The Rootkitrevealer results make for a large file. The rest of the
missing
data starts like those at bottom here, apparently from Recyler/Norton
Protected files. In total, it's about 5 times as much data as this space
will allow. Are these possible culprits? It sure would be easier to
email
these and the other two files to you as attachments. I promise I'm a good
citizen and will not release your email address to anyone.
HKLM\SOFTWARE\Microsoft\Microsoft SQL
Server\VAIO_VEDB\MSSQLServer\uptime_time_utc 12/13/2005 4:18 PM 8 bytes
Data
mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Prefetcher\TracesProcessed 12/13/2005 4:19 PM 4 bytes
Data
mismatch between Windows API and raw hive data.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 2
for RootkitRevealer[1].zip 12/13/2005 4:18 PM 0 bytes Visible in Windows
API,
but not in MFT or directory index.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 2
for RootkitRevealer[1].zip\RootkitRevealer.chm 12/7/2005 2:19 PM 99.77
KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 2
for RootkitRevealer[1].zip\RootkitRevealer.chm:Zone.Identifier 12/7/2005
2:19
PM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 3
for RootkitRevealer[1].zip 12/13/2005 4:19 PM 0 bytes Visible in Windows
API,
but not in MFT or directory index.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet
Files\Content.IE5\SHYZ8XMV\Thumbs.db 12/13/2005 4:26 PM 62.00 KB Hidden
from
Windows API.
C:\RECYCLER\NPROTECT 12/13/2005 4:22 PM 0 bytes Hidden from Windows API.
C:\RECYCLER\NPROTECT\00008711. 12/9/2005 5:12 PM 3.39 MB Hidden from
Windows
API.
C:\RECYCLER\NPROTECT\00008738. 6/11/2005 12:21 PM 37.00 KB Hidden from
Windows API.
C:\RECYCLER\NPROTECT\00008741. 12/9/2005 5:12 PM 39.00 KB Hidden from
Windows API.
needlove said:
Post the rootkitrevealer scan results next