EP_X0FF wrote:the random driver will recreated while deleted by other antirootkit tool.RkU Version: 3.8.388.590, Type LE (SR2)But you need to do quick reset. That's the key :)
==============================================
!-->[Hidden] C:\WINDOWS\system32\drivers\paqkkmhplelf.sys
!-->[Hidden] C:\WINDOWS\system32\drivers\str.sys
edit:
Beaten by GamingMaster. Yes, here it is - magic :)
in my test,Safe Returner could remove the new Black Energy 2.1+ rootkit. (Use "DATEA0B.tmp.exe" sample)
Attachments
rootkit1.png (60.17 KiB) Viewed 764 times