AFX Windows Rootkit 2003

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search

AFX Windows Rootkit 2003 is a user mode rootkit that hides files, processes and registry.

Installation

[edit | edit source]

When the installer of the rootkit is executed, the installer creates the files iexplore.dll and explorer.dll in the system directory. The iexplore.dll is injected into explorer.exe, and the explorer.dll is injected into all running processes.[1]

Payload

[edit | edit source]

The injected DLLs hooks the Windows API functions to hide files, processes and registry.[1]

References

[edit | edit source]
  1. ^ a b Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).