| View previous topic :: View next topic |
| Author |
Message |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Sat Jul 15, 2006 1:31 pm Post subject: ADS question |
|
|
As many of you know I started fighting rootkits and the like a while back by removing drives and scanning them as slave drives to cripple the rootkit . I know that ADS are now often accompanying rootkits .
What would be the best NON-antimalware methods for destroying ADS ? I heard renaming the system32 folder and naming it back could destroy one of them . From what I have read it sounds like ADS are kind of like a file that has been deleted . It is still there but NTFS isn't keeping track of it so it can be overwritten . Would cut and paste also copy the ADS or would (because it is not being kept track of) just be ignored ? What about defrag ?
|
|
| Back to top |
|
 |
AbuIbrahim
Security Expert Special Response Team
 Joined: Jan 18, 2006 Posts: 1930
|
|
| Back to top |
|
 |
wawadave
Special Response Team Special Response Team
 Joined: Nov 22, 2002 Posts: 21503 Location: Installing Vista http://tinyurl.com/2l9qyd
|
|
| Back to top |
|
 |
Ikeb
Special Response Team Forums Admin
 Joined: Apr 20, 2003 Posts: 16543
|
Posted: Sat Jul 15, 2006 6:57 pm Post subject: |
|
|
So I take it ADS is a mechanism that can create rootkit-like files? I tried creating a few files as per Lawrence's tutorial but get "The filename, directory name, or volume label syntax is incorrect." Can I assume that ADS is not activated on my system?
|
|
| Back to top |
|
 |
plunx
Lieutenant

 Joined: Nov 01, 2005 Posts: 194 Location: Sweden
|
Posted: Sat Jul 15, 2006 7:21 pm Post subject: |
|
|
| Ikeb wrote: | | So I take it ADS is a mechanism that can create rootkit-like files? I tried creating a few files as per Lawrence's tutorial but get "The filename, directory name, or volume label syntax is incorrect." Can I assume that ADS is not activated on my system? |
Hi Ikeb
As I understands it ADS is always active within NTFS volumes.
Example from F-Secure:
http://www.f-secure.com/v-descs/mailbot_az.shtml
Question:
As F-Secure remarks a file can support ADS or not and how is that
done.... EDIT It was "file system" within F-Secures description and that must be NTFS or not.
Symantecs description:
http://www.sarc.com/avcenter/venc/data/backdoor.rustock.a.html
The "gentlemens" at R--tkit.com also has some more about it.
regards
plunx
|
|
| Back to top |
|
 |
AbuIbrahim
Security Expert Special Response Team
 Joined: Jan 18, 2006 Posts: 1930
|
Posted: Sat Jul 15, 2006 7:30 pm Post subject: |
|
|
It worked fine with me.
You probably misstyped something.
Is your root drive formatted with NTFS file system? _________________ Microsoft MVP - Consumer Security 2008
An Invitation to Think - York University
|
|
| Back to top |
|
 |
Ikeb
Special Response Team Forums Admin
 Joined: Apr 20, 2003 Posts: 16543
|
Posted: Sun Jul 16, 2006 4:52 am Post subject: |
|
|
Ah! Not the root but I tried it on an NTFS-formatted volume and indeed ADS is active. Does this mean it's best *not* to format NTFS volumes?
|
|
| Back to top |
|
 |
plunx
Lieutenant

 Joined: Nov 01, 2005 Posts: 194 Location: Sweden
|
Posted: Sun Jul 16, 2006 9:13 am Post subject: |
|
|
| Ikeb wrote: | | Ah! Not the root but I tried it on an NTFS-formatted volume and indeed ADS is active. Does this mean it's best *not* to format NTFS volumes? |
Hi Ikeb
If a "normal" user (also "educated" about risks) with "normal" surf/mail habits and a protected patched PC compare risks I would say that everyone should choose NTFS despite of ADS.
http://www.theeldergeek.com/ntfs_or_fat32_file_system.htm
If we also checks F-Secures PE386 description the bad guys uses alternative tacticts with or without ADS.
| Quote: | When the rootkit driver is executed, it creates a copy of itself to an Alternate Data Stream - %SystemRoot%\system32:[random_number]. However, since the code does not seed the pseudorandom-number generator (code bug), the alternate data stream is always created as:
* %SystemRoot%\System32:18467
If the file system does not support Alternate Data Streams, the driver is installed to:
* %SystemRoot%\System32\Drivers\pe386.sys
|
Nevertheless it´s strange that ADS cannot be disabled........ ??
http://www.windowsecurity.com/articles/Alternate_Data_Streams.html
MS Basic:
http://support.microsoft.com/kb/105763
regards
plunx
|
|
| Back to top |
|
 |
wawadave
Special Response Team Special Response Team
 Joined: Nov 22, 2002 Posts: 21503 Location: Installing Vista http://tinyurl.com/2l9qyd
|
Posted: Sun Jul 16, 2006 3:53 pm Post subject: |
|
|
if you disable ads than you won,t be able to see mac computers. possibly Linux as well. since most servers are Linux unix based this may or may not be a problem, as packets are sent and received . but it would mean computers on a lan may or may not be able to see shared doc folders etc.
but it would be nice if some security app could disable this.
there may be a reason other than whats publicly release about ads and what they do that we are not being told. _________________ Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
|
|
| Back to top |
|
 |
plunx
Lieutenant

 Joined: Nov 01, 2005 Posts: 194 Location: Sweden
|
|
| Back to top |
|
 |
wawadave
Special Response Team Special Response Team
 Joined: Nov 22, 2002 Posts: 21503 Location: Installing Vista http://tinyurl.com/2l9qyd
|
|
| Back to top |
|
 |
negster22
Security Expert Premium Member
 Joined: Mar 10, 2004 Posts: 5394
|
Posted: Mon Jul 17, 2006 1:05 am Post subject: |
|
|
I used ADS Spy to remove ADS which were left from an incomplete CWS infection removal. Kaspersky AV identfified a few of the files, and that was the first indication of their presence. When I used Merjin's ADS Spy, it identified many additional ADS infected files and removed all of them. So I would give it a thumbs up.
In the case of a rootkit driver hidden in the ADS of the system32 folder such as PE386, the driver must be unloaded first before attempting ADS removal of the driver file. _________________ Negster22 - MS MVP - Consumer Security 2006-2008
|
|
| Back to top |
|
 |
wawadave
Special Response Team Special Response Team
 Joined: Nov 22, 2002 Posts: 21503 Location: Installing Vista http://tinyurl.com/2l9qyd
|
|
| Back to top |
|
 |
plunx
Lieutenant

 Joined: Nov 01, 2005 Posts: 194 Location: Sweden
|
|
| Back to top |
|
 |
wawadave
Special Response Team Special Response Team
 Joined: Nov 22, 2002 Posts: 21503 Location: Installing Vista http://tinyurl.com/2l9qyd
|
Posted: Mon Jul 17, 2006 6:27 am Post subject: |
|
|
i think software companies and ms add data to them to id files. if you d/l with ie i,ll bet the time date and ip of where is hidden useing this. i,ll bet many windows files have many things hidden by these and i know windows its self has many rootkit like functions. but beyound my skills to prove or disprove.
are there any apps that let you read the ads info? _________________ Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
|
|
| Back to top |
|
 |
|
|