![]() |
Checking out my Log |
Post Reply
|
| Author | |
southcot
Newbie
Joined: 16 February 2006 Location: United Kingdom Online Status: Offline Posts: 6 |
Post Options
Quote Reply
Topic: Checking out my LogPosted: 27 March 2006 at 6:04am |
|
Thanks for your help
|
|
![]() |
|
namrehto
Senior Member
Joined: 23 June 2005 Location: Scotland Online Status: Offline Posts: 3861 |
Post Options
Quote Reply
Posted: 27 March 2006 at 6:02am |
|
Googling for the CLSIDs is the immediate route for trying to identify their origin. Since the keys showed 0 bytes in size then there's not much more to do on that score.
Edited by namrehto - 27 March 2006 at 8:25am |
|
|
Gil
|
|
![]() |
|
southcot
Newbie
Joined: 16 February 2006 Location: United Kingdom Online Status: Offline Posts: 6 |
Post Options
Quote Reply
Posted: 27 March 2006 at 3:56am |
|
Wuth regard to the null entries in the registry, I did a google and forum search for the CLSIDS but they found nothing conculsive. Is there any way of telling whether the entries relate to an legitmate piece of software or not?
|
|
![]() |
|
southcot
Newbie
Joined: 16 February 2006 Location: United Kingdom Online Status: Offline Posts: 6 |
Post Options
Quote Reply
Posted: 27 March 2006 at 3:53am |
|
Many Thanks - just got this from the Seti forum too.
|
|
![]() |
|
namrehto
Senior Member
Joined: 23 June 2005 Location: Scotland Online Status: Offline Posts: 3861 |
Post Options
Quote Reply
Posted: 27 March 2006 at 2:46am |
|
They're all false positives due to changes while RKR was scanning, some maybe due to unfortunately timed background maintenance. Next time prevent the SETI software from running and ensure you don't use the machine.
|
|
|
Gil
|
|
![]() |
|
southcot
Newbie
Joined: 16 February 2006 Location: United Kingdom Online Status: Offline Posts: 6 |
Post Options
Quote Reply
Posted: 27 March 2006 at 1:25am |
|
I have run RootKitRevealer and am including the log below. Being new to this I have done my best to clarify the results. I would however welcome any observations on my interpretation.
I have removed the keys using RegDelNull in lines 1 & 2.It would seem form other posts on the forum that line 3 is a false positive as are lines 8 to 32. I have posted a request for clarification on the BOINC entries at the SETI Site
|
|
![]() |
|
Post Reply
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |