Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 13th, 2012, 04:22 PM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Gmer couldn't terminate a Process

hi i was running Gmer just for fun on one off my offline machine x64 bit win 7
i found a notepad.exe process hidden

so before Doing anything i tried all other x64 Rootkit scanner Didn't find anything
hidden this process also was hidden to all Process manger

Process explorer , Kill switch and the normal task manager

so i tried tuminating the process via Gmer and a massage appeard "0xffffff"

is this a bug or should i investigate more
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #2  
Old April 13th, 2012, 06:14 PM
3x0gR13N 3x0gR13N is offline
Frequent Poster
 
Join Date: May 2008
Posts: 580
Default Re: Gmer couldn't terminate a Process

gmer isn't 64bit compatible, so funky stuff will happen on 64bit.
  #3  
Old April 14th, 2012, 10:36 AM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Gmer couldn't terminate a Process

So just keep my eyes closed and my finger crossed that i don't have a Rootkit ??
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #4  
Old April 14th, 2012, 10:55 AM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,049
Default Re: Gmer couldn't terminate a Process

Quote:
Originally Posted by Ranget
So just keep my eyes closed and my finger crossed that i don't have a Rootkit ??
if your worried then just run a few scans with antimalware boot disks. see my sig for recommendations.
__________________
Active@ Disk Image | 10 On-Demand Scanners

  #5  
Old April 14th, 2012, 10:59 AM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Gmer couldn't terminate a Process

i don't think antimalware Boot disk will detect anything
as far as i know they Run on Signature scanning

if the Rootkit is not known by the company it won't be detected by
those disk

but i think it won't hurt to try
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #6  
Old April 15th, 2012, 08:17 PM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,049
Default Re: Gmer couldn't terminate a Process

Quote:
Originally Posted by Ranget
i don't think antimalware Boot disk will detect anything
as far as i know they Run on Signature scanning

if the Rootkit is not known by the company it won't be detected by
those disk

but i think it won't hurt to try
a rootkit is not a rootkit when windows is not running because it cant hide itself at all from scanning engines (when scanned from a boot disk) so they are there for the taking. .

if your still paranoid after the boot disk scans then contact a specialist forum like majorgeeks
__________________
Active@ Disk Image | 10 On-Demand Scanners

  #7  
Old April 15th, 2012, 10:58 PM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,494
Default Re: Gmer couldn't terminate a Process

Using Xboot, I periodically make a bootable AntiMalware DVD which contains:

1. Kaspersky Rescue Disk 10
2. Dr.Web LiveCD
3. Avira Rescue System CD
4. Bitdefender Rescue CD

The DVD also contains numerous Linux OS's, MemTest86+, etc.

This DVD is easy and convenient to use.
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
  #8  
Old April 22nd, 2012, 01:27 PM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Gmer couldn't terminate a Process

it's an offline machine But if it's a bug i don't need the extra Work

anyway what is an 0xffffffff error
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #9  
Old April 22nd, 2012, 09:16 PM
kupo's Avatar
kupo kupo is offline
Frequent Poster
 
Join Date: Jan 2011
Posts: 919
Default Re: Gmer couldn't terminate a Process

You can also ask for help here -http://www.techguy.org/
And I've read this quote there.
Quote:
If you have a 64 bit computer do not download or run Gmer as it is not designed to work on a 64 bit system (no currently available rootkit scanner is) so will not give any useful information.
  #10  
Old April 30th, 2012, 03:18 PM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Gmer couldn't terminate a Process

when i found the process i run another scanner
that will analyse what in the memory and found the process

so Gmer isn't False i think it's some kind of a Logger anyway i could terminate it nor do anything else so i will wait and see if any automated program would
detect it
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #11  
Old May 15th, 2012, 06:44 PM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Gmer couldn't terminate a Process

the Hidden Process now is with a Different name

and it's not detected by any of the x64 Rootkit scanners

Gmer,truex64,tdsskiller,Sophos,sanitycheck

could it be something like Bios Rootkit or hypervisor rootkit
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #12  
Old May 16th, 2012, 05:46 AM
Cutting_Edgetech's Avatar
Cutting_Edgetech Cutting_Edgetech is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: USA
Posts: 1,728
Default Re: Gmer couldn't terminate a Process

Have you tried running Combofix to see if it finds anything? Its great, but use it with caution. If you use it incorrectly it can cause your machine to become inoperable so if your not sure something is safe to remove then visit mybleepingcomputer. They will assist you. Also, Malwarebytes is capable of finding rootkits. I have removed rootkits from machines using Malwarebytes so I know it detects them. You could also try running Hitman Pro just to see if it finds any other type of threats. Usually when I find a rootkit on someones machine it is accompanied with other nasties. You may also try UnHackMe. I believe its specifically for rootkits. I have never tried it so I don't know how good it is, but I have been curious about its capabilities / performance. Now may be a good time to put it to the test, but I do not know how safe it is to use. -http://www.greatis.com/unhackme/ GMER is one of my preferred apps for rootkits, but you have already taken that route. I also like Kaspersky, and Bitdefender rescue disk. For free expert help to verify you are infected, and removal assistance visit mybleeping computer, and read this thread -http://www.bleepingcomputer.com/forums/topic182397.html You may even further your education there from this experience.
__________________
Netgear Prosecure UTM25 | Online Armor | NOD 32 | Appguard | VoodooShield | Shadow Defender 1.1.0.325

Last edited by Cutting_Edgetech : May 16th, 2012 at 05:55 AM.
  #13  
Old May 16th, 2012, 05:54 AM
Cutting_Edgetech's Avatar
Cutting_Edgetech Cutting_Edgetech is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: USA
Posts: 1,728
Default Re: Gmer couldn't terminate a Process

BTW.. there use to be a thread here at Wilders with a list of experts that can a assist you. I wasn't able to locate it so i'm not sure if it still exist.
__________________
Netgear Prosecure UTM25 | Online Armor | NOD 32 | Appguard | VoodooShield | Shadow Defender 1.1.0.325
  #14  
Old May 20th, 2012, 12:59 PM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Gmer couldn't terminate a Process

thanks but i heard that unhackme has nothing new

i'm not going to use ComboFix nor CCE i have a Bad history with them
btw Combofix uses Gmer engine
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:46 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums