Results 1 to 10 of 11

Thread: RootKit Analyzer Deep Scan Results, do I have a RootKit?

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #1

    Default RootKit Analyzer Deep Scan Results, do I have a RootKit?

    Heres my scan logs, I have no idea if any of this is bad:

    :: RootAlyzer Results
    File:"Unknown ADS","C:\Users\Matt\Local Settings:P4B9xHBUVoEcIaPw0ywC:$DATA"
    File:"Unknown ADS","C:\Users\Matt\AppData\Local:P4B9xHBUVoEcIaPw0ywC:$DATA"
    File:"Unknown ADS","C:\Users\Matt\AppData\Local\3xAHBiaTTG:zH4MA7j5SOc4Svn6w0D9Q:$DATA"
    File:"Unknown ADS","C:\Users\Matt\AppData\Local\Application Data:P4B9xHBUVoEcIaPw0ywC:$DATA"
    File:"Unknown ADS","C:\ProgramData\Microsoft:9Oyhl36j8JRO1OR8haiHu:$DATA"
    File:"Unknown ADS","C:\ProgramData\Microsoft:viBoRxnQpSb51qm7FuRetaUqE:$DATA"
    File:"Unknown ADS","C:\ProgramData\Microsoft\YfPUvE4qBtufJQ:U8BnASnuhOFScTeU:$DATA"
    File:"No admin in ACL","C:\cygwin64\usr\share\doc\Cygwin\ctags-5.8.README"
    File:"No admin in ACL","C:\cygwin64\usr\share\doc\ctags-5.8\ctags.html"
    File:"No admin in ACL","C:\cygwin64\home\Matt\.bash_history"
    File:"No admin in ACL","C:\cygwin64\etc\inittab"
    File:"No admin in ACL","C:\cygwin64\etc\rebase.db.x86_64"
    RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Applets\SysTray\BattMeter\","Flyout"
    RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Wow6432Node\Microsoft\Security Center\","Svc"


    also, I closed the Analyzer without deleting these entries, do I have to rerun a complete Deep Scan again if I do actually need to delete any of these items?
    Last edited by tashi; 2014-10-06 at 07:09. Reason: Removed code box

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •