Archive for the ‘Rootkits’ Category

Got Root?

November 17th, 2008

Our Sandbox has some cool new features:

- It collects rootkits that are totally invisible to Windows

- an XML event log is dynamically generated for automated adjudication

Jerome Segura

  • Posted in Rootkits
  • |
  • (0) comments
  • |
  • Add your comments

Kit of the root (RootKit)

July 3rd, 2008

There is something annoying about certain pieces of malware: they are shy and hide from you. :(

However, they do some real nasty stuff in the background, so much so that you may want to get rid of them.

I was analyzing some malware samples and found this fake Soundman.exe (the real one is a process from RealTek sound cards). I use Process Explorer (a better Taskmanager-like utility) to show me what running processes are on my PC, and see this SoundMan.exe process, right there, doing some bad stuff.

 

Process Explorer tells me that the file is located under c:\Windows, but I can’t find it!

 Reason is, this file is a rootkit, which means it has capability of hidding itself from Windows, as well as other processes. If Windows won’t show it to you, most likely your Anti Virus won’t either. You may want to use a rootkit scanner to find it out, there are several free tools available. Keep it mind though that not all rootkit scanners will detect AND let you remove the files.

Personally, I prefer to use a more “hands on” approach: I grab a Linux boot CD (here I use Ubuntu, one of Linux’s several distros) and reboot the PC under the Linux OS. Then I mount the Windows disk, search for the file and voila!

It is there indeed :) Now I feel free to delete it from the system, and can safely reboot. Bye, bye Rootkit :)

By the way, the file is effectively malware:

Jerome Segura

  • Posted in Rootkits
  • |
  • (0) comments
  • |
  • Add your comments




Location

You are currently browsing the archives for the Rootkits category.




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.