Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 29th, 2009, 05:41 AM
thathagat
 
Posts: n/a
Unhappy prevx says clean but gmer shows rootkit modification

well prevx and dr web av 5 realtime give this pc a clean bill of health but gmer scan has a scary tale to tell....so can i trust prevx or am i missing something ?
screen shot:
Attached Thumbnails
Click image for larger version

Name:	prevx clean gmer not.JPG
Views:	28
Size:	148.7 KB
ID:	210833  

  #2  
Old July 29th, 2009, 06:03 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: prevx says clean but gmer shows rootkit modification

Hi, not really scary, but if you're not used to ARK's then they sure can be !

Looks like legit entries to me.

sr.sys = Sytem Restore which appears to be disabled ?

svchost = i imagine are normal windows files

You could always upload them to VT & Jotti to check
  #3  
Old July 29th, 2009, 10:03 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: prevx says clean but gmer shows rootkit modification

I agree with SteveO - this looks like a false positive from GMER because the files are in the correct paths and under the correct service names. It might be worth installing and trying another antirootkit program to see if it finds anything as well.

Also note that some system protection programs (not Prevx, however) prevent antirootkit programs from functioning properly so you may want to double check with them disabled/uninstalled.

Let me know what you find
  #4  
Old July 29th, 2009, 10:44 AM
thathagat
 
Posts: n/a
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Let me know what you find
well panda antirootkit and rootkit revealer did not reveal any rootkit but there was one more entry in red by gmer that is not seen in the screen shot it was.
Quote:
Disk\Device\Harddisk\DRO sector 00:rootkit-like behavior;
but now i bid adieu to gmer for good its a bit too much for my tender heart
  #5  
Old July 29th, 2009, 10:52 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: prevx says clean but gmer shows rootkit modification

Could you let us know what other security software you're using? (Mostly just so we prevent any FPs in the future which could be similar to GMER's )
  #6  
Old July 29th, 2009, 11:03 AM
thathagat
 
Posts: n/a
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by PrevxHelp
Could you let us know what other security software you're using? (Mostly just so we prevent any FPs in the future which could be similar to GMER's )
oh well this was an old laptop xp sp3 which i dusted out to use so it won't feel neglected it has dr web av v5 /rollback but then i put my fav green eye alias prevx to check its wellbeing all seemed well but windows update icon in the tool bar with 0% update got the hercule poirot in me to investigate the net result .... to to
i think i need to look for something else than rollback rx for my pcs it seems to cause a lot more fp warnings any suggestions?
  #7  
Old July 29th, 2009, 12:14 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by PrevxHelp
I agree with SteveO - this looks like a false positive from GMER because the files are in the correct paths and under the correct service names. It might be worth installing and trying another antirootkit program to see if it finds anything as well.

Also note that some system protection programs (not Prevx, however) prevent antirootkit programs from functioning properly so you may want to double check with them disabled/uninstalled.

Let me know what you find
Are you sure there are false positives?
@thathagat
can you scan with MBAM, SAS, HitmanPro and esp pls try RootRepeal.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #8  
Old July 29th, 2009, 01:47 PM
thathagat
 
Posts: n/a
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by aigle
@thathagat
can you scan with MBAM, SAS, HitmanPro and esp pls try RootRepeal.
here..........hope the mods don't Repeal this post
SAS:quick scan clean
Mbam:quick scan clean
Hitman pro:clean
RootRepeal:Among other hidden files about prevx/dr web this too
Quote:
Hidden/Locked Files
-------------------
Path: Volume C:\
Status: MBR Rootkit Detected!
Hidden Services
-------------------
Service Name: PSched
Image PathSystem32\DRIVERS\psched.sys
Gmer:Oh once again
Quote:
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior; <-- ROOTKIT !!!
---- Services - GMER 1.0.15 ----

Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] CryptSvc <-- ROOTKIT !!!
Service C:\WINDOWS\System32\DRIVERS\psched.sys (*** hidden *** ) [MANUAL] PSched <-- ROOTKIT !!!
Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [MANUAL] seclogon <-- ROOTKIT !!!
Service C:\WINDOWS\system32\DRIVERS\sr.sys (*** hidden *** ) [DISABLED] sr <-- ROOTKIT !!!
Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [AUTO] srservice <-- ROOTKIT !!!
  #9  
Old July 29th, 2009, 05:27 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: prevx says clean but gmer shows rootkit modification

Often when using ARK's they highlight normal files etc that can behave in an RK fashion. Nothing to worry about generally, but i agree it's very alarming at first until you get more used to it. The danger is, deleting legit files that show up. Always try and cross reference with other Apps, and using a search www before even thinking of doing anything.

I still feel they are FP's, but if you send them to Prevx they'll soon tell you. Try to copy them to a new folder etc, via one of your ARK's.

PSCHED.SYS = Safe to use

The filename PSCHED.SYS is used by objects that are classified as safe. It has not yet been seen to be associated with malicious software.

http://www.prevx.com/filenames/33884...SCHED.SYS.html


cryptsvc = Microsoft

seclogon = Secondary Logon Microsoft
  #10  
Old July 29th, 2009, 06:00 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: prevx says clean but gmer shows rootkit modification

I agree that these are most likely FPs - thathagat: can you try removing the other security software you have installed to see if they are FPs caused by other product's protection? We had an FP a while back with our rootkit detection because of Comodo's disk protection making us think that files were rootkits which may be similar to what is happening here.
  #11  
Old July 29th, 2009, 06:37 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: prevx says clean but gmer shows rootkit modification

Thanks. I just wonder why gmer is doing this. I will still like to post it over sysinternals.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #12  
Old July 30th, 2009, 12:24 AM
thathagat
 
Posts: n/a
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by PrevxHelp
thathagat: can you try removing the other security software you have installed to see if they are FPs caused by other product's protection?
well instead of un-installing softwares i went to base installation snapshot which has no av/as/am nothing and ran gmer+rootrepeal
gmer-now shows only one entry no hidden services etc
Quote:
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior; <-- ROOTKIT !!!
rootrepeal: shows no hidden sevices only this file
Quote:
Path: Volume C:\
Status: MBR Rootkit Detected!
gmer screen shot:
Attached Thumbnails
Click image for larger version

Name:	gmer 1 detection.JPG
Views:	9
Size:	116.2 KB
ID:	210846  

  #13  
Old July 30th, 2009, 01:41 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by thathagat
well instead of un-installing softwares i went to base installation snapshot

What program are you using for taking installation snapshots? Many of them hide the MBR which would explain the warning you're receiving.
  #14  
Old July 30th, 2009, 03:42 AM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by PrevxHelp
What program are you using for taking installation snapshots? Many of them hide the MBR which would explain the warning you're receiving.

From the screenshot looks like he's using Returnil, which would explain the false positive
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute
  #15  
Old July 30th, 2009, 04:14 AM
kasperking's Avatar
kasperking kasperking is offline
Frequent Poster
 
Join Date: Nov 2008
Posts: 406
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by PrevxHelp
What program are you using for taking installation snapshots? Many of them hide the MBR which would explain the warning you're receiving.
its rollback rx the tray icon is oh so unmistakeably horrendous... at least for me
  #16  
Old July 30th, 2009, 10:42 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: prevx says clean but gmer shows rootkit modification

Quote:
Originally Posted by kasperking
its rollback rx the tray icon is oh so unmistakeably horrendous... at least for me

Rollback Rx would most likely be the culprit for the rootkit warning as it does hide the MBR.

A word of caution: don't use the fix MBR utilities on your system as you may lose your snapshots if they think they're cleaning the rootkit which is actually your rollback software
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:55 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums