CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

RED ALERT: New Rootkits in the Wild
Goto page Previous  1, 2, 3, 4, 5, 6, 7  Next
 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Jul 02, 2007 2:45 pm    Post subject: Troj/NtRootK-BX
Reply with quote

Troj/NtRootK-BX

Type Rootkit

Troj/NtRootK-BX is a kernel driver rootkit for the Windows platform.

Identification available since 2 July 2007

http://www.sophos.com/security/analyses/trojntrootkbx.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Jul 09, 2007 3:10 pm    Post subject: Rootkit:W32/Agent.EA
Reply with quote

Rootkit:W32/Agent.EA

Alias: Trojan.Srizbi, Agent.ea, Rootkit.Win32.Agent.ea

Type: Trojan, Rootkit

Summary
Rootkit.Win32.Agent.ea is kernel malware that hides itself and sends spam messages.


Disinfection

Detection and Disinfection of Rootkits

If the rootkit is not detected or it is hidden so that F-Secure Anti-Virus cannot detect its file, it is still possible to detect the malicious activity by scanning the system with a generic rootkit scanner, such as F-Secure BlackLight.

http://www.f-secure.com/v-descs/rootkit_w32_agent_ea.shtml


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Thu Jul 12, 2007 2:10 pm    Post subject: Troj/Rootkit-BJ
Reply with quote

Name Troj/Rootkit-BJ

Type Trojan

Troj/Rootkit-BJ is a rootkit component for the Windows platform.

Troj/Rootkit-BJ is installed by other malware as a system driver, then is used to hide processes

Protection available since 12 July 2007

http://www.sophos.com/security/analyses/trojrootkitbj.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Fri Jul 27, 2007 2:11 am    Post subject: Troj/NTRootK-BY
Reply with quote

Troj/NTRootK-BY

Type Trojan

Side effects Reduces system security
Dropped by malware

Aliases Rootkit.Win32.Agent.dw
VirTool:WinNT/Marun.gen!A


Troj/NTRootK-BY is a rootkit Trojan for the Windows platform

Protection available since 27 July 2007

http://www.sophos.com/security/analyses/trojntrootkby.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Thu Aug 09, 2007 10:43 pm    Post subject: Troj/NTRootK-BZ
Reply with quote

Troj/NTRootK-BZ

Type Trojan

Troj/NTRootK-BZ is a Trojan for the Windows platform

Protection available since 9 August 2007

http://www.sophos.com/security/analyses/trojntrootkbz.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Wed Aug 29, 2007 1:55 am    Post subject: RTKT_XCP.B
Reply with quote

RTKT_XCP.B

Malware type: Others


Malware Overview

This rootkit arrives on a system as part of the Sony MicroVault USM-F fingerprint reader application. The said application allows a user to restrict access to files stored in the Sony MicroVault USM-F USB drive through the recognition of user-preset fingerprints.

Once the application is installed, this rootkit is also installed as a driver which is capable of hiding processes under the Windows folder.

The path and files inside the hidden processes are not visible to the user.

More:


http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=RTKT%5FXCP%2EB


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Sep 10, 2007 2:28 pm    Post subject: Troj/RootKit-BM
Reply with quote

Name Troj/RootKit-BM
Type Trojan

Affected operating systems Windows

Side effects Reduces system security

Troj/RootKit-BM is a rootkit for the Windows platform.


Protection available since 10 September 2007

http://www.sophos.com/security/analyses/trojrootkitbm.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Sep 10, 2007 5:47 pm    Post subject: Troj/NTRootK-CC
Reply with quote

Name Troj/NTRootK-CC
Type

* Trojan

Affected operating systems

* Windows

Protection available since 10 September 2007

http://www.sophos.com/security/analyses/trojntrootkcc.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Oct 08, 2007 4:42 pm    Post subject: Troj/NtDwnl-A
Reply with quote

Name Troj/NtDwnl-A
Type Rootkit

Affected operating systems Windows

Side effects Modifies data on the computer
Downloads code from the internet
Installs itself in the Registry

Troj/NtDwnl-A is a downloader and a rootkit Trojan for the Windows platform.

Once installed Troj/NtDwnl-A modifies the Windows Start Page and overwrites the HOSTS file.



Identification available since 8 October 2007

http://www.sophos.com/security/analyses/trojntdwnla.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Tue Oct 09, 2007 5:15 am    Post subject: Troj/NtDwnl-B
Reply with quote

Name Troj/NtDwnl-B
Type Rootkit

Affected operating systems Windows

Side effects Modifies data on the computer
Downloads code from the internet

Troj/NtDwnl-B is a Trojan for the Windows platform.

Troj/NtDwnl-B includes functionality to download code from the internet and to modify the Start Page settings

Identification available since 9 October 2007

http://www.sophos.com/security/analyses/trojntdwnlb.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Tue Nov 06, 2007 3:43 pm    Post subject: Troj/RootCK-Gen
Reply with quote

Troj/RootCK-Gen

Type Rootkit

Affected operating systems Windows

Identification available since 6 November 2007

http://www.sophos.com/security/analyses/trojrootckgen.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Fri Nov 09, 2007 4:23 pm    Post subject: Troj/RootKC-Gen
Reply with quote

Troj/RootKC-Gen

Type Rootkit

Affected operating systems Windows


Identification available since 9 November 2007

http://www.sophos.com/security/analyses/trojrootkcgen.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Sat Nov 17, 2007 3:51 pm    Post subject: W32/Tdibd-C
Reply with quote

W32/Tdibd-C
Rootkit


Type Rootkit

How it spreads Removable storage devices

Affected operating systems Windows

Side effects Steals information
Records keystrokes
Installs itself in the Registry
Leaves non-infected files on computer

Identification available since 17 November 2007

http://www.sophos.com/security/analyses/w32tdibdc.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Tue Nov 20, 2007 6:10 am    Post subject: Troj/NTRootK-CE
Reply with quote

Troj/NTRootK-CE

Type Rootkit

Affected operating systems Windows


Identification available since 20 November 2007

http://www.sophos.com/security/analyses/trojntrootkce.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11730

MVP Premium Rootkit Experts Security Experts

PostPosted: Sun Nov 25, 2007 5:16 pm    Post subject: Troj/NTRootK-CF
Reply with quote

Name Troj/NTRootK-CF
Type Trojan

Affected operating systems Windows

Side effects Dropped by malware

Aliases VirTool:Win32/Rootkitdrv.CK


Protection available since 25 November 2007

http://www.sophos.com/security/analyses/trojntrootkcf.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page Previous  1, 2, 3, 4, 5, 6, 7  Next
Page 4 of 7

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer