Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 28-05-2005, 05:32 PM   #1 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default ROOTKITS...the new threat !?


Did you know that it is possible to hide spyware or a virus in a way that will fool even the traditional antivirus/antispyware products? Some spyware programs are already using so-called rootkits to hide deep on your pc !

F-Secure has developed a new Beta version of their BlackLight Rootkit Eliminator. it is a tool that detects files, folders and processes that are hidden from the user and other programs. BlackLight is also able to remove hidden malware by renaming them.

Rootkits for Windows work in a different way and are typically used to hide malicious software from, for example, an antivirus program. it is used for malicious purposes by viruses, worms, backdoors and spyware. A virus combined with a rootkit produces what as known as full stealth viruses. Rootkits are more common in the spyware field and they are now also becoming more commonly used among virus authors as well.

for more info and a download visit : http://www.f-secure.com/blacklight/
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 28-05-2005, 07:25 PM   #2 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

Yeah they linux users must be familiar with "rootkits"
Its becoming common in the windows environment too.

Check Rootkit.com


Sysinternals have a Rootkit Revealer.You may as well check that out.
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
Old 28-05-2005, 07:32 PM   #3 (permalink)
Broken In
 
Join Date: Aug 2004
Location: Goa
Posts: 102
Default

Is F-Secure Blacklight the only solution?
netcracker is offline  
Old 28-05-2005, 10:51 PM   #4 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

No...SysInternals RootkitRevealer is a tool which is freely available.
http://www.sysinternals.com/ntw2k/fr...itreveal.shtml
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 29-05-2005, 01:18 AM   #5 (permalink)
Wise Old Owl
 
Join Date: Dec 2004
Location: South Side Crater, Mars
Posts: 1,038
Default

downloaded .....

nice link digen .. rootkit.com sure has loads of info!!
grinning_devil is offline  
Old 29-05-2005, 02:56 AM   #6 (permalink)
pq
Right Off the Assembly Line
 
Join Date: May 2005
Posts: 9
Default

Thanks anandk for ur info. I m goin to try it.
__________________
pq
pq is offline  
Old 17-08-2005, 06:13 PM   #7 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

ROOTKITS are now an emerging type of “Super Spyware�
which affect both Windows and Linux operating systems, hide
themselves efficiently, impact the operating system kernel directly,
and usually carry a more serious secondary payload.
Use this tool when you have done all other reasonable cleaning, have
also checked for viruses, and you are sure your system is still
seriously infested with malware even though no tool is showing it.
'ROOTKIT REVEALER' as mentioned above by swatkat is really worth a try. www.sysinternals.com
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 17-08-2005, 06:26 PM   #8 (permalink)
Commander in Chief
 
QwertyManiac's Avatar
 
Join Date: Jul 2005
Posts: 6,658
Default

so, y doesnt it appear, wats the problem with anti's code ?
__________________
Harsh J
www.harshj.com
QwertyManiac is offline  
Old 18-08-2005, 12:31 PM   #9 (permalink)
In The Zone
 
anomit's Avatar
 
Join Date: Mar 2005
Location: Kharagpur
Posts: 252
Default

For geek stuff on RootKit detection

I don't think rootkits can be completely removed from a system. Or am I wrong?
__________________
Don\'t SYN me, I'll SYN you. :p
anomit is offline  
Old 18-08-2005, 05:07 PM   #10 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

Nice link there anonmit.Its a pity that phrack is no more around.
As far as your question goes,as far as my knowledge goes rootkits operate under the so called "stealth" mode hence majortiy of them wont be detectable with say HijackThis or any port to application mapping program like Process Explorer.
The low level or kernel level operation of programs makes it a dangerous threat.
Detecting is a thing while removing is another.Completely removing even the slight traces of a rootkit would involve detailed or simple "forensics" on the comprimised machine depending upon the level of detail the rootkit posses.

Usually & especially in a corporate environment from what I heard the best practise if its a "server" machine that is comprimised is to format it & install a clean copy with all the patches & necessary updates.The gamble of knowing that the malicous threat has been removed would be a disaster.Infection of a server machine shouldnt happen in the first place but thats another story.
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
Old 18-08-2005, 07:36 PM   #11 (permalink)
Wise Old Owl
 
siriusb's Avatar
 
Join Date: May 2005
Location: Chennai, India, Asia, the Earth, the Solar system, the Milky Way, the Local group, this Universe.
Posts: 1,171
Default

Here's another one from a friend of mine: http://research.microsoft.com/rootkit/
__________________
http://myxp.blogspot.com
-----------------------
Winchester 3200+ @2,500MHz
LeadTek 7900GT VOLT MODDED @ 680 core, 1800 mem
2x1GB Transcend DDR400 @ DDR454 2.5,3,3,5,1T
siriusb is offline  
Old 19-08-2005, 09:50 AM   #12 (permalink)
In The Zone
 
anomit's Avatar
 
Join Date: Mar 2005
Location: Kharagpur
Posts: 252
Default

Quote:
Originally Posted by digen
Usually & especially in a corporate environment from what I heard the best practise if its a "server" machine that is comprimised is to format it & install a clean copy with all the patches & necessary updates.
I too had learnt that the best way to get rid of rootkits is to make a bcakup and then make a clean reinstall of the OS. But I was confused at the way soome others have posted about rootkit removal softwares. I thought maybe new techniques have been developed.

And about Phrack, they had given this indication almost a year ago. Just when I had started to learn.
WHY DOES THIS HAPPEN TO ME???!!!

I have to make do with the archive issues.
__________________
Don\'t SYN me, I'll SYN you. :p
anomit is offline  
Old 13-11-2005, 06:55 PM   #13 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

"Recently, Sony was discovered to have been installing software on people's computers without the user knowing it. When a user inserted a Sony CD into their computer CD-ROM drive, a "root kit" was installed that enabled the music giant to install "copy protection" without the user knowing. Some spyware developers and trojan horse virus makers have already begun to make use of Sony's root kit to hide their presence on the user's machine".

check out
http://news.com.com/FAQ+Sonys+rootki...l?tag=nefd.top

INCIDENTALLY webroot spy sweeper 4.5 has added the 'rootkit' detection option to its arsenal. its cool, eh !?
www.webroot.com
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 13-11-2005, 09:24 PM   #14 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

The lastet version of WebRoot SpySweeper is also able to detect the spyware which "hide" themselves using Rootkit technology.
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 14-11-2005, 12:54 PM   #15 (permalink)
Alpha Geek
 
Join Date: Jun 2005
Location: The New World Order
Posts: 523
Default

Norton AntiVirus, Kaspersky Anti-Virus and NOD32 also detect rootkits.....
__________________
Last edited by Happy Bytes: Today, at 3:45 AM. Reason: added a signature spreading worm....
AcceleratorX is offline  
Old 15-11-2005, 08:24 PM   #16 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

now even Microsoft has decided to "root" out Sony spyware

..."Sony has come under heavy fire for using so-called "rootkit"
cloaking techniques, normally associated with hackers..."

http://www.infoworld.com/article/05/...oftsony_1.html
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 18-08-2006, 07:52 PM   #17 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

"Symantec has released details of a new rootkit labeled Rustock.A that uses a cunning combination of techniques to evade detection by current rootkit detectors. First, Rustock.A has no process. The malicious code runs inside the driver and in kernel threads." Second, "Rustock.A uses NTFS Alternate Data Stream to hide its driver into the \System32:18467" ADS. In addition, this ADS can't be enumerated by ADS-aware tools since it is protected by the rootkit.

The news is not all bad; F-Secure has already updated their BlackLight rootkit detector to pick up Rustock.A. The cat and mouse game continues..."
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 24-08-2006, 01:38 PM   #18 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

here is a nice new anti-rootkit freeware tool from SOPHOS
click http://www.sophos.com/products/free-...i-rootkit.html for download and info.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 27-08-2006, 10:39 PM   #19 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: ROOTKITS...the new threat !?

Also Just Released : AVG Anti-Rootkit - can even remove Trojans and Rootkits that are hiding inside NTFS Alternate Data Streams
http://www.majorgeeks.com/AVG_Anti-Rootkit_d5249.html
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 02-09-2006, 05:09 PM   #20 (permalink)
Tux Fan
 
shaunak's Avatar
 
Join Date: Mar 2004
Location: Mumbai
Posts: 1,188
Default Re: ROOTKITS...the new threat !?

The systeminternals link is not working.
__________________
Cheers
Shaunak
Feel free to PM/email me.

Visit me sometime @ http://shaunak.ws
shaunak is offline  
Old 03-09-2006, 10:11 AM   #21 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

Quote:
Originally Posted by shaunak
The systeminternals link is not working.
http://www.sysinternals.com/Utilitie...tRevealer.html works.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 09-10-2006, 08:42 PM   #22 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default Re: ROOTKITS...the new threat !?

Nice info here:
Rooting Out the Dangers: Rootkit Removal for Beginners.
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 12-10-2006, 01:43 PM   #23 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: ROOTKITS...the new threat !?

nice link thanx !

guys for more about rootkits http://swatrant.blogspot.com/ is worth a visit !
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by topgear
- by Charan

Advertisement




All times are GMT +5.5. The time now is 06:09 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2