nellie2 Posted November 12, 2005 Report Share Posted November 12, 2005 There has been some discussion recently about Rootkits, especially with the Sony Rootkit debacle going on at the minuteHowever... people can get a little confused about rootkits (me included) but Suzi at SpywareWarrior has written an excellent information piece on Rootkits --------------------------------------------------------------------Quote Suzi;Since rootkits are in the news recently, and a lot of people don't know much, if anything, about rootkits, I thought I'd post some info and a list of rootkit detection apps.Definitions:http://searchsecurity.techtarget.com/gDefi...i547279,00.htmlA rootkit is a collection of tools (programs) that enable administrator-level access to a computer or computer network. Typically, a hacker installs a rootkit on a computer after first obtaining user-level access, either by exploiting a known vulnerability or cracking a password. Once the rootkit is installed, it allows the attacker to mask intrusion and gain root or privileged access to the computer and, possibly, other machines on the network.It's a good write up and talks about the histoy of rootkits.Excellent article here with a lot more detailed technical information:http://online.securityfocus.com/print/infocus/1850In anti-spyware forums like this one, rootkit technology is sometimes found with spyware and/or trojans, backdoors and RATs (remote access tools). One spyware company, Enternet Media, has been documented to use rootkit technology to hide the presence of their spyware. Enternet Media is the company responsible for SearchMiracle/Elitebar spyware.http://www3.ca.com/securityadvisor/pest/pe...px?id=453090724http://www.f-secure.com/v-descs/elitebar.shtmlA screenshot of a rootkit revealer log showing Elitetoolbar can be seen in this link:http://netrn.net/spywareblog/archives/2005...hos-your-daddy/Rootkits have been found on machines with Rbot and SDbot and keyloggers.http://www.dslreports.com/forum/remark,14493487http://www.dslreports.com/forum/remark,13680927http://spywarewarrior.com/viewtopic.php?t=16103Presumably the rootkit is used to hide the tojans which can be used by the attacker to take total control of a machine while the keyloggers transmit information back to the attackers including passwords and data from the infected machine. An ugly situation at best. In cases like this I think the safest thing for a user to do is format and reinstall because there is no way to tell how severly the machine has been compromised and what dangers may lurk inside, even if the trojans and rootkit files are removed, if they can even be removed.Here's an example where format and reinstall was advised on a severely compromised network computer.http://spywarewarrior.com/viewtopic.php?t=16273Here's a list of rootkit detection apps, copied from Eric Howes' website:https://netfiles.uiuc.edu/ehowes/www/soft5.htm#rootkitBlacklight http://www.f-secure.com/blacklight/cure.shtml IceSwordhttp://xfocus.net/tools/200505/1032.html InvisibleThings.org http://invisiblethings.org/tools.html Microsoft - Malicious Software Removal Tool http://www.microsoft.com/security/malwareremove/default.mspx or http://www.microsoft.com/downloads/details.aspx?... RootkitRevealer http://www.sysinternals.com/Utilities/RootkitRevealer.html UnHackMe http://www.greatis.com/unhackme/index.htmlNote these tools should be used with the guidance of an experienced malware removal expert or advanced user.Some anti-spyware apps have added rootkit detection, Spy Sweeper for one, and there may be others I'm not aware of yet. Other sites for rootkit information:http://research.microsoft.com/rootkit/Microsoft webcast on rootkits:http://msevents.microsoft.com/cui/WebCastE...&CountryCode=UShttp://www.securityfocus.com/columnists/358http://www.viruslist.com/en/analysis?pubid=168740859Rootkits in the news:http://www.eweek.com/article2/0,1759,1829744,00.asphttp://www.eweek.com/article2/0,1759,1816972,00.asphttp://www.eweek.com/article2/0,1895,1841266,00.aspAIM worm drops rootkit and more:http://blogs.zdnet.com/Spyware/?p=687Sony's DRM rootkit:http://www.sysinternals.com/Blog/PestPatrol will detect and remove Sony's rootkit:http://blogs.zdnet.com/Spyware/?p=698The ultimate rootkit site:http://www.rootkit.com/Anyone who finds this helpful is welcome to post it at their own site or other sites. A link back here would be nice. :) Quote Link to comment Share on other sites More sharing options...
-pops- Posted November 12, 2005 Report Share Posted November 12, 2005 Sony has said it will suspend the production of music CDs with anti-piracy technology which can leave computers vulnerable to viruses.http://news.bbc.co.uk/1/hi/technology/4430608.stmAll very well and gracious (not) of Sony but it does nothing about the disks already in circulation. Quote Link to comment Share on other sites More sharing options...
-pops- Posted November 12, 2005 Report Share Posted November 12, 2005 Anothe demonstration of the importance of a good backup regime if you want to avoid the hassle of re-installing or re-formatting or any other messing about that infection with rootkit generated malware might incur. Quote Link to comment Share on other sites More sharing options...
Redhat Posted November 12, 2005 Report Share Posted November 12, 2005 First and foremost, the company that made this DRM software (First4Internet, a UK company) needs to cease production of such technology. They are unskilled, incompentent programmers. Who the HELL seriously creates an open-rootkit that is basically a framework for malware to use, and parades it as "protecting intellectual property"? Sony also needs to be held accountable. They knew what the ROOTKIT was like, as the owner of First4Internet was actually a former Director of Sony Entertainment. I find it inconceivable that they did not know what was happening. It's their intellectual property, but OUR COMPUTERS.</rant> Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted November 13, 2005 Report Share Posted November 13, 2005 http://news.zdnet.co.uk/internet/security/...39236971,00.htmI now really think that Microsoft are taking security seriously as they plan on releasing Windows security tools that will detect and remove the Sony DRG rootkit.I don't think that they would bother if it wasn't for the fact that having the rootkit on your PC increases the threat of malware getting on your PC. Quote Link to comment Share on other sites More sharing options...
scuzzman Posted November 16, 2005 Report Share Posted November 16, 2005 First and foremost, the company that made this DRM software (First4Internet, a UK company) needs to cease production of such technology. They are unskilled, incompentent programmers. Who the HELL seriously creates an open-rootkit that is basically a framework for malware to use, and parades it as "protecting intellectual property"? Sony also needs to be held accountable. They knew what the ROOTKIT was like, as the owner of First4Internet was actually a former Director of Sony Entertainment. I find it inconceivable that they did not know what was happening. It's their intellectual property, but OUR COMPUTERS.Hear hear!Sony has recently recalled the DRM CDs. There is also this page on EFF that shows How to tell if you have an XCP protected disc, and which discs are XCP protected. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted November 17, 2005 Report Share Posted November 17, 2005 Nellie,Thanks for the research and the excellent information! Quote Link to comment Share on other sites More sharing options...
Nick Posted November 18, 2005 Report Share Posted November 18, 2005 Microsoft has released signatures for the removal of the rootkit portion of the Sony XCP DRM software. There are 2 ways to get these. One is by updating Microsoft Antispyware with the November 17th update, which is numbered 5777. After updating, choose the full system scan. The other way is to try the Windows Live Safety Center and select the "Full Service Scan" followed by the "Quick scan" option.... Microsoft will also include detection and removal of the XCP rootkit with the December release of their Malicious Software Tool. That will be release on the 2nd Tuesday of the month or December 13th. ref hereNote that either Microsoft removal technique will only remove the rootkit portion of the XCP software. The digital rights management software will remain. Also, some of the other removal tools do not remove the rootkit but only uncloak it. Unfortunately, there has been some confusion with regard to the level of cleaning that antivirus (AV) companies are providing for the rootkit. Some articles imply that AV companies remove all of the Sony DRM software in the cleaning process, but they are in fact only disabling and removing the Aries.sys driver that implements the rootkit cloaking functionality. Unfortunately, all of the AV cleaners I’ve looked at disable it improperly by unloading it from memory - the same way Sony’s patch behaves - which as I noted previously, introduces the risk of a system crash ref from hereWith that in mind, I would use the Microsoft method to remove it. Looks like the AV companies jumped on the bandwagon and said they'd fix it, which was only partially true. They only decloaked it but left it intact. The actual removal is risky and they didn't want to have everyones CD drives disappear. Yet they let people assume on their own that it would be fixed. Quote Link to comment Share on other sites More sharing options...
nellie2 Posted November 18, 2005 Author Report Share Posted November 18, 2005 Thanks for the update Nick! B) Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.