Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 31st, 2012, 09:07 PM
crykid crykid is offline
Infrequent Poster
 
Join Date: Mar 2012
Posts: 6
Default Radix rootkit scan result

Radix rootkit found this

C:\WINDOWS\system32\services.exe:ADVAPI32.dll: services.exe:CreateProcessAsUserW --[HOOKED]--

Could this be malicious, or is it normal for ADVAPI32 to be hooked by legitimate programs?

Thank you.
  #2  
Old April 1st, 2012, 10:02 AM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,562
Default Re: Radix rootkit scan result

Its legit and from MS and normal that hook at that level:
http://en.wikipedia.org/wiki/Windows_API

Check that the file is MS digitally signed and not broken. Done...
  #3  
Old April 1st, 2012, 10:17 AM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,513
Default Re: Radix rootkit scan result

You could upload the file to VirusTotal.
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
  #4  
Old April 1st, 2012, 11:12 AM
crykid crykid is offline
Infrequent Poster
 
Join Date: Mar 2012
Posts: 6
Default Re: Radix rootkit scan result

Quote:
Originally Posted by fax
Its legit and from MS and normal that hook at that level:
http://en.wikipedia.org/wiki/Windows_API

Check that the file is MS digitally signed and not broken. Done...

It is, but does it mean that im protected. Because it doesnt matter if the file is valid, that valid file is being hooked by something that could be malicious, right? Im not a security expert so you could explain that for me.
  #5  
Old April 1st, 2012, 02:22 PM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,562
Default Re: Radix rootkit scan result

That hooking is normal... the DLL is overseeing the shutdown/restart of the system (or abort), start/stop/create a windows service, manage user accounts.

Not yet convinced? Upload to virustotal... not yet convinced? Then contact Radix support, they will explain you the false positive.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:09 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums