A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12268  by nullptr
 Thu Mar 22, 2012 2:31 pm
In my testing of recent samples, it seems that TDSSKiller v2.7.22.0 does a pretty good job of curing the infected driver + cleaning out the $NtUninstallKBxxxxx$ directory. The empty $NtUninstallKBxxxxx$ remains after it's finished, but just needs permissions changed to delete. Other than that, there's just the usual dregs to clean up.
  • 1
  • 25
  • 26
  • 27
  • 28
  • 29
  • 38