Sunday, March 12, 2006

Spyware, Malware, Viruses, Trojans, Rootkits

So I've been handed perhaps the most infected PC ever. There were a smattering of different malware types present. When are the 'antivirus people' going to stand up and own the whole malware prevention pie? Seems that instead of declaring that Trojans (something that have long been part of the antivirus watch list) have gotten smarter by being by rootkits they (Mcafee, Symantec, the others) seem to turn a blind eye. Perhaos not a blind eye - perhaps there's just a lag to develop a "new" product that will help against these new threats.

These ARE NOT new threats. They are the same old threats. Instead of a trojan being installed under the guise of doing something good, and instead deleting my mail, they are claiming something good - and installing other viruses or spawning processes, etc.

I spent the better part of 5 hours tracing down what turned out to be a rootkit based malware. The two files involved were sffelide.sys and sposhx32.exe. Knowing this didn't help either - a google search on these filenames results in ZERO hits -- are people just that unaware of these types of exploits? Doesn't look like the current slate of antivirus/antispyware programs detected this. The anti-rootkit apps (unhackme) seemed to be able to detect it, but could not automatically remove it.

This sucks.

2 Comments:

At 12:37 AM, March 13, 2006, Blogger Casual Penguin said...

ah ha - this seems to suggest that the press is aware

 
At 9:22 PM, March 20, 2006, Anonymous Corey said...

Hmmm... SysInternals Rootkit tool didn't help remove either?

 

Post a Comment

Links to this post:

Create a Link

<< Home