Jump to content

Is this a real rootkit?

Recommended Posts

Malwarebytes' Anti-Malware 1.26

Database version: 1126

Windows 5.1.2600 Service Pack 1

9/8/2008 8:30:01 AM

mbam-log-2008-09-08 (08-29-54).txt

Scan type: Quick Scan

Objects scanned: 46403

Time elapsed: 5 minute(s), 4 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 4

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\secdrv (Rootkit.Agent) -> No action taken.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\secdrv (Rootkit.Agent) -> No action taken.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\secdrv (Rootkit.Agent) -> No action taken.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\secdrv (Rootkit.Agent) -> No action taken.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

D:\WINDOWS\system32\drivers\secdrv.sys (Rootkit.Agent) -> No action taken.

I am curious because if I do a google search on secdrv.sys it doesn't come up as such. :unsure: Please advise. and edited to add I am concerned because I let MBAM delete everything.

Link to post
Share on other sites

I did a search with a FF extension made specifically for malware searches. That's what I got from Threat Expert. If nosirrah says it's a F/P then that's where I would put my $. There is also here . I don't think you searched very well, it has mixed reviews. http://www.google.com/search?q=secdrv&...lient=firefox-a

Link to post
Share on other sites

It was a FP as the malware that comes with this (a lot of other malware) is nowhere to be seen .

There were 2 DB versions that this FP existed in and the first scan log shows that you did have one of the two .

That being said the file in question here is far from critical and unliekly to ever have an impact on your system one way or another so restoring (while recommended) will likely not change the function of your computer one way or another .

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.