A new rootkit.

Discussion in 'NOD32 version 2 Forum' started by DonKid, Feb 15, 2006.

Thread Status:
Not open for further replies.
  1. DonKid

    DonKid Registered Member

    Joined:
    Jun 27, 2004
    Posts:
    566
    Location:
    S?o Paulo, Brazil
    I read today, that Mr. and Mrs. Smith DVD installs a rootkit in your PC.
    According to Settec, they have a uninstall for their tecnology called Alpha-DISC, in their website.
    F-Secure has published the news yesterday , but Cool Daddy told us since february 9.
    I hope NOD32 can detect it.

    http://www.f-secure.com/weblog/archi....html#00000810

    Best Regards,

    DonKid.
     
  2. Brian N

    Brian N Registered Member

    Joined:
    Jul 7, 2005
    Posts:
    2,174
    Location:
    Denmark
    Yeah NOD detects it. HB actually wrote about it somewhere.. Lemme just find it

    Edit: Well maybe not. He was checking it out though
     
  3. seamaiden

    seamaiden Registered Member

    Joined:
    Dec 8, 2004
    Posts:
    67
    Location:
    Fresno, California, USA
  4. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    Well we need to here from someone in this forum to tackle this new Rootkit!! :thumbd: :thumbd: And not just Eset but all other products in this forums!!:doubt: :doubt:
     
    Last edited: Feb 15, 2006
  5. FirePost

    FirePost Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    213
    Why not change the auto play option to take no action. Then one can choose which player to use and the autostart junk they try to add is never activated.
     
  6. tony62

    tony62 Registered Member

    Joined:
    Aug 26, 2005
    Posts:
    214
    Location:
    UK
    Or simply disable Shell Hardware Detection Service.;)
     
  7. DonKid

    DonKid Registered Member

    Joined:
    Jun 27, 2004
    Posts:
    566
    Location:
    S?o Paulo, Brazil
    Or a simple solution.
    After insert a DVD, keep Shift pressed, so the DVD drive won´t run anything.
     
  8. FirePost

    FirePost Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    213
    But one must remember to press the key then :)
     
  9. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    But it does not ask or tell you that it is installing anything that's why I wonder why NOD does not pick it up or even BOclean? And now I have the Dam thing on my Box My Burning speed will not go above 1.8x on a 16x Burner!!

    I am asking how to get it off my Computer because I think it is Malware as I cannot not burn a DVD any faster which sucks! o_O o_O

    Could someome from Eset comment on this?

    TIA,

    Daniel
     
    Last edited: Feb 17, 2006
  10. DonKid

    DonKid Registered Member

    Joined:
    Jun 27, 2004
    Posts:
    566
    Location:
    S?o Paulo, Brazil
    Hi Triple Helix.

    If the rookit is from Settec, please look here:

    http://uninstall.settec.com/eng/

    Best Regards,

    DonKid.
     
  11. Elwood

    Elwood Registered Member

    Joined:
    Sep 12, 2005
    Posts:
    205
    Location:
    Mis'sippi
    You might want to ask Kevin McAleavey why BOClean didn't pick up on it? He's easy to get in touch with.
     
  12. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    Thanks Elwood! Done!!

    Cheers,
     
  13. Elwood

    Elwood Registered Member

    Joined:
    Sep 12, 2005
    Posts:
    205
    Location:
    Mis'sippi
    You're welcome. I'd be interested to know the gist of what he says.
     
  14. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    I will post back when I get some info!!

    Regards,
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.