Need Help Interpreting Scan Results of RootkitRevealer by Sysinternals

S

Summer

Hi,

Can someone tell me if I need to do anything about these two
"discrepancies"?

Was instructed to run this scan on an "idle" system, but I'm not sure if I
understand what idle means. I'm guessing idle = "run w/no programs running"
not "run in safe mode". I did the former, but did not shut down any programs
in the system tray. Hope this is correct. Anyway...

RootkitRevealer by Sysinternals - Scan results:
Scan complete: 2 discrepancies found.

HKLM\SYSTEM\ControlSet001\Services\Eventlog\Application\SamplApp\EventMessageFile
12/30/2004 5:21 PM 35 bytes Data mismatch between Windows API and raw hive
data.

HKLM\SYSTEM\ControlSet002\Services\Eventlog\Application\SamplApp\EventMessageFile
12/30/2004 5:21 PM 35 bytes Data mismatch between Windows API and raw hive
data.

I feel fortunate that this is all that was found on my system. I update and
regularly use ZoneAlarm (free version), CounterSpy (active monitoring),
AdAware (active monitoring), Spybot S&D, and Avast! (active monitoring). I
feel my system isn't "broke" so I have d/l'd but not yet installed (the more
powerful?) hijackthis, cwshredder, and spywareblaster.

Using XP Pro, w/broadband and recently installed a wireless G network
(Linksys router w/SRX200), so we now have a hardware firewall.

Thanks in advance for any insights you can share!
 
F

frodo

Summer said:
HKLM\SYSTEM\ControlSet001\Services\Eventlog\Application\SamplApp\EventMessageFile
12/30/2004 5:21 PM 35 bytes Data mismatch between Windows API and raw hive
data.
HKLM\SYSTEM\ControlSet002\Services\Eventlog\Application\SamplApp\EventMessageFile
12/30/2004 5:21 PM 35 bytes Data mismatch between Windows API and raw hive
data.

those are benign.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top