Forum Home
Press F1
 
Thread ID: 88448 2008-03-27 20:35:00 RootAlyzer jayal (1291) Press F1
Post ID Timestamp Content User
653402 2008-03-27 20:35:00 "if you haven't updated your SpyBot Search & Destroy software recently, you should do so. The developers released a new component called RootAlyzer, which "goes through the file system, the Registry, and process related lists" in an attempt to discover rootkits."

this from a news letter from "Windows Secrets"

so i downloaded it, ran it and this resulted

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Reinstall\3 squares.\(i.e. the square character)

in the registry under Data this:- d:\radeonxp\install\driver\2kpx_inf\cx_26410.inf

can someone shed some light on this for me please?
jayal (1291)
653403 2008-03-27 20:41:00 Thats the setup/ini file for your videocard. And what it puts in your registry

When you install the video card drivers

And d is where the videocard drivers are installed
Speedy Gonzales (78)
653404 2008-03-27 22:15:00 Thanks Speedy, once again - any thoughts on the "RootAlyzer" programme? jayal (1291)
653405 2008-03-27 22:21:00 Nope, I dont use it, and dont use Spybot either

It depends on WHAT its meant to actually do and what it thinks is a rootkit

I would have a look in the Spybot forums and see if anyone has posted a similar question, and received an answer
Speedy Gonzales (78)
653406 2008-03-28 00:02:00 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Reinstall\3 squares.\(i.e. the square character)


Rootkit finders are not an exact science, they usually find things that look suspicious. Because it had odd characters it flagged it.
pctek (84)
653407 2008-03-28 05:42:00 thanks for that jayal (1291)
1