Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Mar 25, 2007 | Updated May 21, 2010

Win32/Rustock.A!gen

Detected by Microsoft Defender Antivirus

Aliases: Spam-Mailbot.c!Rootkit (McAfee) Backdoor.Rustock (Sunbelt Software) Backdoor.Rustock.B (Symantec)

Summary

Backdoor:Win32/Rustock is a rootkit-enabled proxy trojan used to send large volumes of spam from infected computers. The trojan consists of a user mode installer and a kernel mode rootkit driver. The rootkit driver hides registry keys, files, TCP ports and memory objects and also hides itself from applications containing the following strings: RootkitReveller, BlackLight, Rkdetector, Gmer, Endoscope, DarkSpy, Anti-rootkit.
Manual removal is not recommended for this threat. Use Microsoft Security Essentials or another up-to-date scanning and removal tool to detect and remove this threat and other unwanted software from your computer. For more information on Microsoft security products, see http://www.microsoft.com/protect/products/computer/default.mspx.
Follow us