Open Side Menu Go to the Top
Register
rootkit revealer discrepancies rootkit revealer discrepancies

08-14-2009 , 05:55 AM
Ran rootkitrevealer and it found 4 discrepancies:

HKLM\SECURITY\Policy\secrets\SAC*
HKLM\SECURITY\Policy\secrets\SAI*
C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp .edb

The first two were debated in some forums but seem to be okay, I posted them anyway for another opinion... the other two, I'm not so sure they are safe.

Any comments/help is appreciated!
rootkit revealer discrepancies Quote
08-14-2009 , 01:15 PM
All of these show up on the sysinternals forums and do not seem to be a problem. I am surprised that these are the only things that showed up on your scan. I usually get a much longer list.
rootkit revealer discrepancies Quote
08-14-2009 , 03:33 PM
I believe they are safe.

Ricks, can you post the link you're referring to?
rootkit revealer discrepancies Quote
08-14-2009 , 03:56 PM
thx for the replies guys, I restarted my comp and ran it again just as an experiment to see if I would find the same results... to my surprise I lost one discrepancy and got 3 more, this is what it found this time:

HKLM\SECURITY\Policy\Secrets\SAC* 7/23/2009 1:03 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 7/23/2009 1:03 AM 0 bytes Key name contains embedded nulls (*)
C:\System Volume Information\_restore{CD7812B2-54EA-4CA5-B653-B5CC553F7844}\RP40\A0004964.ini 8/14/2009 3:16 PM 2.67 KB Hidden from Windows API.
C:\System Volume Information\_restore{CD7812B2-54EA-4CA5-B653-B5CC553F7844}\RP40\A0004965.INI 8/14/2009 3:16 PM 497.03 KB Hidden from Windows API.
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp .edb 8/14/2009 3:32 PM 64.00 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 8/14/2009 3:42 PM 513 bytes Hidden from Windows API.

Are these still all safe? Why would it show inconsistent results? I may have ran CCleaner the first time around... very curious if this is normal.
rootkit revealer discrepancies Quote
08-14-2009 , 04:15 PM
They all appear to be safe.
rootkit revealer discrepancies Quote
08-14-2009 , 04:38 PM
Quote:
Originally Posted by LirvA
I believe they are safe.

Ricks, can you post the link you're referring to?
Sorry, the forums are here.
rootkit revealer discrepancies Quote
08-14-2009 , 05:11 PM
ty ty. Always good to have links to references IMO.
rootkit revealer discrepancies Quote
08-21-2009 , 06:02 AM
Thx guys,

I Had another entry pop up recently...

C:\Windows\system32\wbem\Logs\wbemcore.log

Is this one safe as well?

If yes, would you happen to know why are these files are hidden?
rootkit revealer discrepancies Quote
08-21-2009 , 01:39 PM
That log probably changed during the scan.

Reading the last section of this page, Hidden from Windows API, may help.
rootkit revealer discrepancies Quote

      
m