I ran a scan with rootkit revealer and this is what I was shown:
Path: HKLM\SOFTWARE\Classes\webcal\URL Protocol
Timestamp: 7/2/2004 8:17 PM
Size: 13 bytes
Description: Data mismatch between Windows API and raw hive data.
Path: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\
Timestamp: 10/26/2005 9:33 PM
Size: 0 bytes
Description: Key name contains embedded nulls (*)
Path: C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb
Timestamp: 11/2/2005 6:07 PM
Size: 64.00 KB
Description: Visible in Windows API, but not in MFT or directory index.
This is the first time I've scanned my system for rootkits and, after much searching on google and the sysinternal forum, I wasn't able to determine what these are or if I should do anything about them. I couldn't even locate the first two items in the regedit, assuming thats even where they are. Help would be appreciated.
Path: HKLM\SOFTWARE\Classes\webcal\URL Protocol
Timestamp: 7/2/2004 8:17 PM
Size: 13 bytes
Description: Data mismatch between Windows API and raw hive data.
Path: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\
Timestamp: 10/26/2005 9:33 PM
Size: 0 bytes
Description: Key name contains embedded nulls (*)
Path: C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb
Timestamp: 11/2/2005 6:07 PM
Size: 64.00 KB
Description: Visible in Windows API, but not in MFT or directory index.
This is the first time I've scanned my system for rootkits and, after much searching on google and the sysinternal forum, I wasn't able to determine what these are or if I should do anything about them. I couldn't even locate the first two items in the regedit, assuming thats even where they are. Help would be appreciated.