Questions tagged [rootkit]

Rootkits are programs designed to hide malicious activity on a compromised computer by hiding files, processes or registry entries.

77 questions
60
votes
7 answers

My webcam just came on "out of the blue"

I have a Microsoft LifeCam HD sitting atop my monitor. Today, completely out of the blue, its light came on -- I was simply browsing the web (in Chrome) when it happened. After about 5 minutes the webcam turned off. Naturally, I immediately…
AngryHacker
  • 19,327
11
votes
4 answers

Am I attacked or just stupid?

I run a server using Debian Squeeze with several OpenVZ containers. The containers run mostly Squeeze, some Lenny, and some already updated to Wheezy. The host doesn't do that much beyond iptables and DHCP. File servers, proxies, mail servers,…
Lars Hanke
  • 211
  • 1
  • 5
10
votes
9 answers

UAC being turned off once a day on Windows 7

I have strange problem on my HP laptop. This began to happen recently. Whenever I start my machine, Windows 7 Action Center displays the following warning: You need to restart your computer for UAC to be turned off. Actually, this does not…
7
votes
3 answers

Suspicious drivers, is it a rootkit?

The following entries show up in DriverView on my PC: C:\Windows\System32\Drivers\dump_dumpata.sys C:\Windows\System32\Drivers\dump_dumpfve.sys C:\Windows\System32\Drivers\dump_msahci.sys These files do not exist or are hidden. I didn't find…
user56312
  • 183
  • 1
  • 1
  • 5
6
votes
2 answers

Why is elasticsearch user running SSHD?

My home network is frequently down and I've narrowed down the problem to my ubuntu box. $ ps -ef | grep elastic elastic+ 11183 1 0 8월10 ? 00:07:49 [.ECC6DFE919A382] eugenek+ 14482 14453 0 22:08 pts/19 00:00:00 grep elastic elastic+…
eugene
  • 317
6
votes
5 answers

BIOS root kit? Or, how do I fresh install a clean BIOS?

So I was installing questionable operating system onto my EEE pc and it required me to downgrade the BIOS which I really am not an expert at. I used a patch and it appeared to work. Now, I'm paranoid about the downgrade because, honestly, I have no…
Leopold_Bloom
5
votes
8 answers

Which rootkit cleaner do you recommend for Windows XP?

Answering the question "Task Manager shows 100% CPU utilization, but nothing in process list does.", Paul Woodward stated that his problem with 100% CPU was a rootkit infecting his computer. My computer seems to suffer from the same problem. Which…
4
votes
4 answers

Strange phishing attack?

When I login to wachovia/wells fargo/amazon/paypal , no matter the user/pass that I insert, i get a "we need to verify your information" page where they ask me everything, from the atm pin to my ssn to my mom's maiden name (LOL) Then, when i insert…
Magnetic_dud
  • 3,702
3
votes
2 answers

OS X rootkit/spyware scanners?

For OS X, I have discovered Rootkit Hunter recently and liked the functionality. What other rootkit/spyware scanners for OS X have been developed that are available for use?
Troggy
  • 10,259
3
votes
4 answers

How does badBIOS jumps airgaps?

I was reading this article from Ars on badBIOS and came across this line which states the malware, has the ability to use high-frequency transmissions passed between computer speakers and microphones to bridge airgaps. and wondered if this attack…
Ashildr
  • 2,770
  • 5
  • 28
  • 45
3
votes
3 answers

Is there a way to find rootkits on 64-bit Windows 7

I was at work and got a help desk call about a rather severe malware infection and it got me thinking about my own computer. I am running Windows 7 64-bit RC1 on my everyday laptop. I run ESET NOD32 antivirus which does a good job of keeping…
3
votes
2 answers

what does it mean for MalwareBytes to find malicious registry keys but nothing else?

I have a machine that is obviously infected, and when I ran MalwareBytes it told me that it found some "malicious" registry keys (surprisingly enough these contained file path to currently non-existent javascript files). But, that's it. Full scan…
3
votes
1 answer

Can signature verification expose a rootkit?

I know that rootkits operate as part of the kernel, driver or service running on the system, injecting themself into DLLs or installing as a legitimate applications. If I were to scan the system with sigverif.exe, would the files injected with the…
Dean
  • 359
3
votes
1 answer

Are spare sectors stored in a hard drive's Host Protected Area (HPA)?

I need to wipe some used hard drives before using them in case they contain malware. Is it safe to remove the host protected area? Is the HPA used to store spare sectors? It is only 1 MB but might contain malware. Can the HPA be wiped, then…
3
votes
1 answer

Linux workstation: how to know if it has been rooted?

I was working on my Linux "workstation" (it has no sound and I don't play on it nor watch any movie: it's purely a work-machine, hence I call it my "workstation") and suddenly something very weird happened. I was browsing, using a temporary user…
Weezy
  • 535
1
2 3 4 5 6