Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista General

Rootkits in Vista RC-1 and RC-2 ?

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 10-11-2006   #1 (permalink)
breakin hardware
Guest


 

Rootkits in Vista RC-1 and RC-2 ?

I have Win XP on my first physical drive and a second physical drive for
trying out Vista
Before the Vista install my system was clean of virus's and root kits
After the install I ran root kit revealer again and have 27 discrepancies
over both drives
I have had some strange behavior in XP, I burned a linux DVD for my other
box and when I shut down Nero I got the small hourglass flickering next to my
mouse pointet
I did the three finger salute and looked at the process tab in task
manager, I spotted rundll.32 appearing and disappearing all over the place
I reopened Nero and closed it to calm things down
I am concerned about these findings, I tried sophos antirootkit and it
found two files on my Vista drive
Does Vista use a new boot scheme ? I noticed some new files in the root
directory of my XP drive and the boot.ini has been tweaked
Boot times for XP have increased a bit
And then the strange behavior
Looks like I get to format half a terabyte a drive space and start over

My System SpecsSystem Spec
Old 10-11-2006   #2 (permalink)
Rick Rogers
Guest


 

Re: Rootkits in Vista RC-1 and RC-2 ?

Hi,

The roottkit tool may not know what to do with various Vista functions, so
before making assumptions check with the distributor.

Vista uses winload.exe to start the OS before passing control to
ntoskrnl.exe, and it (winload.exe) relies on reading a BCD file under
C:\boot. This initial startup sequence is very different than that used by
previous NT systems, so may be part of what is confusing the rootkit tool.

Nero has had problems reported on every build of Vista so far, I wouldn't
rely on anything regarding it thus far. Hopefully, the folks at Ahead will
get it worked out shortly as Vista goes RTM.

> Looks like I get to format half a terabyte a drive space and start over


You should not get involved in beta products if you are not willing and able
to do this. It's par for the course.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Windows help - www.rickrogers.org

"breakin hardware" <breakinhardware@discussions.microsoft.com> wrote in
message news:35C43A83-FD2B-4026-B31D-F997B3DB7D01@microsoft.com...
>I have Win XP on my first physical drive and a second physical drive for
> trying out Vista
> Before the Vista install my system was clean of virus's and root kits
> After the install I ran root kit revealer again and have 27 discrepancies
> over both drives
> I have had some strange behavior in XP, I burned a linux DVD for my other
> box and when I shut down Nero I got the small hourglass flickering next to
> my
> mouse pointet
> I did the three finger salute and looked at the process tab in task
> manager, I spotted rundll.32 appearing and disappearing all over the place
> I reopened Nero and closed it to calm things down
> I am concerned about these findings, I tried sophos antirootkit and it
> found two files on my Vista drive
> Does Vista use a new boot scheme ? I noticed some new files in the root
> directory of my XP drive and the boot.ini has been tweaked
> Boot times for XP have increased a bit
> And then the strange behavior
> Looks like I get to format half a terabyte a drive space and start over


My System SpecsSystem Spec
Old 10-11-2006   #3 (permalink)
Kerry Brown
Guest


 

Re: Rootkits in Vista RC-1 and RC-2 ?

I agree with Rick Rogers. I wouldn't trust the output from a rootkit scanner
on a computer that has Vista installed. The boot process is very different
and Vista has changed the ACLs on many folders and files which may cause the
rootkit scanner to give false positives. Interpeting the result from a
rootkit scanner takes an expert. I have been cleaning viruses, malware, and
rootkits for years and I often have to do a considerable amount of research
when interpeting the results of any given scan. If you want to use a rootkit
scanner with Vista the only way to proceed would be to set up the computer
without Vista, scan it and note the results. Install Vista, run the scan,
and note the differences. For future scans look for any more changes and
then research these changes.

--
Kerry
MS-MVP Windows - Shell/User
http://www.vistahelp.ca


breakin hardware wrote:
> I have Win XP on my first physical drive and a second physical drive
> for trying out Vista
> Before the Vista install my system was clean of virus's and root kits
> After the install I ran root kit revealer again and have 27
> discrepancies over both drives
> I have had some strange behavior in XP, I burned a linux DVD for my
> other box and when I shut down Nero I got the small hourglass
> flickering next to my mouse pointet
> I did the three finger salute and looked at the process tab in task
> manager, I spotted rundll.32 appearing and disappearing all over the
> place
> I reopened Nero and closed it to calm things down
> I am concerned about these findings, I tried sophos antirootkit and it
> found two files on my Vista drive
> Does Vista use a new boot scheme ? I noticed some new files in the
> root directory of my XP drive and the boot.ini has been tweaked
> Boot times for XP have increased a bit
> And then the strange behavior
> Looks like I get to format half a terabyte a drive space and start
> over



My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
RE: RootKits? oscar Vista General 3 08-13-2008 10:24 AM
Removing RootKits cyranodesade Vista security 14 08-16-2007 04:12 PM
Removing RootKits cyranodesade Vista file management 14 08-16-2007 04:12 PM
Removing Rootkits from Boot Sector. cyranodesade Vista General 2 08-05-2007 08:40 PM
Windows Rootkits/Virus Issues. Spot Vista security 2 01-24-2007 03:14 PM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51