Lollipop

Welcome to PcCare.com

Rootkit Revealer

 

 

RootkitRevealer -> Microsoft's rootkit tool

 

  • Rootkit revealer displays registry keys, process etc that are hidden by rootkits

 

The following set of findings are ok and do not represent viral entries:

 

HKLM\Security\Policy\Secrets\SAC*

HKLM\Security\Policy\Secrets\SAI*

 

 

$Repair:$Config

\$Txf
\$TxLog
\$TxfLog\$Tops:$T
C:\$Extend\RmMetadata\$Repair
C:\$Extend\RmMetadata\$Txf
C:\$Extend\RmMetadata\$TxfLog
C:\$Extend\RmMetadata\$TxfLog\$Tops
C:\$Extend\RmMetadata\$TxfLog\$TxfLog.bif
C:\$Extend\RmMetadata\$TxfLog\$TxfLogXContainer000000000000001
C:\$Extend\RmMetadata\$TxfLog\$TxfLogXContainer000000000000002

 

C:\System Volume Information\catalog.wci\0001000D.ci 10/04/2006 4:41 PM 12.00 KB Hidden from Windows API.

C:\System Volume Information\catalog.wci\0001000D.dir 10/04/2006 4:41 PM 368 bytes Hidden from Windows API.

C:\System Volume Information\catalog.wci\0001000E.ci 10/04/2006 5:08 PM 12.00 KB Hidden from Windows API.

C:\System Volume Information\catalog.wci\0001000E.dir 10/04/2006 5:08 PM 362 bytes Hidden from Windows API.

 

 

An alternative method for discovering rootkits.



 

 

 

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. PcCare.com will not be held responsible if changes you make cause a system failure.

Please review our Terms of Service and Privacy statement before initiating service or using this site. Microsoft® and the Office logo are trademarks or registered trademarks of Microsoft Corporation in the United States and/or other countries. PcCare Site Map. About Us