Archived from groups: microsoft.public.windowsxp.help_and_support (
More info?)
Sam said ...
> Galen said ...
> > Did you ever let the rootkit tool run? It's a really odd situation you have
> > there and it's worth at least checking that though - to be frank - that too
> > could be fooled into ignoring stuff. *chuckles*
> >
> no I didn't but attempt will do so at some stage.
>
Just ran Rootkitrevealer twice. The results are below. Most of the
entries refer to keirnet/K9 which is a Bayesian spam filter I've been
using for about 2 years on this and my previous PC. Does this reveal
anything?
C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles
\h91wf1ji.default\parent.lock 26/07/2005 17:04 0 bytes
Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Owner\Local Settings\Temp\~DF8223.tmp
26/07/2005 12:34 16.00 KB Visible in Windows API, MFT,
but not in directory index.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files
\Content.IE5\KHA70T6R\wbk32.tmp 26/07/2005 17:04 4.90 KB
Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files
\Content.IE5\KHA70T6R\wbk34.tmp 26/07/2005 17:04 2.70 KB
Visible in Windows API, but not in MFT or directory index.
C:\Program Files\KeirNet\K9\Emails\Recent\72627B94.kml 24/07/2005 19:00
1.62 KB Visible in Windows API, but not in MFT or directory
index.
C:\Program Files\KeirNet\K9\Emails\Recent\D30689C5.kml 24/07/2005 19:00
3.62 KB Visible in Windows API, but not in MFT or directory
index.
C:\Program Files\KeirNet\K9\Emails\Spam\0E4B7DD0.kml 03/11/2004 20:17
2.85 KB Visible in Windows API, but not in MFT or directory
index.
C:\Program Files\KeirNet\K9\Emails\Spam\72627B94.kml 24/07/2005 19:00
1.62 KB Hidden from Windows API.
C:\Program Files\KeirNet\K9\Emails\Spam\B6D4932A.kml 03/11/2004 20:17
1.84 KB Visible in Windows API, but not in MFT or directory
index.
C:\Program Files\KeirNet\K9\Emails\Spam\D30689C5.kml 24/07/2005 19:00
3.62 KB Hidden from Windows API.
D: 01/01/1601 01:00 0 bytes Error mounting volume
An earlier run which I ran from the command line and sent to a csv file
(fred) and in which I showed the NTFS metadata files looks like this ...
Data mismatch between Windows API and raw hive data.,26/07/2005 18:14,80
bytes,"HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed"
Hidden from Windows API.,05/08/2004 09:27,2.50 KB,"C:\$AttrDef"
Hidden from Windows API.,05/08/2004 09:27,0 bytes,"C:\$BadClus"
Hidden from Windows API.,05/08/2004 09:27,13.68 GB,"C:\$BadClus:$Bad"
Hidden from Windows API.,05/08/2004 09:27,2.17 MB,"C:\$Bitmap"
Hidden from Windows API.,05/08/2004 09:27,8.00 KB,"C:\$Boot"
Hidden from Windows API.,05/08/2004 09:27,0 bytes,"C:\$Extend"
Hidden from Windows API.,05/08/2004 09:27,0 bytes,"C:\$Extend\$ObjId"
Hidden from Windows API.,05/08/2004 09:27,0 bytes,"C:\$Extend\$Quota"
Hidden from Windows API.,05/08/2004 09:27,0 bytes,"C:\$Extend\$Reparse"
Hidden from Windows API.,30/10/2004 17:55,0 bytes,"C:\$Extend\$UsnJrnl"
Hidden from Windows API.,30/10/2004 17:55,32 bytes,"C:\$Extend\$UsnJrnl:
$Max"
Hidden from Windows API.,05/08/2004 09:27,64.00 MB,"C:\$LogFile"
Hidden from Windows API.,05/08/2004 09:27,170.70 MB,"C:\$MFT"
Hidden from Windows API.,05/08/2004 09:27,4.00 KB,"C:\$MFTMirr"
Hidden from Windows API.,05/08/2004 09:27,0 bytes,"C:\$Secure"
Hidden from Windows API.,05/08/2004 09:27,128.00 KB,"C:\$UpCase"
Hidden from Windows API.,05/08/2004 09:27,0 bytes,"C:\$Volume"
Hidden from Windows API.,26/07/2005 18:17,763 bytes,"C:\Documents and
Settings\Owner\Application Data\Microsoft\Office\Recent\fred.LNK"
Visible in Windows API, but not in MFT or directory index.,24/07/2005
18:20,2.30 KB,"C:\Program Files\KeirNet\K9\Emails\Recent\67B3DF18.kml"
Visible in Windows API, but not in MFT or directory index.,24/07/2005
18:20,36 bytes,"C:\Program Files\KeirNet\K9\Emails\Recent
\67B3DF18.kml:KAVICHS"
Hidden from Windows API.,26/07/2005 18:28,2.30 KB,"C:\Program Files
\KeirNet\K9\Emails\Spam\67B3DF18.kml"
Hidden from Windows API.,26/07/2005 18:28,36 bytes,"C:\Program Files
\KeirNet\K9\Emails\Spam\67B3DF18.kml:KAVICHS"
Visible in Windows API, but not in MFT or directory index.,03/11/2004
19:17,1.46 KB,"C:\Program Files\KeirNet\K9\Emails\Spam\914CE960.kml"
Hidden from Windows API.,03/06/2005 16:41,2.44 KB,"C:\System Volume
Information\_restore{2C64A447-4679-4204-A039-16352F4E0E7D}\RP332
\A0037360.lnk"
Hidden from Windows API.,25/07/2005 15:13,672 bytes,"C:\System Volume
Information\_restore{2C64A447-4679-4204-A039-16352F4E0E7D}\RP332
\A0037361.LNK"
Visible in Windows API, but not in MFT or directory index.,26/07/2005
18:11,0 bytes,"C:\WINDOWS\system32\spool\PRINTERS\FP00000.SHD"
Visible in Windows API, but not in MFT or directory index.,26/07/2005
18:11,0 bytes,"C:\WINDOWS\system32\spool\PRINTERS\FP00000.SPL"
Error mounting volume,01/01/1601 01:00,0 bytes,"D:"
--
Sam