Jump to content

Malwarebytes

Rootkit that disables windows update


3 replies to this topic

#1
Timay

    New Member

  • Members
  • Pip
  • 2 posts
Hey i am new to the forums and came across this rootkit that mbam did not detect. scanned with 1927 definitions

Quote

File 3ff122ce.sys received on 04.01.2009 02:08:11 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 15/40 (37.5%)
Virus Total

The file seems to disable both BITS and Automatic updates by replacing %systemroot% with %fystemroot%

Filename also seems to be random.

hxxp://rapidshare.com/files/215959670/rootkit.zip.html
password: malwarebytes

includes the rootkit and one of its registry keys

First time doing stuff like this let me know if i am missing anything or doing it wrong.

#2
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,161 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
Thank you for the files! Please upload both rootkits here:
http://uploads.malwarebytes.org/

Now detected by ESET NOD32 Antivirus.
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#3
Timay

    New Member

  • Members
  • Pip
  • 2 posts
Uploaded them both.

#4
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,161 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
Thank you! I guess that as soon as possible, they will be added to the definitions of MalwareBytes' Anti-Malware.
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us