Microsoft anti-spyware

G

Guest

In the middle of running a scan with it I got an alert from my Norton
antivirus that I was infected with Hacktool.Rootkit and it was in
system32/svkp.sys.

I keep Norton up to date daily I'm just wondering if Microsoft is using this
file to search for rootkits?

Any one else had this problem? I might add I have just installed Spy Sweeper
yesterday or the day before.
 
B

Bill Sanderson

Here's what McAfee says about SVKP.SYS, in relation to a different trojan:
----
The presence of SVKP.SYS does not necessarily mean that this trojan is
installed. SVKP.SYS is part of SVK Protector, which this trojan is packed
with. SVK Protector is used in innocent programs as well.
----

So--this may be a false positive from Norton.

I'd recommend reading their write up on Hacktool

http://securityresponse.symantec.com/avcenter/venc/data/hacktool.rootkit.html

and seeing whether you find any other evidence, besides that file, to
support the idea that you've been hacked.
 
G

Guest

Thanks Bill

I did just that and it looks like there are no other signs of it being a
virus so I think it was a false positive.

Thanks for your help.
 
B

Bill Sanderson

You're welcome--stay safe!
--

Russ Mullen said:
Thanks Bill

I did just that and it looks like there are no other signs of it being a
virus so I think it was a false positive.

Thanks for your help.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top