This thread's last reply is from February 6, 2011, 1:02 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
tangerine
--== Dump Hidden Registry Value on HKLM ==--
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Recording\Restricted
Root : 0
SubKey : Restricted
ValueName : ccc
Data : 48 E7 E 92 58 B3 13 E6 ...
ValueType : 3
AccessType: 0
FullLength: 0x66
DataSize : 0xc8
[HIDDEN_REGISTRY][Hidden Reg Key]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\43
SubKey : 43
FullLength: 0x59
2 hidden registry entries found.
does this make any sense?
tangerine
is this anything to worry about?
Begin scan in 'C:\'
C:\Users\Chris\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\7D037C60-000026B3.eml
[0] Archive type: MIME
[DETECTION] Contains recognition pattern of the PHISH/FraudHS.A phishing file/email
--> Verify.html
[DETECTION] Contains recognition pattern of the PHISH/FraudHS.A phishing file/email
askey127
Those registry items are OK.
The last two are e-mails that you already deleted, probably because they were fake. Unless you were to restore them, they are not a problem.
I am still looking at your log(s).
tangerine
ok thank you. Just got sophos and trend micro both flag those files as rootkits thats why got worried?
Appreciate your help
tangerine
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\43
SubKey : 43
what is this file for please?
askey127
That's part of Windows Search related to indexing the hard drive.
You do not seem to have a rootkit.
If you don't have any further questions, you should be good to go.
tangerine
How about this one please?
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Recording\Restricted
anything else I need to do?
tangerine
rootkin flagged this up too
Location: C:\Windows\winsxs\x86_microsoft-windows-s..sor-native-whitebox_31bf3856ad364e35_6.0.6001.18000_none_a0f56f6331781dea\secproc.dll
Removable: Yes (but clean up not recommended for this file)
one last thing
my mouse just started moving on its own is that anything to be concerned about?
thanks
askey127
You can run a full scan with Antivir to remove any infected files.
I would not continue running Rootkit detector scans.
They are specialized tools, and the results they give are not meant for the interpretation of the average computer user.
If the system behavior becomes unacceptable due to damage caused from using utorrent, you will need to save your data files on an external media and reformat / re-install windows.
One tutorial is here: http://ask-leo.com/how_do_i_reformat_and_reinstall_windows.html
There are a lot of them on the Internet to print out and follow.