As was foretold, we've added advertisements to the forums! If you have questions, or if you encounter any bugs, please visit this thread: https://forums.penny-arcade.com/discussion/240191/forum-advertisement-faq-and-reports-thread/
Options

No idea how to deal with Rootkit revealer output...

TetraNitroCubaneTetraNitroCubane The DjinneratorAt the bottom of a bottleRegistered User regular
edited May 2007 in Help / Advice Forum
So I've been doing a lot of computer-paranoia type virus checking and maintenance lately (mainly because if my computer breaks or gets compromised, I'm SOL). Sorry if these redundant threads are against policy, but google just isn't cutting it for a search on this. Mods, feel free to lock this thread if this thread isn't appropriate.

Long story short, I ran a rootkit revealer scan on my system, but am woefully uneducated about deciphering the results that I see after the scan. I'm hoping someone might be able to tell me whether or not these registry keys are legit - Some of them give me no hits in google. Some of them do give me hits, but they're all in german. The first two ("Policy\Secrets\") seem to by Spybot entries, so I'm not too worried about them regardless of their suspicious name.

Since Rootkit revealer won't save output files for me for some reason, I've attached an image of the output (EDIT: image spoilered for silly H-scroll):
Root1.jpg

The first three entries were listed as "Key name contains embedded nulls". The next two were "Data mismatch between Windows API and raw hive data". The last one was listed as "Hidden from Windows API". Any help anyone could give identifying these keys would be much appreciated - And any help learning how to identify keys in general or deal with the rootkit revealer output would be great too.

TetraNitroCubane on

Posts

  • Options
    VoroVoro Registered User regular
    edited May 2007
    The last entry in the list should be OK as long as you have Daemon Tools v3.46 installed on that PC. The "Hidden from Windows API" is likely part of its anti-blacklisting measures. I'll let you know if I find out anything about the other keys.

    Voro on
    XBL GamerTag: Comrade Nexus
  • Options
    TetraNitroCubaneTetraNitroCubane The Djinnerator At the bottom of a bottleRegistered User regular
    edited May 2007
    Voro wrote: »
    The last entry in the list should be OK as long as you have Daemon Tools v3.46 installed on that PC. The "Hidden from Windows API" is likely part of its anti-blacklisting measures. I'll let you know if I find out anything about the other keys.

    Thanks, that was one of the more worrisome entries - But I do in fact have Daemon Tools installed on that machine. I remember reading about Daemon Tools using rootkits to actually execute its intended function, so I suppose it's no red flag on that entry.

    TetraNitroCubane on
Sign In or Register to comment.