Rootkit.Boot.SST

If a system is infected with root kit, it becomes really difficult to run it. But MAXSS root kit cannot be detected in Combo fix at the moment. The rootkit can be found thanks to fake recovery. The first step to solve it is to extract and launch GMER and tdsskiller. Once it is cleaned from fake recovery rogue, the security will be connected and the user can download it. There will be a security setup during which a scan will be performed and come back clear. Overall the removal of root kit can be really difficult.

Rootkit.boot.SST.B (and SST.A) is the MaxSS modifcation of TDL4.

It is difficult to run tdsskiller and gmer on systems infected with this rootkit.Currently COMBOFIX doesnot detect this MAXSS rootkit.

This rootkit can be found on the system infected with fake recovery rogue.


TDSSkiller will not launch.GMER shows the following error:


Here is a way to run tdsskiller and GMER :

http://ad13.geekstogo.com/RootRepeal.zip

Extract and launch it.




Launch TDSSkiller now.




Run tdsskiller once to make sure it is clean.


Download:

http://public.avast.com/~gmerek/aswMBR.htm

Make sure the scan comes out clean.

NOTE:

This rootkit is a difficult one to remove and the FIXMBR and FIXBOOT commands are not going to help you in this case. You may therefore need a LIVE boot CD to remove this infection if all malware removal method fails.

Published by sundar7701 - Last update on March 2, 2012 08:57 PM by Virginia Parsons
This document entitled « Rootkit.Boot.SST » from Kioskea.net (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.
Suggestions
  •  Rootkit.Boot.SST
  •  Sinowal/Mebroot/MBR Rootkit infection » Tips : The MBR Rootkit is one of the most advanced and malicious type of rootkit infection that can create an insurmountable threat to the security of the computer. This malware is very dangerous as it replaces the MBR or the Master Boot Record of the...
  •  No bootable device insert boot disk » Hello, After a nasty virus attack by "Win 7 Internet Security" I tried to reset my laptop to the factory settings. I cancelled midway and found myself looking at this: "Intel UNDI, PXE-2.0 (build 083) Copyright (C) 1997-2000 Intel Corporation For...
  •  Windows XP Reboot Loop: Help! (Solved) » Best answer: it has to do with your registry after installing sp3,i had it and fixed it myself,below is what i did after going on in safe mode. HOW TO STOP ENDLESS LOOP REBOOT FROM SP3 1.) First, boot into Safe Mode. After a reboot or two, you'll pro
  •  Laptop wont boot (Solved) » Best answer: soon as your pc boots start pressing f-12 then reboot from last known good configuration
  •  Vista boot disk » Download : Ultimate Boot CD ( UBCD) is a CD bootable containing an outfit of tools which can show itself of a big utility when the system refuses to start: -Diagnosis hard disk (Maxtor, Seagate, Samsung, Digital Western and IBM). -Cloning of disk (g4u,...
All file associations corrupted
[Antivir Avira]Disable WMI support