Notices

Overclockers Forums > Software > Internet, Networking, and Security
Internet, Networking, and Security Networking and Viruses/Malware trouble. Get the answers here.
Forum Jump

RookitRevealer findings.

Post Reply New Thread Subscribe Search this Thread
 
 
Thread Tools
Old 11-10-05, 08:03 PM Thread Starter   #1
Schalldampfer
Member

 
Schalldampfer's Avatar 

Join Date: Sep 2004
Location: Under a ceiling.

 
RookitRevealer findings.


After hearing so much about the Sony's DRM troubles, I thought I'd give the RootKitRevealer a try, and this is what it found:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Rei nstall\€ 10/16/2005 6:08 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf 40 11/10/2005 4:45 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\User Name\Local Settings\Temp\plugtmp\Map.xml 11/10/2005 7:45 PM 14.88 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\User Name\Local Settings\Temp\plugtmp\parameters.xml 11/10/2005 7:45 PM 569 bytes Visible in Windows API, but not in MFT or directory index.

But, since I'm a complete newbie at this... I don't know what kind of action I should take. Advices will be greatly appreciated. Thanks.
Schalldampfer is offline   QUOTE Thanks
Old 11-10-05, 08:15 PM   #2
Captain Newbie
Senior Django-loving Member

 
Captain Newbie's Avatar 

Join Date: Jan 2004
Location: Right seat with a bored "don't kill me" expression

 
This article has very complete information on the Sony DRM rootkit.

__________________
B.S. Computer Science, B.A. Political Science | Commercial Pilot Airplane Single and Multiengine Land, Instrument Airplane
"And, while with silent lifting mind I've trod
The high untresspassed sanctity of space
Put out my hand, and touched the face of God."

Strong * Focused * Safe
Apple Mac Pro 4,1, Two Nehalem Xeons 2.26GHzx4 (Hyperthreaded), 12 GB DDR3 FBDRAM | MacBook Pro 15" (2009)
Captain Newbie is offline   QUOTE Thanks
Old 11-10-05, 08:57 PM Thread Starter   #3
Schalldampfer
Member

 
Schalldampfer's Avatar 

Join Date: Sep 2004
Location: Under a ceiling.

 
Quote:
Originally Posted by Captain Newbie
This article has very complete information on the Sony DRM rootkit.
Thanks for the article, but I'm looking for some help on my system, and I have no Sony music CD's that are recent.
Schalldampfer is offline   QUOTE Thanks
Old 11-11-05, 01:44 AM   #4
klingens
Member



Join Date: Apr 2002
Location: Xanadu

 
No, you don't have a rootkit installed.
klingens is offline   QUOTE Thanks
Old 11-11-05, 08:38 PM Thread Starter   #5
Schalldampfer
Member

 
Schalldampfer's Avatar 

Join Date: Sep 2004
Location: Under a ceiling.

 
Thanks for the assurance, Klingens, but how did you find that out?
Schalldampfer is offline   QUOTE Thanks
Old 11-12-05, 01:52 PM   #6
klingens
Member



Join Date: Apr 2002
Location: Xanadu

 
For starters, none of the displayed file is an executable. No driver in there either. And tmp files which are visible from DosFindFile but not in the MFT, are files which are currently open, but not saved/closed before. Especially since they're in temp folders...
And it's really hard to hide data in registry keys that are 0 bytes in length.

Last but not least: a rootkit is bigger than 15kB over all.

Any more questions?
klingens is offline   QUOTE Thanks

Post Reply New Thread Subscribe


Overclockers Forums > Software > Internet, Networking, and Security
Internet, Networking, and Security Networking and Viruses/Malware trouble. Get the answers here.
Forum Jump

Thread Tools Search this Thread
Search this Thread:

Advanced Search


Mobile Skin
All times are GMT -5. The time now is 10:21 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
You can add these icons by updating your profile information to include your Heatware ID, Benching Profile ID or your Folding/SETI profile ID. Edit your profile!
X

Welcome to Overclockers.com

Create your username to jump into the discussion!

New members like you have made this the best community on the Internet since 1998!


(4 digit year)

Why Join Us?

  • Share experience
  • Max out your hardware
  • Best forum members anywhere
  • Customized forum experience

Already a member?