[Full-disclosure] Re: unknown windows rootkit

From: Derek (derek_at_angelofsin.net)
Date: 11/21/05

  • Next message: securityadvisory: "[Full-disclosure] Computer Terrorism Security Advisory (Reclassification) - Microsoft Internet Explorer JavaScript Window() Vulnerability"
    Date: Mon, 21 Nov 2005 08:28:53 -0500
    To: full-disclosure@lists.grok.org.uk
    
    

    Your notes indicate you had trouble removing some registry entries. I'd
    suggest running PSExec from Sysinternals. It's free and comes with
    source from www.sysinternals.com, and the command would be something like:

     psexec /s /i /d c:\path\to\regedt32.exe

    If you can't edit or delete those keys this way, I don't know of another
    tool that will let you without resorting to an offline registry editor.

    >>We found what seems to be a unknown rootkit on a
    >>customer system which was windows 2000 sp4.
    >>It is a kernel resident infector as it installs itself as
    >>hidden device driver operating in kernel level to hide
    >>its directories and programs aswell as network connections.
    >>For our research we named it Win32/McSport-A.
    >>
    >>
    >>More Detailed informations aswell as removal instructions
    >>can be found here: http://www.groundzero-security.com/mcsport.html
    >>
    >>
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: securityadvisory: "[Full-disclosure] Computer Terrorism Security Advisory (Reclassification) - Microsoft Internet Explorer JavaScript Window() Vulnerability"

    Relevant Pages

    • Re: Disk cleanup registry changes?
      ... > I'm trying to script the Windows 2000 & XP disk cleanup. ... Upon doing this step, registry entries ... > command: cleanmgr.exe /sagerun:n. ...
      (microsoft.public.win2000.cmdprompt.admin)
    • Disk cleanup registry changes?
      ... I'm trying to script the Windows 2000 & XP disk cleanup. ... Upon doing this step, registry entries ... command: cleanmgr.exe /sagerun:n. ...
      (microsoft.public.win2000.cmdprompt.admin)
    • registry entries created with regedit do not get shadowed
      ... A software installer that I wrote installs some registry entries under ... copied during the install mode. ... Open command prompt. ... Open regedit and create a registry entry under HKCU. ...
      (microsoft.public.win2000.termserv.apps)
    • RE: Correct way of unistalling MSDE instance
      ... Possibly you can use a batch file to delete the folders from the drives. ... You can use a script to delete the registry entries. ... The command that you can use to remove registry entries is ...
      (microsoft.public.sqlserver.msde)