Jump to content

Microsoft: Stealth Rootkits Are Bombarding XP SP2 Boxes


Chris
 Share

Recommended Posts

More than 20 percent of all malware removed from Windows XP SP2 (Service Pack 2) systems are stealth rootkits, according to senior official in Microsoft Corp.'s security unit.

Jason Garms, architect and group program manager in Microsoft's Anti-Malware Technology Team, said the open-source FU rootkit ranks high on the list of malicious software programs deleted by the free Windows worm zapping utility.

"I can tell you that FU is the fifth most removed piece of malware. We're finding the FU rootkit in many different versions of Rbot," Garms said, referring to the IRC controlled backdoor used to illegally infect Windows PCs with spyware.

In addition to the FU rootkit, Garms said the WinNT/Ispro family of kernel mode rootkits features in the top-five list every month.

WinNT/Ispro, like FU, is often bundled with illegally installed spyware to allow an attacker to modify certain files and registry keys to avoid detection on an infected machine.

"Hacker Defender," another rootkit program that is available for sale on the Internet, has also been detected and deleted regularly.

More | Here

Link to comment
Share on other sites

Rootkits are dangerous! But not all are bad. Mostly they are just used for hiding other programs and or viruses. There is a program here which will list all rootkits currently on a system. This does not mean you have to delete all of them.

A good free detection and removal utility from F-Secure (BETA. Free until Jan 1, 2006)

Link to comment
Share on other sites

A good free detection and removal utility from F-Secure (BETA. Free until Jan 1, 2006)

I tried that out a few weeks ago and I also run it earlier on today and it found nothing and I'm not surprised as the scan took only around 5 seconds to complete!

This seems too quick to be a thorough scan? :huh:

I downloaded and run Rootkit Revealer and the scan took a lot longer (around 15 minutes) and after completing it found 9 discrepancies as shown in my attachment :o

Are these anything to worry about?

How come the 2 rootkit detectors give different results i.e. one says I'm clean and the other says I have 9 discrepancies?

post-2412-1133964330_thumb.jpg

Link to comment
Share on other sites

This is taken from sysinternals site:

"You should examine all discrepancies and determine the likelihood that they indicate the presence of a rootkit. Unfortunately, there is no definitive way to determine, based on the output, if a rootkit is present, but you should examine all reported discrepancies to ensure that they are explainable. If you determine that you have a rootkit installed, search the web for removal instructions."

So I have to determine the results myself then? :unsure:

Link to comment
Share on other sites

I know it's not of much help to you but, C:\System Volume Inf is where system restore points, among other things, are kept. It also contains the following - Distributed Link Tracking Service, Content Indexing Service, and Volume Shadow Copy.

Link to comment
Share on other sites

I, too, tried it and it came up with two discrepancies after about 35 minutes scanning.

I am inclined to ignore the first (0 bytes) but in my ignorance don't know about the second.

Anyone any thoughts?

Well it would help if you expanded the Path section to give us a bit more info like I have done in my screenshot (obviously editing out any confidential info like your name as I have done).

I ran the Rootkit Revealer for the second time and this time it came up with 10 entries!

I have determined that I only have the one rootkit which is highlighted in my screenshot.

It may not be a rootkit as such, I'm not really sure so I will do a Google search to see what I come up with!

The others are either zero bytes, temporary internet files or related to Mozilla, so I assume these are safe?

post-2412-1133967894_thumb.jpg

Link to comment
Share on other sites

Handy tip: Alt + PrintScreen captures only the active window. :)

Thanks expertec :flowers:

I don't know if you were referring to me but if you were, in order to get the whole width of the scanner results in my screenshot, I had to use Irfanview and not Paint which is the application that I am more familiar with.

Link to comment
Share on other sites

I think we are worrying about nothing.

I disagree as according to the title headline of this thread over 20% of SP2 PC's are infected which is rather a lot.

I think that most of us on computer forums are lucky as we are sensible and keep our PC's regularly updated with security updates.

What about PC newcomers who know little or nothing about security?

Also look at what happened with the notorious Sony rootkit, millions of PC's were infected without anyone realising until it made the headlines :o

Link to comment
Share on other sites

I know it's not of much help to you but, C:\System Volume Inf is where system restore points, among other things, are kept. It also contains the following - Distributed Link Tracking Service, Content Indexing Service, and Volume Shadow Copy.

Well it would help if you expanded the Path section to give us a bit more info like I have done in my screenshot (obviously editing out any confidential info like your name as I have done).

Thanks be@vis and Curly. I can only manage a screen shot showing the abbreviated path. I tried another scan this morning and it found 180 entries!

So I ran CrapCleaner and scanned again. All had gone except the zero bytes one which I shall ignore.

I am inclined not to get concerned any more.

Thos. :)

Link to comment
Share on other sites

I can only manage a screen shot showing the abbreviated path. I tried another scan this morning and it found 180 entries!

To expand the section just drag the border to the right using the mouse.

So I ran CrapCleaner and scanned again. All had gone except the zero bytes one which I shall ignore.

They probably disappeared as they were temporary internet files which were flushed out when you run CrapCleaner?

I am a bit puzzled as to how an entry can be zero bytes in length though as it wouldn't exist if it was this length :blink:

It could just be registry remnants that are being picked up in these cases?

Link to comment
Share on other sites

Prior to scanning with Rootkit Revealer, a bit of "housework" should be done on the system i.e. run CCleaner, as Thos did, and get rid of any rubbish, particularly old internet files, and clear the browser cache. Most of the items flagged by Rootkit Revealer appear to be just rubbish that's lying around on the HD. Only someone who uses the PC regularly knows what should, or should not, be on the machine so it's difficult for a third party to give advice as to what to do with anything flagged by Rootkit Revealer but, as far as I can make out, Rootkits usually have a title so it may not be too difficult to spot them.

Info on rootkits at - http://www.rootkit.com/

http://www.sysinternals.com/Forum/forum_topics.asp?FID=15

http://www.sysinternals.com/Utilities/RootkitRevealer.html

Link to comment
Share on other sites

I think we are worrying about nothing.

I disagree as according to the title headline of this thread over 20% of SP2 PC's are infected which is rather a lot.

I think that most of us on computer forums are lucky as we are sensible and keep our PC's regularly updated with security updates.

What about PC newcomers who know little or nothing about security?

Also look at what happened with the notorious Sony rootkit, millions of PC's were infected without anyone realising until it made the headlines :o

This is my point. We all keep so many anti crap programs running that I seriously doubt that we need worry. As regards those who do not visit the forum, there is nothing that we can do to help them. I have tried to advise my daughter, but she thinks that I worry about nothing, Whenever I look at her crap top, Adaware and Spybot etc are usually at least three weeks out of date. Windows update never is up to date, and so on. One day she may well be sorry.

Link to comment
Share on other sites

I can only manage a screen shot showing the abbreviated path. I tried another scan this morning and it found 180 entries!

To expand the section just drag the border to the right using the mouse.

The trouble is that the results are shown full screen with the borders at the extreme edge so I cannot drag the border. I suppose I could take a screen shot with the mouse hovering over creating the full path but I am inclined now to pops and andsome's take on this and not to worry any further.

Thos. :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy