Full Disclosure mailing list archives

Re: Full-Disclosure Digest, Vol 89, Issue 15 suspicion of rootkit (Alexandru Balan)


From: Григорий Братислава <musntlive () gmail com>
Date: Thu, 12 Jul 2012 11:00:36 -0400

On Thu, Jul 12, 2012 at 9:57 AM, phocean <0x90 () phocean net> wrote:
The only antivirus I have tried so far is Microsoft Security Essentials. And
it finds nothing, which I certainly don't trust at all.
Especially because it shows a very unusual certificate alert during the
setup.
I also scanned a few files that I chose (some dll and services) on
VirusTotal with no results except some false positive. I also had a look on
the disassembly of these files.
So, I don't know what it is, but if it is a rootkit it is not a trivial one
and I am afraid it is smarter than me :)

--- phocean


0x00 you say: "The only antivirus I have tried so far is Microsoft
Security Essentials." and this is why you're obvious fail.

Everyone knows only is Kaspersky and F-Secure is find any virus. They
is after all discover Flame single-handedisly.

I just checked your machine for you. You are is safe. Stay thirsty my friend

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: