Please help with RootkitRevealer scan results

dredd2929

Senior member
Jun 4, 2005
230
0
0
I downloaded RootkitRevealer v1.7 and ran a scan. I got the following results:

HKLM\SECURITY\Policy\Secrets\SAC* 11/26/2008 1:49 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 11/26/2008 1:49 AM 0 bytes Key name contains embedded nulls (*)
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090905.004\vscanmsx.dat 9/5/2009 8:19 PM 2.02 KB Hidden from Windows API.
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb 9/5/2009 8:13 PM 64.00 KB Visible in Windows API, but not in MFT or directory index.

I'm running Windows XP SP3, Windows Firewall, Symantec AntiVirus 9.2.0.1000, and Windows Defender. Do any of the above listings sound fishy?

I ran the scan because I was getting strange behavior with Windows Firewall. Every time I start my computer, WF momentarily disables (and gives the usual warning message) and then after a few seconds it turns back on. It appears this happens when it is loading HP Digital Imaging Monitor. After finding no threats with a virus scan or Windows Defender scan, I read about RootkitRevealer and I thought I would try it. Problem is, it doesn't really say what the results mean or what I should do about them. Any advice would be appreciated.
 

Billb2

Diamond Member
Mar 25, 2005
3,035
70
86
Originally posted by: dredd2929

...0 bytes Key name contains embedded nulls (*)
...Hidden from Windows API.
...Visible in Windows API, but not in MFT or directory index.
That's not enough info.
Just tells you that there are suspicious things present.

As you are finding, Windows firewall is useless.

Try a Virus scan (hopefully with the latest definitions!)
Have a look at Malwarebits.

 

dredd2929

Senior member
Jun 4, 2005
230
0
0
Do you mean Malwarebytes?

How does this replace Windows Firewall? Can I run this program at the same time as Windows Defender?

I did run a virus scan with the latest definitions.
 

dredd2929

Senior member
Jun 4, 2005
230
0
0
It turns out that, after further research, the results of my scan are innocuous.

However, I'm still curious about the ability to run Windows Defender and Malwarebytes in tandem.
 

lxskllr

No Lifer
Nov 30, 2004
59,471
9,990
126
Free Malwarebytes is a scanner only, so it won't interfere with Defender. The pay version has realtime protection, but I don't know how it interacts with other products.
 

tzdk

Member
May 30, 2009
152
0
0
You should probably focus more on the question if it make sense to run old versions of Antivirus.
 

dredd2929

Senior member
Jun 4, 2005
230
0
0
My current version of Anitvirus seems to be working fine...I get updated definitions at least once a day. I'm using it through a corporate license through my school. Does this version not offer adequate protection?