CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Icesword, vsdatant

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
spiritbeing

Cadet
Cadet


Joined: Oct 13, 2006
Posts: 2
Location: USA

PostPosted: Fri Oct 13, 2006 5:51 pm    Post subject: Icesword, vsdatant
Reply with quote

I ran Icesword and I found no red items for processes and win32 but I found a few in SSDT. All pointed to C:\systemRoot\System32\vsdatant.sys. The original and current addresses are different and maybe that's to protect itself from viruses trying to turn it off.

I'm also running zone alarm and I understand that it uses this file so maybe there is nothing wrong with this. Would this be a false positive?

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Oct 13, 2006 7:12 pm    Post subject:
Reply with quote

Yes, a false positive, that is indeed ZA. Icesword reports on both good and bad rootkits, and ZA (like most firewalls) use rootkit techniques to link into the OS at a very low level in the kernel.

BTW, I'm moving this thread to the Rootkit Revelations Forum where it is more appropriate, and marking it done since there is nothing to fix.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
spiritbeing

Cadet
Cadet


Joined: Oct 13, 2006
Posts: 2
Location: USA

PostPosted: Fri Oct 13, 2006 8:10 pm    Post subject:
Reply with quote

Thanks for the confirmation. From Icesword it looks like I can eliminate a rootkit as the possible cause. If the symptoms show up again I'll try other tools although Icesword is supposed to be one of the best if not the best.

I've tried NOD32, Spysweeper, adaware, defender, zone alarm and nothing showed up so I thought it might be a rootkit. I'll just keep my fingers crossed.

Thanks again.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer