I have a computer that was behaving funny, so i used rootkit unhooker to scan its code hooks. 130 odd hooks on ntoskrnl.exe.
would that be a rootkit?
a bit inexperienced in this so im asking for advice.
Possible rootkit?, Seems strange
Possible rootkit?, Seems strange
|
|
Jun 20 2007, 10:26 AM, updated 19y ago
Show posts by this member only | Post
#1
|
|
Moderator
1,154 posts Joined: Sep 2004 |
I have a computer that was behaving funny, so i used rootkit unhooker to scan its code hooks. 130 odd hooks on ntoskrnl.exe.
would that be a rootkit? a bit inexperienced in this so im asking for advice. |
|
|
|
|
|
Jun 20 2007, 11:28 AM
Show posts by this member only | Post
#2
|
![]() ![]() ![]()
Junior Member
371 posts Joined: Aug 2006 |
QUOTE(Mudmaniac @ Jun 20 2007, 10:26 AM) I have a computer that was behaving funny, so i used rootkit unhooker to scan its code hooks. 130 odd hooks on ntoskrnl.exe. Looks like it. But to be sure, you can use several AV programs incorporating rootkit to confirm as you would want to see the related files used. check out fsecure blacklight, Panda, Avira(http://www.antirootkit.com/software/Avira-Rootkit-Detection.htm), Sophos (http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html). Finally, start using an AV which supports rootkit detection and removal...would that be a rootkit? a bit inexperienced in this so im asking for advice. Hope this helps... |
|
|
Jun 20 2007, 12:02 PM
Show posts by this member only | Post
#3
|
|
Moderator
1,154 posts Joined: Sep 2004 |
heres the weird thing. i just scanned it again. and all the hooks disappeared. this is really pissing me off.
|
|
|
Jun 20 2007, 12:08 PM
Show posts by this member only | Post
#4
|
|
VIP
2,496 posts Joined: Jan 2003 From: LowYatDotNet Status:Agast |
download sysinternal's rootkit revealer from the pinned thread and let's have a look at your screenie. since it doesn't have removal capabilities, use killbox downloadable from http://killbox.net/ but let's take a look first.
|
|
|
Jun 20 2007, 12:21 PM
Show posts by this member only | Post
#5
|
|
Moderator
1,154 posts Joined: Sep 2004 |
cant get a screenie because the box is offline. usb doesnt seem to power up properly.
but there were three entries. i know this is vague, but 2 talk about secrets(i have seen these on all computer i have scanned with revealer), one is a mismatch in microsoft crypto random number generator seed or something. |
|
|
Jun 21 2007, 01:43 PM
Show posts by this member only | Post
#6
|
![]() ![]() ![]() ![]()
Senior Member
684 posts Joined: Apr 2006 From: FPSO kwame nkrumah |
sry to ask noob question but wat does rootkit unhooker do to ur comptr..
Thankss... |
|
|
Jul 3 2007, 10:39 PM
Show posts by this member only | Post
#7
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,188 posts Joined: Nov 2005 |
First Google, Next Ask.
Rootkit Unhooker Scans for Possible Places where a Rootkit might reside. (If I am not mistaken, includes API Hooks, ADS in NTFS and so on...) @TS, Why not ask for some help from Technical Support? I believe the mods there will be very informed about rootkits. Cheers! |
| Change to: | 0.0144sec
0.73
5 queries
GZIP Disabled
Time is now: 24th December 2025 - 11:58 AM |