Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Help, possible rootkit |
|---|---|
| Date: | Mon, 25 Oct 2004 12:58:39 -0400 |
You could try HIDEWNDW (http://www.winsite.com/bin/Info?500000013369). You can use it to Show hidden Windows. If you see things there that look out of place, you can shut it down. Additionally, swing on by SYSINTERNALS, download the PSTOOLS and PROCESS EXPLORER. Use them to get a good understanding of EXACTLY what is running on your system. Use the Process Explorer to identify everything running under that Hidden Window you found using the hidewndw program. It will lists, DLL's, path's etc.. Another useful tool is FILEMON. That will list out every file that is touched/accessed in real time. Nice sorting/highlighting too. Maybe download ETHEREAL and monitor all incoming/outgoing traffic. You may see something there. Under XP, you can run MSCONFIG and see what you have starting up under windows, whether it be Processes or Registry RUN items.. You can disable them there. All the while, confirming that your ANTIVIRUS DAT Files are up to date and that your computer comes up clean after a SCAN. If you don't have an AV solution, that's most likely your problem. However, you can swing on over to TREND MICRO (http://housecall.trendmicro.com/) for a free scan. BTW, have you looked at SPYBOT and ADAWARE? Also.. If your MOUSE is jumpy, are you using WIRELESS products, ie KEYBOARD or Mouse. Are your batteries fairly new? I've seen bad batteries cause jumpy mice/keyboards. Also.. STUCK KEYS can cause that too! Confirm you have no debris/food stuck in your keys. Imagine you start your computer and the ENTER key is stuck down. That might cause some problems =). However I'd tend to think that would cause a KEY STUCK error on boot. If it was me, I would try to identify the problem, and once I figured it out, I would REFORMAT anyway. Once your PC is "infected" by some MALWARE, there is never a way to get it back 100% to the way it was. It's just not worth the hassle. Reformat and be on your way! Good Luck. JMB -----Original Message----- From: Okiwaso [mailto:okiwaso@hotmail.com] Sent: Saturday, October 23, 2004 12:07 PM To: security-basics@securityfocus.com Subject: Help, possible rootkit I have noticed that my XP system is behaving like I have a rootkit. - My mouse is jumpy (it freezes for a second when I move it around the desktop) and the minimized Taskmanager in the systray shows I have around 25 - 30 % usage, but when I open it, there is no process listed using this much. - I did a netstat, fport, openports and none of these show that I have any odd ports open or any connections established. - even when I disconnect from the Internet these symptoms do not stop. They stop if I reboot, but then start again. I have ran VICE, Klister, PatchFinder and RkDetect from rootkit.com and they could not find anything. Any more suggestions ? Any more rootkit finding tools for Windows ? Thanks Bill
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Searching for Canadian IT Security agencies...., marcus peddle |
|---|---|
| Next by Date: | Re: XML Soap reporting support in security devices, Atul Gosain |
| Previous by Thread: | Help, possible rootkit, Okiwaso |
| Next by Thread: | Secure SMTP setup/ISA 2004, Dan Tesch |
| Indexes: | [Date] [Thread] [Top] [All Lists] |