Topic: EF-ing ROOTKITS  (Read 3366 times)

0 Members and 1 Guest are viewing this topic.

Offline AlchemistiD

  • Lt. Junior Grade
  • *
  • Posts: 440
  • Gender: Male
  • No Replacement For Displacement
EF-ing ROOTKITS
« on: August 22, 2008, 04:36:22 am »
Recently picked up a rootkit infestation.

Which is kind of like catching a cold.  There's no F**************** cure.  So after careful analysis and steps to combat the infestation I took the only course left to me, I shot the patient.

Don't you love it when windows refers to something as a "Destructive Rebuild"? 

I archived everything to disks in safe mode before putting old yeller down, said disks have been checked with fresh versions of every anti-whatever we own. 

I ran zonealarm after, just to put a bullet in the thing's corpse.

Anyone else have trouble with these things?




Offline toasty0

  • Application.Quit();
  • Captain
  • *
  • Posts: 8045
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #1 on: August 22, 2008, 07:10:45 am »

Don't you love it when windows refers to something as a "Destructive Rebuild"? 


 :rofl:
MCTS: SQL Server 2005 | MCP: Windows Server 2003 | MCTS: Microsoft Certified Technology Specialist | MCT: Microsoft Certified Trainer | MOS: Microsoft Office Specialist 2003 | VSP: VMware Sales Professional | MCTS: Vista

Offline Dracho

  • Global Moderator
  • Rear Admiral
  • *
  • Posts: 18289
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #2 on: August 22, 2008, 04:15:52 pm »
Use a tool utility to back up your registry and critical system files.  Unwanted root kit or browser hijack appears, clear it, kill the files and restore clean system files.

Happened to me a couple of weeks ago.. only problem has been with Quicktime for my ITunes app.  I installed it after my last backup but I backed up again, and there is some registry hook so deep I can't completely uninstall Quicktime.  I keep getting a "A new version of quicktime is installed, installation aborting".

Haven't had time or inclination to go after it again yet, but the rest of the system was fine.

Also, on linux or unix, be sure the pword files are in \etc\shadow so they're encrypted.. and always su to root... and using syskey to encrypt your windows SAM database isn't a bad idea either.
« Last Edit: August 22, 2008, 05:37:14 pm by Dracho »
The worst enemy of a good plan is the dream of a perfect plan.  - Karl von Clausewitz

Offline Just plain old Punisher

  • Vice Admiral
  • *
  • Posts: 36927
  • Gender: Male
  • I'm not facist, I just like wearing jackboots
Re: EF-ing ROOTKITS
« Reply #3 on: August 22, 2008, 06:28:26 pm »
I run several rootkit scanners every few weeks during safemode to see if anything ever gets installed. It's frustrating, and it leads people to formating their computer and reinstalling every few months.

"Sex is a lot like pizza.  If you're not careful you can blister your tongue". -Dracho

Offline AlchemistiD

  • Lt. Junior Grade
  • *
  • Posts: 440
  • Gender: Male
  • No Replacement For Displacement
Re: EF-ing ROOTKITS
« Reply #4 on: August 22, 2008, 10:39:46 pm »
Still reloading everything  :'(

Offline Dash Jones

  • Sub-Commander of the Dark Side
  • Captain
  • *
  • Posts: 6477
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #5 on: August 23, 2008, 05:06:10 am »
I run several rootkit scanners every few weeks during safemode to see if anything ever gets installed. It's frustrating, and it leads people to formating their computer and reinstalling every few months.

And exactly how do you do that with Vista.  XP allows a reinstall, but without a ghost, Vista seems to rely on you having something already installed.  Do you do a reformat as well?
"All hominins are hominids, but not all hominids are hominins."


"Is this a Christian perspective?

Now where in the Bible does it say if someone does something stupid you should shoot them in the face?"

-------

We have whale farms in Jersey.   They're called McDonald's.

There is no "I" in team. There are two "I"s in Vin Diesel. screw you, team.

Offline toasty0

  • Application.Quit();
  • Captain
  • *
  • Posts: 8045
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #6 on: August 23, 2008, 10:24:05 am »
I run several rootkit scanners every few weeks during safemode to see if anything ever gets installed. It's frustrating, and it leads people to formating their computer and reinstalling every few months.

And exactly how do you do that with Vista.  XP allows a reinstall, but without a ghost, Vista seems to rely on you having something already installed.  Do you do a reformat as well?

Are you on a network?
MCTS: SQL Server 2005 | MCP: Windows Server 2003 | MCTS: Microsoft Certified Technology Specialist | MCT: Microsoft Certified Trainer | MOS: Microsoft Office Specialist 2003 | VSP: VMware Sales Professional | MCTS: Vista

Offline Dash Jones

  • Sub-Commander of the Dark Side
  • Captain
  • *
  • Posts: 6477
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #7 on: August 23, 2008, 05:55:04 pm »
I suppose, depends on which computer.
"All hominins are hominids, but not all hominids are hominins."


"Is this a Christian perspective?

Now where in the Bible does it say if someone does something stupid you should shoot them in the face?"

-------

We have whale farms in Jersey.   They're called McDonald's.

There is no "I" in team. There are two "I"s in Vin Diesel. screw you, team.

Offline toasty0

  • Application.Quit();
  • Captain
  • *
  • Posts: 8045
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #8 on: August 23, 2008, 06:05:43 pm »
I suppose, depends on which computer.


Not sure this will be helpful, but it might: http://technet.microsoft.com/en-us/library/cc721929.aspx
MCTS: SQL Server 2005 | MCP: Windows Server 2003 | MCTS: Microsoft Certified Technology Specialist | MCT: Microsoft Certified Trainer | MOS: Microsoft Office Specialist 2003 | VSP: VMware Sales Professional | MCTS: Vista

Offline Dash Jones

  • Sub-Commander of the Dark Side
  • Captain
  • *
  • Posts: 6477
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #9 on: August 23, 2008, 06:40:37 pm »
It doesn't really.  That is dependant on not needed to authenticate and not for individual copies from what I see.  Hence, useless.

It also depends on only having one computer as master.

It also, is as it seems, basically making a ghost, but in this case a two computer ghosting process.  You still need an installation to do it as well, so once infected it's still useless.

If you took precautions prior, and kept it up and somehow kept the stuff from spreading over the network, and had the right version, it is plausible.

but it still would rely on a version that probably didn't need authentication from what it looks like.

Otherwise, it seems you're up a creek with Vista.
"All hominins are hominids, but not all hominids are hominins."


"Is this a Christian perspective?

Now where in the Bible does it say if someone does something stupid you should shoot them in the face?"

-------

We have whale farms in Jersey.   They're called McDonald's.

There is no "I" in team. There are two "I"s in Vin Diesel. screw you, team.

Offline toasty0

  • Application.Quit();
  • Captain
  • *
  • Posts: 8045
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #10 on: August 23, 2008, 06:44:26 pm »
It doesn't really.  That is dependant on not needed to authenticate and not for individual copies from what I see.  Hence, useless.

It also depends on only having one computer as master.

It also, is as it seems, basically making a ghost, but in this case a two computer ghosting process.  You still need an installation to do it as well, so once infected it's still useless.

If you took precautions prior, and kept it up and somehow kept the stuff from spreading over the network, and had the right version, it is plausible.

but it still would rely on a version that probably didn't need authentication from what it looks like.

Otherwise, it seems you're up a creek with Vista.

No, it's not "ghosting" or cloning your OS.
MCTS: SQL Server 2005 | MCP: Windows Server 2003 | MCTS: Microsoft Certified Technology Specialist | MCT: Microsoft Certified Trainer | MOS: Microsoft Office Specialist 2003 | VSP: VMware Sales Professional | MCTS: Vista

Offline Dash Jones

  • Sub-Commander of the Dark Side
  • Captain
  • *
  • Posts: 6477
  • Gender: Male
Re: EF-ing ROOTKITS
« Reply #11 on: August 23, 2008, 06:48:05 pm »
Cloning okay...hadn't heard that before so gotta excuse me on not knowing the actual term.
"All hominins are hominids, but not all hominids are hominins."


"Is this a Christian perspective?

Now where in the Bible does it say if someone does something stupid you should shoot them in the face?"

-------

We have whale farms in Jersey.   They're called McDonald's.

There is no "I" in team. There are two "I"s in Vin Diesel. screw you, team.