CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

RK the next generation....

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Wed Sep 20, 2006 6:11 am    Post subject: RK the next generation....
Reply with quote

Prince_Serendip wrote:
Researchers discover 'invisible' rootkit
Will run on Vista too


http://www.pcadvisor.co.uk/news/index.cfm?newsid=6606


Quote:
and the SYS driver is polymorphic, changing its code from sample to sample.


Besides its new non hooking and being very hard to find its polymorphic sig is an insidious mix.

i think reading that link will show some of the things i have been saying are comeing about.

i see it uses ads quite well.

there should be a way of loging ads on clean machines as a base and compareing memory use of that with infected machines.
jmho


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Wed Sep 20, 2006 10:13 pm    Post subject:
Reply with quote

That rootkit is pe386 and some variants use ADS to hide their rootkit driver on (NTFS file systems) in the system32 folder. It uses a SYSENTER hook, and does not hook the SSDT, IceSword, AVG Anti-Rootkit Beta, GMER, DarkSpy, Sophos AR - all detect it. With IceSword you must use the registry funtion to see the service autostart. CombFix detects it but cannot remove it.

The AVG Anti-Rootkit Beta is probably the easiest way to remove it. Sophos can detect it but it will crash the system if removal is attempted. (they warn you not to remove it). Merjin's ADS Spy can also remove the ADS streams once the pe386 driver is uncloaked, by removing the service autostart and rebooting.

Check this GMER video out:
http://www.gmer.net/pe386.wmv

ADS were used by CWS in Their Home Search Asst. variant about three years ago. But this new threat combines ADS and a rootkit.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer