Author Topic: Do I need to remove antirootkit entries for SndVolSSO.dll?  (Read 5708 times)

0 Members and 1 Guest are viewing this topic.

July 05, 2014, 03:48:42 AM

Dan Bridgman

  • Guest
Do I need to remove antirootkit entries for SndVolSSO.dll?
« on: July 05, 2014, 03:48:42 AM »
I need suggestions for what to remove in RK report.
Thanks
-dan

RogueKiller V9.1.0.0 [Jun 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : One hand clapping [Admin rights]
Mode : Scan -- Date : 07/04/2014  17:58:46

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 7 ¤¤¤
[PUM.Policies] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0  -> FOUND
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1361578720-2741409265-2114749344-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2  -> FOUND
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1361578720-2741409265-2114749344-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowControlPanel : 2  -> FOUND
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1361578720-2741409265-2114749344-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0  -> FOUND
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1361578720-2741409265-2114749344-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0  -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> FOUND

¤¤¤ Scheduled tasks : 4 ¤¤¤
[Suspicious.Path] \\{17F5FBA1-CC23-4D57-9A0F-5ABBA2F43ED1} -- C:\Windows\system32\pcalua.exe (-a "C:\Users\One hand clapping\Downloads\Penumbra_Full_1.1.exe" -d "C:\Users\One hand clapping\Downloads") -> FOUND
[Suspicious.Path] \\{90315557-1CD1-4E1B-9F18-C1C640108D04} -- C:\Windows\system32\pcalua.exe (-a C:\Windows\zipinst.exe -c /uninst "C:\Users\One hand clapping\Documents\Tools\Nirsoft\NirSoft Software\uninst1~.nsu") -> FOUND
[Suspicious.Path] \\{E10DBF3A-218F-4809-B98C-16DE640CF939} -- C:\Windows\system32\pcalua.exe (-a "C:\Users\One hand clapping\Downloads\sp44351.exe" -d "C:\Users\One hand clapping\Downloads") -> FOUND
[Suspicious.Path] \\{EF4DD966-7860-40DB-A13D-6CC39FEFC224} -- C:\Windows\system32\pcalua.exe (-a "C:\Users\One hand clapping\Downloads\irfanview_plugins_425_setup.exe" -d C:\Windows\system32) -> FOUND

¤¤¤ Files : 0 ¤¤¤

¤¤¤ HOSTS File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 3 ¤¤¤
[EAT:Addr] (explorer.exe) XmlLite.dll - DllCanUnloadNow : C:\Windows\System32\SndVolSSO.dll @ 0x749b155f
[EAT:Addr] (explorer.exe) XmlLite.dll - DllGetClassObject : C:\Windows\System32\SndVolSSO.dll @ 0x749b4852
[EAT:Addr] (explorer.exe) XmlLite.dll - DllMain : C:\Windows\System32\SndVolSSO.dll @ 0x749b12fb

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST325031 0AS SCSI Disk Device +++++
--- User ---
[MBR] e3b2deb6c017a47369d002b3522f62d2
[BSP] ff2edfb7badeebf86c8c6a5916eb23d3 : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 226949 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 464792580 | Size: 11523 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Incorrect function. )


Reply #1July 07, 2014, 08:05:49 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Do I need to remove antirootkit entries for SndVolSSO.dll?
« Reply #1 on: July 07, 2014, 08:05:49 AM »
Hello
Rootkit entries cannot be removed.

SndVolSSO looks legit, I'll whitelist the DLL.

Reply #2July 12, 2014, 05:40:53 AM

Dan Bridgman

  • Guest
Re: Do I need to remove antirootkit entries for SndVolSSO.dll?
« Reply #2 on: July 12, 2014, 05:40:53 AM »
Thanks very much.  Sleeping better, now.
Dan