Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 06, 2008, 08:59:59 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
197723
Posts
22760
Topics
54696
Members
Latest Member:
itman2000my
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Anti Virus/Malware Products/Other Security products
Rootkit Detected
« previous
next »
Pages:
[
1
]
Author
Topic: Rootkit Detected (Read 1246 times)
eaglehorse.houndsofhell
Newbie
Offline
Posts: 10
Rootkit Detected
«
on:
September 23, 2007, 11:17:45 AM »
While running RookitRevealer Comodo AV Quarantined something called Downloader.JS.Small.fv it is listed as C:\sun\SDK\jmaki\scripts\. Only these two programs have detected it . Haven't tried Hijack This yet but no other programs no eve BOClean has detected it and I know that is a good program because of a past operator error. I have just reinstalled XP and scanned every thing but the updates for Netbeans 6.0 Beta. Was not able ( or intellegent enough) to scan this but none of the security programs detected it . Any Suggestions or help.
Logged
Goose18
Comodo's Hero
Offline
Posts: 1145
Re: Rootkit Detected
«
Reply #1 on:
September 23, 2007, 11:28:40 AM »
AVG have a free Anti-Rootkit it'll detect and remove any that it finds here's the lnik to it
http://www.grisoft.com/doc/download-free-anti-rootkit/us/crp/0
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
aladinonl
Comodo's Hero
Offline
Posts: 331
Re: Rootkit Detected
«
Reply #2 on:
September 23, 2007, 11:44:22 AM »
I havnt used rkrevealer but as I kno, rkrvl detects suspicious things but whether thing is a real rk or not downs to da user. Da same technic is employed in HJT! u need knowledge & xperience to deal w those apps.
CAVS mite haf false positiv as well.
Quote
I have just reinstalled XP and scanned every thing but the updates for Netbeans 6.0 Beta
i dun really get it, u mean u've just installed XP and update Netsbean?
I dun kno wat netsbean is but if ur XP is genuine (i mean not fr a pirate disc or pirate site) and netsbean is legitimate, nothing to wori much. Most probably its a false positiv fr CAVS.
However, u mite wanna check da file w virustotal at
www.virustotal.com
For an anti-rk app which aim at average users, Panda anti-rk (free) is also well-recommended.
Logged
small minds discuss people, normal minds discuss events, great minds discuss ideas
eaglehorse.houndsofhell
Newbie
Offline
Posts: 10
Re: Rootkit Detected
«
Reply #3 on:
September 23, 2007, 12:37:54 PM »
AVG Rootkit came up with nothing but reran the rootkitRevealer and again Comodo AV Caught it .
I just had to reload the os because something was corrupting files and shutting down comodo firewall and the rest of the security system noting showed up except a .js extention error that was not repaiable.
Logged
aladinonl
Comodo's Hero
Offline
Posts: 331
Re: Rootkit Detected
«
Reply #4 on:
September 23, 2007, 01:02:24 PM »
how did u reload OS? ur computer could b infected before u reloaded and the nasty could survive thru da process (yes, it can even if u reformat ur hard disk and instal a fresh new OS).
P.S:I just checked Netbeans and it appears legitimate.
Can u specify how rkrvl describe the nasty?
u can try some online scanners such as Panda, Trendmicro, KAV, Bitdefender, McAfee... to see how
And Important: next time if u wanna reinstal OS after suspected infected, scan for badies before reinstaling to make sure nothings sneakin in ur hard disk. If not, u mite haf a false sense of being secured.
«
Last Edit: September 23, 2007, 01:20:05 PM by aladinonl
»
Logged
small minds discuss people, normal minds discuss events, great minds discuss ideas
eaglehorse.houndsofhell
Newbie
Offline
Posts: 10
Re: Rootkit Detected
«
Reply #5 on:
September 23, 2007, 02:35:01 PM »
Before I reloaded my OS I was only able to boot it after that it would lock up . That was this past Fri. The day before I had run Spyware scan it came up with nada . I am using Comodo AV it detected Nada. I had a program from Smallfrogs (I dont remember the name) It only showed a .js extention error.
I reformated the hard Drive and reloaded the OS . ans have been paranoid so I been a good little knucklehead and scanned all my downloaded programs. I am baffled.
Logged
Goose18
Comodo's Hero
Offline
Posts: 1145
Re: Rootkit Detected
«
Reply #6 on:
September 23, 2007, 02:39:10 PM »
What anti spyware do you have? (Spybot Search & Destroy, Super Anti Spyware, AVG Anti Spyware, A-Squared?)
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
eaglehorse.houndsofhell
Newbie
Offline
Posts: 10
Re: Rootkit Detected
«
Reply #7 on:
September 23, 2007, 09:04:35 PM »
I use Spyware Terminator, Comodo BoClean and spywareblaster as a passive defense.
Logged
Goose18
Comodo's Hero
Offline
Posts: 1145
Re: Rootkit Detected
«
Reply #8 on:
September 23, 2007, 09:06:04 PM »
maybe try spybot search & destroy and super anti spyware and see if any of them find something?
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
Japo
x Help from Above x
Global Moderator
Comodo's Hero
Offline
Posts: 1146
Life starts everyday anew. Prospects not so good.
Re: Rootkit Detected
«
Reply #9 on:
September 24, 2007, 09:09:54 AM »
There are even on-line scanners so you don't have to install the full software, for example:
http://www.ewido.net/en/onlinescan/
Anyway don't really know and can't judge your chances of having a rootkit, but if you had it would be hiding malware so it wouldn't be detected by programs that would detect it were it not for the rootkit. About rootkit detection and removal I've heard good things about Blacklight, you can get a free trial beta, I tried it (found nothing) and it's even self-contained. They say it's thorough and also you don't need expertise to judge the results.
http://www.f-secure.com/blacklight/try_blacklight.html
Logged
How the right user account can help your computer security
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.182 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com