Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Possible rootkit?, Seems strange

views
     
TSMudmaniac
post Jun 20 2007, 10:26 AM, updated 19y ago

Creepy Uncle Liar
Group Icon
Moderator
1,154 posts

Joined: Sep 2004


I have a computer that was behaving funny, so i used rootkit unhooker to scan its code hooks. 130 odd hooks on ntoskrnl.exe.

would that be a rootkit?
a bit inexperienced in this so im asking for advice.
bean_man
post Jun 20 2007, 11:28 AM

Casual
***
Junior Member
371 posts

Joined: Aug 2006


QUOTE(Mudmaniac @ Jun 20 2007, 10:26 AM)
I have a computer that was behaving funny, so i used rootkit unhooker to scan its code hooks. 130 odd hooks on ntoskrnl.exe.

would that be a rootkit?
a bit inexperienced in this so im asking for advice.
*
Looks like it. But to be sure, you can use several AV programs incorporating rootkit to confirm as you would want to see the related files used. check out fsecure blacklight, Panda, Avira(http://www.antirootkit.com/software/Avira-Rootkit-Detection.htm), Sophos (http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html). Finally, start using an AV which supports rootkit detection and removal...

Hope this helps...
TSMudmaniac
post Jun 20 2007, 12:02 PM

Creepy Uncle Liar
Group Icon
Moderator
1,154 posts

Joined: Sep 2004


heres the weird thing. i just scanned it again. and all the hooks disappeared. this is really pissing me off.

AsenDURE
post Jun 20 2007, 12:08 PM

je suis desole. je n'y crois pas a ces conneries!!
Group Icon
VIP
2,496 posts

Joined: Jan 2003
From: LowYatDotNet Status:Agast
download sysinternal's rootkit revealer from the pinned thread and let's have a look at your screenie. since it doesn't have removal capabilities, use killbox downloadable from http://killbox.net/ but let's take a look first.
TSMudmaniac
post Jun 20 2007, 12:21 PM

Creepy Uncle Liar
Group Icon
Moderator
1,154 posts

Joined: Sep 2004


cant get a screenie because the box is offline. usb doesnt seem to power up properly.

but there were three entries.

i know this is vague, but 2 talk about secrets(i have seen these on all computer i have scanned with revealer), one is a mismatch in microsoft crypto random number generator seed or something.
~hunter~
post Jun 21 2007, 01:43 PM

PLsS bE PatiEnT (I'm FasTinG)
****
Senior Member
684 posts

Joined: Apr 2006
From: FPSO kwame nkrumah



sry to ask noob question but wat does rootkit unhooker do to ur comptr..

Thankss...
natakaasd
post Jul 3 2007, 10:39 PM

Look at all my stars!!
*******
Senior Member
2,188 posts

Joined: Nov 2005


First Google, Next Ask.

Rootkit Unhooker Scans for Possible Places where a Rootkit might reside. (If I am not mistaken, includes API Hooks, ADS in NTFS and so on...)

@TS,
Why not ask for some help from Technical Support? I believe the mods there will be very informed about rootkits.

Cheers!

 

Change to:
| Lo-Fi Version
0.0144sec    0.73    5 queries    GZIP Disabled
Time is now: 24th December 2025 - 11:58 AM