Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Security > RootkitRevealer on Windows 7??? HELP!

Reply
Thread Tools Display Modes

RootkitRevealer on Windows 7??? HELP!

 
 
MikoCat
Guest
Posts: n/a

 
      07-21-2009

After my computer acted suspicious yesterday I have scanned it with m
anti-virus and Spybot Search and Destroy with only few minor problems.

I then decided to try RootkitRevealer. I am running Windows 7 - Buil
7100 and when I ran the RootkitRevealer, a new window pops up saying "
program running on this computer is trying to display a message"
followed by the options "View the message" and "Ask me later"

So after clicking "View the message" the RootkitRevealer progra
interface is displayed in it's own separate screen away from the deskto
so I figured "Meh, it should still work". So I click "search" and afte
no time I am presented with a few minor registry values

Then about 5 minutes into the scan, millions (yeah, millions) of file
appear in the list! Pretty much every file on my PC + more is listed i
RootKitRevealer

Probably about 95% of the millions of results are "Visible in Window
API, but not in MFT or index."

Most of the results also have extremely long and obscene path's such a
"C:\Users\Home\Local Settings\Application Data\Applicatio
Data\Application Data\Application Data\Application Data\Applicatio
Data\Application Data\Application Data\Application Data\Applicatio
Data\Application Data\Application Data\Application Data\Applicatio
Data\(Some random letters)"... ***

Do I have a serious rootkit that is disguising itself within a list o
millions? Am I screwed
Or is RootKitRevealer not compatible with Windows 7 and I should not b
worried

Someone please help

--
MikoCat
 
Reply With Quote
 
 
 
 
Vista Succubus Hunter
Guest
Posts: n/a

 
      07-22-2009

MikoCat wrote:

>
> Someone please help!
>
>


There are plenty of articles out on Google that will show you what to
look for in the screen displays of RootKitReveler to determine what is a
threat and what is not a threat. You need to do the search.
 
Reply With Quote
 
Peter Foldes
Guest
Posts: n/a

 
      07-22-2009
You should post this issue of yours over to the microsoft.
public.security.homeusers for a comprehensive answer from one of the experts there

news://msnews.microsoft.com/microsof...rity.homeusers


--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"MikoCat" <> wrote in message
news:...
>
> After my computer acted suspicious yesterday I have scanned it with my
> anti-virus and Spybot Search and Destroy with only few minor problems.
>
> I then decided to try RootkitRevealer. I am running Windows 7 - Build
> 7100 and when I ran the RootkitRevealer, a new window pops up saying "A
> program running on this computer is trying to display a message",
> followed by the options "View the message" and "Ask me later".
>
> So after clicking "View the message" the RootkitRevealer program
> interface is displayed in it's own separate screen away from the desktop
> so I figured "Meh, it should still work". So I click "search" and after
> no time I am presented with a few minor registry values.
>
> Then about 5 minutes into the scan, millions (yeah, millions) of files
> appear in the list! Pretty much every file on my PC + more is listed in
> RootKitRevealer.
>
> Probably about 95% of the millions of results are "Visible in Windows
> API, but not in MFT or index."
>
> Most of the results also have extremely long and obscene path's such as
> "C:\Users\Home\Local Settings\Application Data\Application
> Data\Application Data\Application Data\Application Data\Application
> Data\Application Data\Application Data\Application Data\Application
> Data\Application Data\Application Data\Application Data\Application
> Data\(Some random letters)"... ***?
>
> Do I have a serious rootkit that is disguising itself within a list of
> millions? Am I screwed?
> Or is RootKitRevealer not compatible with Windows 7 and I should not be
> worried?
>
> Someone please help!
>
>
> --
> MikoCat


 
Reply With Quote
 
d0z3r
Guest
Posts: n/a

 
      08-10-2009

--
d0z3r


"Vista Succubus Hunter" wrote:

> MikoCat wrote:
>
> >
> > Someone please help!
> >
> >

>
> There are plenty of articles out on Google that will show you what to
> look for in the screen displays of RootKitReveler to determine what is a
> threat and what is not a threat. You need to do the search.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59