Chris Posted December 6, 2005 Report Share Posted December 6, 2005 More than 20 percent of all malware removed from Windows XP SP2 (Service Pack 2) systems are stealth rootkits, according to senior official in Microsoft Corp.'s security unit.Jason Garms, architect and group program manager in Microsoft's Anti-Malware Technology Team, said the open-source FU rootkit ranks high on the list of malicious software programs deleted by the free Windows worm zapping utility."I can tell you that FU is the fifth most removed piece of malware. We're finding the FU rootkit in many different versions of Rbot," Garms said, referring to the IRC controlled backdoor used to illegally infect Windows PCs with spyware.In addition to the FU rootkit, Garms said the WinNT/Ispro family of kernel mode rootkits features in the top-five list every month.WinNT/Ispro, like FU, is often bundled with illegally installed spyware to allow an attacker to modify certain files and registry keys to avoid detection on an infected machine."Hacker Defender," another rootkit program that is available for sale on the Internet, has also been detected and deleted regularly.More | Here Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted December 6, 2005 Report Share Posted December 6, 2005 Rootkits are dangerous! But not all are bad. Mostly they are just used for hiding other programs and or viruses. There is a program here which will list all rootkits currently on a system. This does not mean you have to delete all of them.A good free detection and removal utility from F-Secure (BETA. Free until Jan 1, 2006) Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 7, 2005 Report Share Posted December 7, 2005 A good free detection and removal utility from F-Secure (BETA. Free until Jan 1, 2006)I tried that out a few weeks ago and I also run it earlier on today and it found nothing and I'm not surprised as the scan took only around 5 seconds to complete! This seems too quick to be a thorough scan? :huh: I downloaded and run Rootkit Revealer and the scan took a lot longer (around 15 minutes) and after completing it found 9 discrepancies as shown in my attachment :o Are these anything to worry about?How come the 2 rootkit detectors give different results i.e. one says I'm clean and the other says I have 9 discrepancies? Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 7, 2005 Report Share Posted December 7, 2005 This is taken from sysinternals site:"You should examine all discrepancies and determine the likelihood that they indicate the presence of a rootkit. Unfortunately, there is no definitive way to determine, based on the output, if a rootkit is present, but you should examine all reported discrepancies to ensure that they are explainable. If you determine that you have a rootkit installed, search the web for removal instructions." So I have to determine the results myself then? :unsure: Quote Link to comment Share on other sites More sharing options...
expertec Posted December 7, 2005 Report Share Posted December 7, 2005 Hmm... when I try to run it, I just get "Rootkit Revealer must be run from the console". :huh: Quote Link to comment Share on other sites More sharing options...
Thos Posted December 7, 2005 Report Share Posted December 7, 2005 I, too, tried it and it came up with two discrepancies after about 35 minutes scanning.I am inclined to ignore the first (0 bytes) but in my ignorance don't know about the second.Anyone any thoughts?Thos. Quote Link to comment Share on other sites More sharing options...
Guest be@vis Posted December 7, 2005 Report Share Posted December 7, 2005 I know it's not of much help to you but, C:\System Volume Inf is where system restore points, among other things, are kept. It also contains the following - Distributed Link Tracking Service, Content Indexing Service, and Volume Shadow Copy. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 7, 2005 Report Share Posted December 7, 2005 I, too, tried it and it came up with two discrepancies after about 35 minutes scanning.I am inclined to ignore the first (0 bytes) but in my ignorance don't know about the second.Anyone any thoughts?Well it would help if you expanded the Path section to give us a bit more info like I have done in my screenshot (obviously editing out any confidential info like your name as I have done).I ran the Rootkit Revealer for the second time and this time it came up with 10 entries!I have determined that I only have the one rootkit which is highlighted in my screenshot.It may not be a rootkit as such, I'm not really sure so I will do a Google search to see what I come up with!The others are either zero bytes, temporary internet files or related to Mozilla, so I assume these are safe? Quote Link to comment Share on other sites More sharing options...
expertec Posted December 7, 2005 Report Share Posted December 7, 2005 Handy tip: Alt + PrintScreen captures only the active window. :) Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 7, 2005 Report Share Posted December 7, 2005 Handy tip: Alt + PrintScreen captures only the active window. :)Thanks expertec :flowers: I don't know if you were referring to me but if you were, in order to get the whole width of the scanner results in my screenshot, I had to use Irfanview and not Paint which is the application that I am more familiar with. Quote Link to comment Share on other sites More sharing options...
Guest be@vis Posted December 7, 2005 Report Share Posted December 7, 2005 Webcal - http://www.google.co.uk/search?q=webcal&so...:en-GB:official Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 7, 2005 Report Share Posted December 7, 2005 Webcal - http://www.google.co.uk/search?q=webcal&so...:en-GB:officialThat's strange as according to the Google results it is a browser-based calendar program.I don't remember ever installing one of these but it doesn't sound like malware so I will forget it.Thanks be@vis Quote Link to comment Share on other sites More sharing options...
andsome Posted December 7, 2005 Report Share Posted December 7, 2005 I also got similar results to the above, with about half a dozen discrepancies including a registry entry. I have chosen to ignore this scan and not bother again. None of my other malware programs show anything. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 7, 2005 Report Share Posted December 7, 2005 None of my other malware programs show anything.I don't think other malware programs would be able to show them anyway as you need a rootkit detector to detect rootkits. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted December 7, 2005 Report Share Posted December 7, 2005 These "descrepencies" do not mean virus or spyware. Rootkit Revealer will not remove them, only list them.If you feel you have malware, post a HijackThis log. Quote Link to comment Share on other sites More sharing options...
Tankus Posted December 7, 2005 Report Share Posted December 7, 2005 7 seconds and found nowt........! Quote Link to comment Share on other sites More sharing options...
Boris Posted December 7, 2005 Report Share Posted December 7, 2005 This is all it found on mine. Quote Link to comment Share on other sites More sharing options...
andsome Posted December 8, 2005 Report Share Posted December 8, 2005 I posted a Hijack This scan a few days ago and it was clear. I think we are worrying about nothing. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 8, 2005 Report Share Posted December 8, 2005 I think we are worrying about nothing.I disagree as according to the title headline of this thread over 20% of SP2 PC's are infected which is rather a lot.I think that most of us on computer forums are lucky as we are sensible and keep our PC's regularly updated with security updates.What about PC newcomers who know little or nothing about security?Also look at what happened with the notorious Sony rootkit, millions of PC's were infected without anyone realising until it made the headlines :o Quote Link to comment Share on other sites More sharing options...
Thos Posted December 8, 2005 Report Share Posted December 8, 2005 I know it's not of much help to you but, C:\System Volume Inf is where system restore points, among other things, are kept. It also contains the following - Distributed Link Tracking Service, Content Indexing Service, and Volume Shadow Copy.Well it would help if you expanded the Path section to give us a bit more info like I have done in my screenshot (obviously editing out any confidential info like your name as I have done).Thanks be@vis and Curly. I can only manage a screen shot showing the abbreviated path. I tried another scan this morning and it found 180 entries!So I ran CrapCleaner and scanned again. All had gone except the zero bytes one which I shall ignore.I am inclined not to get concerned any more.Thos. :) Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted December 8, 2005 Report Share Posted December 8, 2005 I can only manage a screen shot showing the abbreviated path. I tried another scan this morning and it found 180 entries!To expand the section just drag the border to the right using the mouse.So I ran CrapCleaner and scanned again. All had gone except the zero bytes one which I shall ignore.They probably disappeared as they were temporary internet files which were flushed out when you run CrapCleaner?I am a bit puzzled as to how an entry can be zero bytes in length though as it wouldn't exist if it was this length :blink: It could just be registry remnants that are being picked up in these cases? Quote Link to comment Share on other sites More sharing options...
Guest be@vis Posted December 8, 2005 Report Share Posted December 8, 2005 Prior to scanning with Rootkit Revealer, a bit of "housework" should be done on the system i.e. run CCleaner, as Thos did, and get rid of any rubbish, particularly old internet files, and clear the browser cache. Most of the items flagged by Rootkit Revealer appear to be just rubbish that's lying around on the HD. Only someone who uses the PC regularly knows what should, or should not, be on the machine so it's difficult for a third party to give advice as to what to do with anything flagged by Rootkit Revealer but, as far as I can make out, Rootkits usually have a title so it may not be too difficult to spot them.Info on rootkits at - http://www.rootkit.com/http://www.sysinternals.com/Forum/forum_topics.asp?FID=15http://www.sysinternals.com/Utilities/RootkitRevealer.html Quote Link to comment Share on other sites More sharing options...
-pops- Posted December 8, 2005 Report Share Posted December 8, 2005 I ran Rootkit Revealer on my main machine and got 19 items flagged up - 12 of them "0" bytes.I ran CCleaner and scanned again and one "0" item remained. I think I'll ignore that one. Quote Link to comment Share on other sites More sharing options...
andsome Posted December 8, 2005 Report Share Posted December 8, 2005 I think we are worrying about nothing.I disagree as according to the title headline of this thread over 20% of SP2 PC's are infected which is rather a lot.I think that most of us on computer forums are lucky as we are sensible and keep our PC's regularly updated with security updates.What about PC newcomers who know little or nothing about security?Also look at what happened with the notorious Sony rootkit, millions of PC's were infected without anyone realising until it made the headlines :oThis is my point. We all keep so many anti crap programs running that I seriously doubt that we need worry. As regards those who do not visit the forum, there is nothing that we can do to help them. I have tried to advise my daughter, but she thinks that I worry about nothing, Whenever I look at her crap top, Adaware and Spybot etc are usually at least three weeks out of date. Windows update never is up to date, and so on. One day she may well be sorry. Quote Link to comment Share on other sites More sharing options...
Thos Posted December 8, 2005 Report Share Posted December 8, 2005 I can only manage a screen shot showing the abbreviated path. I tried another scan this morning and it found 180 entries!To expand the section just drag the border to the right using the mouse.The trouble is that the results are shown full screen with the borders at the extreme edge so I cannot drag the border. I suppose I could take a screen shot with the mouse hovering over creating the full path but I am inclined now to pops and andsome's take on this and not to worry any further.Thos. :) Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.