Windows 7 Forums


Reply
Thread Tools

Possible rootkit

 
 
Robert Brereton
Guest
Posts: n/a
Thanked:
 
      12-13-2009
Hi All
I have just run Sophos anti root kit scanner and it has popped up with this
as a hidden registry item:

Area: Windows registry
Description: Hidden registry key
Location: \HKEY_USERS\S-1-5-18\Software\Microsoft\CTF\Assemblies\0x00000409
Removable: No
Notes: (no more detail available)

Does anyone know what it is? I suspect it is the US version of the
keyboard, which is not used here (in UK) but am concerned it may actually be
something nasty.

Thanks in advance

Bob

 
Reply With Quote
 
 
 
 
R. C. White
Guest
Posts: n/a
Thanked:
 
      12-13-2009
Hi, Robert.

I don't know what else may be hidden in your Registry, but THAT key should
be benign. ;<)

I have the same entry exactly. My only question might be the values in the
final key. Here in the USA, I also have the key
HKEY_USERS\S-1-5-18\Software\Microsoft\CTF\Assemblies\0x00000409

That "0409" at the end of the value is hex code for 1033, which is the
location code for the USA. In the UK, you might need a different code,
perhaps 0x0809. You might want to take a look around here:
United Kingdom Keyboard
http://msdn.microsoft.com/en-us/library/ee485827.aspx

FYI: Here is the full text of my entries in that Registry key, exported as
a .txt file:
<paste>
Windows Registry Editor Version 5.00

[HKEY_USERS\S-1-5-18\Software\Microsoft\CTF\Assemblies\0x00000409]

[HKEY_USERS\S-1-5-18\Software\Microsoft\CTF\Assemblies\0x00000409\{34745C63-B2F0-4784-8B67-5E12C8701A31}]
"Default"="{00000000-0000-0000-0000-000000000000}"
"Profile"="{00000000-0000-0000-0000-000000000000}"
"KeyboardLayout"=dword:04090409
</paste>

I know nothing about Sophos or rootkits, but you may be getting a false
positive here.

RC
--
R. C. White, CPA
San Marcos, TX

Microsoft Windows MVP
Windows Live Mail 2009 (14.0.8089.0726) in Win7 Ultimate x64

"Robert Brereton" <> wrote in message
news:nAVUm.12283$2...
> Hi All
> I have just run Sophos anti root kit scanner and it has popped up with
> this as a hidden registry item:
>
> Area: Windows registry
> Description: Hidden registry key
> Location:
> \HKEY_USERS\S-1-5-18\Software\Microsoft\CTF\Assemblies\0x00000409
> Removable: No
> Notes: (no more detail available)
>
> Does anyone know what it is? I suspect it is the US version of the
> keyboard, which is not used here (in UK) but am concerned it may actually
> be something nasty.
>
> Thanks in advance
>
> Bob


 
Reply With Quote
 
 
 
 
Robert Brereton
Guest
Posts: n/a
Thanked:
 
      12-13-2009
Thanks for that it's put my mind at rest. :-)

Bob
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
what is a rootkit virus ? MushroomNZ alt.windows7.general 22 10-16-2012 03:03 PM
OT: CarrierIQ Rootkit Found on Android, iOS cell phones..... DanS alt.windows7.general 5 12-03-2011 09:23 PM
is it possible to make the desktop resolution larger than the physical resolution? Roland Schweiger alt.windows7.general 7 05-16-2010 04:42 AM
possible setup help when win 7 will not alllow user access at all WyldBlackWolf Installation, Setup and Updates 0 01-07-2010 05:50 AM
Win2000Pro to Win7 upgrade: possible? Dave-UK alt.windows7.general 3 10-26-2009 08:52 PM


All times are GMT +1. The time now is 04:59 AM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.