|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
wawadave
Special Response Team Special Response Team
 Joined: Nov 22, 2002 Posts: 21503 Location: Installing Vista http://tinyurl.com/2l9qyd
|
Posted: Wed Sep 20, 2006 6:11 am Post subject: RK the next generation.... |
|
|
| Quote: | | and the SYS driver is polymorphic, changing its code from sample to sample. |
Besides its new non hooking and being very hard to find its polymorphic sig is an insidious mix.
i think reading that link will show some of the things i have been saying are comeing about.
i see it uses ads quite well.
there should be a way of loging ads on clean machines as a base and compareing memory use of that with infected machines.
jmho _________________ Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5394
|
Posted: Wed Sep 20, 2006 10:13 pm Post subject: |
|
|
That rootkit is pe386 and some variants use ADS to hide their rootkit driver on (NTFS file systems) in the system32 folder. It uses a SYSENTER hook, and does not hook the SSDT, IceSword, AVG Anti-Rootkit Beta, GMER, DarkSpy, Sophos AR - all detect it. With IceSword you must use the registry funtion to see the service autostart. CombFix detects it but cannot remove it.
The AVG Anti-Rootkit Beta is probably the easiest way to remove it. Sophos can detect it but it will crash the system if removal is attempted. (they warn you not to remove it). Merjin's ADS Spy can also remove the ADS streams once the pe386 driver is uncloaked, by removing the service autostart and rebooting.
Check this GMER video out:
http://www.gmer.net/pe386.wmv
ADS were used by CWS in Their Home Search Asst. variant about three years ago. But this new threat combines ADS and a rootkit. _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|