Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19

Thread: potentially rootkit-masked files...?

  1. #11
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    i thought it was weird though that spysweeper found NOTHING when i ran it in safemode, but it finds a rootkit every time i run in normal mode?
    I think that is odd also. Wonder if this could be a false positive?

    You might also search for these two files manually in C:\Windows\
    imsins.log
    KB887998.log

  2. #12
    Join Date
    Sep 2006
    Posts
    12
    here is what happened when i ran the sophos rootkit remover, and what it said.

    http://i98.photobucket.com/albums/l2...006/sophos.jpg

    i was scared to remove what it found, since it looked like it might screw up my computer further. would you please advise me what to do next?

  3. #13
    Join Date
    Sep 2006
    Posts
    12
    i did search for them manually, and found them, but could not delete them when i searched.

  4. #14
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Well this problem evidently has popped up for many, because my search this evening has produced several results...yesterday and day before...none.

    I believe now, unless your computer is running very badly, that these ARE false/ postives results. I have just found this on numerous sites;

    "Because of the technology that Spysweeper uses, alot of times it alarms you of potentially masked rootkit files. Typically this is nothing to be alarmed about as it only looks for differences between the disk and what Windows reports back. This is not definition based.
    There is a setting in the shield tab to check for root kits, untick this option.True rootkit detection is far beyond an app like SpySweeper"


    Add the above remarks to the results of your Sophos Rootkit Remover I would say that in all likelyhood you DO NOT have a rootkit on your computer.
    So unless you are having major problems, I would ignore this warning and follow the directions given in italics above for NOT having Spysweeper check for rootkits.

  5. #15
    Join Date
    Sep 2006
    Posts
    12
    ok... i am wary, but i will do as you suggest. i have just been scared to access my bank account or even email accounts from my pc, for fear that someone may be logging my passwords... =o/

  6. #16
    Join Date
    Sep 2006
    Posts
    12
    and i dont see a shield for rootkits... closest thing i see is one for keyloggers...?

  7. #17
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok, do this;
    Go to this website http://virusscan.jotti.org/
    The page will upload this file from your computer and run it through multiple virus scans. You will receive a report on what each one finds. Save it as a text file on your computer.

    At the very top of that page there is a place to place the name of the files that spysweeper keeps noting.
    Below are the four files you need to submit, one at a time. The page will scan each file and give you a report on each. Save the reports and post them here. If NOTHING is found on any of them then don't bother to post the report for that one just post back that nothing was found. Here are the files. Do them one at a time.

    C:\WINDOWS\imsins.log
    C:\WINDOWS\imsins.BAK
    C:\WINDOWS\Kb887998.log
    C:\WINDOWS\KB887742.log

  8. #18
    Join Date
    Sep 2006
    Posts
    12
    ok... so this is weird. (is it?)

    C:\WINDOWS\imsins.log & C:\WINDOWS\Kb887998.log
    now no longer exist. (at least not in C:\WINDOWS.)

    the other two, i uploaded, and they scanned clean. should i assume i am safe now? do you know why those other 2 files would have disappeared?

  9. #19
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    They were removed by one or another of the programs. OR they never really existed and Spysweeper was showing a false positive as mentioned earlier.
    Yes, I would say your system is clean now.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •