http://isc.sans.edu/diary.html
Read very careful (I quote):
The problem with this new bootkit is that it forges the cleaning part. For example, when the security product tries a Write method, the trojan will change to Read. This will make the security product believe that the cleaning was successful while it was not. (*)
and
Regarding MS's Popureb, the current recommendation is to fix the MBR and rebuild the machine.
(*) edit to clarify: this forging of cleaning is when the user has an antivirus running inside the infected operating system. A good antivirus can potentially block the installation of a virus. More advanced cleaning options on an infected operating system can be available with livecd's containing an antivirus product.
Microsoft Beta's Rootkit Removal Tool
-
coopertronic
- Posts: 255
- Joined: Wed Apr 09, 2008 3:41 am
- Location: The Moon
- Contact:
You're scaring the living daylights out of me. i'M SCANNING ALL MY PC'S NOW.
I'm running 4 Linux boxes and 3 Windows boxes here. I'll post the results tomorrow, it's a bit late here now. I did have grub2 menus disaper off a system last week. It was easy to fix with the live disk, but I'm $#@!ed if I know what caused it.
I got 1 warning lwp-request has bee replaced by a script lwp-request which is a perl -w script. This is on linux Mint 10 Julia.
This is the only warning I got. All my machines are virus free and rootkit free.
Admitidly Linux can get infected but I just haven't seen it yet. I see it all the time with Windows machines.
I'm running 4 Linux boxes and 3 Windows boxes here. I'll post the results tomorrow, it's a bit late here now. I did have grub2 menus disaper off a system last week. It was easy to fix with the live disk, but I'm $#@!ed if I know what caused it.
I got 1 warning lwp-request has bee replaced by a script lwp-request which is a perl -w script. This is on linux Mint 10 Julia.
This is the only warning I got. All my machines are virus free and rootkit free.
Admitidly Linux can get infected but I just haven't seen it yet. I see it all the time with Windows machines.
Last edited by coopertronic on Tue Jul 05, 2011 2:18 pm, edited 1 time in total.
Yellow eyed, flat headed hissing maniacs.
Matt made a video about this M$ tool, so you can see for yourself if it's something for you or not.
http://www.youtube.com/watch?v=oJV12mftZMY
http://www.youtube.com/watch?v=oJV12mftZMY

-
Bard
- Posts: 4263
- Joined: Tue Jan 24, 2006 8:00 am
- Location: Within your command center, enacting fatal attacks upon your conscripts
- Contact:
Ask Dorjan about Linux boxes getting infected. Apache servers in particular! `gucoopertronic wrote:QUOTE (coopertronic @ Jul 3 2011, 06:02 PM) You're scaring the living daylights out of me. i'M SCANNING ALL MY PC'S NOW.
I'm running 4 Linux boxes and 3 Windows boxes here. I'll post the results tomorrow, it's a bit late here now. I did have grub2 menus disaper off a system last week. It was easy to fix with the live disk, but I'm $#@!ed if I know what caused it.
I got 1 warning lwp-request has bee replaced by a script lwp-request which is a perl -w script. This is on linux Mint 10 Julia.
This is the only warning I got. All my machines are virus free and rootkit free.
Admitidly Linux can get infected but I just haven't seen it yet. I see it all the time with Windows machines.
-
coopertronic
- Posts: 255
- Joined: Wed Apr 09, 2008 3:41 am
- Location: The Moon
- Contact:
I was thinking the same thing...Bard wrote:QUOTE (Bard @ Jul 11 2011, 12:14 PM) Ask Dorjan about Linux boxes getting infected. Apache servers in particular! `gu
I decided to relive the days gone by in my new blog.
---
Remember, what I say is IMO always. If I say that something sucks, it actually means "I think it sucks" OK?


---
Remember, what I say is IMO always. If I say that something sucks, it actually means "I think it sucks" OK?
Cookie Monster wrote:QUOTE (Cookie Monster @ Jan 31 2012, 03:09 PM) True story.
Except the big about dorjan being jelly, that's just spidey's ego.


And with the entire world looking for them, it won't take long.Andon wrote:QUOTE (Andon @ Jul 11 2011, 12:59 PM) Everything can be rooted, regardless of what's on there - for the simple reason that with the pace that code is added/removed, you add an exploit for each one you fix. It's just a matter of time before they're found.






Omnia Mutantur, Nihil Interit.

