Lunarsoft Forums: Rootkit Revealer, 2 new items. - Lunarsoft Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Rootkit Revealer, 2 new items.

#1 User is offline   Harry 

  • Lunar Novice
  • Group: Members
  • Posts: 12
  • Joined: 28-March 07
  • Location:The Colony, Texas
  • Interests:Gardening, ,computers, church, and work, not necessarily in that order.

Posted 13 July 2007 - 09:51 PM

Ran the latest version of rootkit revealer and these 2 entries showed up. Ran after updating XP today with the latest MS fixes. Do they belong to rootkit revealer. or to MS? I have ran RKR on 3 computers and this shows up on 2 of them. One is an Intel, dual processor and the other is an AMD Athlon 2000. They did not show under the previous version of RKR, so I don'y know if they have been there all along or if the new version checks deeper. Anyone else ran into this?

HKLM\Security\Policy\Secrets\SAC* Key name contains embedded nulls

HKLM\Security\Policy\Secrets\SAI* Key name contains embedded nulls

Harry
0

#2 User is offline   Tarun 

  • Area 5 Investigator
  • Group: Administrators
  • Posts: 4,539
  • Joined: 05-September 05
  • Gender:Male
  • Location:Bon Temps
  • OS: Windows 7 Ultimate x86
  • Country:United States
    country_flag

Posted 13 July 2007 - 10:29 PM

They're nothing to worry about. The new version simply changed how Rootkit Revealer performs the scanning process. :hello:
Posted ImagePosted Image
Posted ImagePosted Image
Posted ImagePosted Image
Posted ImagePosted Image

Have we helped you out? Please help support Lunarsoft.net!
0

#3 User is offline   Photogrrlz 

  • Lunar Novice
  • Group: Members
  • Posts: 45
  • Joined: 24-July 06
  • Location:Ohio

Posted 14 November 2007 - 11:43 PM

Okay I have a dumb question since I seen it on the combofix... what is a rootkit? also I guess that is the catchme program off of combofix? I read that it was because of a rootkit that the system32 folder was deleted
0

#4 User is offline   Tarun 

  • Area 5 Investigator
  • Group: Administrators
  • Posts: 4,539
  • Joined: 05-September 05
  • Gender:Male
  • Location:Bon Temps
  • OS: Windows 7 Ultimate x86
  • Country:United States
    country_flag

Posted 15 November 2007 - 12:54 AM

A rootkit is a general description of a set of programs which work to subvert control of an operating system from its legitimate operators. Usually, a rootkit will obscure its installation and attempt to prevent its removal through a subversion of standard system security. Techniques used to accomplish this can include concealing running processes, files or system data from the operating system. Rootkits have their origin in benign applications, but in recent years have been used increasingly by malware to help intruders maintain access to systems while avoiding detection. Rootkits exist for a variety of operating systems, such as Microsoft Windows, Mac OS X , Linux and Solaris. Rootkits often modify parts of the operating system or install themselves as drivers or kernel modules.

Source: Rootkit - Wikipedia
Posted ImagePosted Image
Posted ImagePosted Image
Posted ImagePosted Image
Posted ImagePosted Image

Have we helped you out? Please help support Lunarsoft.net!
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users