Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 20th, 2012, 09:36 AM
maxygolf maxygolf is offline
Infrequent Poster
 
Join Date: May 2012
Location: United States of America
Posts: 3
Default Zwcreatethread

Using TrendMicro Rootkitbuster, it found
ZwCreateThread, ZwLoadDrivers, ZwSetSystemInformation, ZwSystemDebugControl
all hooked by system32\drivers\ehdrv.sys and unable to fix.
What should I do?
  #2  
Old May 20th, 2012, 09:42 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Zwcreatethread

Ehdrv.sys is ESET's HIPS & Self-defense driver, there's nothing to fix and other programs should ignore it.
  #3  
Old May 20th, 2012, 10:04 AM
maxygolf maxygolf is offline
Infrequent Poster
 
Join Date: May 2012
Location: United States of America
Posts: 3
Default Re: Zwcreatethread

I know that ehdrv.sys is from ESET.
Looking it up online, ZwCreateThread, etc. is discussed as malware that can locate financial passwords or email passwords when I looked it up.
I was notified that the group "Anonymous" gathered my personal information due to a subscription to STRATFOR months ago, and don't know if that could have affected my computer system.
I have also had many problems with my computer over the last few months and had to reinstall the operating systerm twice recently.
I could not get the original OEM install CD to work and had to rely on the backup system on another drive.
I was afraid my ehdrv.sys got corrupted.
Is it possible to corrupt the ehdrv.sys?
  #4  
Old May 20th, 2012, 11:15 AM
stackz stackz is offline
Frequent Poster
 
Join Date: Dec 2007
Posts: 537
Default Re: Zwcreatethread

Quote:
Originally Posted by maxygolf
Is it possible to corrupt the ehdrv.sys?
If you try hard enough it's possible to corrupt anything, but in your case I highly doubt that ehdrv.sys is corrupt.

ZwCreateThread is a function that can be used for millions of reasons. It's by no means anything out of the ordinary and like many API functions can be used or abused.

Last edited by stackz : May 20th, 2012 at 11:20 AM.
  #5  
Old May 20th, 2012, 07:12 PM
maxygolf maxygolf is offline
Infrequent Poster
 
Join Date: May 2012
Location: United States of America
Posts: 3
Default Re: Zwcreatethread

Thank you!
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:05 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums