Rootkits
Home > Ask the Security Experts > SearchSecurity.com's Expert Archive Questions & Answers > How can I prevent an FU rootkit from spreading throughout a network?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How can I prevent an FU rootkit from spreading throughout a network?

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 26 September 2006
I believe that a user at my company has a rootkit installed on her laptop. Research on the Internet leads me to believe that the malware is an updated version of the FU rootkit. I'm worried that this infection could spread. Are there any steps I can take to isolate this offending malware so it doesn't infect our network systems?

>
EXPERT RESPONSE
The good news is that the most popular versions of the FU rootkit are not self-propagating, and they will not single-handedly penetrate other systems on your network. The bad news is that the FU rootkit may have been installed by some other form of malware (such as a worm or a bot) that could be using FU to hide itself. In that case, FU could be spread; not in and of itself, but by another pathogen on your network.

How do you prevent that from occurring? First, thoroughly clean the infected machine. One way to remove the pathogens from the system would be to run a couple of passes from two different antivirus tools. While that might eliminate the pathogen, you could go even further -- back up the user data from the machine, reformat the hard drive and then reinstall the operating system. That takes time, of course, but will give you a more thorough and trustworthy clean system.

To prevent the malware from spreading, make sure your network's systems have up-to-date antivirus tools with real-time protection. Carefully scrutinize any systems on which the users of the infected system have accounts, including server machines and those of other clients. The malware may have spread using the credentials of the users logged into "patient zero." Also, unless you have a defined business need for protocols like those supporting file and print sharing (using TCP and UDP ports 135-139 and 445), filter these Windows-associated systems at your network borders, and even on your internal network. If you do need these protocols, you likely only need to support them to and from file servers, printers, and perhaps Exchange mail servers. You most likely don't need them from client to client. Consider such filters as a preventative step for the next time around. If you are into scripting, you could write a login script on other systems that will look for the registry keys you found on the one infected machine. Then, you can see if the keys have been compromised.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Rootkits
Tips for SQL injection protection
Software still plagued with security holes, researcher says
Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
Yahoo, McAfee to warn users of dangerous websites
Botnets and ethics
Security Services: Webroot Email Security SaaS
Reasearch on Coding Backdoors Presents Ugly Picture
Microsoft PatchGuard: Locking down the kernel, or locking out security?
New Storm attack exploits April Fool's Day
Microsoft acquires rootkit detection vendor

SearchSecurity.com's Expert Archive
Are there antivirus suites that pick up more than just run-of-the-mill viruses?
What tools can a hacker use to crack a laptop password?
Are social networking sites an easy target for malicious hackers?
What are the dangers of cross-site request forgery attacks (CSRF)?
Should social engineering tests be included in penetration testing?
Best practices for using restriction policy whitelists
What kind of data is compromised during a Google hack?
Defining mobile device security concerns
What are the risks associated with RIM's line of PDAs?
What security measures can be taken to stop crimeware kits?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
keylogger  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts