Welcome, Guest. Please login or register.
December 27, 2009, 12:38:08 AM

Login with username, password and session length

345440 Posts
38149 Topics
86624 Members

Latest Member: gerrance

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Which Product do you want Comodo to develop next?
| | |-+  Rootkits!
« previous next »
Pages: [1] Go Down Print
Author Topic: Rootkits!  (Read 1331 times)
Vunox
Comodo Member
**
Offline Offline

Posts: 27


« on: May 15, 2009, 08:35:13 AM »

Hi I have been using Comdo Firewall for sometime and am very happy with it!! Well done!
However I have recently tried sorting a friends PC which had been infected with more than one rootkit.
These are very very bad news!!! Intecepting them before the OS boots seems the only way. Many anti rootkit softweare seems unable to catch or clean every one. I for one would like to see some clear protection for this built in to CIS. Are there plans?
  After many hours work I am still not sure If this PC is clean!
Something to boot off or load first would be a cool idea. (as not to slow the boot process down it could be disabled)
 I can't see these things going away!
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6574


Why not ? The choice is yours !


« Reply #1 on: May 15, 2009, 09:24:44 AM »

Comodo starts up as the first application so you should besafe anytime. Wenn going on a computer so infected remember to put defense+ in costum policy mode.

Thanks
Xan
Logged

Rotty
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 898


http://www.venganza.org/ - Noodly Appendage


« Reply #2 on: May 15, 2009, 10:43:06 PM »

In that situation I would suggest wiping that hard drive using a linux boot disk such as DBAN (You need to wipe every bit of the hard drive, including the MBR).  It's nearly impossible to be 100% sure that a rootkit is gone without wiping the drive(s) of the computer.  Even then, I wouldn't necessary suggest flashing the BIOS (At this point) but it's remotely possible that its compromised too.

Also, only restore the computer with media that is known to be clean (Hasn't been burnt when the computer was infected).

Firewalls and antivirus products are best for prevention against rootkits, once a rootkit takes hold the OS cannot be trusted.



« Last Edit: May 15, 2009, 10:46:32 PM by Rotty » Logged

The opinions expressed in my posts are my own. 
They do NOT necessarily represent or reflect the views of my employer.
Vunox
Comodo Member
**
Offline Offline

Posts: 27


« Reply #3 on: May 17, 2009, 03:55:45 AM »

Sadly that is what I have had to do. It would be still nice if Comodo had some feature which is the kicks in  before the OS actually does . Unhackme appears as far as I know be the only app to do this . But I not sure to trust this app or not. Better Comodo!
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.034 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com