ABXZone Computer  Forums



Welcome to the ABXZone Computer Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Reply
 
LinkBack Thread Tools Display Modes
Old 10-18-2006, 10:31 AM   #1
Registered User
 
Join Date: Oct 2006
Posts: 2
Red face RootKit Hook Analyzer


Hey
Hope someone has some exp. with this..
I disabeled my Kaspersky Av and ran a scan with RootkitRevealer from Sysinternals and came up with these results ?
I use Alcohol52% (having un/install problems with Alcohol120%)
Thats the last 2 entries BUT what is the other entries ??

HKLM\S-1-5-21-3242297509-133608637-364582197-1004\Control Panel\PowerCfg\PowerPolicies\6\Policies 18-10-2006 16:00 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\S-1-5-21-3242297509-133608637-364582197-1004\Software\Microsoft\Keyboard\Native Media Players\QuickTime Player\ExePath 04-10-2006 02:47 43 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 17-10-2006 16:23 0 bytes Access is denied.
HKLM\SYSTEM\ControlSet001\Services\Vax347s\Config\jdgg40 14-10-2006 14:14 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\Vax347s\Config\jdgg41 13-04-2006 17:07 0 bytes Hidden from Windows API.

thank you

(Offline)   Reply With Quote
Old 10-18-2006, 02:18 PM   #2
Registered User
 
Join Date: Oct 2006
Posts: 2
Angry

Quote:
Originally Posted by jack montana View Post
Hey
Hope someone has some exp. with this..
I disabeled my Kaspersky Av and ran a scan with RootkitRevealer from Sysinternals and came up with these results ?
I use Alcohol52% (having un/install problems with Alcohol120%)
Thats the last 2 entries BUT what is the other entries ??

HKLM\S-1-5-21-3242297509-133608637-364582197-1004\Control Panel\PowerCfg\PowerPolicies\6\Policies 18-10-2006 16:00 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\S-1-5-21-3242297509-133608637-364582197-1004\Software\Microsoft\Keyboard\Native Media Players\QuickTime Player\ExePath 04-10-2006 02:47 43 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 17-10-2006 16:23 0 bytes Access is denied.
HKLM\SYSTEM\ControlSet001\Services\Vax347s\Config\jdgg40 14-10-2006 14:14 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\Vax347s\Config\jdgg41 13-04-2006 17:07 0 bytes Hidden from Windows API.

thank you
hey again
in the meantime i have found out that the :
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg

but I cant remove SPTD my system chrashes when im using RkU3.0.80.295 to "unhook all" tryed in safe mode and with system restore disabled
also tryed to give difrent security settings in REGEDIT

So q HOW can I delete this ?
I belive this entrence has something to do with my problem in/uninstallation of Alcohol120%
Keeps getting error 25002 (no mather what ver. im trying to install EXPEPT Alcohol 52% )
(Offline)   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.1
vBulletin Skin developed by: vBStyles.com