Is there a known/recommended way to do a rootkit scan of 64-bit windows system?

For kernel-mode rootkits, detection is considerably more complex, requiring careful scrutiny of the System Call Table to look for hooked functions where the malware may be subverting system behavior. Such access allows a potential attacker to browse, steal and modify information at will by subverting and even bypassing existing account authorisation mechanisms. If a rootkit stays on a PC after reboot,

This class of rootkit has unrestricted security access, but is more difficult to write. The complexity makes bugs common, and any bugs in code operating at the kernel level may seriously

The method is complex and is hampered by a high incidence of false positives.

When it does 64bit will be required.

An example is the "Evil Maid Attack", in which an attacker installs a bootkit on an unattended computer, replacing the legitimate boot loader with one under their control. With that, a few firewall products offer system-level protection (I'm thinking Comodo, for instance) which will allow you to see system-level prompts informing of many changes that are occurring in your system.

Rootkits for Dummies.

In addition, the rootkit needs to monitor the system for any new applications that execute and patch those programs' memory space before they fully execute. — Windows Rootkit Overview, Symantec. In our case the payload component avcmd.dll was injected into svchost.exe system process which started communicating with C&C IP addresses stored in the configuration file.

Signature-based detection methods can be effective against well-published rootkits, but less so against specially crafted, custom-root rootkits. Another method that can detect rootkits compares "trusted" raw data with "tainted" content

One of the ways to carry this out is to subvert the login mechanism, such as the /bin/login program on Unix-like systems or GINA on Windows. Windows Vista or Windows 7 64-bit users should read on. There are at least two options to do that, all with tools already included in the operating system: Open a command prompt, with

Thanks for your help.

Is it normal for userinit to be "re-installed" or "re-init" after doing a scan using MalwareBytes?

The Droppers The first level dropper implements LZMA decompression for the second level dropper and the malicious driver module.

It's therefore highly recommended that you scan your system using the free rescue disks provided by more than one vendor, as a mix of technologies and scanning methods is much more effective. The software will run for 15 minutes or more depending on the size of your disk.

But these checks are based on standard, already-known tricks. For the most part these applications make no use of, neither they have a use for, any of these features.

Full control over a system means that existing software can be modified, including software that might otherwise be used to detect or circumvent it.

Post the new logs as explained in the prep guide.

Advanced Mac OS X Rootkits