|
Posted by Massimo on April 23, 2008, 11:46 pm
If you were Registered and logged in, you could reply and use other advanced thread options Hello,
>Massimo wrote:
>> Hello Tom,
>>
>>
>>
>>>Massimo wrote:
>>>
>>>>Hello,
>>>>
>>>>I did a full scan of my system with Avira virusscanner Free Version
>>>>and it found nothing.
>>>>Then a rootkit scan with Blacklight and it found nothing
>>>>After that a rootkit scan with Trend Micro's Rootkit Buster: it found
>>>>nothing.
>>>>Finally I did a rootkit scan with Avira's Anti Rootkit Tool and it
>>>>found this:
>>>>
>>>>Results:
>>>>Hidden key :
>>>>HKEY_USERS\S-1-5-21-1614895754-796845957-682003330-1004\Software\Microsoft\Protected
>>>>Storage System
>>>>Provider\S-1-5-21-1614895754-796845957-682003330-1004\data
>>>>Hidden value :
>>>>HKEY_USERS\S-1-5-21-1614895754-796845957-682003330-1004\Software\Microsoft\Protected
>>>>Storage System Provider\S-1-5-21-1614895754-796845957-682003330-1004
>>>>-> migrate
>>>>
>>>>Now I am not an expert and I am asking myself what to do with these
>>>>findings.
>>>>Do they point to a rootkit? And if so, what should be my next actions?
>>>>
>>>>Thanks,
>>>>
>>>>Massimo
>>>
>>>I wouldn't worry much about it, I have the almost same key in my system,
>>>mine ends in 1003 instead of 1004, but that may just mean different OS
>>>version.
>>
>>
>> Thank you for your reaction.
>> And why should I stop worrying about *my* rootkit only because you too
>> have one?? :-))
>>
>> Massimo
>Allow me to re-phrase that. I don't think it's a rootkit.
Allright, thank you!
Massimo
|