VOGONS

Common searches


Help! I've been infected by rootkit!

Topic actions

Reply 20 of 25, by Kreshna Aryaguna Nurzaman

User metadata
Rank l33t
Rank
l33t
h-a-l-9000 wrote:

Is there some strange entry in device manager -> multimedia -> [audio/video]codecs -> properties?

Hmm.... I have checked the drivers of my CD-ROM, and I haven't found anything suspicious (Unless if PxHelp20.sys is part of malicious software), but I have overlooked the codecs. Thanks!

Never thought this thread would be that long, but now, for something different.....
Kreshna Aryaguna Nurzaman.

Reply 21 of 25, by eL_PuSHeR

User metadata
Rank l33t++
Rank
l33t++

Try running the K-Lite Codec Tweak Tool to fix issues. Just check the FIX section (first section).

Attachments

  • Filename
    K-Lite_Codec_Tweak_Tool.zip
    File size
    321.03 KiB
    Downloads
    249 downloads
    File comment
    K-Lite Tweak Tool (it fixes broken codecs and more)
    File license
    Fair use/fair dealing exception

Intel i7 5960X
Gigabye GA-X99-Gaming 5
8 GB DDR4 (2100)
8 GB GeForce GTX 1070 G1 Gaming (Gigabyte)

Reply 22 of 25, by Jorpho

User metadata
Rank l33t++
Rank
l33t++

The first rootkit doodad that comes to mind is RootkitRevealer from http://www.sysinternals.com .

Anyway, I think what might be helpful here is the Filter Check Tool. I think that generally the problems that fixes are a little more lower-level, but maybe it's the case here.
http://www.cdr-zone.com/forum/viewtopic.php?t=4719

Reply 23 of 25, by franpa

User metadata
Rank Oldbie
Rank
Oldbie

sysinternals got bought by microsoft didnt they? didnt microsoft stop the project and bundle everything and release as freeware like 2 years ago? isnt it useless against latest rootkits now?

AMD Ryzen 3700X | ASUS Crosshair Hero VIII (WiFi) | 16GB DDR4 3600MHz RAM | MSI Geforce 1070Ti 8GB | Windows 10 Pro x64.

my website

Reply 24 of 25, by Jorpho

User metadata
Rank l33t++
Rank
l33t++

Er, what? Sysinternals has been carrying on in its merry way ever since the buyout. Very little has changed. And how exactly would the "latest rootkits" be fundamentally different from other rootkits?

(Actually, now that I look at it, there's no longer any sign of their Windows 98 NTFS driver, but that's not really surprising.)

Reply 25 of 25, by Kreshna Aryaguna Nurzaman

User metadata
Rank l33t
Rank
l33t
h-a-l-9000 wrote:

Is there some strange entry in device manager -> multimedia -> [audio/video]codecs -> properties?

Well here's the list of the audio codecs being installed:
IMA ADPCM Audio CODEC
Microsoft ADPCM Audio CODEC
Microsoft CCIT G.711 Audio CODEC
Microsoft ADPCM Audio CODEC
DSP Group TrueSpeech(TM) Audio CODEX
msg723.acm
Windows Media Audio Codec
Sipro Lab Telecom Audio Codec
Indeo audio software
Fraunhofer IIS MPEG Layer-3 Codec
Microsoft PCM Converter

While this is the list for video codecs
Cinepak Codec by Radius Inc.
Indeo codec by Intel
Indeo video 5.10
ir41_32.ax
iyuv_32.dll
Microsoft RLE Codec
Microsoft Video 1
msh261.drv
msh263.drv
msyuv.dll
TechSmith Screen Capture Codex
tsbyuv.dll

I'm not sure, but so far there ain't anything suspicious --or am I wrong?

Never thought this thread would be that long, but now, for something different.....
Kreshna Aryaguna Nurzaman.