republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » One in Five PC's Infected With Rootkits
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
AVG7.5 Free Update Manager problems »
« Avira AntiVir Personal Classic and Premium  
AuthorAll Replies


AB
Premium
join:2006-04-04
Leesburg, VA

reply to Bubba17
Re: One in Five PC's Infected With Rootkits

said by Bubba17 See Profile :

said by AB See Profile :

I think I owe a debt of gratitude to SipSizurp's and the others' clients though, that shouldered the burden and helped to keep me in that other 75 or 80% percentile.
Whew! Close one!
You found something?
Nope. Not a thing.

This is why I'm in that 'other percentile'.


Bubba17
Less is More
Premium
join:2006-09-21

reply to AB
said by AB See Profile :

I think I owe a debt of gratitude to SipSizurp's and the others' clients though, that shouldered the burden and helped to keep me in that other 75 or 80% percentile.
Whew! Close one!
You found something? And, successfully eradicated it?

You used RkU? Did you try GMER?
--
HN7000s | Horizons 1 (127W) | Gateway: 1110Mhz | Dish: .98m 2 Watt | Pro+

"Fast is fine, but accuracy is everything" --Wyatt Earp


AB
Premium
join:2006-04-04
Leesburg, VA

reply to Bubba17
said by Bubba17 See Profile :

Notice ... I didn't announce I was clean.
Yes, I notice that.
Well, allow me to announce-- my machine is clean!
Yeah, baby! Yee-haaa!

I think I owe a debt of gratitude to SipSizurp's and the others' clients though, that shouldered the burden and helped to keep me in that other 75 or 80% percentile.
Whew! Close one!

Thanks, gents!


fatdcuk
Premium
join:2005-02-20
England


2 edits
reply to Bubba17
Here is the GMER 1.0.14 Beta link>>>
»www2.gmer.net/beta/

I've been using the Beta version for around 4 weeks now and can safely say it is more stable for my setup and has gained some more functionability over the previous version:)


Bubba17
Less is More
Premium
join:2006-09-21

reply to fatdcuk
Well, based on the test results you've shared (again, thanks), I obtained GMER 1.0.13 (wasn't able to obtain your beta version) and it's not finding anything.

Notice ... I didn't announce I was clean.


fatdcuk
Premium
join:2005-02-20
England


1 edit
reply to daveinpoway
Sorry for the delay folks but as promised yesterday here is are the screenshots/data returned from testing some of the tools mentioned in this thread versus samples from my Zoo collection.

All RK malwares used have been harvested from in the wild infections over the last 18months and there are no proof-of-concept RK's used.These are live malware rootkits

Testbed1(loaded malware RK's)
1)Rustock B (huy32.sys)
2)Nulprot (asc3550.sys+asc3550p.sys)*
3)Haxdoor (ntio256.sys+protector.exe)
4)Srizbi (Eyvw95.sys)
5)Cutwail/Bulknet (Runtime2.sys)**

*Imports a secondary infection from the WWW that is not hidden.
**Drops other files after installation that are not hidden.

Prev-X CSI= 4/5 Is blind to Nulprot.



AVG AntiRootKit= 4/5 Is blind to Nulprot.


RKU= 4/5 Is blind to Nulprot.


GMER 1.0.14 Beta= 5/5


Nulprot VT upload today>>>
»www.virustotal.com/resultado.htm···7b697495

Testbed2(loaded malware RK's)
1)Rustock A (lzx32.sys)
2)Wincom32 (Wincom32.sys)
3)TR.inject/allinone(VideoAti0.sys+dll+exe)
4)Haxdoor.sm(Pasksa.dll+p81eskse.sys)

Prev X CSI= 3/4 Blind to Allinone


AVG AntiRootKit= 4/4


RKU =4/4


GMER 1.0.14Beta= 4/4


TR.Inject/Allinone VT report today>>>
»www.virustotal.com/resultado.htm···f327bde6
Forums » Up and Running » Security » SecurityAVG7.5 Free Update Manager problems »
« Avira AntiVir Personal Classic and Premium  


Tuesday, 01-Dec 02:07:27 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [56] Baltimore To Ban Lazy Cable Installs
· [47] Broadband Killed The Game Console
· [33] Rural Carriers Quickly Embracing Fiber
· [28] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [24] Charter Exits Chapter 11
· [21] Midcontinent Socked With Easement Lawsuit
· [3] Monday Morning Links
· [2] Monday Evening Links
Most people now reading
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Rant] called out sick! [Rants, Raves, and Praise]
· persistent connection to qw-in-f113.1e100.net on boot [Security]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· [Future9] Guaging interest. [VOIP Tech Chat]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]