Quantcast
Channel: A blog about rootkits research and the Windows kernel
Viewing all articles
Browse latest Browse all 58

Necurs rootkit detection

$
0
0
Detailed information (and droppers too) available on
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=897
http://www.kernelmode.info/forum/viewtopic.php?f=14&t=1177&p=8933#p8859

Block drivers of many AV tools.

 GMER

 tdsskiller


 Xuetr

Rku

After was started, creates device NtSecureSys.


Detection (for example, with VBA Antirootkit).

Kernel modules


Stack of devices, attaches itself to Tcp dev


Hooks NtOpenProcess, NtOpenThread functions in SSDT


Registers registry callback for self-defence and load module notify for disable of AV drivers loading.


Rootkit driver locked on disk.

Tdsskiller in your hands for deletion :)

Skip error message


Perform scanning

Malicious service was detected, set action to "delete".


Reboot need...


Viewing all articles
Browse latest Browse all 58

Trending Articles