CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

RED ALERT: New Rootkits in the Wild
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next
 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Tue Jan 08, 2008 4:14 pm    Post subject: Troj/NtRootK-CO
Reply with quote

Name Troj/NtRootK-CO
Type Rootkit

Affected operating systems Windows

Identification available since 8 January 2008

http://www.sophos.com/security/analyses/trojntrootkco.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Thu Jan 10, 2008 5:13 pm    Post subject:
Reply with quote

FYI...

Port-Hiding Rootkit
- http://blog.trendmicro.com/a-port-hiding-rootkit/
January 10, 2008 - "...TrendLabs researchers have come across another rootkit that hides ports. We’ve discovered a rootkit file that is able to hook TCPIP.SYS and related functions inside. It is able to hide ports

DestinationPort>3000 OR (DestinationPort<1000 AND DestinationPort!=80 AND DestinationPort!=25)

which are being used in the infect machine. The said malware, TROJ_ROOTKIT.DU, was indirectly included in the TROJ_PUSHDO.AD, TROJ_PUSHDO.AR (eCard), and WORM_NUWAR.EN (spam mail) package. Upon executing the aforementioned TROJ_PUSHDO.AD/TROJ_PUSHDO.AR/WORM_NUWAR.EN, the malware downloads the said TROJ_ROOTKIT.DU as a rootkit component to add stealth to the said malware families..."

(Screenshot available at the URL above.)

.


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Sat Jan 12, 2008 6:51 am    Post subject: Troj/Rootkit-BP
Reply with quote

Name Troj/Rootkit-BP
Type Trojan

Affected operating systems Windows

Side effects Modifies data on the computer
Reduces system security

Aliases Trojan-Proxy.Win32.Wopla.as
TR/Rootkit.Gen
Rkit/Agent.EZ
RTKT_AGENT.AJAY
RTKT_AGENT.AJAZ

Protection available since 12 January 2008

http://www.sophos.com/security/analyses/trojrootkitbp.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Tue Feb 12, 2008 6:13 am    Post subject: Troj/NtRootK-CW
Reply with quote

Name Troj/NtRootK-CW
Type Rootkit

Affected operating systems Windows


Identification available since 12 February 2008

http://www.sophos.com/security/analyses/trojntrootkcw.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Thu Feb 21, 2008 12:01 am    Post subject: Troj/NtRootK-CX
Reply with quote

Name Troj/NtRootK-CX
Type

* Rootkit

Affected operating systems

* Windows


Identification available since 20 February 2008

http://www.sophos.com/security/analyses/trojntrootkcx.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Thu Feb 21, 2008 6:13 am    Post subject: Troj/NtRootK-CY
Reply with quote

Name Troj/NtRootK-CY
Type Rootkit

Affected operating systems Windows

Side effects Downloads code from the internet

Identification available since 21 February 2008

http://www.sophos.com/security/analyses/trojntrootkcy.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Thu Feb 21, 2008 3:29 pm    Post subject: Troj/NtRootK-CZ
Reply with quote

Name Troj/NtRootK-CZ
Type Rootkit

Affected operating systems Windows

Identification available since 21 February 2008

http://www.sophos.com/security/analyses/trojntrootkcz.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Mar 03, 2008 6:22 am    Post subject: Troj/NtRootK-DB
Reply with quote

Name Troj/NtRootK-DB
Type Rootkit

Affected operating systems Windows

Identification available since 3 March 2008

Detected by Sophos Anti-Rootkit

http://www.sophos.com/security/analyses/trojntrootkdb.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Mar 03, 2008 3:33 pm    Post subject: Troj/NtRootK-DC
Reply with quote

Name Troj/NtRootK-DC
Type Rootkit

Affected operating systems Windows

Identification available since 3 March 2008

Detected by Sophos Anti-Rootkit

http://www.sophos.com/security/analyses/trojntrootkdc.html


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Fri Apr 04, 2008 5:09 am    Post subject: Troj/NtRootK-DE
Reply with quote

Troj/NtRootK-DE
Category Viruses and Spyware

Type Rootkit


Affected operating systems Windows

Protection available since 4 April 2008

http://www.sophos.com/security/analyses/viruses-and-spyware/trojntrootkde.html?_log_from=rss


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Sat Apr 05, 2008 3:15 pm    Post subject: Troj/NtRootK-DF
Reply with quote

Category Viruses and Spyware

Type Trojan

Protection available since 5 April 2008

Troj/NtRootK-DF is a rootkit for the Windows platform.


http://www.sophos.com/security/analyses/viruses-and-spyware/trojntrootkdf.html?_log_from=rss


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Sun Apr 06, 2008 6:07 pm    Post subject: Troj/RootKit-CI
Reply with quote

Troj/RootKit-CI


Category Viruses and Spyware

Type Rootkit


Affected operating systems Windows

Protection available since 6 April 2008

http://www.sophos.com/security/analyses/viruses-and-spyware/trojrootkitci.html?_log_from=rss


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Fri May 02, 2008 2:23 pm    Post subject: Troj/RootE-Gen
Reply with quote

Troj/RootE-Gen

Category Viruses and Spyware

Type Rootkit

Troj/RootE-Gen is a rootkit Trojan for the Windows platform.

Protection available since 2 May 2008

http://www.sophos.com/security/analyses/viruses-and-spyware/trojrootegen.html?_log_from=rss


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Fri May 02, 2008 2:25 pm    Post subject: Troj/RootD-Gen
Reply with quote

Troj/RootD-Gen


Category Viruses and Spyware

Type Rootkit

Troj/RootD-Gen is a rootkit Trojan for the Windows platform.

Protection available since 2 May 2008

http://www.sophos.com/security/analyses/viruses-and-spyware/trojrootdgen.html?_log_from=rss


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11731

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon May 19, 2008 5:52 am    Post subject: Troj/NtRootK-DH
Reply with quote

Troj/NtRootK-DH

Category Viruses and Spyware

Type Rootkit

Troj/NtRootK-DH is a rootkit Trojan for the Windows platform

Protection available since 19 May 2008

http://www.sophos.com/security/analyses/viruses-and-spyware/trojntrootkdh.html?_log_from=rss


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next
Page 6 of 8

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer