PDA

View Full Version : Pls check my RootAlyzer outputs and advise re further steps



jbionic
2015-12-13, 09:36
Hi all,

I am a newbie woth RootAlyzer. This is what it's found. However no Action was shown, so I am not sure what to do with this crap.
Any advice from more experienced users will be very much appreciated

File:"Unknown ADS","C:\Windows\Temp\FacRecovery\mount:$WIMMOUNTDATA:$DATA"
File:"Unknown ADS","C:\Users\UserName\OneDrive:ms-properties:$DATA"
File:"Unknown ADS","C:\Users\UserName\OneDrive\Share:ms-properties:$DATA"
File:"Unknown ADS","C:\Users\UserName\OneDrive\Документы:ms-properties:$DATA"
File:"Unknown ADS","C:\Users\UserName\OneDrive\Документы\Новая папка:ms-properties:$DATA"
File:"Unknown ADS","C:\Users\UserName\OneDrive\Документы\Новая папка (2):ms-properties:$DATA"
File:"Unknown ADS","C:\Users\UserName\Documents\Scanned Documents\Приветствие программы сканирования.jpg:3or4kl4x13tuuug3Byamue2s4b:$DATA"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a11-9b1a-11d4-9123-0050047759bc}","8"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SYSTEM\ControlSet001\Control\Nsi\{eb004a11-9b1a-11d4-9123-0050047759bc}","8"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Microsoft\Security Center\Svc","Upgrade"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Microsoft\InputMethod\Jpn","DuState"

tashi
2015-12-14, 03:25
Hello jbionic,

The RootAlyzer is more of an analyst tool, how is the computer running, any issues? :)

Best regards.

jbionic
2015-12-14, 03:46
Thanks, tashi. I've had a few malicious candies that were identified and removed by MalwareBytes. Right after removing them that I decided to double-check with Spybot S&D just to make sure there were no more hidden left-overs. If you say those from the list are ok, then I feel relieved.

tashi
2015-12-14, 04:36
Hi jbionic,

They appear to be normal files.

if any issues out of the ordinary do pop up let me know and I will direct you to the malware forum so someone can take a look at the system. :)

All the best.