PDA

View Full Version : Rootkit.Unclassified/USBHubB found by SuperAntiSpyware run within UBCD4Win


Sylvander
10-01-2008, 06:23 AM
Just playing around in UBCD4Win.

Ran SuperAntiSpyware scanning program.

Found...
Rootkit.Unclassified/USBHubB = 8 Detected Items. SURPRISED! :eek:

Removed those.

No sign of usbhubb.sys anywhere on C:
Normally in c:\windows\system32\drivers\ I believe.

c:\windows\system32\drivers\usbhub.sys is there OK.

Also found a great list of cookies.
Left those alone; not sure if it's a good idea to remove such as those.

Comments anyone? :)

powysbiker
01-10-2009, 04:07 PM
This is a false alarm because the version of SuperAntiSpyware on UBCD4WIN is out of date. See: http://forums.superantispyware.com/viewtopic.php?f=4&t=2130&p=10946

I'm probably preaching to the converted on here but I always find that it's also worth doing a scan with Spyware Doctor (Free functional version on http://pack.google.com) as soon as the target machine is up and running again. These two between them seem to find most things but each finds things that the other doesn't.

--
Pete

star_sau
07-28-2010, 01:08 AM
Is this a recommended download? RootkitRevealer v1.71 By Bryce Cogswell

jlreich
07-28-2010, 12:11 PM
No sign of usbhubb.sys anywhere on C:
The very nature of a rootkit is that it is well hidden and you can't see it with normal means.

usbhub.sys is a normal system file. usbhubb.sys (with the second b) is sometimes showing as a rootkit but is also a legitimate custom usb file for booting windows from a USB drive. Did you ever try to get XP booting from USB?

Also there are a lot of false positives out there today. I am currently running Comodo AV/FW and it flags many of my malware removal tools as well as no-DVD fixes for games and some other known good system utilities as malware. Avast, which I just stopped using because it has become as bloated as Norton and bogs down my system, did the same thing.