Microsoft Beta's Rootkit Removal Tool

Non-Allegiance related. High probability of spam. Pruned regularly.
peet
Posts: 4972
Joined: Sun Jul 16, 2006 6:57 pm
Location: Holland

Post by peet »

http://isc.sans.edu/diary.html

Read very careful (I quote):

The problem with this new bootkit is that it forges the cleaning part. For example, when the security product tries a Write method, the trojan will change to Read. This will make the security product believe that the cleaning was successful while it was not. (*)

and

Regarding MS's Popureb, the current recommendation is to fix the MBR and rebuild the machine.


(*) edit to clarify: this forging of cleaning is when the user has an antivirus running inside the infected operating system. A good antivirus can potentially block the installation of a virus. More advanced cleaning options on an infected operating system can be available with livecd's containing an antivirus product.
Last edited by peet on Sun Jul 03, 2011 5:53 pm, edited 1 time in total.
Image
coopertronic
Posts: 255
Joined: Wed Apr 09, 2008 3:41 am
Location: The Moon
Contact:

Post by coopertronic »

You're scaring the living daylights out of me. i'M SCANNING ALL MY PC'S NOW.

I'm running 4 Linux boxes and 3 Windows boxes here. I'll post the results tomorrow, it's a bit late here now. I did have grub2 menus disaper off a system last week. It was easy to fix with the live disk, but I'm $#@!ed if I know what caused it.

I got 1 warning lwp-request has bee replaced by a script lwp-request which is a perl -w script. This is on linux Mint 10 Julia.

This is the only warning I got. All my machines are virus free and rootkit free.

Admitidly Linux can get infected but I just haven't seen it yet. I see it all the time with Windows machines.
Last edited by coopertronic on Tue Jul 05, 2011 2:18 pm, edited 1 time in total.
Yellow eyed, flat headed hissing maniacs.
peet
Posts: 4972
Joined: Sun Jul 16, 2006 6:57 pm
Location: Holland

Post by peet »

Matt made a video about this M$ tool, so you can see for yourself if it's something for you or not.

http://www.youtube.com/watch?v=oJV12mftZMY
Image
Bard
Posts: 4263
Joined: Tue Jan 24, 2006 8:00 am
Location: Within your command center, enacting fatal attacks upon your conscripts
Contact:

Post by Bard »

coopertronic wrote:QUOTE (coopertronic @ Jul 3 2011, 06:02 PM) You're scaring the living daylights out of me. i'M SCANNING ALL MY PC'S NOW.

I'm running 4 Linux boxes and 3 Windows boxes here. I'll post the results tomorrow, it's a bit late here now. I did have grub2 menus disaper off a system last week. It was easy to fix with the live disk, but I'm $#@!ed if I know what caused it.

I got 1 warning lwp-request has bee replaced by a script lwp-request which is a perl -w script. This is on linux Mint 10 Julia.

This is the only warning I got. All my machines are virus free and rootkit free.

Admitidly Linux can get infected but I just haven't seen it yet. I see it all the time with Windows machines.
Ask Dorjan about Linux boxes getting infected. Apache servers in particular! `gu
ImageImageImageImageImage
Image Omnia Mutantur, Nihil Interit.
coopertronic
Posts: 255
Joined: Wed Apr 09, 2008 3:41 am
Location: The Moon
Contact:

Post by coopertronic »

This is looking good. Malewarebytes is still pretty much essencial and I'm sure there will be a fix for the activation before long. All round it's bloody usful live disk to have.
Yellow eyed, flat headed hissing maniacs.
Dorjan
Posts: 5024
Joined: Sun Oct 07, 2007 9:56 am
Location: England

Post by Dorjan »

Bard wrote:QUOTE (Bard @ Jul 11 2011, 12:14 PM) Ask Dorjan about Linux boxes getting infected. Apache servers in particular! `gu
I was thinking the same thing...
I decided to relive the days gone by in my new blog.
---
Remember, what I say is IMO always. If I say that something sucks, it actually means "I think it sucks" OK?
Cookie Monster wrote:QUOTE (Cookie Monster @ Jan 31 2012, 03:09 PM) True story.

Except the big about dorjan being jelly, that's just spidey's ego.
ImageImage
Andon
Posts: 5453
Joined: Sun Jun 03, 2007 8:29 pm
Location: Maryland, USA
Contact:

Post by Andon »

Everything can be rooted, regardless of what's on there - for the simple reason that with the pace that code is added/removed, you add an exploit for each one you fix. It's just a matter of time before they're found.
Image
ImageImage
raumvogel
Posts: 5910
Joined: Sun Jul 20, 2003 7:00 am
Location: My lawn
Contact:

Post by raumvogel »

Andon wrote:QUOTE (Andon @ Jul 11 2011, 12:59 PM) Everything can be rooted, regardless of what's on there - for the simple reason that with the pace that code is added/removed, you add an exploit for each one you fix. It's just a matter of time before they're found.
And with the entire world looking for them, it won't take long.
Image
Post Reply