backdoor.bulknet.417

[OUPA]MrNutz

Expert Member
Joined
Jan 21, 2005
Messages
1,788
hey peeps..

has anyone encountered this litter bugger before?

i've tried to clean it on customer's pc using.

drweb - id's it and apparently cleans it but next time the pc smells the web it's back.
kaspersky - no go - as ndis.sys is attacked and kaspersky cannot wrap around the network dll's
avast - doesn't detect it
avira - does detect it - but doesn't help.
malware bytes - picks up a rootkit - cleans it - but when internet is accessed - it's back
same with spybot - detects it - but after web sniff it's back.

i've cleaned the pc and enabled firewall without any open ports - but this thing keeps opening ports - verified by using netstat -a.
reinstall is an option but its the last option :)

regards
mrnutz
 

Random717

Expert Member
Joined
May 30, 2006
Messages
2,121
'sfc /scanonce' might help, reboot to run the scan.
Try kill explorer.exe in task manager and do an av scan, or even better chuck the drive into another system and run the scan there.
Might be worth a try to copy a 'healthy' ndis.sys from another system?
 
Top