Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
?rootkit infections

Reply  
Thread Tools
perfume's Avatar
perfume has a Photo Album
Computer Specs
Account Disabled with 2,011 posts.
 
Join Date: Sep 2008
Location: A DUDE WITH ATTITUDE! ALIEN.
Experience: Intermediate++
02-Mar-2009, 04:45 AM #1
?rootkit infections
I just ran an Sophos Anti-Rootkit scan and it showed up a report that there are three"hidden objects". All three are in the registry. When i left-clicked on the first value, this is what was shown:"Area: Windows registry
Description: Hidden registry value
Location: \HKEY_USERS\S-1-5-21-854245398-1993962763-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C446A68B-A797-18B0-8DED-A855C1233527}\jadkddiepgdbelfofdpa
Removable: No
Notes: (type 3, length 6) "baci "

The second value:"Area: Windows registry
Description: Hidden registry value
Location: \HKEY_USERS\S-1-5-21-854245398-1993962763-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C446A68B-A797-18B0-8DED-A855C1233527}\iadllbiknfajefmgbl
Removable: No
Notes: (type 3, length 24) "kaegomapkkhpmlidififld "

The third value:"Area: Windows registry
Description: Hidden registry value
Location: \HKEY_USERS\S-1-5-21-854245398-1993962763-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C446A68B-A797-18B0-8DED-A855C1233527}\hajkfbcnefmllkbo
Removable: No
Notes: (type 3, length 24) "kaegomapkkhpnlnflddflm "

Help! Thanks in advance.
rainforest123's Avatar
Distinguished Member with 6,632 posts.
 
Join Date: Dec 2004
Experience: Advanced
02-Mar-2009, 06:46 AM #2
p:
Did you run the tool because of a problem, or another reason? If a problem, please describe it.

There are a # of rootkit revealers; GMER, Sysinternals, AVG, Sophos, et al.

I have had varying success with each. Most recently, I had run gmer, which found nothing. MBAM found a hidden file, but was unable to dis-infect it. I booted to my Win XP CD, rec console, renamed filename.sys to filename.ysy . Then, MBAM could remove it. Before running MBAM, I submitted the file to http://virusscan.jotti.org , which identified it as malware in about 1/2 of the scanners.

RF123
__________________
Give someone a fish and they eat for a day. Teach someone to fish and they eat for a lifetime.
Change is constant. Growth is optional.
Attributes. http://www.wayneburke.com/Changeqte.html
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:27 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.