Wednesday 14 October 2009

The cutwall spambot

Wow what a nasty little Trojan/rootkit/spambot this is. Took a full day to get rid of it. AVG found the virus but was unable to get rid of it fully, this thing takes over your windows filesystem and hides itself in multiple files. I even read stories that a full format wouldn't fully remove it and a subsequent fresh install of windows would allow it to start all over again.

Eventually I decided to use avast. After a lot of googling (on a non infected Linux box) it suggested this was the program to use. Avast had a great boottime scanner which gave the filesystem a thorough scan and is reminicent of the chkdsk utility. This flagged tons of infected files and after a couple of hours the machine booted back into windows.

After logging in All hell broke loose and avast started flagging multiple problems prompting me to fix the new issues it had found. In my haste I decided to use "delete" rather than heal. It chewed through and after another couple of hours it had finished the scan. I decided to reboot and see if all was well.

Windows wouldn't boot, dos splash screen cycling away. Avast had done a good job however in doing so must have killed a lot of critical system files.

So out came the XP install disk, reinstalled, opted to repair the exisiting installation and eventually a healthy machine!!

1 whole day.


No comments:

Post a Comment