CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[FIXED]MBR rootkit or false alarm?

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
szaryszakal

Cadet
Cadet


Joined: Apr 30, 2008
Posts: 4
Location: Poland

PostPosted: Wed Apr 30, 2008 8:21 am    Post subject: MBR rootkit or false alarm?
Reply with quote

Heere is some output from Gmer:
---- System - GMER 1.0.14 ----

SSDT \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) ZwCreateProcess [0xF7669662]
SSDT \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) ZwCreateProcessEx [0xF76696F6]
SSDT \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) ZwCreateSection [0xF76690A6]
SSDT \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) ZwCreateThread [0xF7668F5C]
SSDT \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) ZwWriteVirtualMemory [0xF7668FDC]

Code \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) IoCreateDevice

---- User code sections - GMER 1.0.14 ----

.text C:\WINDOWS\system32\SearchIndexer.exe[488] kernel32.dll!WriteFile 7C810D87 7 Bytes JMP 00C91B19 C:\WINDOWS\system32\mssrch.dll (mssrch.lib/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[1876] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 32605629 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)

---- Devices - GMER 1.0.14 ----

AttachedDevice \FileSystem\Ntfs \Ntfs FSfilter.sys
AttachedDevice \FileSystem\Ntfs \Ntfs FSrec.sys

Device \Driver\Tcpip \Device\Ip fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\Tcp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SGEFLT.SYS (PnP Disk Filter Driver/Utimaco Safeware AG)

Device \Driver\Tcpip \Device\Udp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\RawIp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\IPMULTICAST fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

---- Processes - GMER 1.0.14 ----

Process hidden process (*** hidden *** ) 328

---- Disk sectors - GMER 1.0.14 ----

Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior

What I should do ?
Regards,




hijackthis.txt
 Description:
Hijackthis log

Download
 Filename:  hijackthis.txt
 Filesize:  14.13 KB
 Downloaded:  114 Time(s)

Back to top
View users profile Send private message
szaryszakal

Cadet
Cadet


Joined: Apr 30, 2008
Posts: 4
Location: Poland

PostPosted: Thu May 01, 2008 6:24 am    Post subject:
Reply with quote

Any ideas ? I got only one sector changed no copy of MBR detected. But I got this unknow hidden process. Please help me. I don't know what to think about it.
Many Thanks

Back to top
View users profile Send private message
szaryszakal

Cadet
Cadet


Joined: Apr 30, 2008
Posts: 4
Location: Poland

PostPosted: Thu May 01, 2008 3:04 pm    Post subject:
Reply with quote

For this change MBR is responsible pre-boot authentication (PBA) software Now I know but how to idenify this hidden proces if it is safe or not ?

Back to top
View users profile Send private message
negster22

Security Expert
Premium Member

Joined: Mar 10, 2004
Posts: 5394

Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Security Experts SRT

PostPosted: Fri May 02, 2008 2:05 am    Post subject:
Reply with quote

I suspect you are OK and that process maybe due to your SafeGuard disk encryption software. One of its features is that it makes a backup copy of your MBR when it is installed - in the event you experience MBR corruption. You also have many F-Secure processes and services running.

You can run another anti-rootkit program to see if that can identify the name of the hidden process, but first I'd like you to run a program that cleans out your temp files, and browser cache.

Please download ATF Cleaner by Atribune

  • Close Internet Explorer and any other open browsers
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

If you use Firefox browser

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.

If you use Opera browser

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.


Next, download, extract, and run Rootkit Unhooker

1.) Download Rootkit Unhooker (RKU).

Note: Since the RKU archive is in RAR format, you may need this free archiver called 7-Zip to extract it if the do not currently have a archiving program that can deal with the RAR format: http://www.7-zip.org/download.html

2.) Next, it is very important for you to Temporarily Disable Active Protection for any security programs you have enabled, especially HIPs programs (such as Prevx or Process Guard, etc.), while we complete the fixes. You may keep your firewall enabled, but disconnect from the internet.

3.) If you have run Gmer, you must unload the driver before running RKU, by opening a command prompt (start -> run -> cmd) and issuing the following command:
net stop gmer

Arrow Running Rootkit Unhooker:

Double-click rku37300509.exe (the Rootkit Unhooker EXE file) to run the program.

  • Click SSDT- then click File --> Quick Report and save the information on that page.
  • Click Shadow SSDT- then click File --> Quick Report and save the information on that page.
  • Click Processes - then click File --> Quick Report and save the information on that page.
  • Click Drivers- then click File --> Quick Report and save the information on that page.
  • Click Stealth Code- then click File --> Quick Report and save the information on that page.
  • Click Code Hooks Detector- then click File --> Quick Report and save the information on that page.
  • Click Files- then click File --> Quick Report and save the information on that page.
  • Then click the Report tab, followed by the Scan button to start scanning. Do not touch your computer or mouse during the scan.
  • At the end of the scan save the report and post it back here in your next reply. (See Note)
  • Reboot and re-enable all active protection.

Note: Only if the scan is unable to complete successfully, post back the individual reports.


_________________
Negster22 - MS MVP - Consumer Security 2006-2008 image
Back to top
View users profile Send private message Visit posters website
szaryszakal

Cadet
Cadet


Joined: Apr 30, 2008
Posts: 4
Location: Poland

PostPosted: Mon May 12, 2008 11:47 am    Post subject:
Reply with quote

Hmm I have run several rootkit hunter programs and it show nothing now. I run gmer and the same. It was false positive. But thank you for your answer and your time.This post can be marked as closed.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer