billybob0626
2008-04-29, 00:06
I originally posted on April 17th about "9 hidden registry keys found" and you promptly responded that they probably were corrupted keys (the list of keys follows
:: RootAlyzer Results
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\????????\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?
SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?
SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
The details said that it could not open keys.
Yesterday I ran the updated version of root analyzer and the keys did not show up but here is what did:
// info: Rootkit removal help file
// copyright: (c) 2008 Safer Networking Ltd. All rights reserved.
:: RootAlyzer Results
File:"Reserved filename","N:\autorun.inf\lpt3.This folder was created by Flash_Disinfector"
File:"Reserved filename","D:\autorun.inf\lpt3.This folder was created by Flash_Disinfector"
File:"No admin in ACL","C:\WINDOWS\Temp\hsperfdata_SYSTEM\596"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130468.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130485.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130503.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130521.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130537.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130553.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130569.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130585.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130601.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130617.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130633.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130649.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130665.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130681.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130713.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130745.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130796.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130812.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130828.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130844.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130860.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130876.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130892.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130908.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130924.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\192947.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Adobe\Adobe Photoshop CS2\Presets\Photoshop Actions\Frazers Sketch.atn:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\2f7f05b4_502488.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\4d83db18_812004.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\91fee0dd_975119.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\a52894af_786799.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\b098a97b_864504.jpg:SummaryInformation:$DATA"
File:"No admin in ACL","C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk"
File:"Reserved filename","C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector"
Directory:"No admin in ACL","N:\System Volume Information"
Directory:"No admin in ACL","C:\System Volume Information"
I am on expert (that is why I turned to you) but I know that the Easy Share application uses back web lite and the three files with reserved names came from a flash drive cleaner that I used.
Also, I am puzzled as to why my N drive has system volume information since I use that drive to store jpeg and avi files. Could you help me "interpret" the results of the scan?
a greatful BillyBob0626
:: RootAlyzer Results
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\????????\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?
SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\?
SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\",""
RegyKey:"Hidden registry key","HKEY_LOCAL_MACHINE","\SOFTWARE\Classes\??SID\{B2847E28-5D7D-4deb-8B67-05D28BCF79F5}\",""
The details said that it could not open keys.
Yesterday I ran the updated version of root analyzer and the keys did not show up but here is what did:
// info: Rootkit removal help file
// copyright: (c) 2008 Safer Networking Ltd. All rights reserved.
:: RootAlyzer Results
File:"Reserved filename","N:\autorun.inf\lpt3.This folder was created by Flash_Disinfector"
File:"Reserved filename","D:\autorun.inf\lpt3.This folder was created by Flash_Disinfector"
File:"No admin in ACL","C:\WINDOWS\Temp\hsperfdata_SYSTEM\596"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130468.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130485.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130503.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130521.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130537.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130553.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130569.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130585.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130601.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130617.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130633.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130649.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130665.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130681.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130713.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130745.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130796.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130812.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130828.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130844.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130860.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130876.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130892.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130908.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\130924.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Kodak\Kodak EasyShare software\Originals\192947.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Program Files\Adobe\Adobe Photoshop CS2\Presets\Photoshop Actions\Frazers Sketch.atn:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\2f7f05b4_502488.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\4d83db18_812004.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\91fee0dd_975119.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\a52894af_786799.jpg:SummaryInformation:$DATA"
File:"Unknown ADS","C:\Documents and Settings\Owner\Local Settings\Application Data\HP\Digital Imaging\Vault\b098a97b_864504.jpg:SummaryInformation:$DATA"
File:"No admin in ACL","C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk"
File:"Reserved filename","C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector"
Directory:"No admin in ACL","N:\System Volume Information"
Directory:"No admin in ACL","C:\System Volume Information"
I am on expert (that is why I turned to you) but I know that the Easy Share application uses back web lite and the three files with reserved names came from a flash drive cleaner that I used.
Also, I am puzzled as to why my N drive has system volume information since I use that drive to store jpeg and avi files. Could you help me "interpret" the results of the scan?
a greatful BillyBob0626