{"id":784,"date":"2011-09-08T13:52:24","date_gmt":"2011-09-08T12:52:24","guid":{"rendered":"http:\/\/www.stevenwhiting.com\/blog\/?p=784"},"modified":"2011-09-08T13:54:57","modified_gmt":"2011-09-08T12:54:57","slug":"ntos-virus-cleaning","status":"publish","type":"post","link":"https:\/\/stevenwhiting.com\/blog\/?p=784","title":{"rendered":"ntos virus cleaning"},"content":{"rendered":"<p>To help cleaning off NTOS<\/p>\n<p>NTOS.exe stealth\u2019s itself, sysinternals autorun<\/p>\n<p><a title=\"Sysinternals AutoRun\" href=\"http:\/\/technet.microsoft.com\/en-gb\/sysinternals\/bb963902\" target=\"_blank\">\u00a0http:\/\/technet.microsoft.com\/en-gb\/sysinternals\/bb963902<\/a><\/p>\n<p>will show an entry in the &#8220;HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit&#8221; section where NTOS.exe is tagged on the end of the usual &#8220;C:\\WINDOWS\\system32\\userinit.exe,&#8221; but if you set autoruns to remove the entry it will immediately reappear. When you look at the location using windows explorer it will not show the file.<\/p>\n<p>Using killbox<\/p>\n<p><a title=\"KillBox\" href=\"http:\/\/killbox.net\/\">\u00a0http:\/\/killbox.net\/<\/a><\/p>\n<p>Run killbox and put in the path to the naughty file &#8211; usually &#8220;c:\\windows\\system32\\ntos.exe&#8221; &#8211; then select the replace on reboot radio button and check the &#8216;use dummy&#8217; box. now click the remove file button (red with white cross). After rebbot you will be able to remove the startup entry and both see and delete the dummy NTOS.exe in %systemroot%\\System32\\.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>To help cleaning off NTOS NTOS.exe stealth\u2019s itself, sysinternals autorun \u00a0http:\/\/technet.microsoft.com\/en-gb\/sysinternals\/bb963902 will show an entry in the &#8220;HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit&#8221; section where NTOS.exe is tagged on the end of the usual &#8220;C:\\WINDOWS\\system32\\userinit.exe,&#8221; but if you set autoruns to remove the entry &hellip; <a href=\"https:\/\/stevenwhiting.com\/blog\/?p=784\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[163,139],"class_list":["post-784","post","type-post","status-publish","format-standard","hentry","category-it-notes","tag-ntos","tag-virus"],"_links":{"self":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=784"}],"version-history":[{"count":4,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/784\/revisions"}],"predecessor-version":[{"id":787,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/784\/revisions\/787"}],"wp:attachment":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}