UnHackMe
•  Greatis •  AppDatabase •  Utilities •  Delphi/CB •  Visual Basic • .NET •  Outsourcing

UnHackMe - First BootWatch AntiRootkit
 UnHackMe     Entire site
Choose one
For home users

Professional - for anticrime squad

Roaming - for admins

Enterprise - for small and large business

Education

Free TDL Rootkit Detector

Info
Warrior Benefits

Features

ScreenShots

How it works

Download

Rootkit Testing

FAQ

UnHackMe for beginners...

One-click purchase
UnHackMe Single

UnHackMe Family

UnHackMe Business

UnHackMe Family+Business

UnHackMe Roaming

UnHackMe Pro

Download trial
UnHackMe
Forums
Greatis Forum

Home Download Order Support Press Room   Newsletter Your shopping cart ?


Spooldr rootkit is spread by e-mail. Often attachment has the file name: "ecard.exe" or the similar name.

UnHackMe detects the working driver (not hidden) during the "Scan for Viruses" process:

Also it detects the open process immediately after reboot:

But the spooldr.exe file is hidden by rootkit technology.


The main interesting thing is how does "Spooldr" automatically start after reboot.

I used the Bootlog XP software to track the boot process. I found that the spooldr.sys is started immediately after "%SysDir%\Drivers\tcpip.sys".

I checked the file sign of the tcpip.sys and I found that it is not signed. However the original tcpip.sys is signed.

I discovered the contents of the "tcpip.sys" and found the string "spooldr.sys" in the end of the file.


How rootkit works?

The virus in the TCPIP.SYS is used for loading "spooldr.sys" driver.

After that the driver executes "spooldr.exe" and hides the executable file.

Spooldr.exe is used for propagation.


Removal

UnHackMe detects the "spooldr.sys" driver and it removes the driver at the next reboot. After that we can simply delete spooldr.exe and restore old tcpip.sys in the %SysDir%\Drivers and in the %SysDir%\dllcache folders.

In addition, we need to remove "spooldr.exe" from the Windows Firewall Exclusion list.

Also, delete the "spooldir.ini" from "Documents and Settings\UserName" fodler.


Purchase
Buy Now UnHackMe

Supported Windows NT4/2000/XP/2003/Vista/Seven.

Compatible with all known antiviral software.

Free updates. On-line support.

System Requirements.


They say

My PC had gotten a bad rootkit
that my ISP antivirus software (powered by McAfee) could not detect, nor could fix. I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.

Jeff

Bob Rankin

What's new?
January 23 2012

Released UnHackMe 2012 Build: 397!


November 3 2011

Morto Removal Video

July 27 2011

Popureb.E Rootkit Removal Video

Zero Access Rootkit Removal Video

Released


All News...


Now Google Search is redirected in Windows 64 bit too if you are infected by TDL3++ (also known as TDL4).



RegRun Warrior download (for burning your own CD)


Resolving problem with


Awards
Paul's Picks
Shareware Winner  

More...


Greatis Software Greatis | Security | AppDatabase | Utilities | Delphi/CB | Visual Basic | .NET | Outsourcing

Contacts | Add to Favorites | Recommend to a Friend | Privacy Policy | Copyright © 1998-2012 Greatis Software

tumblr hit counter