28-05-2005, 05:32 PM
|
#1 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
ROOTKITS...the new threat !?
Did you know that it is possible to hide spyware or a virus in a way that will fool even the traditional antivirus/antispyware products? Some spyware programs are already using so-called rootkits to hide deep on your pc !
F-Secure has developed a new Beta version of their BlackLight Rootkit Eliminator. it is a tool that detects files, folders and processes that are hidden from the user and other programs. BlackLight is also able to remove hidden malware by renaming them.
Rootkits for Windows work in a different way and are typically used to hide malicious software from, for example, an antivirus program. it is used for malicious purposes by viruses, worms, backdoors and spyware. A virus combined with a rootkit produces what as known as full stealth viruses. Rootkits are more common in the spyware field and they are now also becoming more commonly used among virus authors as well.
for more info and a download visit : http://www.f-secure.com/blacklight/
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
|
Advertisements. Register and be a member of the community to get rid of them.
|
|
Advertisement
|
|
28-05-2005, 07:25 PM
|
#2 (permalink)
|
|
Alpha Geek
Join Date: Feb 2004
Location: Belgaum
Posts: 745
|
Yeah they linux users must be familiar with "rootkits"
Its becoming common in the windows environment too.
Check Rootkit.com
Sysinternals have a Rootkit Revealer.You may as well check that out.
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
|
|
|
28-05-2005, 07:32 PM
|
#3 (permalink)
|
|
Broken In
Join Date: Aug 2004
Location: Goa
Posts: 102
|
Is F-Secure Blacklight the only solution?
|
|
|
29-05-2005, 01:18 AM
|
#5 (permalink)
|
|
Wise Old Owl
Join Date: Dec 2004
Location: South Side Crater, Mars
Posts: 1,038
|
downloaded .....
nice link digen .. rootkit.com sure has loads of info!!
|
|
|
29-05-2005, 02:56 AM
|
#6 (permalink)
|
|
Right Off the Assembly Line
Join Date: May 2005
Posts: 9
|
Thanks anandk for ur info. I m goin to try it.
__________________
pq
|
|
|
17-08-2005, 06:13 PM
|
#7 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
ROOTKITS are now an emerging type of “Super Spyware�
which affect both Windows and Linux operating systems, hide
themselves efficiently, impact the operating system kernel directly,
and usually carry a more serious secondary payload.
Use this tool when you have done all other reasonable cleaning, have
also checked for viruses, and you are sure your system is still
seriously infested with malware even though no tool is showing it.
'ROOTKIT REVEALER' as mentioned above by swatkat is really worth a try. www.sysinternals.com
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
17-08-2005, 06:26 PM
|
#8 (permalink)
|
|
Commander in Chief
Join Date: Jul 2005
Posts: 6,658
|
so, y doesnt it appear, wats the problem with anti's code ?
__________________
Harsh J
www.harshj.com
|
|
|
18-08-2005, 12:31 PM
|
#9 (permalink)
|
|
In The Zone
Join Date: Mar 2005
Location: Kharagpur
Posts: 252
|
For geek stuff on RootKit detection
I don't think rootkits can be completely removed from a system. Or am I wrong?
__________________
Don\'t SYN me, I'll SYN you. :p
|
|
|
18-08-2005, 05:07 PM
|
#10 (permalink)
|
|
Alpha Geek
Join Date: Feb 2004
Location: Belgaum
Posts: 745
|
Nice link there anonmit.Its a pity that phrack is no more around.
As far as your question goes,as far as my knowledge goes rootkits operate under the so called "stealth" mode hence majortiy of them wont be detectable with say HijackThis or any port to application mapping program like Process Explorer.
The low level or kernel level operation of programs makes it a dangerous threat.
Detecting is a thing while removing is another.Completely removing even the slight traces of a rootkit would involve detailed or simple "forensics" on the comprimised machine depending upon the level of detail the rootkit posses.
Usually & especially in a corporate environment from what I heard the best practise if its a "server" machine that is comprimised is to format it & install a clean copy with all the patches & necessary updates.The gamble of knowing that the malicous threat has been removed would be a disaster.Infection of a server machine shouldnt happen in the first place but thats another story.
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
|
|
|
18-08-2005, 07:36 PM
|
#11 (permalink)
|
|
Wise Old Owl
Join Date: May 2005
Location: Chennai, India, Asia, the Earth, the Solar system, the Milky Way, the Local group, this Universe.
Posts: 1,171
|
Here's another one from a friend of mine: http://research.microsoft.com/rootkit/
__________________
http://myxp.blogspot.com
-----------------------
Winchester 3200+ @2,500MHz
LeadTek 7900GT VOLT MODDED @ 680 core, 1800 mem
2x1GB Transcend DDR400 @ DDR454 2.5,3,3,5,1T
|
|
|
19-08-2005, 09:50 AM
|
#12 (permalink)
|
|
In The Zone
Join Date: Mar 2005
Location: Kharagpur
Posts: 252
|
Quote:
|
Originally Posted by digen
Usually & especially in a corporate environment from what I heard the best practise if its a "server" machine that is comprimised is to format it & install a clean copy with all the patches & necessary updates.
|
I too had learnt that the best way to get rid of rootkits is to make a bcakup and then make a clean reinstall of the OS. But I was confused at the way soome others have posted about rootkit removal softwares. I thought maybe new techniques have been developed.
And about Phrack, they had given this indication almost a year ago. Just when I had started to learn.
WHY DOES THIS HAPPEN TO ME???!!!
I have to make do with the archive issues.
__________________
Don\'t SYN me, I'll SYN you. :p
|
|
|
13-11-2005, 06:55 PM
|
#13 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
"Recently, Sony was discovered to have been installing software on people's computers without the user knowing it. When a user inserted a Sony CD into their computer CD-ROM drive, a "root kit" was installed that enabled the music giant to install "copy protection" without the user knowing. Some spyware developers and trojan horse virus makers have already begun to make use of Sony's root kit to hide their presence on the user's machine".
check out
http://news.com.com/FAQ+Sonys+rootki...l?tag=nefd.top
 INCIDENTALLY webroot spy sweeper 4.5 has added the 'rootkit' detection option to its arsenal. its cool, eh !?
www.webroot.com
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
13-11-2005, 09:24 PM
|
#14 (permalink)
|
|
Human Spambot
Join Date: Mar 2004
Location: India
Posts: 2,033
|
The lastet version of WebRoot SpySweeper is also able to detect the spyware which "hide" themselves using Rootkit technology.
__________________
http://swatrant.blogspot.com/
|
|
|
14-11-2005, 12:54 PM
|
#15 (permalink)
|
|
Alpha Geek
Join Date: Jun 2005
Location: The New World Order
Posts: 523
|
Norton AntiVirus, Kaspersky Anti-Virus and NOD32 also detect rootkits.....
__________________
Last edited by Happy Bytes: Today, at 3:45 AM. Reason: added a signature spreading worm....
|
|
|
15-11-2005, 08:24 PM
|
#16 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
now even Microsoft has decided to "root" out Sony spyware
..."Sony has come under heavy fire for using so-called "rootkit"
cloaking techniques, normally associated with hackers..."
http://www.infoworld.com/article/05/...oftsony_1.html
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
18-08-2006, 07:52 PM
|
#17 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
"Symantec has released details of a new rootkit labeled Rustock.A that uses a cunning combination of techniques to evade detection by current rootkit detectors. First, Rustock.A has no process. The malicious code runs inside the driver and in kernel threads." Second, "Rustock.A uses NTFS Alternate Data Stream to hide its driver into the \System32:18467" ADS. In addition, this ADS can't be enumerated by ADS-aware tools since it is protected by the rootkit.
The news is not all bad; F-Secure has already updated their BlackLight rootkit detector to pick up Rustock.A. The cat and mouse game continues..."
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
24-08-2006, 01:38 PM
|
#18 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
here is a nice new anti-rootkit freeware tool from SOPHOS
click http://www.sophos.com/products/free-...i-rootkit.html for download and info.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
27-08-2006, 10:39 PM
|
#19 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
Re: ROOTKITS...the new threat !?
Also Just Released : AVG Anti-Rootkit - can even remove Trojans and Rootkits that are hiding inside NTFS Alternate Data Streams
http://www.majorgeeks.com/AVG_Anti-Rootkit_d5249.html
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
02-09-2006, 05:09 PM
|
#20 (permalink)
|
|
Tux Fan
Join Date: Mar 2004
Location: Mumbai
Posts: 1,188
|
Re: ROOTKITS...the new threat !?
The systeminternals link is not working.
__________________
Cheers
Shaunak
Feel free to PM/email me.
Visit me sometime @ http://shaunak.ws
|
|
|
03-09-2006, 10:11 AM
|
#21 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
Quote:
|
Originally Posted by shaunak
The systeminternals link is not working.
|
http://www.sysinternals.com/Utilitie...tRevealer.html works.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
09-10-2006, 08:42 PM
|
#22 (permalink)
|
|
Human Spambot
Join Date: Mar 2004
Location: India
Posts: 2,033
|
Re: ROOTKITS...the new threat !?
__________________
http://swatrant.blogspot.com/
|
|
|
12-10-2006, 01:43 PM
|
#23 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
Re: ROOTKITS...the new threat !?
nice link thanx !
guys for more about rootkits http://swatrant.blogspot.com/ is worth a visit !
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|