What is a RootKit?
Miscellaneous Forums/General Discussion/What is a RootKit?
Anyone know what the heck a Root Kit is and why a powerpoint about it is being sent to people via Skype? It's apparently a hook to open a backdoor on a pc providing hackers access... but how and why was I targetted via Skype?
Anyone anymore on this please?
IPete2
Not sure about the Skype thing, but...
http://en.wikipedia.org/wiki/Root_kit
Thanks,
NOTE If anyone recieves a document via SKYPE from me or another Blitz Forum member called "RootKit.ppt", or anything else
PLEASE DO NOT ACCEPT it !!!!
I don't know how or why this is happening, but it has happend.
Im in the middle of a full scan to be sure, not sure how good that result will leave me.
IPete2.
NOTE If anyone recieves a document via SKYPE from me or another Blitz Forum member called "RootKit.ppt", or anything else
I'd go as far as to say if anyone ever receives any file from anyone whatsoever in email or any instant messaging program, don't open it or don't accept it until you know what it is. MSN has had a series of trojans which operate like this.
Hopefully this is nothing serious, and often it isn't, but it does pay to be cautious. I've taken the odd risk at times and been very lucky so far, I'd have to say.
It's a jungle out there, folks. ;)
You are right of course,
The problem is this came from someone I know, and he received the same thing from me.
We both asked each other "Whats this youve sent me?" and by then it was too late.
CAUTION Will Robinson!
IPete2.
There has been a recent scare regarding a Skype worm that has been downgraded.
Not sure I have heard of this RootKit.ppt
You say yourself and the other party got this from each other. Did this RootKit.ppt send itself (without the sender knowing) or did it attach itself to an email that was meant to be sent?
Is this in relation to a particular email - ie, if you send another email now is this thing attaching itself to everything you send?
I found a similar named attachment coming from DC214 - this is a sort of hacking group - they come under the Defcon Groups. This is coming under the guise of Black Security Research Group - I see no Black Security Research Group - I couldn't trace them as a company, but tracked them to
http://blacksecurity.org/ - their attachment which is 'rootkit_basics.ppt' is basically a powerpoint presentation on how to design a rootkit.
On browsing their site, I am find various .ppt files that have Rootkit in the title 'BL4CK_-_Rootkit_Basics' etc.
You can probably safely open the .ppt file in notepad, just to get an idea of what is contained in there - there will be a lot of garbage (probably the bulk of it), but there should be recognisable English in there as to what the ppt is about.
Puki,
This thing appeared on both our desktops as a note saying the other person was sendin it. I know this other guy and though oh I wonder that this is then...
At exactly the same time - he thought the same and we both sent each other a Skype message, like msn chat but Skype chat.
We then both quizzed each other with a worried tone - this is a joke right? You did send it to me didnt you - except niether of us sent it.
A little worrying. A full scan last night revealed no problems, but you never know do you?
IPete2.
It just reveals that skype, like any other app you allow to use the internet, is not secure. It reveals a fatal security problem of skype: A new computer virus/worm/trojan seems to make use of the adress book of skype. That's the new bit. Everything else is well known. We've seen this especially with worms that used to read the microsoft adressbook that is used most times with outlook. Where at the other hand outlooks vulnerabilities were used to distribute the virus. So this time it's skype. It usually depends on the popularity of an application.
The problem with a well-designed rootkit is that you'll never actually know it's there.
If you sustect that your machine has a rootkit, the only safe, sure way to detect it is to boot off (say) a BartPE CD or a Linux LiveCD. Then, you go hunting for something that's not supposed to be there.
There is a program, somewhere, that you can put on a BartPE CD that simply lists every file/directory on the HD, and you run this twice: once under Windows (or whatever OS you suspect has the rootkit), and once from the live CD. The results are compared, and if file/directories appear in the LiveCD scan that are not there under the Windows scan, then something (possibly a rootkit) is actively hiding something from the host OS.
The only safe, sure way to fix a rootkit is totally wipe the HD and reinstall.
Sorry, guys.
actually I wouldn't count on ms when it comes to rootkit removing. The OS is like a garden for rootkits.
Maybe better try something like Icesword or so.
RootkitRevealer... that's the one!
Just because it's a MS tool doesn't mean it's bad. As far as I can remember, that particular one came from Microsoft Research.
afaik rootkit revealer is from sysinternals not from microsoft. It is also only a diagnose tool and can't remove or kill selfprotecting malware, where icesword can do. that said, you need to know what you do with icesword since it allows to actually remove anything.
an easier tool would be blacklight of f-secure,although it may miss a couple of things.
kits like vanquish for example can only be detected by browsing processes that have been autoloaded and/or used to bend system vectors and calls, eg. by dll injection.
Icesword may also allow you to prepare a list of processes that should be killed at one time, so a process cannot stay alive trough cloning itself.
See also this page:
www.invisiblethings.org
I'm not sure he has been infected by a rootkit though - I think the situation here is purely the fact that somehow a file called 'RootKit.ppt' has arrived/left (or both), or tried to, arrive/leave (or both) his computer.
Feel free to email this 'RootKit.ppt' file to me. I shall proceed to slap its arse.
It wasn't a rootkit, but since the file was saved without his request, it looks rather like malware, additionally, the name rootkit.ppt is a teaser name, like paris-hilton-naked.ppt. If you receive such a thing for no reason then it surely is a virus.
paris-hilton-naked.ppt
Ew Gross!!! :))
A rootkit is a nasty spyware package that tries to defeat deletion...it can even restore itself after you delete it...you have to find the root which is sometimes in the systemvolumeinfo folder.
All the spyware killer software I had could find it and delete it but could never delete the root because it was in a read only folder ^^
Had to manually track down and delete the darn thing.
Those cyber sickies never give up do they...
Tried to use Skype - it wouldn't work properly - not sure if this is the rootkit messing up my installation.
Anyway I have syetm restored to earlier on the day it happened. Sykpe working properly again. I shall keep an eye out for dodgy goings on and keep you guys posted - thanks for the replys btw, useful although slightly worrying.
IPete2.