site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies

qrkx
Premium
join:2003-04-26
Montreal, QC

reply to Blackbird

Re: One in Five PC's Infected With Rootkits

said by Blackbird:

To clarify: I'm not accusing them. It's just that when you make, sell, and use hammers intensively, everything can start to look like a nail.
Well - nine out of seven dentists believe scotch is better than Novocain.

I thought it is agreed upon the fact that once root-ed zee boxen needs to be incinerated.

What I find amusing is that by the very attempt of hiding their presence, rootkits give themselves away. What if rootkits stop hooking enumerating&query API's and just operate in your face? Are we back to file signatures?

rgds.



Blackbird
Built for Speed
Premium
join:2005-01-14
Fort Wayne, IN
kudos:2
Reviews:
·Frontier Communi..

said by qrkx:

...I thought it is agreed upon the fact that once root-ed zee boxen needs to be incinerated. ...
Nah... just the hard-drives and firmware flash chips. And in those rare instances of really pesky rootkits, the metal chassis may have to be scrubbed and rinsed thoroughly... or better still, repainted.
--
If God wanted us to work with electrons, He'd make them big enough to see...

Qwerky

join:2006-05-24
Adanac

reply to qrkx

said by qrkx:

Well - nine out of seven dentists believe scotch is better than Novocain.
And five out of four people have trouble with fractions.

But three out of five people, aren't the other two.

Anyway, is SysInternals RootkitRevealer sufficient, or should one be using more/different tools?
--
Mr. Qwerky - The Lone Stranger
Hi-Ho Tinfoil, Away!

lefty1

join:2002-10-25
Clay, NY
Reviews:
·Time Warner Cable

Anyway, is SysInternals RootkitRevealer sufficient, or should one be using more/different tools?
While running SystInternals RootkitRevealer, it stops every minute or so and gives me an error message about only having partial compatibility with Vista. Now why am I not surprised by that?


AB
Premium
join:2006-04-04
Leesburg, VA
kudos:3
Reviews:
·Verizon Online DSL

1 edit

said by lefty1:

While running SystInternals RootkitRevealer, it stops every minute or so and gives me an error message about only having partial compatibility with Vista. Now why am I not surprised by that?
The most recent version of RR seems to have been released on 11/1/2006-- prior to Vista.
Likely why.

*Edit- sp

Tuesday, 29-May 16:49:06 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics