<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 Forums - Coffeehouse - I&#39;ve got a rootkit...</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Forums/rss"></atom:link>
	<image>
		<url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
		<title>Channel 9 Forums - Coffeehouse - I&#39;ve got a rootkit...</title>
		<link>http://channel9.msdn.com/Forums</link>
	</image>
	<description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
	<link>http://channel9.msdn.com/Forums</link>
	<language>en</language>
	<pubDate>Thu, 23 May 2013 08:52:02 GMT</pubDate>
	<lastBuildDate>Thu, 23 May 2013 08:52:02 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<c9:totalResults>38</c9:totalResults>
	<c9:pageCount>-38</c9:pageCount>
	<c9:pageSize>-1</c9:pageSize>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>Apparently my Windows 7 x64 laptop is infected with something, it intercepts HTTP traffic and hijacks links to different websites to webplains.net, which then issues HTTP redirects to various websites that have presumably paid for this &quot;service&quot;.</p><p>It works regardless of what browser is used, and it only seems to affect Google.com search results (so Bing has a use after all).</p><p>Some searching, especially for &quot;webplains.net&quot; suggests this may be the work of a known malware, TDSS, that can be removed with a one-off Kaspersky tool. I ran the tool, but it reported nothing out of the ordinary. Furthermore I can't find any tools that help with removing malware on 64-bit systems.</p><p>I don't really have anything to boot off to have a look at the filesystem. I can't see any malware in my current filesystem (of course, that's how rootkits work) - but I did find a malware file in my SysWow64 directory that has since been deactivated (it setup a Scheduled Task to rundll.exe itself on system startup).</p><p>My computer doesn't have an optical drive, so I'll have to boot from a USB stick, but I don't know what system is best for this. I have run the official WinPE in the past and I wasn't too impressed with it, but BartPE leaves a lot to be desired. Unfortunately the HDD in my laptop cannot be removed without breaking the warranty (as it involves the complete removal of the underside cover).</p><p>Any suggestions?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/9d974b278cee4ff1a4169f920029d46b#9d974b278cee4ff1a4169f920029d46b</link>
		<pubDate>Sat, 05 Nov 2011 02:32:17 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/9d974b278cee4ff1a4169f920029d46b#9d974b278cee4ff1a4169f920029d46b</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>Didn't you use to say you didn't run antivirus? *grin*</p><p>So for a windows solution there's a connect beta right now of System Sweeper - <a href="http://connect.microsoft.com/systemsweeper">http&#58;&#47;&#47;connect.microsoft.com&#47;systemsweeper</a></p><p>Webplains doesn't seem to be using root kits though, from what I can see. Did you remove the system TDSSserve.sys hidden device first? And checked proxy settings once rebooted and scanned?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/2ae4d3f648044f2688ca9f92003196ac#2ae4d3f648044f2688ca9f92003196ac</link>
		<pubDate>Sat, 05 Nov 2011 03:00:32 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/2ae4d3f648044f2688ca9f92003196ac#2ae4d3f648044f2688ca9f92003196ac</guid>
		<dc:creator>blowdart</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/blowdart/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p><a href="http://www.browserhijackers.com/fixerror/remove-webplains.net-to-get-rid-of-browser-hijacks/167">This</a> came up on Bing search. <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif?v=c9' alt='Wink' /></p><p>BTW, how did you discover you had this malware?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/3c5c15ef0965408bb2309f9200338c7c#3c5c15ef0965408bb2309f9200338c7c</link>
		<pubDate>Sat, 05 Nov 2011 03:07:41 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/3c5c15ef0965408bb2309f9200338c7c#3c5c15ef0965408bb2309f9200338c7c</guid>
		<dc:creator>cbae</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/cbae/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>That's very foolish of you.</p><p>You should probably download something like AVG to do a scan of your system. If that doesn't work, you might want to consider formatting your machine and starting over.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/6680d572b3a74de796a69f9200bad7e4#6680d572b3a74de796a69f9200bad7e4</link>
		<pubDate>Sat, 05 Nov 2011 11:20:16 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/6680d572b3a74de796a69f9200bad7e4#6680d572b3a74de796a69f9200bad7e4</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>Why waste time attempting to remove it? The Windows installation is suspect, it is beyond repair.&nbsp;</p><p>Buy a 2.5&quot; HDD caddy, copy off all of the files you need, format it including destroying the MBR (if it has one) then use a USB Key to reinstall Windows and copy your files back across.&nbsp;</p><p>Even if you were able to remove the rootkit, you likely won't get all of the components or be able to determine if it added a reinfection vector (e.g. added malware CA, HOSTS corruption, new trusted sites, et al). &nbsp; &nbsp;</p><p>The more I learn the less willing I am to ever attempt to remove infections. &quot;Reinstall Windows&quot; is the call of both the guru and low-hanging technical fruit alike.&nbsp;</p><p>&nbsp;</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/b3951fd5c3d54b8495d99f9200cb0753#b3951fd5c3d54b8495d99f9200cb0753</link>
		<pubDate>Sat, 05 Nov 2011 12:19:12 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/b3951fd5c3d54b8495d99f9200cb0753#b3951fd5c3d54b8495d99f9200cb0753</guid>
		<dc:creator>Manip</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/ManipUni/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>I would agree with ManipUni's appoach.&nbsp; You could run this: <a href="http://technet.microsoft.com/en-gb/sysinternals/bb897445">RootkitRevealer v1.71&nbsp; </a></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ae6e55630501434b92459f9200cd26e0#ae6e55630501434b92459f9200cd26e0</link>
		<pubDate>Sat, 05 Nov 2011 12:26:56 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ae6e55630501434b92459f9200cd26e0#ae6e55630501434b92459f9200cd26e0</guid>
		<dc:creator>Wayne Taylor</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Kryptos/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/ae6e55630501434b92459f9200cd26e0">37 minutes&nbsp;ago</a>, <a href="/Niners/Kryptos">Kryptos</a> wrote</p><p>I would agree with ManipUni's appoach.&nbsp; You could run this: <a href="http://technet.microsoft.com/en-gb/sysinternals/bb897445">RootkitRevealer v1.71&nbsp; </a></p><p></p></div></blockquote>Doesn't work anymore because the rootkit writers would keep finding ways to circumvent it.<p></p><p>&nbsp;</p><p>What I like to know W3bbo is how you got it? You are probably up-to-date with your patches on MicrosoftUpdate&nbsp;and don't run executable stuff from e-mail attachments nor do you download malware from websites and click yes on the UAC dialog. Was it Flash or Java that allowed your pc to get infected? Are they up-to-date?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/cbd274b76ae9459ab22e9f9200d7dd5b#cbd274b76ae9459ab22e9f9200d7dd5b</link>
		<pubDate>Sat, 05 Nov 2011 13:05:56 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/cbd274b76ae9459ab22e9f9200d7dd5b#cbd274b76ae9459ab22e9f9200d7dd5b</guid>
		<dc:creator>ZippyV</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/ZippyV/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>@<a href="/Forums/Coffeehouse/Ive-got-a-rootkit#c9d974b278cee4ff1a4169f920029d46b">W3bbo</a>: A simple google toolbar infection combined with some entries in the Hosts file could exhibit the behavior as well.&nbsp; It may not be a rootkit.&nbsp; Then again, if it is a rootkit you need to blow that partition away and recreate it.&nbsp; If you don't take the approach to just reinstall Windows, then you will spend more time analyzing and trying to clean and then more time still wondering and watching if it was actually clean.</p><p>Even if the infection is not a rootkit, what is to say that the infection has not put in enough hooks to always have a backdoor in place no matter how many different virus cleaners you run on it.&nbsp; Whack-a-mole style.</p><p>Save your data files and blow that partition away.</p><p>I presume you have other machines with which you can download the Win7 ISO and use the Windows 7 USB/DVD Download Tool ( <a href="http://wudt.codeplex.com/">http://wudt.codeplex.com/</a>&nbsp;) to reinstall.</p><p>There is also the option to do an in place upgrade of Windows 7 to see if that might work.&nbsp; Although I don't know how it would distinguish a viral hook from any other legitimate hook.</p><p>In conclusion ... Blow it away and reinstall!</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/508f0de6618344dab7fa9f9200e2ec76#508f0de6618344dab7fa9f9200e2ec76</link>
		<pubDate>Sat, 05 Nov 2011 13:46:12 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/508f0de6618344dab7fa9f9200e2ec76#508f0de6618344dab7fa9f9200e2ec76</guid>
		<dc:creator>Dave Williamson</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/davewill/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/cbd274b76ae9459ab22e9f9200d7dd5b">1 hour&nbsp;ago</a>, <a href="/Niners/ZippyV">ZippyV</a> wrote</p><p>What I like to know W3bbo is how you got it? You are probably up-to-date with your patches on MicrosoftUpdate&nbsp;and don't run executable stuff from e-mail attachments nor do you download malware from websites and click yes on the UAC dialog. Was it Flash or Java that allowed your pc to get infected? Are they up-to-date?</p><p></p></div></blockquote><p></p><p>The #1 way of getting infected is not being exploited, but running an exe written directly by the malware author. These tend to be either<br>a) Quick download my smileys!<br>b) Run this program to get rid of malware!<br>c) Run me because I am *popular game* / crack for a *popular game*!&nbsp;<br>d) Click me to install codecs to watch *popular movie* / porn<br>e) Install this toolbar to use *popular application*<br>f) Install this toolbar to use *seemingly popular website*<br>g) Friend sends &quot;Run this program it's amazing&quot; which then installs malware and sends &quot;Run this program it's amazing&quot; to all of your friends.&nbsp;</p><p>Only after all of these does drive-by infections kick in as methods of infecting computers - and again malware authors are lazy and tend to use easy-to-exploit bugs or bugs whose PoC are easy to turn around, which in practise means you need to be <em>quite </em>out of date for drive-by-downloads to work.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/237ebc14e9fe487bae5a9f9200f24cdf#237ebc14e9fe487bae5a9f9200f24cdf</link>
		<pubDate>Sat, 05 Nov 2011 14:42:11 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/237ebc14e9fe487bae5a9f9200f24cdf#237ebc14e9fe487bae5a9f9200f24cdf</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>Don't forget secret option</p><p>h) Someone breaks into a trusted software vendor and injects it into your favourite desktop application.&nbsp;</p><p>In theory if they signed their releases it wouldn't be an issue, but very few Open Source Windows application installers do (e.g. Filezilla, GAIM, [The] GIMP, et al). &nbsp;&nbsp;</p><p>&nbsp;</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/24fcd318bd9142c785389f9200f37961#24fcd318bd9142c785389f9200f37961</link>
		<pubDate>Sat, 05 Nov 2011 14:46:27 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/24fcd318bd9142c785389f9200f37961#24fcd318bd9142c785389f9200f37961</guid>
		<dc:creator>Manip</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/ManipUni/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>Format windows partition and delete all&nbsp;executables on all other&nbsp;partitions&nbsp;on internal and external storage devices that had writing access.</p><p>Last time a roommate of mine reported his computer behaving odd and after checking and finding malware I recommend reinstalling Windows. I forgot to mention he shouldn't reinstall his applications from backed up installer&nbsp;executables&nbsp;and so he promptly reinfected his fresh windows again. Bah. He gave up and ran his computer infected, obviously I avoided any software that he tried to give me on USB keys like a plague.</p><p>Don't advertise that you got infected and did not do a proper&nbsp;sanitation of&nbsp;your (build?) environment. You aren't making me&nbsp;confident&nbsp;your software on your web properties are safe, there are enough scary stories on the internet with compromised upsteam. This paragraph will self destruct in a few hours.&nbsp;</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/fbbbcf5508bb4ef59e709f9200f5ccce#fbbbcf5508bb4ef59e709f9200f5ccce</link>
		<pubDate>Sat, 05 Nov 2011 14:54:55 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/fbbbcf5508bb4ef59e709f9200f5ccce#fbbbcf5508bb4ef59e709f9200f5ccce</guid>
		<dc:creator>RoyalSchrubber</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/RoyalSchrubber/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>How did you discover this? From your router?</p><p>&nbsp;</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/658ff62282a245d1b8469f9200fbd39d#658ff62282a245d1b8469f9200fbd39d</link>
		<pubDate>Sat, 05 Nov 2011 15:16:52 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/658ff62282a245d1b8469f9200fbd39d#658ff62282a245d1b8469f9200fbd39d</guid>
		<dc:creator>Bass</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Bass/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/fbbbcf5508bb4ef59e709f9200f5ccce">43 minutes&nbsp;ago</a>, <a href="/Niners/RoyalSchrubber">Royal​Schrubber</a> wrote</p><p>&nbsp;</p><p>Don't advertise that you got infected and did not do a proper&nbsp;sanitation of&nbsp;your (build?) environment. You aren't making me&nbsp;confident&nbsp;your software on your web properties are safe, there are enough scary stories on the internet with compromised upsteam. This paragraph will self destruct in a few hours.&nbsp;</p><p></p></div></blockquote><p></p><p>A certificate authority has gone offline this week because their servers were used to distribute malware. *boggle*</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/597b3729aea04db1a37e9f92010200e7#597b3729aea04db1a37e9f92010200e7</link>
		<pubDate>Sat, 05 Nov 2011 15:39:21 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/597b3729aea04db1a37e9f92010200e7#597b3729aea04db1a37e9f92010200e7</guid>
		<dc:creator>blowdart</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/blowdart/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>@<a href="/Forums/Coffeehouse/Ive-got-a-rootkit#c597b3729aea04db1a37e9f92010200e7">blowdart</a>: Who went offline?&nbsp; Someone other than RSA?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/3aa61eece3544a3494479f92010710a3#3aa61eece3544a3494479f92010710a3</link>
		<pubDate>Sat, 05 Nov 2011 15:57:47 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/3aa61eece3544a3494479f92010710a3#3aa61eece3544a3494479f92010710a3</guid>
		<dc:creator>Dave Williamson</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/davewill/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>Some CA in Malaysia had their authority revoked by the major browser makers for distributing 512-bit certificates. Don't know if that's related.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ea5138ca890b42ef8b529f92010a5580#ea5138ca890b42ef8b529f92010a5580</link>
		<pubDate>Sat, 05 Nov 2011 16:09:41 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ea5138ca890b42ef8b529f92010a5580#ea5138ca890b42ef8b529f92010a5580</guid>
		<dc:creator>Bass</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Bass/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/2ae4d3f648044f2688ca9f92003196ac">13 hours&nbsp;ago</a>, <a href="/Niners/blowdart">blowdart</a> wrote<p></p><p>Didn't you use to say you didn't run antivirus? *grin*</p><p>So for a windows solution there's a connect beta right now of System Sweeper - <a href="http://connect.microsoft.com/systemsweeper">http://connect.microsoft.com/systemsweeper</a></p><p>Webplains doesn't seem to be using root kits though, from what I can see. Did you remove the system TDSSserve.sys hidden device first? And checked proxy settings once rebooted and scanned?</p></div></blockquote><p></p><p>Yes, I am put to shame. To make things even worse I had UAC disabled at the time.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/3c5c15ef0965408bb2309f9200338c7c">13 hours&nbsp;ago</a>, <a href="/Niners/cbae">cbae</a> wrote</p><p><a href="http://www.browserhijackers.com/fixerror/remove-webplains.net-to-get-rid-of-browser-hijacks/167">This</a> came up on Bing search. <img src="http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif?v=c9" alt="Wink"></p><p>BTW, how did you discover you had this malware?</p><p></p></div></blockquote><p></p><p>I started noticing google search links were being hijacked. I ran my Live HTTP Headers extension for Firefox and it showed that HTTP 301 redirects were being inserted. At first I thought Wikipedia was hacked (as it only affected links to WP to begin with). Then it started happening to other links and in other browsers, I ruled out anything at my ISP and realised something was amiss locally.</p><p>Process Explorer revealed that the Task Scheduler was launching rundll.exe with a program argument to a DLL called &quot;dswaved.dll&quot; under SysWow64. I quickly terminated it and extracted the file. The question remains how Task Scheduler was manipulated.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/6680d572b3a74de796a69f9200bad7e4">5 hours&nbsp;ago</a>, <a href="/Niners/evildictaitor">evildictait​or</a> wrote</p><p>That's very foolish of you.</p><p>You should probably download something like AVG to do a scan of your system. If that doesn't work, you might want to consider formatting your machine and starting over.</p><p></p></div></blockquote><p></p><p>I'm running a Trend Micro house call right now, but I'm sceptical - rootkits usually can't be detected by AV software by their very nature.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/b3951fd5c3d54b8495d99f9200cb0753">4 hours&nbsp;ago</a>, <a href="/Niners/ManipUni">ManipUni</a> wrote</p><p>Why waste time attempting to remove it? The Windows installation is suspect, it is beyond repair.&nbsp;</p><p>Buy a 2.5&quot; HDD caddy, copy off all of the files you need, format it including destroying the MBR (if it has one) then use a USB Key to reinstall Windows and copy your files back across.&nbsp;</p><p>Even if you were able to remove the rootkit, you likely won't get all of the components or be able to determine if it added a reinfection vector (e.g. added malware CA, HOSTS corruption, new trusted sites, et al). &nbsp; &nbsp;</p><p>The more I learn the less willing I am to ever attempt to remove infections. &quot;Reinstall Windows&quot; is the call of both the guru and low-hanging technical fruit alike. </p><p></p></div></blockquote><p></p><p>You missed the part where I said the HDD was inaccessible.</p><p>Nonetheless, Sony was meant to collect my laptop for repairs last week (hint: they didn't) so there's not much on it anyway.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/ae6e55630501434b92459f9200cd26e0">4 hours&nbsp;ago</a>, <a href="/Niners/Kryptos">Kryptos</a> wrote</p><p>I would agree with ManipUni's appoach.&nbsp; You could run this: <a href="http://technet.microsoft.com/en-gb/sysinternals/bb897445">RootkitRevealer v1.71&nbsp; </a></p><p></p></div></blockquote><p></p><p>RootkitRevealer only works on 32-bit systems.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/cbd274b76ae9459ab22e9f9200d7dd5b">3 hours&nbsp;ago</a>, <a href="/Niners/ZippyV">ZippyV</a> wrote</p><p>*snip*Doesn't work anymore because the rootkit writers would keep finding ways to circumvent it.</p><p>&nbsp;</p><p>What I like to know W3bbo is how you got it? You are probably up-to-date with your patches on MicrosoftUpdate&nbsp;and don't run executable stuff from e-mail attachments nor do you download malware from websites and click yes on the UAC dialog. Was it Flash or Java that allowed your pc to get infected? Are they up-to-date?</p><p></p></div></blockquote><p></p><p>The Date Created field on the DLL file I recovered was at 2011-11-05 01:22.</p><p>I checked my browser history, I was browsing two websites at the time, stackoverflow.com, and a thread on iphonedevsdk.com - I'm going to assume Jeff Atwood's website is secure, but iphonedevsdk.com runs vBadvanced 3.1.0 which is an old version. A cursory Google search suggests that version of vBadvanced has a number of security vulnerabilities that may have been broken.</p><p>Assuming that's the case, the vector was that broken website, and something in my browser, possibly Flash or Acrobat (though I am running the latest version of both of these softwares). But the odd thing is that I run Flashblock in Firefox, so I'm stuck for ideas.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/508f0de6618344dab7fa9f9200e2ec76">2 hours&nbsp;ago</a>, <a href="/Niners/davewill">davewill</a> wrote</p><p>@<a href="/Forums/Coffeehouse/Ive-got-a-rootkit#c9d974b278cee4ff1a4169f920029d46b">W3bbo</a>: A simple google toolbar infection combined with some entries in the Hosts file could exhibit the behavior as well.&nbsp; It may not be a rootkit.&nbsp; Then again, if it is a rootkit you need to blow that partition away and recreate it.&nbsp; If you don't take the approach to just reinstall Windows, then you will spend more time analyzing and trying to clean and then more time still wondering and watching if it was actually clean.</p><p>Even if the infection is not a rootkit, what is to say that the infection has not put in enough hooks to always have a backdoor in place no matter how many different virus cleaners you run on it.&nbsp; Whack-a-mole style.</p><p>Save your data files and blow that partition away.</p><p>I presume you have other machines with which you can download the Win7 ISO and use the Windows 7 USB/DVD Download Tool ( <a href="http://wudt.codeplex.com/">http://wudt.codeplex.com/</a>&nbsp;) to reinstall.</p><p>There is also the option to do an in place upgrade of Windows 7 to see if that might work.&nbsp; Although I don't know how it would distinguish a viral hook from any other legitimate hook.</p><p>In conclusion ... Blow it away and reinstall!</p><p></p></div></blockquote><p></p><p>Looks like I'll be taking that path.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/237ebc14e9fe487bae5a9f9200f24cdf">1 hour&nbsp;ago</a>, <a href="/Niners/evildictaitor">evildictait​or</a> wrote</p><p>*snip*</p><p>The #1 way of getting infected is not being exploited, but running an exe written directly by the malware author. These tend to be either<br>a) Quick download my smileys!<br>b) Run this program to get rid of malware!<br>c) Run me because I am *popular game* / crack for a *popular game*!&nbsp;<br>d) Click me to install codecs to watch *popular movie* / porn<br>e) Install this toolbar to use *popular application*<br>f) Install this toolbar to use *seemingly popular website*<br>g) Friend sends &quot;Run this program it's amazing&quot; which then installs malware and sends &quot;Run this program it's amazing&quot; to all of your friends.&nbsp;</p><p>Only after all of these does drive-by infections kick in as methods of infecting computers - and again malware authors are lazy and tend to use easy-to-exploit bugs or bugs whose PoC are easy to turn around, which in practise means you need to be <em>quite </em>out of date for drive-by-downloads to work.</p></div></blockquote><p></p><p>I can assure you, I haven't been running any programs like that. This appears to be an example of the worst kind of drive-by download you can get: unauthorised remote code execution.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/24fcd318bd9142c785389f9200f37961">1 hour&nbsp;ago</a>, <a href="/Niners/ManipUni">ManipUni</a> wrote</p><p>Don't forget secret option</p><p>h) Someone breaks into a trusted software vendor and injects it into your favourite desktop application.&nbsp;</p><p>In theory if they signed their releases it wouldn't be an issue, but very few Open Source Windows application installers do (e.g. Filezilla, GAIM, [The] GIMP, et al). &nbsp;&nbsp;</p><p></p></div></blockquote><p></p><p>Now you've got me scared. I recently downloaded and installed the ffmpeg binaries from <a href="http://ffmpeg.zeranoe.com/builds/">http&#58;&#47;&#47;ffmpeg.zeranoe.com&#47;builds&#47;</a>, but that was hours before any problems started appearing.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/fbbbcf5508bb4ef59e709f9200f5ccce">1 hour&nbsp;ago</a>, <a href="/Niners/RoyalSchrubber">Royal​Schrubber</a> wrote</p><p>Format windows partition and delete all&nbsp;executables on all other&nbsp;partitions&nbsp;on internal and external storage devices that had writing access.</p><p>Last time a roommate of mine reported his computer behaving odd and after checking and finding malware I recommend reinstalling Windows. I forgot to mention he shouldn't reinstall his applications from backed up installer&nbsp;executables&nbsp;and so he promptly reinfected his fresh windows again. Bah. He gave up and ran his computer infected, obviously I avoided any software that he tried to give me on USB keys like a plague.</p><p>Don't advertise that you got infected and did not do a proper&nbsp;sanitation of&nbsp;your (build?) environment. You aren't making me&nbsp;confident&nbsp;your software on your web properties are safe, there are enough scary stories on the internet with compromised upsteam. This paragraph will self destruct in a few hours.&nbsp;</p><p></p></div></blockquote><p></p><p>Good point, why would any potential customer or client of mine want to be trust in someone who lets his own laptop get infected?</p><p>Fortunately &quot;W3bbo&quot; isn't associated with my &quot;real-life&quot; business identity <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/658ff62282a245d1b8469f9200fbd39d">1 hour&nbsp;ago</a>, <a href="/Niners/Bass">Bass</a> wrote</p><p>How did you discover this? From your router?</p><p></p></div></blockquote><p></p><p>See above: after I noticed search results being hijacked.</p><p>Oddly enough, searching for &quot;webplains.net&quot; in Google, gave me an immediate 301 redirect to <a href="http://support.microsoft.com/kb/827315">http&#58;&#47;&#47;support.microsoft.com&#47;kb&#47;827315</a> - the evidence suggests that that redirect was caused by the malware - perhaps the author was under duress when he wrote it? (In any event, that Microsoft support article didn't help).</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/d7806b1bb4394c01b4d29f92011dca1a#d7806b1bb4394c01b4d29f92011dca1a</link>
		<pubDate>Sat, 05 Nov 2011 17:20:31 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/d7806b1bb4394c01b4d29f92011dca1a#d7806b1bb4394c01b4d29f92011dca1a</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>To all those who said I should use AV software:</p><p>I just put the captured dodgy file through MSE, Kaspersky, and Trend Micro, and <em>none of them reported it as being malware</em>.</p><p>If none of these AV programs can detect malware, what's the point of running it at all?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/f254c13c54ac48f886dd9f920123a25a#f254c13c54ac48f886dd9f920123a25a</link>
		<pubDate>Sat, 05 Nov 2011 17:41:48 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/f254c13c54ac48f886dd9f920123a25a#f254c13c54ac48f886dd9f920123a25a</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/d7806b1bb4394c01b4d29f92011dca1a">1 hour&nbsp;ago</a>, <a href="/Niners/W3bbo">W3bbo</a> wrote</p><p>I'm running a Trend Micro house call right now, but I'm sceptical - rootkits usually can't be detected by AV software by their very nature.</p><p></p></div></blockquote><p></p><p>On the contrary. That's actually one of the rare things that AV companies are good at. AVs go out of their way to make sure any common strain of malware in the wild gets pick up by them. If you're the first to be hit with a new strain they might not pick it up straight away, but if you got it from dodgy executables, drive-by-downloads or publically known exploits on the internet the AV will have seen it and signatured it.</p><p></p><blockquote><div class="quoteText"><p></p><p>I can assure you, I haven't been running any programs like that. This appears to be an example of the worst kind of drive-by download you can get: unauthorised remote code execution.</p><p></p></div></blockquote><p></p><p>If you're running latest OS / browser / flash it won't have been a drive-by download attack. Zero days are traded for hundreds of thousands of dollars on the black market and criminals aren't stupid enough to use them on machines that don't have something really valuable on them.</p><p></p><blockquote><div class="quoteText"><p></p><p>Now you've got me scared. I recently downloaded and installed the ffmpeg binaries from <a href="http://ffmpeg.zeranoe.com/builds/">http://ffmpeg.zeranoe.com/builds/</a>, but that was hours before any problems started appearing.</p><p></p></div></blockquote><p></p><p>Lots of malware is bundled with the single task of download and run executables from a known source. The original exploit kit or executable author then &quot;sells&quot; installs to the criminals behind zeus and other malware who are then responsible for monetizing the infected computers - either through credit card theft, information theft, attaching the computer to a bot-net for DDoS and so on.</p><p>This behaviour can cause a delay between you running something dodgy and it getting picked up by AV vendors, or between you running something and your computer starting to behave maliciously.</p><p>To be honest, I know you think you probably haven't done anything wrong and it's easier to blame ingenious hackers and exploits, but the reality is that exploits are the exception rather than the norm (and almost exclusively against old machines running Windows XP and running software that hasn't been patched for months on end) for client machines getting infected.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/23429b9c1eac4fe7ad7e9f9201370d0c#23429b9c1eac4fe7ad7e9f9201370d0c</link>
		<pubDate>Sat, 05 Nov 2011 18:52:30 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/23429b9c1eac4fe7ad7e9f9201370d0c#23429b9c1eac4fe7ad7e9f9201370d0c</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>Install Scriptblock instead of Flashblock.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/2521e72cd763408ea3639f92013ee34f#2521e72cd763408ea3639f92013ee34f</link>
		<pubDate>Sat, 05 Nov 2011 19:21:02 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/2521e72cd763408ea3639f92013ee34f#2521e72cd763408ea3639f92013ee34f</guid>
		<dc:creator>ZippyV</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/ZippyV/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>I'm running the TrendMicro House Call on my laptop still. Been going for over 6 hours now and it's only 60% complete :o</p><p>Interestingly, it says it's found &quot;2 threats&quot;.</p><p>It won't tell me what they are until the scan's over, it'll be interesting to see what they are.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/11b78f2c27704f0b924a9f9201831198#11b78f2c27704f0b924a9f9201831198</link>
		<pubDate>Sat, 05 Nov 2011 23:29:16 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/11b78f2c27704f0b924a9f9201831198#11b78f2c27704f0b924a9f9201831198</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/11b78f2c27704f0b924a9f9201831198">39 minutes&nbsp;ago</a>, <a href="/Niners/W3bbo">W3bbo</a> wrote</p><p>I'm running the TrendMicro House Call on my laptop still. Been going for over 6 hours now and it's only 60% complete :o</p><p>Interestingly, it says it's found &quot;2 threats&quot;.</p><p>It won't tell me what they are until the scan's over, it'll be interesting to see what they are.</p><p></p></div></blockquote><p></p><p>Didn't you say had hardly any data on this HD? Dayam.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/2cb65c9700174766872e9f930002e33d#2cb65c9700174766872e9f930002e33d</link>
		<pubDate>Sun, 06 Nov 2011 00:10:30 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/2cb65c9700174766872e9f930002e33d#2cb65c9700174766872e9f930002e33d</guid>
		<dc:creator>cbae</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/cbae/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/f254c13c54ac48f886dd9f920123a25a">6 hours&nbsp;ago</a>, <a href="/Niners/W3bbo">W3bbo</a> wrote</p><p>To all those who said I should use AV software:</p><p>I just put the captured dodgy file through MSE, Kaspersky, and Trend Micro, and <em>none of them reported it as being malware</em>.</p><p>If none of these AV programs can detect malware, what's the point of running it at all?</p><p></p></div></blockquote><p></p><p>That is because the &quot;dodgy file&quot; you&nbsp;refer to&nbsp;is really part of DirectX. See the file listed&nbsp;<a href="http://support.microsoft.com/kb/279803">here</a>. There is&nbsp;some other&nbsp;executable that you missed that is the real culprit.</p><p>Seriously, running something like MSE&nbsp;takes no noticeable resources, and I run some heavy duty realtime music applications at low buffer latencies without any audio glitches. And I don't see what the big issue is with leaving UAC turned on. Once in a while I have click on &quot;Yes/No&quot;. I really can't remember the last time I had an infection, it has been years now.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ee6b67a7d96f454e81099f93000b22d5#ee6b67a7d96f454e81099f93000b22d5</link>
		<pubDate>Sun, 06 Nov 2011 00:40:32 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ee6b67a7d96f454e81099f93000b22d5#ee6b67a7d96f454e81099f93000b22d5</guid>
		<dc:creator>BitFlipper</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/BitFlipper/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/2cb65c9700174766872e9f930002e33d">26 minutes&nbsp;ago</a>, <a href="/Niners/cbae">cbae</a> wrote</p><p>*snip*</p><p>Didn't you say had hardly any data on this HD? Dayam.</p><p></p></div></blockquote><p></p><p>I meant to clarify that as &quot;hardly any data worth keeping&quot; - i.e. personal documents, it still feels the need to scan my 80GB collection of <em>legitimately acquired</em> MP3s, the MSDN content installations and of course, the tens of gigabytes that Microsoft Windows likes to amass in the WinSxS directory.</p><p>It's now 2011-11-06 00:40 and it's just hit 70%, so far it's found 4 threats, I note that for as long as I've been watching it it's been scanning my Firefox cache - so if the malware installer found its way through there it makes sense.</p><p>I'll post a follow-up when I check back in the morning.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/635e28b53d8d41468b899f93000b4a74#635e28b53d8d41468b899f93000b4a74</link>
		<pubDate>Sun, 06 Nov 2011 00:41:06 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/635e28b53d8d41468b899f93000b4a74#635e28b53d8d41468b899f93000b4a74</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/635e28b53d8d41468b899f93000b4a74">56 minutes&nbsp;ago</a>, <a href="/Niners/W3bbo">W3bbo</a> wrote</p><p>*snip*</p><p>I meant to clarify that as &quot;hardly any data worth keeping&quot; - i.e. personal documents, it still feels the need to scan my 80GB collection of <em>legitimately acquired</em> MP3s, the MSDN content installations and of course, the tens of gigabytes that Microsoft Windows likes to amass in the WinSxS directory.</p><p></p></div></blockquote><p></p><p>Well obviously it's going to scan all your MP3s, one of those might contain viral code. As for WinSxS, it's a bunch of hard links to files elsewhere, it doesn't really occupy &quot;tens of gigabytes&quot;</p><p>If there's nothing worth keeping though I don't really see the point of trying to disinfect the machine, reformatting and reinstalling is really the only sane option anyway. And this time leave UAC on and actually use a proper on-access virus scanner at all times.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/7803057d3c2343a3bef69f930020123a#7803057d3c2343a3bef69f930020123a</link>
		<pubDate>Sun, 06 Nov 2011 01:56:46 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/7803057d3c2343a3bef69f930020123a#7803057d3c2343a3bef69f930020123a</guid>
		<dc:creator>AndyC</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/AndyC/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>The scan completed a short while ago, 7 threats were found in total.</p><p>However all of them were inactive (i.e. just passive virulent files that weren't configured by the system to be loaded anywhere). Curiously enough, it flagged a JPEG file as a virus. I inspected it with a binary editor and apparently it was a renamed zip file containing an EXE. It came attached with some email.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/a0b4d114efb44b44bb249f9300f0abf1#a0b4d114efb44b44bb249f9300f0abf1</link>
		<pubDate>Sun, 06 Nov 2011 14:36:15 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/a0b4d114efb44b44bb249f9300f0abf1#a0b4d114efb44b44bb249f9300f0abf1</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>That must be a pretty crappy rootkit if you could detect it without even switching operating systems.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/b4e5dd14af334921a6a09f93010a0962#b4e5dd14af334921a6a09f93010a0962</link>
		<pubDate>Sun, 06 Nov 2011 16:08:36 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/b4e5dd14af334921a6a09f93010a0962#b4e5dd14af334921a6a09f93010a0962</guid>
		<dc:creator>Bass</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Bass/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/b4e5dd14af334921a6a09f93010a0962">22 minutes&nbsp;ago</a>, <a href="/Niners/Bass">Bass</a> wrote</p><p>That must be a pretty crappy rootkit if you could detect it without even switching operating systems.</p><p></p></div></blockquote>&#43;&#43;<p></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/b66f1fd176aa41acaf3e9f930110338c#b66f1fd176aa41acaf3e9f930110338c</link>
		<pubDate>Sun, 06 Nov 2011 16:31:03 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/b66f1fd176aa41acaf3e9f930110338c#b66f1fd176aa41acaf3e9f930110338c</guid>
		<dc:creator>PaoloM</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/PaoloM/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/a0b4d114efb44b44bb249f9300f0abf1">1 hour&nbsp;ago</a>, <a href="/Niners/W3bbo">W3bbo</a> wrote</p><p>The scan completed a short while ago, 7 threats were found in total.</p><p>However all of them were inactive (i.e. just passive virulent files that weren't configured by the system to be loaded anywhere). Curiously enough, it flagged a JPEG file as a virus. I inspected it with a binary editor and apparently it was a renamed zip file containing an EXE. It came attached with some email.</p><p></p></div></blockquote>Using a better browser (with real security features) and an av would have prevented all that to show up on your system.<p></p><p>Live and learn, eh? <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/e71f7b2d1108474495979f930110c130#e71f7b2d1108474495979f930110c130</link>
		<pubDate>Sun, 06 Nov 2011 16:33:04 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/e71f7b2d1108474495979f930110c130#e71f7b2d1108474495979f930110c130</guid>
		<dc:creator>PaoloM</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/PaoloM/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/b4e5dd14af334921a6a09f93010a0962">1 hour&nbsp;ago</a>, <a href="/Niners/Bass">Bass</a> wrote</p><p>That must be a pretty crappy rootkit if you could detect it without even switching operating systems.</p><p></p></div></blockquote><p></p><p>On the contrary. The way rootkit detectors work is they ask for the same information in about 100 different ways. If any of them disagree with the others then something is wrong. E.g. if you enumerate the files in a folder and see nothing, but do an NtQueryObject on the directory and discover that it contains 1 file, then something is amiss. The point is that rootkits can hook stuff, but unless they hook <em>everything </em>(which requires a lot of time, effort and Winternals knowledge) they're going to screw up and will get caught.</p><p>Also AVs tend to look for heuristics as well as file signatures, so if an image gets mapped from disk but the file doesn't show up in an ZwOpenFile then something is wrong.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/8283ee71dcb34d4f90dc9f93012b90ba#8283ee71dcb34d4f90dc9f93012b90ba</link>
		<pubDate>Sun, 06 Nov 2011 18:10:41 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/8283ee71dcb34d4f90dc9f93012b90ba#8283ee71dcb34d4f90dc9f93012b90ba</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/a0b4d114efb44b44bb249f9300f0abf1">5 hours&nbsp;ago</a>, <a href="/Niners/W3bbo">W3bbo</a> wrote</p><p>The scan completed a short while ago, 7 threats were found in total.</p><p>However all of them were inactive (i.e. just passive virulent files that weren't configured by the system to be loaded anywhere). Curiously enough, it flagged a JPEG file as a virus. I inspected it with a binary editor and apparently it was a renamed zip file containing an EXE. It came attached with some email.</p><p></p></div></blockquote><p></p><p>The thing is, you now know the system was infected but you don't really know it isn't still compromised by something the anti-virus tool didn't spot. So you've lost the best part of a day scanning a system and you can still only be sure it's clean by reinstalling everything. Not unsurprised to see executables hidden inside renamed files though, that's pretty common.</p><p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/e71f7b2d1108474495979f930110c130">3 hours&nbsp;ago</a>, <a href="/Niners/PaoloM">PaoloM</a> wrote</p><p>*snip*Using a better browser (with real security features) and an av would have prevented all that to show up on your system.</p><p></p></div></blockquote><p></p><p>&#43;&#43;</p><p>Eventually everyone I've ever known to make the statement &quot;I don't need an AV, I know what I am doing&quot; has ended up in exactly this position.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/042e0760deee4a7cb7e89f9301453484#042e0760deee4a7cb7e89f9301453484</link>
		<pubDate>Sun, 06 Nov 2011 19:44:02 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/042e0760deee4a7cb7e89f9301453484#042e0760deee4a7cb7e89f9301453484</guid>
		<dc:creator>AndyC</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/AndyC/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p><a href="http://icanhascheezburger.files.wordpress.com/2007/11/funny-pictures-virus-cat.jpg" rel="lightbox"><img src="http://icanhascheezburger.files.wordpress.com/2007/11/funny-pictures-virus-cat.jpg" alt=""></a></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ca399a545b4a471f98b79f93015470c5#ca399a545b4a471f98b79f93015470c5</link>
		<pubDate>Sun, 06 Nov 2011 20:39:30 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/ca399a545b4a471f98b79f93015470c5#ca399a545b4a471f98b79f93015470c5</guid>
		<dc:creator>blowdart</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/blowdart/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>@<a href="/Forums/Coffeehouse/Ive-got-a-rootkit#c8283ee71dcb34d4f90dc9f93012b90ba">evildictaitor</a>:</p><p>And if the rootkit answers correctly all 100 ways? The fact of the matter is though, there is no perfect security. Intrusion detection with no false negatives has been shown to be an undecidable problem.[1]</p><p>[1]:<strong>&nbsp;</strong><a href="http://vxheavens.com/lib/afc01.html">http&#58;&#47;&#47;vxheavens.com&#47;lib&#47;afc01.html</a></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/115c7a100f934e3c8d399f930170e438#115c7a100f934e3c8d399f930170e438</link>
		<pubDate>Sun, 06 Nov 2011 22:23:05 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/115c7a100f934e3c8d399f930170e438#115c7a100f934e3c8d399f930170e438</guid>
		<dc:creator>Bass</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Bass/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>I've successfully removed some pretty nasty viruses, but if there's no data on there that you care about, just wipe out the partition table&nbsp;and start over. It's much, much faster. Hours versus days.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/f1b4e42ad769459d98c99f9400e46c07#f1b4e42ad769459d98c99f9400e46c07</link>
		<pubDate>Mon, 07 Nov 2011 13:51:39 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/f1b4e42ad769459d98c99f9400e46c07#f1b4e42ad769459d98c99f9400e46c07</guid>
		<dc:creator>Scott</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/spivonious/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/f1b4e42ad769459d98c99f9400e46c07">4 minutes&nbsp;ago</a>, <a href="/Niners/spivonious">spivonious</a> wrote</p><p>I've successfully removed some pretty nasty viruses, but if there's no data on there that you care about, just wipe out the partition table&nbsp;and start over. It's much, much faster. Hours versus days.</p><p></p></div></blockquote><p></p><p>what I'd like Microsoft (or anyone) to make, is a program that inspects a HDD and ensures the boot path from the boot sector to loading the desktop is free of contamination - which means you can safely boot it up and run a manual scan at your leisure knowing your system isn't compromised in a way that betrays your trust in it.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/afab4a2666ed4e42840c9f9400e664ef#afab4a2666ed4e42840c9f9400e664ef</link>
		<pubDate>Mon, 07 Nov 2011 13:58:50 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/afab4a2666ed4e42840c9f9400e664ef#afab4a2666ed4e42840c9f9400e664ef</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/afab4a2666ed4e42840c9f9400e664ef">5 minutes&nbsp;ago</a>, <a href="/Niners/W3bbo">W3bbo</a> wrote</p><p>*snip*</p><p>what I'd like Microsoft (or anyone) to make, is a program that inspects a HDD and ensures the boot path from the boot sector to loading the desktop is free of contamination - which means you can safely boot it up and run a manual scan at your leisure knowing your system isn't compromised in a way that betrays your trust in it.</p><p></p></div></blockquote><p></p><p>And how would you do that? There are so many points that you can plug into legitimately, and of course a myriad of software that does it, which has updates.</p><p>Or of course you can take the trusted boot option, but then, well, you get a lot of complaints that Microsoft is trying to control your software so only Microsoft sourced programs will run.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/7496c774194246d784e79f9400ec2895#7496c774194246d784e79f9400ec2895</link>
		<pubDate>Mon, 07 Nov 2011 14:19:49 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/7496c774194246d784e79f9400ec2895#7496c774194246d784e79f9400ec2895</guid>
		<dc:creator>blowdart</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/blowdart/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/7496c774194246d784e79f9400ec2895">14 hours&nbsp;ago</a>, <a href="/Niners/blowdart">blowdart</a> wrote</p><p>*snip*</p><p>And how would you do that? There are so many points that you can plug into legitimately, and of course a myriad of software that does it, which has updates.</p><p>Or of course you can take the trusted boot option, but then, well, you get a lot of complaints that Microsoft is trying to control your software so only Microsoft sourced programs will run.</p><p></p></div></blockquote><p></p><p>Microsoft could include as part of the install process, a separate, trusted minimal Windows installation (there are a plethora of ways to protect it), that can be used strictly for antivirus and malware scanning. In other words, they can build in to the installation the same thing that technicians cobble together every day with Hirens or UBCD4Win for the exact same purposes. Or just extend the current system recovery image that lets you do system restore and startup file check to include the ability to run virus or malware scans.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/269fec5441924c789a179f95004fa457#269fec5441924c789a179f95004fa457</link>
		<pubDate>Tue, 08 Nov 2011 04:49:58 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/269fec5441924c789a179f95004fa457#269fec5441924c789a179f95004fa457</guid>
		<dc:creator>Craig Matthews</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Craig_Matthews/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p>@<a href="/Forums/Coffeehouse/Ive-got-a-rootkit#c269fec5441924c789a179f95004fa457">Craig_Matthews</a>: That's not the problem blowdart was talking about. The issue is that such a scanner, even if executed from an isolated environment, can still either only detect known threats, or flag all unknown software as threats. The former will produce false negatives (so you still don't know for sure you're clean) and the latter will produce tons of false positives, as there's way too much software that legimitately hooks into the boot process for such a scanner to keep up with.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/e82af68a3b834d12829e9f9500559cce#e82af68a3b834d12829e9f9500559cce</link>
		<pubDate>Tue, 08 Nov 2011 05:11:42 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/e82af68a3b834d12829e9f9500559cce#e82af68a3b834d12829e9f9500559cce</guid>
		<dc:creator>Sven Groot</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Sven Groot/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - I&#39;ve got a rootkit...</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/Ive-got-a-rootkit/7496c774194246d784e79f9400ec2895">15 hours&nbsp;ago</a>, <a href="/Niners/blowdart">blowdart</a> wrote</p><p>*snip*</p><p>And how would you do that? There are so many points that you can plug into legitimately, and of course a myriad of software that does it, which has updates.</p><p>Or of course you can take the trusted boot option, but then, well, you get a lot of complaints that Microsoft is trying to control your software so only Microsoft sourced programs will run.</p><p></p></div></blockquote><p></p><p>On the other hand, it seems perfectly valid request to add boot option that only loads Microsoft signed&nbsp;executables on the boot steps.</p><p>Afterall, most drivers on x64 supposed already have supplied driver that have done that. And non-device drivers are usually non-critical for diagnostic boot and can be appropiately skipped in this scenerio.</p><p>There could be other categories, but when this plan puts out, those affected will seek to have Microsoft sign their binaries.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/0677c178b715431b87b79f95005eeea5#0677c178b715431b87b79f95005eeea5</link>
		<pubDate>Tue, 08 Nov 2011 05:45:38 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/Ive-got-a-rootkit/0677c178b715431b87b79f95005eeea5#0677c178b715431b87b79f95005eeea5</guid>
		<dc:creator>cheong</dc:creator>
		<slash:comments>38</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/cheong/Discussions/RSS</wfw:commentRss>
	</item>
</channel>
</rss>