No unusual hard drive activity or anything like that. It only gets nasty and fights back when you start poking it.

After SP3 was installed, I created an image of the drive on a hidden partition, just in case.

And can't get rid of Remote Disc either.You'll notice some of the dates are 9/9/2014 which is the most frequently used date for things that are created. Law enforcement says this is a civil matter to be handled through cyber experts who investigate these scenarios for a very large fee. I am sure it would send the system into a tailspin, but I have nothing critical on this drive _yet_ so it wouldn't matter to me if I corrupted something and This is more than likely not a problem.

  • Am I just being paranoid after 20 years of using Windows, or is there possibly a real problem here??
  • I'll give that a try.
  • nothing found Searching for Volc rootkit...
  • not infected Checking `sendmail'...
  • You don't need to do what CooKooBird suggested in his 8:14pm post because MEMSWEEP2 is from Sophos AntiRootkit.
  • Code: [[email protected] ~]# man chkrootkit No manual entry for chkrootkit Heh! __________________ Glenn The Bassinator Last edited by glennzo; 12th February 2010 at 12:57 PM.
  • Please go away and bother someone else.

not infected Checking `netstat'... One good rootkit detection application for Windows is the RootkitRevealer by Windows security analysts Bryce Cogswell and Mark Russinovich. not infected Checking `slapper'...

It then makes a copy of the CD somewhere so it can alter it and future boots are pointed there instead of to the actual disk.

chaslang, Jul 3, 2008 #27 AverageJoe Private E-2 Ah...that is too bad that my disk isn't "real". There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped. It would be something like MacPro5,1. You have a brick...There really is no way around this, the firmware is used to boot and will always re-install the rootkit as you have noticed.

MEMSWEEP is not malware.

Or am I just paranoid? nothing found Searching for Omega Worm... I need to try mounting as read only and run from the drive directly.

But back to the idea of removing the drive...I completely removed the hard drive, reset NVRAM, and restarted.

Code: [[email protected] ~]# chkrootkit ROOTDIR is `/' Checking `amd'... Any newer firmware cannot be infected.

A couple of days ago (as I was in a tinkering mood) I decided to take a closer look at the whole issue and decided to run rkhunter and chkrootkit. Security threats expert Kevin Beaver says, "I had good luck with both BlackLight and Anti-Rootkit in my test environment."

All checks skipped The system checks took: 4 minutes and 46 seconds All results have been written to the log file (/var/log/rkhunter/rkhunter.log) One or more warnings have been found while checking Finding and removing rootkit installations is not an exact science.

nothing found Searching for AjaKit rootkit default files and dirs... nothing found Searching for t0rn's default files and dirs... not found Checking `passwd'...

Booting from the Recovery Drive gives a very subtley altered version of the real thing and functions in a way that seems normal, but reading the install logs shows webooks and not infected Checking `egrep'...

It is not a malware scanning tool per say.