PDA

View Full Version : Not sure if malware or not please help :)



da1datwins
2013-05-18, 08:12
:: RootAlyzer Results
File:"Unknown ADS","C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00001.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00002.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00003.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00004.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00005.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00006.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00007.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00009.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00011.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00012.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00013.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00014.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00015.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00016.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00017.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00018.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00019.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00020.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00021.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00022.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00024.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00025.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00026.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00027.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00028.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00029.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00030.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00031.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00032.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00033.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00034.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00035.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00036.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00037.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00038.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00039.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00040.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00041.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00042.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00043.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00044.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00045.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00046.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00047.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00048.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00049.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00050.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00051.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00052.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00053.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00054.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00055.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00056.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00057.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00058.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00059.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00060.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00061.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00062.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00063.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00064.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00065.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00066.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00068.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00069.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00070.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00071.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00072.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00073.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00074.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00075.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00076.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00077.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00078.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00079.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00080.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00081.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00082.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00083.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00084.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00085.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00086.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00087.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00088.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00089.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00090.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00091.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00092.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00093.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00094.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00095.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00096.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00097.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00098.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00099.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00100.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00102.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00103.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00104.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00105.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00116.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00117.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00118.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00119.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00120.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00121.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00122.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00123.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00124.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00125.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\M2U00126.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\musical chairs.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\MVI_1277 - Copy.AVI:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\MVI_1278 - Copy.AVI:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Pictures\twister.MPG:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Documents\Bandicam\bandicam 2013-05-09 16-46-51-461.avi:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\doan\Documents\Bandicam\bandicam 2013-05-09 16-54-50-110.avi:TOC.WMV:$DATA"
File:"Unknown ADS","C:\Users\All Users\TEMP:0B4227B4:$DATA"
File:"No admin in ACL","C:\Users\All Users\Symantec\SRTSP\LightningSand.CFD"
File:"No admin in ACL","C:\Users\All Users\Nero\Nero 10\OnlineServices"
File:"No admin in ACL","C:\Users\All Users\Nero\Nero 10\OnlineServices\controldata.bin"
File:"No admin in ACL","C:\Users\All Users\Nero\Nero 10\OnlineServices\usagestatdata.bin"
File:"No admin in ACL","C:\Users\All Users\Microsoft\OFFICE\DATA"
File:"No admin in ACL","C:\Users\All Users\Microsoft\OFFICE\DATA\OPA12.BAK"
File:"No admin in ACL","C:\Users\All Users\Microsoft\OFFICE\DATA\opa12.dat"
File:"No admin in ACL","C:\ProgramData\Symantec\SRTSP\LightningSand.CFD"
File:"No admin in ACL","C:\ProgramData\Nero\Nero 10\OnlineServices"
File:"No admin in ACL","C:\ProgramData\Nero\Nero 10\OnlineServices\controldata.bin"
File:"No admin in ACL","C:\ProgramData\Nero\Nero 10\OnlineServices\usagestatdata.bin"
File:"No admin in ACL","C:\ProgramData\Microsoft\OFFICE\DATA"

im using windwos vista please respond ASAP im new to spy bot and i like it :) thank you!!

spybotsandra
2013-05-21, 16:13
Hello,

That are no rootkits, just some pics and program files.

Malware sometimes uses rootkit technology to hide itself at system level.
This makes it undetectable by standard tools. Our plugins help Spybot – Search & Destroy to detect this form of malware.
Our Rootkit Scanner tool shows anything that uses certain rootkit technologies. But items with rootkit properties detected here are not necessarily malware. Sometimes, legit software uses rootkit technologies to hide registration data or other things it does not want the user to see in any case. So please keep in mind that the Rootkit Scanner only flags suspicious stuff, not identifying just bad stuff.

If you get ‘No admin in ACL’ this threads in our forum should help explaining:
Unknown ADS and no Admin in ACL what is good and what is bad??? (http://forums.spybot.info/showthread.php?t=27446) and Unknown ADS (http://forums.spybot.info/showthread.php?t=68086) .

The deletion is final and can not be recovered through the Quarantine.
If you still want to remove the found items it is strongly recommend to create a system restore point (http://windows.microsoft.com/en-US/windows-vista/System-Restore-frequently-asked-questions) before doing that.

Best regards
Sandra
Team Spybot