PDA

View Full Version : Rootkit Alyzer



Spybot69
2014-05-18, 15:58
Type: File
Object: System Diagnostics.xml:0v1ieca3Feahez0jAwxjjk5uRh:$DATA
Location: C:\Windows\PLA\System\
Details: Unknown ADS

Type: File
Object: cabundle.crt
Location: C:\ProgramData\Nero\OnlineServices\
Details: No admin in ACL

Type: File
Object: cabundle.crt
Location: C:\ProgramData\Nero\Nero 12\OnlineServices\
Details: No admin in ACL

Type: File
Object: cabundle.crt
Location: C:\ProgramData\Nero\Nero 11\OnlineServices\
Details: No admin in ACL

Type: File
Object: cddbplm.gcf
Location: C:\ProgramData\Nero\Nero 10\OnlineServices\MetaData\
Details: No admin in ACL

Type: File
Object: elists.db
Location: C:\ProgramData\Nero\Nero 10\OnlineServices\MetaData\
Details: No admin in ACL

Type: File
Object: 14e62e1be62dfd9c.dat:5b3ca473-f27c-4c24-9ed2-d728e3023648:$DATA
Location: C:\ProgramData\AVG2014\chjw\
Details: Unknown ADS

Type: File
Object: 26ccaba6ccaa82d.dat:0e1af310-42f8-4f11-af44-a65a7844a708:$DATA
Location: C:\ProgramData\AVG2014\chjw\
Details: Unknown ADS

Type: File
Object: 601e659a1e6569cc.dat:9d7eff13-a4dc-4220-b602-ea5578c3986f:$DATA
Location: C:\ProgramData\AVG2014\chjw\
Details: Unknown ADS

Type: File
Object: c80cc5d80cc4f40.dat:83d37135-58ad-485a-95ed-dc0decd0657c:$DATA
Location: C:\ProgramData\AVG2014\chjw\
Details: Unknown ADS

Type: File
Object: report.xml:Qgrg2rf1Znaluncm1kfl1xla5h:$DATA
Location: C:\PerfLogs\System\Diagnostics\JUNESPC_20140213-000001\
Details: Unknown ADS

Type: Folder
Object: OnlineServices
Location: C:\ProgramData\Nero\
Details: No admin in ACL

Type: Folder
Object: OnlineServices
Location: C:\ProgramData\Nero\Nero 12\
Details: No admin in ACL

Type: Folder
Object: OnlineServices
Location: C:\ProgramData\Nero\Nero 11\
Details: No admin in ACL

Type: Folder
Object: OnlineServices
Location: C:\ProgramData\Nero\Nero 10\
Details: No admin in ACL

Type: Folder
Object: MetaData
Location: C:\ProgramData\Nero\Nero 10\OnlineServices\
Details: No admin in ACL

Type: Key
Object: 8
Location: HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a11-9b1a-11d4-9123-0050047759bc}\
Details: No admin in ACL

Type: Key
Object: 8
Location: HKLM\SYSTEM\ControlSet001\Control\Nsi\{eb004a11-9b1a-11d4-9123-0050047759bc}\
Details: No admin in ACL


Those are the results. Should I remove any of them?

tashi
2014-05-18, 16:17
Hello Spybot69,

I'd leave them alone. :)

See: http://forums.spybot.info/showthread.php?68857-Rootkit-analysis-request

Best regards.

Spybot69
2014-05-18, 16:22
Okay, I will. I just upgraded from Spybot 1.6.2 and was checking out the new Rootkit feature. I was experiencing no issues, so I will leave them alone. Thanks!