PDA

View Full Version : Rootkits



contempt
29 Aug 2007, 08:24pm
Hey folks,

As I was trying to help Sol w/ a problem (MountAppFilesystem() failed: SteamMountAppFilesystem(240,0,0,ox1306fd74) failed with error 1: the registry is in use by another process,timeout expired) and looking for the links to free anti-virus and anti-malware software in "my" Tweaking Companion, I came upon the Rootkit section and decided to download and run RootkitRevealer to scan for rootkits.

For info on what a rootkit is and does, visit:
Rootkits - A New Malware Trend (http://www.emsisoft.com/en/kb/articles/tec060324/)
RootkitRevealer v1.71 (http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx)

After running the program, I found myself puzzled by the results it came up with:
http://img509.imageshack.us/img509/4029/rootkitscanqd2.jpg (http://imageshack.us)

I hope y'all can give me some input on each of these paths, and tell me if they're malicious and need to be deleted.

contempt

Arc
30 Aug 2007, 02:01pm
Don't know about the others but the SecuROM one is to keep you from messing up their retarded copy protection scheme. I don't think it's a rootkit, just more of game DRM type protection scheme.

contempt
30 Aug 2007, 02:16pm
Thank you, Arc. You could be right. I do know, or so I found out, that the HKLM\...\SAC* and SAI* keys are no rootkits, which leaves two to solve: key 2 and 5.

contempt