Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Root/NtHide

 
Threat LevelHigh threat
DamageSevere
DistributionNot widespread

At a glance

Common name:Root/NtHide
Technical name:Rootkit/NtHide
Threat level:Medium
Type:Hacking Tool
Effects:   It allows to carry out dangerous actions for the victims of attacks.
Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95/3.X

First detected on:Sept. 28, 2006
Detection updated on:Dec. 9, 2007
StatisticsNo

Brief Description 

    

Root/NtHide is a rootkit. These are programs used to hide files, Windows Registry entries or processes, either their own or those of other programs.

In this way, even when a user looks for these items on a computer, they won't be able to see them.

Rootkits have been widely used for malicious ends, to camouflage other programs on computers that have previously been compromised through other means.

There are certain examples of malware that use rootkits in order to go unnoticed on the computer they have infected.

 

It uses stealth techniques to avoid being detected by the user:

  • It uses techniques included in its code to hide itself while it is active.

 

Root/NtHide does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer. The means of transmission used include, among others, floppy disks, CD-ROMs, email messages with attached files, Internet downloads, FTP, IRC channels, peer-to-peer (P2P) file sharing networks, etc.

 

Tech details

Effects

Root/NtHide can be used to hide files, Windows Registry entries or processes, either its own or those of other programs.

In this way, even when a user looks for these items on a computer, they won't be able to see them.

There are certain examples of malware that use rootkits in order to go unnoticed on the computer they have infected.

 

Means of transmission 

Root/NtHide does not spread automatically using its own means. It needs the attacking user's intervention in order to reach the affected computer. The means of transmission used include, among others, floppy disks, CD-ROMs, email messages with attached files, Internet downloads, FTP, IRC channels, peer-to-peer (P2P) file sharing networks, etc.

Further Details  

Root/NtHide has the following additional characteristics:

  • It is written in the programming language Assembler x86-32 bit.
  • It is 12192 bytes in size.

Solution

See solution