Security
•  Greatis •  AppDatabase •  Utilities •  Delphi/CB •  Visual Basic • .NET •  just4fun
RegRun Security Suite
Not an antivirus. Detects and removes rootkits/malware/adware that your antivirus could not.
One-click purchase
RegRun NIVA Platinum - Rootkit Killer

NIVA+CD-ROM

More info:
Know more?
Screenshots

FAQ

On-line manual

Print PDF

Download trial
RegRun NIVA Platinum
Forums
Greatis Forum

NI Forum

Mickey Forum

Thank you!

International
Download Russian

Download Ukrainian

Join our localization team

Home Download Order Support   Newsletter Your shopping cart ?
Virus Removal Story: Rootkit Rustock(a,b,c) - lzx32.sys


Rustock is a hidden rootkit with kernel driver "lzx32.sys".

I tested the sample rootkit file and I found that it's hardly hidden than other known rootkits. The lzx32.sys driver is loaded by the system at the early part of Windows boot. It's masked as the boot device. This why it's hard in removal.

UnHackMe 4 (with Partizan) detects the rootkit keys but it could not remove Rustock.

UnHackme Pro 4 correctly detected Rustock's registry key: PE386.

The driver is located in the NTFS stream in the %Windir%\System32:lzx32.sys.

It could not be deleted during Windows normal mode.

No panic!


I found the simple way how to stop Rustock :-).

Removal

Download RegRun Reanimator (3Mb)

Unzip it to any folder. Installation is not required.

  1. Open reanimator.exe.
  2. Click on the "Remove Rustock Rootkit".
  3. You will be prompted for using "RootkitNO" utility.
  4. Run it!
  5. You will be prompted to restart your computer.
  6. After restarting the Rustock file will be removed using Partizan.

After finishing removal process you may remove Partizan from your Windows boot.

Click on the "UnInstall Partizan" button.

Also you can delete "RootkitNo" folder from your drive where installed the Windows.


Conclusion

Suggest you to use RegRun Platinum Edition to be sure that your rootkit's clear!

Good luck!

Dmitry Sokolov


Would you like to add your opinion?

Your Name (Not Required):

Your E-mail to contact (Not Required):


Description:

What's new?

February 9 2010
Updated RegRun Reanimator 6.7.6.76 - freeware software for detecting and removing rootkits/malware.


February 1 2010
Updated RegRun Reanimator 6.7.6.75 - freeware software for detecting and removing rootkits/malware.


January 11 2010
Updated RegRun Reanimator 6.7.6.68 - freeware software for detecting and removing rootkits/malware.


December 23 2009
New! RegRun Warrior!
Removing rootkits is best done from the outside!

Released RegRun Security Suite 6.7 (6.7.6.67)


December 22 2009
Updated RegRun Reanimator 6.7.6.67 - freeware software for detecting and removing rootkits/malware.

December 9 2009
RegRun Platinum Ukrainian 6.5


December 01 2009
New! Malware Removal Blog.

Updated RegRun Reanimator 6.5.6.66 - freeware software for detecting and removing rootkits/malware.
Also released Russian Reanimator

Updated information for localization.


November 20 2009

Released RegRun Suite Platinum 6.5 (6.5.6.65)


November 17 2009
Updated RegRun Reanimator 6.5.6.65 - freeware software for detecting and removing rootkits/malware.

November 9 2009
Updated RegRun Reanimator 6.5.6.64 - freeware software for detecting and removing rootkits/malware.

October 28 2009
Updated RegRun Reanimator 6.5.6.62 - freeware software for detecting and removing rootkits/malware.

Updated RegRun Suite Platinum 6.5 beta (6.5.6.62)

Resolving problem with Google redirect MAX++/TDSS rootkit (win32k.sys:1, win3k.sys:2).


October 23 2009
Updated RegRun Reanimator 6.5.6.61 - freeware software for detecting and removing rootkits/malware.

Updated RegRun Suite Platinum 6.5 beta (6.5.6.61)

Video Lesson how to remove WinLocker Trojan


October 16 2009
Updated RegRun Reanimator 6.5.6.60 - freeware software for detecting and removing rootkits/malware.

October 13 2009
Updated RegRun Reanimator 6.5.6.57 - freeware software for detecting and removing rootkits/malware.

October 6 2009
Try RegRun Suite Platinum 6.5 beta

Updated RegRun Reanimator 6.5.6.55 - freeware software for detecting and removing rootkits/malware.

Malware Removal Lesson

September 25 2009
Updated RegRun Reanimator 6.5.6.54 - freeware software for detecting and removing rootkits/malware.

September 18 2009
Updated RegRun Reanimator 6.5.6.53 - freeware software for detecting and removing rootkits/malware.

September 8 2008
Windows Explorer Redirection DLLS is a new dangerous Windows startup hole...

September 4 2008
Updated RegRun Reanimator - freeware software for detecting and removing rootkits/malware.

June 5 2008
RegRun has been reviewed by 3d2f.com Software Directory: RegRun Security Suite is an excellent tool that will reliably protect you from a plethora of existing and emerging threats and will keep malware at bay.

March 7 2008
Partizan.exe is not a worm. Partizan.exe is a part of RegRun Suite, UnHackMe antirootkit. Updated. Symantec fixed false positive.

February 11 2008
Spyware Doctor false positive. Partizan.sys wrong detection.

What is spXX.sys?

January 28 2007
Removing Medichi Rootkit

October 26 2007
Removal of Noskrnl.exe and Noskrnl.sys Rootkit (Spooldr clone)

July 25 2007
Removal Baidu rootkit (cnprov.sys)

July 24 2007
Removal Spooldr(ecard.exe) rootkit

June 25 2007
Fixing BSOD
in Winlogon Process

June 4 2007
Removal Areses Trojan

May 25 2007
Virus Feebs rootkit removal story

RegRun 5.5 beta updated

Release RegRun Reanimator 5.5.5.900

April 5 2007
What's this? Rthdcpl.exe - Illegal System DLL Relocation...

March 1 2007
Warning! Rootkit Unhooker

February 9 2007
Read our article about Unreal rootkit...

December 28 2006
Released free Rustock Rootkit(lzx32.sys) removal tool

November 29 2006
A#######.sys is a rootkit?

September 8 2006
Rootkit Removal instructions: ntsystem.exe

April 24 2006
What is BDGuard.sys?

April 17 2006
Virus or not? SPTD####.sys

March 31 2006
What is mc21.tmp, mc22.tmp, mc23.tmp?

January 19 2006
ICQCHK.exe, MSX.DLL free remover...
Educational discount...

Services
Ask Computer Guys

Windows startup programs

Articles
Using Registry Tracer...

RegRun against Trojans and Viruses

Specify an order for startup programs

RunGuard prevents a launch...

Using Bootlog Analyser...

They say
"RegRun Security Suite is one of those very rare tool kits that no one who is serious about protecting their PC should ever be without. This toolkit covers all the bases when it comes to eradicating the attempted security threats from malware that we all face - daily. The near real time tech support, direct from Greatis, is nothing sort of superb, something that can be rarely said these days! I have no hesitation in recommending this suite to anyone."

Miles Pearson

Wilders.ORG. Security advisors recommend...

Testimonials
You guys are awesome!!!!
Traci www.pentagonattack911.com

Bob Schmulian:
Absolutely love it and have recommended to many people!

Ian Robinson:
It is FANTASTIC! It has saved my life on more than one occasion since I purchased it less than 6 months ago. I now would not run my system without it... it's worth many times the cost! The service and support are terrific. Helpful - friendly - and accommodating; and generally a reply is received within 12 hours. Just great.

Theodore Soucie:
Since RegRun was installed my system is more stable. I use to experience freezeup daily. I have not had a crash.

Awards
Paul's Picks
Shareware Winner  

More...


Greatis Software Greatis | Security | AppDatabase | Utilities | Delphi/CB | Visual Basic | .NET | just4fun

Contacts | Add to Favorites | Recommend to a Friend | Privacy Policy | Copyright © 1998-2010 Greatis Software