Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

WARNING: New Rootkit?

 
   Security Forums (Home) -> General Discussions RSS
Next:  how can I trace back to find out what file has dr..  
Author Message
animedreamer

External


Since: Apr 27, 2006
Posts: 1



(Msg. 1) Posted: Thu Apr 27, 2006 9:35 am
Post subject: WARNING: New Rootkit?
Archived from groups: alt>comp>anti-virus (more info?)

I was troubleshooting a client's computer and came across a strange
problem. The shares I had setup on their server were randomly
dropping. To say the least, I was quite confused. I rebooted the
server and a Security Warning appeared prompting me if I wanted to run
svchos32.exe. At this point, I suspected some sort of virus infection.
According to the security warning, this file was located in the
C:\Windows\System32 folder. I made sure not to hide hidden files,
inspected the directory in question and could not find anything. At
this point, I began thinking perhaps this could be a rootkit. I went
to the Sysinternals website and downloaded both autoruns and rootkit
reavealer. After performing a search from the autoruns program, I
determined that the file in question was trying to start from an entry
in the registry. The entry had a description of "Microsoft Box."
After disabling this file from starting, I have not experienced any
more problems. I am currently running rootkit revealer and will post
my results if anything of interest appears.

 >> Stay informed about: WARNING: New Rootkit? 
Back to top
Login to vote
edgewalker

External


Since: Apr 07, 2006
Posts: 111



(Msg. 2) Posted: Fri Apr 28, 2006 5:45 pm
Post subject: Re: WARNING: New Rootkit? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Todd H." <comphelp.DeleteThis@toddh.net> wrote in message news:84d5f2effa.fsf@ripco.com...

> But if you've been owned enough to have a full rootkit installed on a
> given machine, you'd be completely nuts to trust any tool to remove a
> rootkit. Smile

In this instance, a rootkit could be a single program - and easily removed

> You'd want to reformat and reinstall from original media.

Rootkits ain't what they used to be. It could be as simple as a filter driver
that hides the presence of one directory from the system's utilities by filtering
data returned from the file system before the utility gets it.

....it used to mean you were completely hosed by the presence of multiple
trojaned executable files

 >> Stay informed about: WARNING: New Rootkit? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
rootkit - Guy here reckons there's very little on the net about the rootkits that are going round at the moment, and suggested I post what we came up with here. Of course it only covers the couple we've worked on, but may be useful for others. So: One of..

RootKit Fix (hopefully) - Disclaimer: This fix is a loose guide and involves editing the registry. If you do not have a current registry backup or do not fully understand the steps then it is recommended you seek help before attempting to remove the RootKit and/or the Trojan. ..

RootKit? - I have a computer that seems to have been compromised. When I do a full system scan with Norton Antivirus, I see files such as: expl0rer.exe ixplore.exe _dll.exe hooker.exe and many others being scanned. As well as a directory called c:\programs\ ..

Rootkit ? - Hi, I think I may have a rootkit. Below is the result of the scan of a special rootkit revealer build. Can someone tell me about it ? HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6\ProductName 19/10/2004 17:12 58 bytes Data...

hacktool.rootkit. - I am trying to be as detailed about this as I can. Sorry if it is too long but I figure more info is better than less. Using a new Dell laptop with XP Home, SP2 and all updates. Norton Antivirus 2005 installed and set for automatic updates. It is als...
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]