2008
    Posts:
    1,988
    Location:
    iAnywhere
    http://forum.sysinternals.com/rustock-abc-rootkit-remover-free_topic9385.html

    Have you tried the Malicious Software Removal Tool?
    http://blogs.technet.com/mmpc/archive/2008/10/18/uprooting-win32-rustock.aspx

    Start Here
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.