![]() |
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
|
Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
br> br> |
| |||||||
|
| | Thread Tools | Display Modes |
| | #1 (permalink) |
| Guest | New Vista installation - rootkit found! I've been running Vista RC1/RC2 for several months without problems so decided to upgrade to the new release. I installed Vista Ultimate OEM on a new hard drive and everything proceeded smoothly. Before doing anything else I went to Grisoft's site and downloaded and installed AVG free. I then ran AVG and it found the trojans c:/windows/system32/agony.sys and c:/windows/system32/winsecurity/mswinup.exe, which I understand are some sort of rootkit. Obviously I wasn't happy about this on a new installation, so I reformatted and installed the whole thing again. This time everything was fine. My questions are: How did this rootkit get itself onto a new system and why didn't UAC and Windows Defender prevent this or, at least, warn me about it? -- Walter. |
My System Specs![]() |
| | #2 (permalink) |
| Guest | Re: New Vista installation - rootkit found! Hi Walter, can you provide a little more information on what way the installations were performed. When you installed Vista RC1, did you "upgrade" something like XP? Where did you get your Vista Disk, was it downloaded from the Microsoft site? Did you find the rootkit on the new hard drive? There is plenty of anti-rootkit info at http://www.antirootkit.com Zoned :-) |
My System Specs![]() |
| | #3 (permalink) |
| Guest | Re: New Vista installation - rootkit found! Walter Docherty wrote: > I've been running Vista RC1/RC2 for several months without problems so > decided to upgrade to the new release. I installed Vista Ultimate OEM > on a new hard drive and everything proceeded smoothly. Before doing > anything else I went to Grisoft's site and downloaded and installed AVG > free. > > I then ran AVG and it found the trojans c:/windows/system32/agony.sys > and c:/windows/system32/winsecurity/mswinup.exe, which I understand are > some sort of rootkit. > > Obviously I wasn't happy about this on a new installation, so I > reformatted and installed the whole thing again. This time everything > was fine. > > My questions are: How did this rootkit get itself onto a new system and > why didn't UAC and Windows Defender prevent this or, at least, warn me > about it? > Dude... it's designed that way. Windows vista has emerged from a long line of windows source code and window is insecure by design. Yes, vista is, at the moment, more secure than previous versions of windows. But give it a few months, weeks, days or hours and it'll prove itself as insecure as every version before it. -- Jerry McBride |
My System Specs![]() |
| | #4 (permalink) |
| Guest | Re: New Vista installation - rootkit found! On 1 Feb 2007 14:50:27 -0800, Zoned wrote: > When you installed Vista RC1, did you "upgrade" something like XP? No, it was a clean install. I triple-boot this machine but prefer to do this via the BIOS. So when I installed Vista I followed my usual procedure of unplugging the existing three drives and installing onto the new, clean, hard drive. > Where did you get your Vista Disk, was it downloaded from the > Microsoft site? Nope. It was purchased, together with the new hard drive, from a large retailer here in the UK and was in the usual sealed MS package. Anyway, the infection couldn't have been on the DVD as the second re-installation was clean. > Did you find the rootkit on the new hard drive? Yes. It was the only drive installed at the time so the infection couldn't have come from any of the existing drives. > There is plenty of anti-rootkit info at http://www.antirootkit.com Thanks. I've had a quick look and bookmarked the site for a more in-depth look when I have more time. I've a lot to learn about this problem - this is the first time I've ever had any kind of infection after running Win95/ME/XP for many years so it's not something I've paid much attention to, beyond running the usual AV/Anti-Spyware software. Thanks for your reply. -- Walter. |
My System Specs![]() |
| | #5 (permalink) |
| Guest | RE: New Vista installation - rootkit found! "Walter Docherty" wrote: > I've been running Vista RC1/RC2 for several months without problems so > decided to upgrade to the new release. I installed Vista Ultimate OEM > I then ran AVG and it found the trojans c:/windows/system32/agony.sys > and c:/windows/system32/winsecurity/mswinup.exe, which I understand are > some sort of rootkit. > My questions are: How did this rootkit get itself onto a new system because it was in your pirated copy of Vista |
My System Specs![]() |
|
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| CD/DVD -- not found after RC1 installation | ShagNasty | Vista hardware & devices | 4 | 10-31-2007 09:20 AM |
| Vista rootkit issue - all legit. software | Bob | Vista security | 6 | 10-04-2007 07:03 PM |
| Can a Rootkit Be Certified for Vista? p2... | spamhotmail | Vista General | 1 | 03-17-2007 06:05 PM |
| Can a Rootkit Be Certified for Vista? | spamhotmail | Vista General | 0 | 03-17-2007 03:48 PM |
| cd-dvd driver not found at installation | Patrick | Vista installation & setup | 0 | 03-13-2007 06:58 PM |
| Complimentary Industry Resources Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today! |