3/26/2009 12:29:00 AM

software: Rootkit is the new virus...

Posted by McSimillian


....well not exactly :p

My lappy got infected with a rootkit a couple o' days ago..T___T
i think it got thru because i forgot to switch on my firewall for a couple of days after playing DoTa yea wtf right... >___>
if you're not sure what a rootkit is, here's a lil definition from wikipedia:

"A rootkit is malware that consists of a program, or combination of several programs, designed to hide or obscure the fact that a system has been compromised."

Its also sometimes known as a "backdoor trojan", which likes to do it from the back
-____-"

i forgot the name of the rootkit but what it did was:
  • starts IE and running automatically in the background and directing to the websites fulldotfind.com or edotfind.com, dont check the sites out, might be harmful...
  • eat up resources
  • the websites will sometimes play a rock music in a very low distorted volume like from a radio
  • and if you do close the IE using task manager, it will start up again within 10 minutes or so...
  • very annoying, but worse of all the PC will eventually freeze, crash, hang or get a BSOD x____x
  • also, since it like to do it from the back, it allows hackers to hack your PC and prevent you from running software that could remove the rootkit using regular antivirus software or weak rootkit removers
How to check if you're infected as well?
  • just open up task manager: press ctrl+alt+del simultaneously to bring up the console
  • go to the processes tab
  • click on User Name field to rearrange the list
  • if you see iexplore.exe but you've not opened IE you could possibly be infected
  • to confirm, check the history for the 2 website either: fulldotfind.com or edotfind.com

solution:
i used UnHackMe, quite a good antirootkit software, very easy to use as well :D
click here to try out the 30 day demo
or get the full version from you know who =p

if you just wanna check if you've got any other rootkits in your system
get this instead
you wont need to install it
just download and scan, its very fast
you'll know if you have rootkits if a result shows up in red colored fonts

0 comments:

Post a Comment


asp hit counter