Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jan 18, 2007 | Updated Sep 15, 2017

Backdoor:WinNT/Rustock.A

Detected by Microsoft Defender Antivirus

Aliases: Spam-Mailbot.c!Rootkit (McAfee) Backdoor.Rustock (Sunbelt Software) Backdoor.Rustock.B (Symantec)

Summary

Backdoor:WinNT/Rustock is a rootkit-enabled proxy trojan used to send large volumes of spam from infected computers. The trojan consists of a user mode installer and a kernel mode rootkit driver. The rootkit driver hides registry keys, files, TCP ports and memory objects and also hides itself from applications containing the following strings: RootkitReveller, BlackLight, Rkdetector, Gmer, Endoscope, DarkSpy, Anti-rootkit.
Follow us