Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

root kit scan

Reply

Old 21st Sep 2012, 07:39
  #1 (permalink)  
Thread Starter
 
Join Date: Jan 2009
Location: England that central part of Britian between Ecosse and Occupied France
Posts: 122
root kit scan

HI, can help with the below found with a sky-bot root kit scan are the malware or just hidden files::





Type: Key
Object: Flyout
Location: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\A pplets\SysTray\BattMeter\
Details: No admin in ACL
Type: Key
Object: Svc
Location: HKLM\SOFTWARE\Wow6432Node\Microsoft\Security Center\
Details: No admin in ACL


Type: Folder
Object: SrtETmp
Location: C:\Users\All Users\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\
Details: No admin in ACL
Type: Folder
Object: SrtETmp
Location: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\
Details: No admin in ACL
much2much is offline  
Reply With Quote
Old 21st Sep 2012, 09:20
  #2 (permalink)  
 
Join Date: Dec 2005
Location: Wellington,NZ
Age: 60
Posts: 1,619
You mean "Spybot" rather than sky-bot, I think?

Last time I looked, the rootkit scanner was a beta. Shouldn't really be used, unless you know what you're doing, if that's the case.

ADS processes found using a rootkit scanner are not necessarily rootkits. When they're flagged, it means it might be suspicious, or it might not.

In this case, it would appear to be part of the process of Norton - which I presume is your antivirus - and probably harmless. And if Norton is not your antivirus, I strongly recommend you remove it.

That said, I'd install, update, and run a scan with MBAM, for a second opinion. It's a very good scanner. There is a free version.
Tarq57 is offline  
Reply With Quote
Old 21st Sep 2012, 11:13
  #3 (permalink)  
More bang for your buck
 
Join Date: Nov 2005
Location: land of the clanger
Age: 76
Posts: 3,511
WoW64 (Windows 32-bit on Windows 64-bit) is a subsystem of the Windows operating system that is capable of running 32-bit applications and is included on all 64-bit versions of Windows.
green granite is offline  
Reply With Quote
Old 21st Sep 2012, 15:56
  #4 (permalink)  
 
Join Date: Jan 2012
Location: .
Posts: 2,179
if you want to check for rootkits use Kasperky's TDSSKiller

Anti-rootkit utility TDSSKiller

Not a bad idea to follow that up with Hitman Pro afterwards

Run both in SAFE mode
Milo Minderbinder is offline  
Reply With Quote
Old 21st Sep 2012, 17:35
  #5 (permalink)  
Thread Starter
 
Join Date: Jan 2009
Location: England that central part of Britian between Ecosse and Occupied France
Posts: 122
thanks guys ,second opinion ,a good idea,already ran malware bytes, all looks well.sky(spy) bot,ok. aviator Frued slip up, or poor humor,and ran the tdss killer .not tks (anti ice)

Last edited by much2much; 21st Sep 2012 at 18:11.
much2much is offline  
Reply With Quote

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Thread Tools
Search this Thread

Contact Us Archive Advertising Cookie Policy Privacy Statement Terms of Service