How to Remove Alureon rootkit To avoid BSOD Crashes in Windows

Windows Update

This is a very important note for all the Windows users especially 32-bit, that before installing the security updates that Microsoft Windows had released last week, you check if the malware known as Alureon Rootkit is present or not and remove it using the Microsoft Windows Malicious Software Removal Tool.  If the malware is present in your system and if you happen to install the security update (KB977165) then there is a high possibility that Windows may crash and it may show only a blue screen during startup (Blue Screen Of Death BSOD).

Alureon Rootkit or Win32/Alureon.gen causes problems with the way Microsoft’s patches interact with the kernel, which has led the company to include a package detection logic that prevents the installation of the security update if the rootkit is present on 32-bit systems.

Windows Crash Reported after installing Security updates:

Windows systems crashed during the latest Microsoft security update last week. According to Microsoft this happened because the systems were infected with a rootkit program that made changes to the operating system kernel and it was not due to the update patches.

“The restarts are the result of modifications the Alureon rootkit makes to Windows Kernel binaries, which places these systems in an unstable state,” Mike Reavey, director of the Microsoft Security Response Center, wrote in a blog post. “In every investigated incident, we have not found quality issues with security update MS10-015.”

Download:

Microsoft Windows Malicious Software Removal Tool

Remove Alureon rootkit To avoid BSOD Crashes in Windows

Microsoft Windows Malicious Software Removal Tool KB890830

microsoft logo

Microsoft updates its Microsoft Windows Malicious Software Removal tool (MWMSRT) and releases the update on the second Tuesday of every month.As usual, Microsoft released updated version of this tool for the month of April (2010) as KB890830.This tool checks your computer for any malicious software and helps to remove it, once it finds the infection.Please make note of the difference between an anti-virus program and thus Malicious Software Removal Tool.

This Microsoft Malicious Software Removal Tool is no replacement to an anti-virus program.An anti-virus program blocks malicious software from running on a computer, whereas this tool only removes malicious software from a computer which is already infected.As they say “Prevention is always better than the cure”, it applies here too ! It’s always desirable to block such malicious software from running on the computer first up,

Windows Malicious Software Removal Tool – April 2010 (KB890830)

Update Released on : April 13, 2010

Update type: Important

Download Size: 9.9 MB

Platforms: Windows 7, Windows Vista, Windows Server 2003, Windows XP, or Windows 2000

Download:

Download the 890830 package now

Download link for x74 version of the software

More information:
http://go.microsoft.com/fwlink/?LinkId=39987

Previous updates : KB977206, KB980182, kb978601

Using Webmaster Tools To Find Malicious Hacks In a Website

These are the days where many websites (even prestigious ones) like FMS (see my post about FMS hack) are getting hacked by malicious parties.These hackers/spammers penetrate into the site and insert spammy or dangerous stuff.Many a times it may not appear to the normal users of the website.But when you do a Google search of the website, it may appear like

buy-generic-cialis[1]

HackedFMSBSchoolwebsite[1]

Thanks to Google Webmaster Tools(GWT), Fetch as Googlebot feature gives a breather to the webmasters.Fetch as Googlebot fetches any webpage of your site as it appears to the Googlebot.

Just login to Webmaster Tools, .Click on Fetch as Googlebot under “Labs” section inside your website profile dashboard.

Fetch as Googlebot in Webmaster tools

Fetching a webpage as Googlebot

Now enter URL of any particular page which you want to fetch as a Googlebot or just leave it as blank to fetch the Homepage of your site.

fetchas googlebot 200 success

Results of Fetch as Googlebot

There you go!! There’s the spammy content that’s being injected.GWT made this easier for you through ‘Fetch as Googlebot’ option.This confirms that the site has been hacked, the next step is to contact your server administrator or your hosting provider to take further actions.

Illustrative Images via Google Webmaster Central Blog post.