Re: WARNING: New Rootkit?




"Gabriela Salvisberg" <salvie@xxxxxxxxxxxx> wrote in message news:39n252lfgcfpub1orkg8unm6847utimcsp@xxxxxxxxxx
comphelp@xxxxxxxxx (Todd H.) wrote:

Gabriela Salvisberg <salvie@xxxxxxxxxxxx> writes:
You could additionally try F-Secure's Blacklight, which not only scans
for rootkits but also should be able to remove them:
http://www.f-secure.com/blacklight/try.shtml

But if you've been owned enough to have a full rootkit installed on a
given machine, you'd be completely nuts to trust any tool to remove a
rootkit. :-)

I agree. Because you never know what someone might already have
(remotely) done with it.

But that is ancillary to the removal of the rootkit, just as removing a backdoor
may be simple - but you don't know what else was done while it was active.

You'd want to reformat and reinstall from original media.

You're right. If it was my machine, I wouldn't trust it anymore,
unless it got formatted and reinstalled.

If I had reason to believe that it wasn't actually used maliciously, I would
just remove it. Otherwise, - that's what a good backup strategy is for.

But in my opinion: Between "don't do anything about the malware" and
"format and reinstall" there's the "remove malware" option, which is
still a bit (only a *little* bit!) better than doing nothing.

:))


.



Relevant Pages

  • Re: Rootkit avoidance: formatting/reloading a good idea or silly overkill?
    ... I think that Curt you really read my original post incorrectly because I ... If you have a rootkit then you cannot trust your machine because of the ... If you have Windows 2000 & want Vista on your system. ...
    (microsoft.public.windowsxp.general)
  • Re: My account was hacked, I would like to share my story to warn others.
    ... temporary internet files when I seen that something had come from ... I'm also not one for straying to websites I don't trust. ... Sounds like you got a rootkit. ... hard it is to create alternate boot systems with Windows. ...
    (alt.games.warcraft)
  • Re: WARNING: New Rootkit?
    ... comphelp@xxxxxxxxx (Todd H.) wrote: ... But if you've been owned enough to have a full rootkit installed on a ... If it was my machine, I wouldn't trust it anymore, ... Between "don't do anything about the malware" and ...
    (alt.comp.anti-virus)
  • Re: Scanning for rootkits
    ... Moby Dick of a rootkit. ... The reason I call it that is that it showed up ... one time when I was scanning my system with spysweeper, ... Post the logs at a specialist Forum: ...
    (microsoft.public.windows.vista.general)
  • Re: system information file
    ... Symantec definately isn't strong when it comes to rootkit detection. ... A file the user has reason to believe is there but isnt visible sounds ... Just my opinion but its worth looking at. ...
    (microsoft.public.windowsxp.general)