Win32/Rustock Trojan

Discussion in 'ESET Smart Security' started by Gwafu, Apr 20, 2010.

Thread Status:
Not open for further replies.
  1. Gwafu

    Gwafu Registered Member

    Joined:
    Apr 20, 2010
    Posts:
    3
    I got one D:
    Anyone know how to remove it.
    (It infected my operating memory :/)
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,374
    Have you tried running a full system scan in safe mode or better from a rescue cd since Rustock is a rootkit and is normally hidden?
     
  3. Gwafu

    Gwafu Registered Member

    Joined:
    Apr 20, 2010
    Posts:
    3
    It says Unable to Clean
     
  4. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,374
    When running a scan in safe mode? What about using a rescue cd to remove the infection?
     
  5. Gwafu

    Gwafu Registered Member

    Joined:
    Apr 20, 2010
    Posts:
    3
    In normal mode.
    Whats rescue cd? is it free?
     
  6. BFG

    BFG Registered Member

    Joined:
    Oct 27, 2004
    Posts:
    482
    Location:
    San Diego
    Hello,

    A scan in Safe mode as shown in this kb article won't see the threat. It's in memory and memory isn't being scanned.

    You could create the SysRescue disc or use a third party cleaner. This article shows how to create the SysRescue disc.

    BFG
     
  7. STRYDER

    STRYDER Registered Member

    Joined:
    Aug 21, 2008
    Posts:
    99
    is there any information outlining the steps on how to scan the memory using the Sysrescue CD? Thanks.
     
  8. Searching_ _ _

    Searching_ _ _ Registered Member

    Joined:
    Jan 2, 2008
    Posts:
    1,988
    Location:
    iAnywhere
    http://forum.sysinternals.com/rustock-abc-rootkit-remover-free_topic9385.html

    Have you tried the Malicious Software Removal Tool?
    http://blogs.technet.com/mmpc/archive/2008/10/18/uprooting-win32-rustock.aspx

    Start Here
     
Thread Status:
Not open for further replies.