PDA

View Full Version : Rootkit?


Charan
15-04-2006, 01:53 AM
Hi guys i just came to know something about rootkits. i guess its something which hooks up with API's and hands over the controls to a attacker. I used AntiHookExec tool and it gave a html file . its showed something with "Checking exports of KERNEL32.DLL for discrepancies" thing which i didnt understand.

http://img405.imageshack.us/img405/6849/rootkit9ok.th.gif (http://img405.imageshack.us/my.php?image=rootkit9ok.gif)

what is this ? is there a problem with my pc?

any comments??

eddie
15-04-2006, 03:09 AM
No there is no problem with your PC. Until you see the name of a DLL or SYS file in the column that says "API Hooked By", you are fine. It is a false alarm.

anandk
15-04-2006, 08:40 AM
click http://www.sysinternals.com/Utilities/RootkitRevealer.html