Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Hidden Rootkit

Does anyone know what this unremovable rootkit belongs to?

There is no other available info on it.

Is there a way to remove it, without rebuilding HD?

\HKEY_USERS\S-1-5-21-1390067357-299502267-725345543-1006

\HKEY_USERS\S-1-5-21-1390067357-299502267-725345543-1006_Classes

 running XP-SP3

:14657


This thread was automatically locked due to age.
Parents
  • Anti-Rootkit tools (including Sophos) scan at a high level using API's and a low level (raw Content) and then compare the difference.

    Therefore items can be hidden to the API scan but exist in the raw scan that are not malicious at all so items show hidden for legitimate reasons.

    Also temporary files that are present in one scan and not the other will show.

    This will account for many of the hidden items (scan difference) seen when a rootkit is not present on a machine.

    Please also remember that some of the more complex rootkits will have more complex techniques (anti-anti-rootkit) and will be aware of a raw data scan occuring and so will unhook and therefore avoid detection. But a rootkit will be there to do something in order to generate revenue for the author and there is always a tell so please contact support if you are unceratin of what any Anti-Rootkit scan shows.

    :15637
Reply
  • Anti-Rootkit tools (including Sophos) scan at a high level using API's and a low level (raw Content) and then compare the difference.

    Therefore items can be hidden to the API scan but exist in the raw scan that are not malicious at all so items show hidden for legitimate reasons.

    Also temporary files that are present in one scan and not the other will show.

    This will account for many of the hidden items (scan difference) seen when a rootkit is not present on a machine.

    Please also remember that some of the more complex rootkits will have more complex techniques (anti-anti-rootkit) and will be aware of a raw data scan occuring and so will unhook and therefore avoid detection. But a rootkit will be there to do something in order to generate revenue for the author and there is always a tell so please contact support if you are unceratin of what any Anti-Rootkit scan shows.

    :15637
Children
No Data