RootkitRevealer -> Microsoft's rootkit tool The following set of findings are ok and do not represent viral entries: HKLM\Security\Policy\Secrets\SAC*
HKLM\Security\Policy\Secrets\SAI* $Repair:$Config
\$Txf \$TxLog \$TxfLog\$Tops:$T C:\$Extend\RmMetadata\$Repair C:\$Extend\RmMetadata\$Txf C:\$Extend\RmMetadata\$TxfLog C:\$Extend\RmMetadata\$TxfLog\$Tops C:\$Extend\RmMetadata\$TxfLog\$TxfLog.bif C:\$Extend\RmMetadata\$TxfLog\$TxfLogXContainer000000000000001 C:\$Extend\RmMetadata\$TxfLog\$TxfLogXContainer000000000000002 C:\System Volume Information\catalog.wci\0001000D.ci 10/04/2006 4:41 PM 12.00 KB Hidden from Windows API.
C:\System Volume Information\catalog.wci\0001000D.dir 10/04/2006 4:41 PM 368 bytes Hidden from Windows API.
C:\System Volume Information\catalog.wci\0001000E.ci 10/04/2006 5:08 PM 12.00 KB Hidden from Windows API.
C:\System Volume Information\catalog.wci\0001000E.dir 10/04/2006 5:08 PM 362 bytes Hidden from Windows API. An alternative method for discovering rootkits.
|