root_drv.sys rootkit
From: Llistes Diverses (deixalles_at_gmail.com)
Date: 11/08/04
- Previous message: Marc Fossi: "SecurityFocus Microsoft Newsletter #213"
- Next in thread: Renouf, Phil: "RE: root_drv.sys rootkit"
- Maybe reply: Renouf, Phil: "RE: root_drv.sys rootkit"
- Maybe reply: Dennis Dimka: "RE: root_drv.sys rootkit"
- Maybe reply: Calder, James (EXP): "RE: root_drv.sys rootkit"
- Maybe reply: Roy Morris: "RE: root_drv.sys rootkit"
- Maybe reply: Ryan Parrish: "Re: root_drv.sys rootkit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 8 Nov 2004 20:02:49 +0100 To: focus-ms@securityfocus.com
Hello all,
I have a Windows 2003 Web Edition Server that has been compromised due
to some big mistakes of us.
The question is that now this server have a rootkit installed. It
contains some complex configuration and i would like sooo much to be
able to keep the server without reinstall !!
The rootkit is loaded from C:\winnt\system32\root_drv.sys (i can see
it running with TaskInfo2003).
File is hidden and can't be seen within windows at user level, but i'm
able to see and remove file from a linux box with samba.
So i remove the file, i remove whole dllcache and i reboot system. But
root_drv is back there again and running !!
Any clue where is that rootkit backed up and/or how can i remove it !!
Any idea which rootkit is that and where can i find some info about?
Help me please!!
Thany you all!
BR,
Xavi.
---------------------------------------------------------------------------
---------------------------------------------------------------------------
- Previous message: Marc Fossi: "SecurityFocus Microsoft Newsletter #213"
- Next in thread: Renouf, Phil: "RE: root_drv.sys rootkit"
- Maybe reply: Renouf, Phil: "RE: root_drv.sys rootkit"
- Maybe reply: Dennis Dimka: "RE: root_drv.sys rootkit"
- Maybe reply: Calder, James (EXP): "RE: root_drv.sys rootkit"
- Maybe reply: Roy Morris: "RE: root_drv.sys rootkit"
- Maybe reply: Ryan Parrish: "Re: root_drv.sys rootkit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|