Rootkit.Boot.Pihar.c

By LoneStar in Rootkits | 250 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

Rootkit.Boot.Pihar.c Description

Rootkit.Boot.Pihar.c is a computer Rootkit that could cause an infected PC to randomly restart and load malicious code causing a system to not respond to normal functions. There are other side effects associated with Rootkit.Boot.Pihar.c causing a PC to become unstable and potentially crash. Rootkit.Boot.Pihar.c may go undetected for long periods of time where it may stall or freeze up. Rootkit.Boot.Pihar.c may also put data at risk of being stolen from a remote source.

Type: Rootkits

How Can You Detect Rootkit.Boot.Pihar.c?

Rootkit.Boot.Pihar.c Removal Details

Rootkit.Boot.Pihar.c has typically the following processes in memory:

  • %System%\drivers\[RANDOM CHARACTERS].sys
  • C:\WINDOWS\system32\[random name].dll

Rootkit.Boot.Pihar.c creates the following files in the system:

  • %Temp%\[random]

Rootkit.Boot.Pihar.c creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0?
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1?
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random].exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0?
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1?
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1?
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = ‘0?
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘Yes’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1?
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoDesktop” = ‘1?
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0?

Important Article Disclaimer

ESG Support Center

This entry was last updated on 08/6/12 and posted on 08/6/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.