Rootkit / malware ?

Discussion in 'malware problems & news' started by gambla, Apr 3, 2010.

Thread Status:
Not open for further replies.
  1. gambla

    gambla Registered Member

    Joined:
    Sep 4, 2007
    Posts:
    161
    Location:
    Frankfurt, Germany
    Hi,
    i need your help on this please:

    I ran some ARKs (RootRepeal, Tizer Rootkit Razor free, GMER, Rootkit Unhooker LE) and all show this:

    unknown NtCreateThread 0xF7A95294 0x80586C45
    unknown NtLoadKey 0xF7A952B2 0x805CE7ED
    unknown NtReplaceKey 0xF7A952BC 0x806564EC
    unknown NtRestoreKey 0xF7A952B7 0x80656081

    All other "hooks" (?) shown in the report are listed with the name of the software (ZoneAlarm, GesWall, ThreatFire), but these entries only show "unknown" ?

    Antivir and several anti-malware scanners didn't find anything (OS + UBCD4win-CD).

    thank you ! your help is appreciated !
     
  2. stackz

    stackz Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    619
    Location:
    Sydney Australia
    Avira Antivir has SSDT hooks that are reported as unknown. To be certain you can either uninstall Antivir or use something like Autoruns to temporarily disable the start up of anything to do with Antivir.

    If you're familiar with WinDbg, you can trace the hook redirections.
     
  3. gambla

    gambla Registered Member

    Joined:
    Sep 4, 2007
    Posts:
    161
    Location:
    Frankfurt, Germany
    Thank you stackz for the hint.
     
  4. Sariel Fallen

    Sariel Fallen Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    17
    Location:
    Wuppertal/Germany
Loading...
Thread Status:
Not open for further replies.