Announcement

Collapse
No announcement yet.

Lets chat about .... ROOTKITS !!

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Lets chat about .... ROOTKITS !!

    Got a customer PC over the weekend that they simply wanted Itunes installed on. Wow, an easy one I'm thinking. I start the install and it locks up the PC.

    Skip forward to several scans using everything I've got, and I finally get around to scanning for a rootkit. OOPS ... well, there it is, hiding in the Windows/Temp folder with several $dgb3 or similar filenames in there, along with some perflibxx.dat files that appear to be prefetch data for the bad stuff stored elsewhere.

    ComboFix found it and said it deleted it, but it was right back when I restarted. MalwareBytes the same thing. I tried a product from McAfee and Sophos with the same results.

    My S.O.P. for these is nuke it from orbit, but the customer doesn't want to do that, so is there ANYTHING that you guys have used that can effectively deal with a rootkit ?? I doubt there is, but I have few options. I'm going to try and talk them into wiping it and I'll use the Easy Transfer wizard to back up what I can.
    Oh if a man tried to take his time on Earth and prove before he died what one man's life could be worth, well I wonder what would happen to this world ? - Harry Chapin

    #2
    Wow, that sounds nasty. You've already tried malwarebytes so I don't have anything to recommend.
    [SIZE=1][B]"Now more than ever the people are responsible for the character of their Congress. If that body be ignorant, reckless, and corrupt, it is because the people tolerate ignorance, recklessness, and corruption." ~President James Garfield[/B][/SIZE]
    <<< Please [URL="http://www.cainslair.com/misc.php?do=donate"]donate[/URL] >>>

    Comment


      #3
      One option, always, NUKE IT.

      Comment


        #4
        Ya, there is no option to safely guarantee its removal at this point. Gonna call the customer and convince him we NEED to nuke it.

        I don't like even working on rootkitted PCs on my home network ... makes me very paranoid, but at least I'm smart enough to password any file shares or access, so it won't be spreading around.

        Thumb drives tho .... that's another story altogether.
        Oh if a man tried to take his time on Earth and prove before he died what one man's life could be worth, well I wonder what would happen to this world ? - Harry Chapin

        Comment


          #5
          What about hijackthis and removing everything?

          Comment


            #6
            Originally posted by mapes View Post
            What about hijackthis and removing everything?
            If MalwareBytes or ComboFix can't remove it permanently, HJT is not gonna do the trick. The thing has several hooks and hidden system calls to replace the .DLL files that I remove after a reboot, and in my experience this is wasted effort when I can run the Win7 Easy Transfer Wizard to back up their data, then blow away all partitions and format that b*tch.
            Oh if a man tried to take his time on Earth and prove before he died what one man's life could be worth, well I wonder what would happen to this world ? - Harry Chapin

            Comment


              #7
              Honestly, you've done the appropriate level of effort.
              I don't know who the customer is, but, your the knowledgeable one.
              Explain to the customer the proper way to store important data they don't wish to lose (on removable/external media) due to such instances. Also elaborate on why it's so important in this day in technology due to how volatile computer data has become with the infection risk with today's computers.
              Then create an image of the machine, ghost, etc.
              Finally NUKE IT!!!!!!!!!!!!!!!!!!!
              [IMG]http://thepebkac.net/images/sigs/Outdoors_sig.jpg[/IMG]
              Like the community? Donate here:
              [URL="http://www.cainslair.com/misc.php?do=donate"]http://www.cainslair.com/misc.php?do=donate[/URL]

              Comment


                #8
                Take notes boys. There are inerrant risks at downloading pron.
                [COLOR="#008080"][/COLOR][SIZE="5"][COLOR="LightBlue"][B]Not everything that counts on the battlefield is countable.[/B][/COLOR][/SIZE]

                Comment


                  #9
                  If he will not let you "Nuke It", give him back his computer and let someone else fight with him. Especially since you were only going to install Itunes.
                  Apache

                  Where do you put the Bayonet?
                  Chesty Puller (upon seeing a flamethrower for the first time)
                  I am all in favor of keeping dangerous weapons out of the hands of fools. Lets start with typewriters.
                  Frank Lloyd Wright

                  Comment


                    #10
                    OOPSIE, I did an oopsie ... is that redundant ?? I backed up the PC using Easy Transfer wizard and when I go to plug in the external drive and run it on the 'new' PC, it only lists it as the OLD PC.

                    I swear I have done this in the past ... back up an XP PC using this utility, then reload the profiles using the freshly loaded OS as the 'new' PC.

                    So now I hafta either set up a Vista box or Win7 box, load the savedata.mig file containing their 22+gb of data and then copy that (manually ?) onto the old WIN XP box ... this is turning into a total clusterf ....
                    Oh if a man tried to take his time on Earth and prove before he died what one man's life could be worth, well I wonder what would happen to this world ? - Harry Chapin

                    Comment


                      #11
                      Originally posted by WalkinTarget View Post
                      If MalwareBytes or ComboFix can't remove it permanently, HJT is not gonna do the trick. The thing has several hooks and hidden system calls to replace the .DLL files that I remove after a reboot, and in my experience this is wasted effort when I can run the Win7 Easy Transfer Wizard to back up their data, then blow away all partitions and format that b*tch.


                      I ran into something like this. I timed the creation of the file and registry keys. I delete the file and registry keys and pulled the plug on the system. Worked for me.

                      Comment


                        #12
                        Skipped the tedious migration onto a Vista/Win7 box and found a handy tool named MigrationRecovery from MS that extracts the .MIG file into its original directory structure.

                        Then its just a matter of adding accounts to the customer PC to match what was there and copying the relevant files/folders into each account on the PC once the migrecover.exe finishes its task.

                        So many other things I could be going with my free time !!
                        Oh if a man tried to take his time on Earth and prove before he died what one man's life could be worth, well I wonder what would happen to this world ? - Harry Chapin

                        Comment


                          #13
                          Your time should not be free.
                          Apache

                          Where do you put the Bayonet?
                          Chesty Puller (upon seeing a flamethrower for the first time)
                          I am all in favor of keeping dangerous weapons out of the hands of fools. Lets start with typewriters.
                          Frank Lloyd Wright

                          Comment


                            #14
                            Originally posted by Apache Warrior View Post
                            Your time should not be free.
                            Apache
                            Ohh, trust me, I am getting paid for the work, but my rates are too low.Standard flat rate for malware removal is $40, and for an OS reload its $50. I should raise both at least $10 and it'd make it somewhat more worthwhile.
                            Oh if a man tried to take his time on Earth and prove before he died what one man's life could be worth, well I wonder what would happen to this world ? - Harry Chapin

                            Comment

                            Cain's Lair Forums Statistics

                            Collapse

                            Topics: 26,187   Posts: 269,850   Members: 6,183   Active Members: 7
                            Welcome to our newest member, Fermin13Q.

                            Today's Birthdays

                            Collapse

                            Top Active Users

                            Collapse

                            There are no top active users.

                            More Posts

                            Collapse

                            • Reply to Hi guys!
                              by Evil_T0NY {CLR}
                              I've been Alpha and will be Beta testing the Delta Force game. It's been really getting good reviews! Definitely a good Battlefield feel to it like the...
                              14 Nov 2024, 08:50 PM
                            • Reply to Hope your all OK over there
                              by Apache Warrior
                              We had 17 inches of rain from the storm on November 7, 2024.
                              Apache
                              11 Nov 2024, 07:55 AM
                            • Reply to Hope your all OK over there
                              by Sirex
                              Aye, I'm inclined to agree with that lmao
                              Gone are the days of warm summers and snow filled winters here, nothing but rain and wind for 8mths of...
                              10 Nov 2024, 08:53 PM
                            • Reply to Hope your all OK over there
                              by Apache Warrior
                              Now we have had a lot of flooding in this area and there are still a lot of houses that have not been repaired. Must be the apocalypse.
                              ...
                              8 Nov 2024, 09:23 AM
                            Working...
                            X