|
Spooldr rootkit is spread by e-mail. Often attachment has the file name: "ecard.exe" or the similar name.
UnHackMe detects the working driver (not hidden) during the "Scan for Viruses" process:
Also it detects the open process immediately after reboot:
But the spooldr.exe file is hidden by rootkit technology.
The main interesting thing is how does "Spooldr" automatically start after reboot.
I used the Bootlog XP software to track the boot process.
I found that the spooldr.sys is started immediately after "%SysDir%\Drivers\tcpip.sys".
I checked the file sign of the tcpip.sys and I found that it is not signed.
However the original tcpip.sys is signed.
I discovered the contents of the "tcpip.sys" and found the string "spooldr.sys" in the end of the file.
How rootkit works?
The virus in the TCPIP.SYS is used for loading "spooldr.sys" driver.
After that the driver executes "spooldr.exe" and hides the executable file.
Spooldr.exe is used for propagation.
UnHackMe detects the "spooldr.sys" driver and it removes the driver at the next reboot.
After that we can simply delete spooldr.exe and restore old tcpip.sys in the %SysDir%\Drivers and in the %SysDir%\dllcache folders.
In addition, we need to remove "spooldr.exe" from the Windows Firewall Exclusion list.
Also, delete the "spooldir.ini" from "Documents and Settings\UserName" fodler.
|
|
 |
|
UnHackMe
Supported Windows NT4/2000/XP(64)/2003(64)/Vista.
Compatible with all known antiviral software.
Free updates. On-line support.
System Requirements.
|
|
 |
 |
|
|
 |
If your tool had not worked, I was going to rebuild my disk from scratch, loading all my apps, downloads, etc. This would have cost me probably 2 days of work.
Great news! What I did last night with UnHackMe just stumbling around the system has cleared the problem!!
I can't tell you how delighted I am.
All the best... Dave Gardner
|
 |
 |
|
|
 |
Bob Schmulian:
Absolutely love it and have recommended to many people!
Ian Robinson:
It is FANTASTIC! It has saved my life on more than one occasion since
I purchased it less than 6 months ago. I now would not run my system without it...
it's worth many times the cost! The service and support are terrific.
Helpful - friendly - and accommodating; and generally a
reply is received within 12 hours. Just great.
Theodore Soucie:
Since RegRun was installed my system is more stable. I use to experience freezeup daily. I have not had a crash.
|
 |
 |
|
|