bhlegend dot com
May 18, 2013, 08:48:55 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: SMF - Just Installed!
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Celebrating my first rootkit!  (Read 1281 times)
0 Members and 1 Guest are viewing this topic.
Herzeg Dva
Like, whatever!
****
Offline Offline

Posts: 3151



View Profile
« on: April 23, 2009, 12:20:39 PM »

I noticed Avast uploading files to a suspicious URL and then it hit me: I got a nasty rootkit! Of course nothing could detect the frakker except for ComboFix. All these resident AV and firewall apps are no good against some of those rootkits. What info could it possibly have stolen? I don't do financial transactions on my PC and prefer the old fashioned way. My emails aren't that important either.

Code:
c:\windows\system32\drivers\ovfsthymnfwabwruwgbobrrnsdknkcpwkwpxbj.sys
c:\windows\system32\ovfsthaisotuibndroqhjqbdqompcpsbxjlgjj.dat
c:\windows\system32\ovfsthcpdcrhroagncpbvobuvrmnhbittadydj.dll
c:\windows\system32\ovfsthepyedijkdaicckfnoyxevvhblqgjlpss.dll
c:\windows\system32\ovfsthlkllxfvemtsorgvxbcxmyowuicdiioag.dll
c:\windows\system32\ovfsthudbmfweufjqoaxenawiiixlvniqsdlkx.dat

Of course the filenames are randomly generated strings but has anyone been affected by this rootkit before? Catchme's log doesn't define the actual rootkit.
Logged
DeadMeat
Global Moderator
BFG
*****
Offline Offline

Posts: 6743


.. just cause!


View Profile
« Reply #1 on: April 26, 2009, 08:45:22 AM »

Rootkits?

Nevah heard of em :p
Logged

Trouble
Like, whatever!
****
Offline Offline

Posts: 4069


The Online Abortion


View Profile
« Reply #2 on: April 26, 2009, 11:17:08 AM »

Never had one, that I know of.

I find the whole thought of them utterly terrifying though.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC Valid XHTML 1.0! Valid CSS!