Workaround to Block Stuxnet Rootkit Exploiting LNK Shortcut (Windows Shell) Vulnerability

by Venkat on July 17, 2010

in security

Hard days are coming for Windows users yet another dangerous Rootkit Stuxnet have been discovered that injects malware through  USB drives to the Computers strangely through LNK shortcut file  opened by Windows Explorer or file manager(Total Commander) that can display icons.

Stuxnet Rootkit installs two mrxnet.sys and mrxcls.sys drivers into computer which are digitally signed drivers with Relatek semiconductor Corp(www.realtek.com). These two drivers injects malware into system processes and hides malware.

Microsoft released Security Advisory(2286198) about the Windows Shell vulnerability and workaround to block  Stuxnet Rootkit before applying Update.

SHARE

Related Posts:

  1. Trend Micro’s Sysclean detects and removes Stuxnet malware exploiting LNK Shortcut Windows Vulnerability
  2. Use Microsoft Fix it to disable .LNK and .PIF File Functionality exploited by Stuxnet Rootkit
  3. Download Stuxnet Remover, Stuxnet Rootkit removal tool
  4. Download BitDefender’s Stuxnet Removal Tool
  5. Download Sophos Windows Shortcut Exploit Protection Tool

Previous post:

Next post: