Results 1 to 4 of 4

Thread: nuclab rootkit

  1. #1
    Junior Member
    Join Date
    Sep 2006
    Posts
    5

    Exclamation nuclab rootkit

    There is a virus that Trend finds as TSPY_GOLDUN.GEN. It cannot be cleaned or quarantined...just identified. It launches a service from the nuclab.sys file in Windows. The service runs stealth and is running in Safe mode.

    In my instance, it came with a file named nuclabdll.dll also in the Windows directory. In SpyBot it shows as being in system.ini and it cannot be "not started" using the SpyBot software (it just adds itself back in). Even tea timer cannot stop it.

    After killing it, there is still residue in the registry that I can't get rid of (lists as LegacyDriver and in service list).

    Hopefully you can put this in your detection list and find a way to kill it off.

    One more thing: When the system boots up, I see something that flashes across the screen that seems to have "Loading" and the letters PPR in it. However, it moves to quickly to determine if this is part of the BIOS or something else. This is a Dell Optiplex.

  2. #2
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    There is a related thread here:

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  3. #3
    Junior Member
    Join Date
    Sep 2006
    Posts
    5

    Default The other thread is not really a related thread.

    I was just pointing out here a malware that I discovered and eradicated. SpyBot SD 1.4 had not located it and I thought it might be of interest to the developers.

    I now understand that this is not the proper forum if I do not have all the scan logs from my cleanup and I apologize for posting here.

  4. #4
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    Quote Originally Posted by Janno View Post
    I was just pointing out here a malware that I discovered and eradicated. SpyBot SD 1.4 had not located it and I thought it might be of interest to the developers.
    That is the proper use of this forum.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •