Author Topic: Win32.Ntldrbot Rustock.C, does avast! detect; is the team aware of it ...?  (Read 4817 times)

0 Members and 1 Guest are viewing this topic.

Happy-Dude

  • Guest
Well, I started reading about the Win32.Ntldrbot Rustock.C rootkit thinggy, and now I'm a bit frightened.

More info:
http://www.virustotal.com/analisis/f3c4811ee9c7129dbabec54356805a62
http://info.drweb.com/show/3342/en
http://forum.sysinternals.com/forum_posts.asp?TID=14844
http://www.wilderssecurity.com/showthread.php?t=208386

I still don't truly comprehend this piece of malware. Very evasive (high end of polymorphism) and almost impossible to detect and remove once it gets into the system.

A few things:
-How do I prevent infection?
-What does it do? Turns your PC into a bot (part of the botnet), but what info gets sent off?
-How do you tell if you're infected?
-What is the avast! team doing about it ?
-What are other security companies doing about it ?

Can someone help me understand this piece of malware better? Anyone able to answer some of my questions?

Thanks very much guys. I really appreciate it :) !!

EDIT-
06-06-08 Added a link to Dr.Web page, which was the first AV to detect the malware.
« Last Edit: June 07, 2008, 01:48:15 AM by Happy-Dude »

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
« Last Edit: June 08, 2008, 09:44:04 PM by Dwarden »
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

street_lethal

  • Guest
So does Avast pick this thing up?

PaulAuckNZ

  • Guest
Get http://www.simplysup.com/ Trojan remover

That should find it


Offline Maxx_original

  • Avast team
  • Super Poster
  • *
  • Posts: 1479
So does Avast pick this thing up?

yes... the detection was added when the information about Rustock.c was confirmed by Dr. Web..

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
BTW the droper has been around (and detected) for at least half a year now...
If at first you don't succeed, then skydiving's not for you.

street_lethal

  • Guest
Thanks for the response.


I know Dr.Web Cureit! also detects it and that's free just in case people want a second opinion.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
BTW the droper has been around (and detected) for at least half a year now...
Thanks... I was becoming worried...
The best things in life are free.

Offline calcu007

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 482
  • I'm lamma!
Now the question is:Does it detect all variants?
Asus Intel i7 8GB RAM , Win 8.1 64 bit, Avast IS

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Now the question is:Does it detect all variants?
Yes, that's the question...
The best things in life are free.