sony rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by jak3y, Dec 8, 2005.

  1. jak3y

    jak3y Guest

    http:// insight .zdnet.co.uk/0,39020415,39237277-4,00.htm

    the only way to get rid of this rootkit is to build a new machine?
    (apparently)
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Working link http://insight.zdnet.co.uk/internet/security/0,39020457,39237277,00.htm

    That's a bit alarmist. Yes, unless one has the rootkit to examine it is hard to tell what files have been modified or replaced.

    To take the approach of 'Nuke' the system, is a bit of overkill. If that's the case them we should just 'Nuke' the system anytime it gets infected.
     
  3. jak3y

    jak3y Guest

    So a clean format wouldn't do it alone?
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If you 'Nuke' the drive, as in low-level format and write a new MBR then wirte a new partion, format & clean install. The system will be clean, but I think going that route is overkill, and journalist who advocate that route are being alarmist.
     
  5. jak3y

    jak3y Guest

    Shadow in the article the guy that recommended killing the system entirely wasn't the journalist I don't think. I think he was a Microsoft progammer that was just being quoted as to what he thought of the thing.
    I'm pretty sure...then again, I could be wrong, I'll read it over. :p :cool:
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Rootkits aren't a new phenomena, they've been around for awhile. Not all rootkits are bad. The main concern here is that this is a grow trend to use rootkits to conceal the presence of a virus or spyware. The trick is knowing the diference between the good, legitimate file, and a bad one. Microsoft being as secretive as they are will make the task of identifing these bad processes more difficult. MS should publish the MD5 for every version of every file in every Windows OS that is currently in use. That would mean going back as far as Windows 3.1, yes I said 3.1.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds