PDA

View Full Version : prevx says clean but gmer shows rootkit modification


thathagat
July 29th, 2009, 05:41 AM
well prevx and dr web av 5 realtime give this pc a clean bill of health but gmer scan has a scary tale to tell....so can i trust prevx or am i missing something ?
screen shot:

StevieO
July 29th, 2009, 06:03 AM
Hi, not really scary, but if you're not used to ARK's then they sure can be !

Looks like legit entries to me.

sr.sys = Sytem Restore which appears to be disabled ?

svchost = i imagine are normal windows files

You could always upload them to VT & Jotti to check

PrevxHelp
July 29th, 2009, 10:03 AM
I agree with SteveO - this looks like a false positive from GMER because the files are in the correct paths and under the correct service names. It might be worth installing and trying another antirootkit program to see if it finds anything as well.

Also note that some system protection programs (not Prevx, however) prevent antirootkit programs from functioning properly so you may want to double check with them disabled/uninstalled.

Let me know what you find :)

thathagat
July 29th, 2009, 10:44 AM
{QUOTE-> Let me know what you find <-QUOTE}
well panda antirootkit and rootkit revealer did not reveal any rootkit but there was one more entry in red by gmer that is not seen in the screen shot it was.{QUOTE-> Disk\Device\Harddisk\DRO sector 00:rootkit-like behavior; <-QUOTE}
but now i bid adieu to gmer for good its a bit too much for my tender heart;)

PrevxHelp
July 29th, 2009, 10:52 AM
Could you let us know what other security software you're using? (Mostly just so we prevent any FPs in the future which could be similar to GMER's ;D)

thathagat
July 29th, 2009, 11:03 AM
{QUOTE-> Could you let us know what other security software you're using? (Mostly just so we prevent any FPs in the future which could be similar to GMER's ;D) <-QUOTE}
oh well this was an old laptop xp sp3 which i dusted out to use so it won't feel neglected it has dr web av v5 /rollback but then i put my fav green eye ;) alias prevx to check its wellbeing all seemed well but windows update icon in the tool bar with 0% update got the hercule poirot in me to investigate the net result ....??? to:doubt: to:wacko:
i think i need to look for something else than rollback rx for my pcs it seems to cause a lot more fp warnings any suggestions?

aigle
July 29th, 2009, 12:14 PM
{QUOTE-> I agree with SteveO - this looks like a false positive from GMER because the files are in the correct paths and under the correct service names. It might be worth installing and trying another antirootkit program to see if it finds anything as well.

Also note that some system protection programs (not Prevx, however) prevent antirootkit programs from functioning properly so you may want to double check with them disabled/uninstalled.

Let me know what you find :) <-QUOTE}
Are you sure there are false positives?
@thathagat
can you scan with MBAM, SAS, HitmanPro and esp pls try RootRepeal.

thathagat
July 29th, 2009, 01:47 PM
{QUOTE->
@thathagat
can you scan with MBAM, SAS, HitmanPro and esp pls try RootRepeal. <-QUOTE}
here..........hope the mods don't Repeal this post
SAS:quick scan clean
Mbam:quick scan clean
Hitman pro:clean
RootRepeal:Among other hidden files about prevx/dr web this too
{QUOTE-> Hidden/Locked Files
-------------------
Path: Volume C:\
Status: MBR Rootkit Detected!
Hidden Services
-------------------
Service Name: PSched
Image PathSystem32\DRIVERS\psched.sys
<-QUOTE}
Gmer:Oh once again:-\
{QUOTE->
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior; <-- ROOTKIT !!!
---- Services - GMER 1.0.15 ----

Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] CryptSvc <-- ROOTKIT !!!
Service C:\WINDOWS\System32\DRIVERS\psched.sys (*** hidden *** ) [MANUAL] PSched <-- ROOTKIT !!!
Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [MANUAL] seclogon <-- ROOTKIT !!!
Service C:\WINDOWS\system32\DRIVERS\sr.sys (*** hidden *** ) [DISABLED] sr <-- ROOTKIT !!!
Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [AUTO] srservice <-- ROOTKIT !!!
<-QUOTE}

StevieO
July 29th, 2009, 05:27 PM
Often when using ARK's they highlight normal files etc that can behave in an RK fashion. Nothing to worry about generally, but i agree it's very alarming at first until you get more used to it. The danger is, deleting legit files that show up. Always try and cross reference with other Apps, and using a search www before even thinking of doing anything.

I still feel they are FP's, but if you send them to Prevx they'll soon tell you. Try to copy them to a new folder etc, via one of your ARK's.

PSCHED.SYS = Safe to use

The filename PSCHED.SYS is used by objects that are classified as safe. It has not yet been seen to be associated with malicious software.

http://www.prevx.com/filenames/3388485042604800442-X1/PSCHED.SYS.html


cryptsvc = Microsoft

seclogon = Secondary Logon Microsoft

PrevxHelp
July 29th, 2009, 06:00 PM
I agree that these are most likely FPs - thathagat: can you try removing the other security software you have installed to see if they are FPs caused by other product's protection? We had an FP a while back with our rootkit detection because of Comodo's disk protection making us think that files were rootkits which may be similar to what is happening here.

aigle
July 29th, 2009, 06:37 PM
Thanks. I just wonder why gmer is doing this. I will still like to post it over sysinternals.

thathagat
July 30th, 2009, 12:24 AM
{QUOTE-> thathagat: can you try removing the other security software you have installed to see if they are FPs caused by other product's protection? <-QUOTE}
well instead of un-installing softwares i went to base installation snapshot which has no av/as/am nothing and ran gmer+rootrepeal
gmer-now shows only one entry no hidden services etc
{QUOTE-> Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior; <-- ROOTKIT !!! <-QUOTE}
rootrepeal: shows no hidden sevices only this file
{QUOTE-> Path: Volume C:\
Status: MBR Rootkit Detected! <-QUOTE}
gmer screen shot:

PrevxHelp
July 30th, 2009, 01:41 AM
{QUOTE-> well instead of un-installing softwares i went to base installation snapshot <-QUOTE}

What program are you using for taking installation snapshots? Many of them hide the MBR which would explain the warning you're receiving.

EraserHW
July 30th, 2009, 03:42 AM
{QUOTE-> What program are you using for taking installation snapshots? Many of them hide the MBR which would explain the warning you're receiving. <-QUOTE}

From the screenshot looks like he's using Returnil, which would explain the false positive

kasperking
July 30th, 2009, 04:14 AM
{QUOTE-> What program are you using for taking installation snapshots? Many of them hide the MBR which would explain the warning you're receiving. <-QUOTE}
its rollback rx the tray icon is oh so unmistakeably horrendous... at least for me

PrevxHelp
July 30th, 2009, 10:42 AM
{QUOTE-> its rollback rx the tray icon is oh so unmistakeably horrendous... at least for me <-QUOTE}

Rollback Rx would most likely be the culprit for the rootkit warning as it does hide the MBR.

A word of caution: don't use the fix MBR utilities on your system as you may lose your snapshots if they think they're cleaning the rootkit which is actually your rollback software :)