D-Jester
December 23rd, 2010, 21:00
This thing got a hold of one of the computers at my work today and it was a real pain to remove.
It installs a rookit via Virtual Device, and replaces userinit.exe. It also killed my internet connection while it was running.
Nearly 4 hours before I could feel confident I had it removed, it killed the process of every antimalware/rootkit detection I tried and then it changes permissions so it can't run again without adjusting them.
http://forums.malwarebytes.org/?showtopic=70883
Probably the most aggressive I have ever come across. Thought someone might like to play with it.
It installs a rookit via Virtual Device, and replaces userinit.exe. It also killed my internet connection while it was running.
Nearly 4 hours before I could feel confident I had it removed, it killed the process of every antimalware/rootkit detection I tried and then it changes permissions so it can't run again without adjusting them.
http://forums.malwarebytes.org/?showtopic=70883
Probably the most aggressive I have ever come across. Thought someone might like to play with it.