LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices

Reply
 
LinkBack Search this Thread
Old 12-30-2005, 10:16 AM   #1
pdeman2
Member
 
Registered: Jul 2005
Location: Maine, USA
Distribution: OpenSUSE, Gentoo, Fedora, Ubuntu, Mandriva, others
Posts: 413

Rep: Reputation: 30
What are some symptoms of rootkits?


I have a Windows computer on my network that starts extensive network communications and hard drive usage at the same time every day. There are no scheduled events or such things. It seems to me that it probably has a rootkit. What are some other symptoms I can look for regarding rootkits?
 
Old 12-30-2005, 10:39 AM   #2
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Lubuntu
Posts: 19,067
Blog Entries: 4

Rep: Reputation: 385Reputation: 385Reputation: 385Reputation: 385
Since this is about a Windows computer, I have moved it to General.
 
Old 12-30-2005, 11:01 AM   #3
cs-cam
Senior Member
 
Registered: May 2004
Location: Australia
Distribution: Gentoo
Posts: 3,544
Blog Entries: 4

Rep: Reputation: 56
Well check what IP it's talking to. If the machine has been comprimised then you mightn't be able to trust what it tells you but the router will keep accurate logs, find out who it's talking to. Once you know that it probably won't be too hard figuring out why they're talking. Go from there.
 
Old 12-30-2005, 11:19 AM   #4
pdeman2
Member
 
Registered: Jul 2005
Location: Maine, USA
Distribution: OpenSUSE, Gentoo, Fedora, Ubuntu, Mandriva, others
Posts: 413

Original Poster
Rep: Reputation: 30
I'll do an ethereal thing today or check the router logs. I'll post after that.

Last edited by pdeman2; 12-30-2005 at 11:20 AM.
 
Old 01-01-2006, 12:14 PM   #5
pdeman2
Member
 
Registered: Jul 2005
Location: Maine, USA
Distribution: OpenSUSE, Gentoo, Fedora, Ubuntu, Mandriva, others
Posts: 413

Original Poster
Rep: Reputation: 30
I just ended up reformatting. It seems to be fine now.
 
Old 01-01-2006, 02:41 PM   #6
slantoflight
Member
 
Registered: Aug 2005
Distribution: Smoothwall
Posts: 283
Blog Entries: 3

Rep: Reputation: 34
Quote:
Originally Posted by pdeman2
I just ended up reformatting. It seems to be fine now.
Well naturally your computer is more secure with no operating system installed.
 
Old 01-01-2006, 03:34 PM   #7
SciYro
Senior Member
 
Registered: Oct 2003
Location: hopefully not here
Distribution: Gentoo
Posts: 2,038

Rep: Reputation: 51
if the rootkit makers were smart, you wouldn't notice a thing (untill its to late).

But since you are talking about windows, it was most likely some script kiddie, or someone who just dont care if you find the rootkit (since there are so many other windows computers around, who cares if you find a rootkit?). In such cases, exessive network traffic would be a good sign, especially connections on a regular basis to the same computer outside your network, strange files/logs, strange processes running, etc. Other subtle tones might be "J0 g07 PWNED" all over your desktop, in big red letters.
 
Old 01-02-2006, 03:44 AM   #8
Charred
Member
 
Registered: Mar 2005
Location: Utah, USA
Distribution: Slackware 11
Posts: 816
Blog Entries: 2

Rep: Reputation: 30
"J0 g07 PWNED"...you crack me up, SciYro!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux rootkits. . should I worry? NetRAVEN5000 Linux - Security 3 10-20-2005 09:22 PM
Neutering Rootkits with a File Restore penguinlnx Linux - Security 6 04-01-2005 12:49 AM
how do rootkits work Chiel Linux - Newbie 1 08-31-2004 05:48 AM
do these symptoms mean my system is compromised? jimlaur Linux - Security 10 03-18-2004 12:20 PM
HELP! Are these HD failure symptoms?? registering Linux - Hardware 2 02-06-2004 11:53 AM


All times are GMT -5. The time now is 05:54 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration