Prosím o kontrolu logu objevil se mi rootkit
Napsal: 23 bře 2010 11:31
HKU\S-1-5-21-1935655697-2025429265-1177238915-1004\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY* 29. 11. 2007 13:21 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAC* 12. 7. 2005 7:51 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 12. 7. 2005 7:51 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 23. 3. 2010 10:21 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 24. 6. 2009 10:07 0 bytes Access is denied.
C:\Documents and Settings\Horej 23. 3. 2010 10:50 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:07 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:04 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:34 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:37 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:55 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:31 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:01 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:42 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:10 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:58 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:12 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:52 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:45 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:15 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:28 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:00 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:11 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:47 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:05 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:02 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:57 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:26 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:30 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:51 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:14 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:54 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:44 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:36 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:40 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:08 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:33 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:43 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:56 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:47 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:35 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:59 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:38 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:02 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:16 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:13 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:53 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:05 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:10 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:50 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:32 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:29 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:07 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:00 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:31 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:12 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:09 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:57 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:33 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:27 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:36 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:06 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:45 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:41 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:15 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:49 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:52 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:03 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:55 42 bytes Hidden from Windows API.
C:\Program Files\GoQ - NetRadio\goq.tt 23. 3. 2010 11:16 42 bytes Hidden from Windows API.
C:\WINDOWS\Temp\6bef4d21-cb8f-4b0e-b57d-18e0aefc5b16.tmp 23. 3. 2010 11:16 0 bytes Hidden from Windows API.
C:\WINDOWS\Temp\88bcaa35-c3f6-479d-a0e6-96b0182db7ad.tmp 23. 3. 2010 10:26 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\Temp\978ef2db-1302-42ee-b5cd-6f39fcc2f5ba.tmp 23. 3. 2010 11:17 0 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\Temp\ee21c3db-85e1-43bd-8918-061c294888a3.tmp 23. 3. 2010 11:13 0 bytes Visible in Windows API, but not in MFT or directory index.
HKLM\SECURITY\Policy\Secrets\SAC* 12. 7. 2005 7:51 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 12. 7. 2005 7:51 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32* 16. 2. 2010 7:44 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 23. 3. 2010 10:21 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 24. 6. 2009 10:07 0 bytes Access is denied.
C:\Documents and Settings\Horej 23. 3. 2010 10:50 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:07 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:04 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:34 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:37 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:55 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:31 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:01 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:42 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:10 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:58 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:12 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:52 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:45 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:15 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:28 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:00 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:11 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:47 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:05 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:02 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:57 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:26 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:30 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:51 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:14 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:54 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:44 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:36 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:40 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:08 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:33 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:43 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:56 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:47 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:35 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:59 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:38 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:02 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:16 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:13 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:53 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:05 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:10 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:50 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:32 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:29 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:07 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:00 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:31 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:12 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:09 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:57 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:33 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:27 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:36 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:06 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:45 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:41 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:15 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:49 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:52 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 11:03 42 bytes Hidden from Windows API.
C:\Documents and Settings\Horej 23. 3. 2010 10:55 42 bytes Hidden from Windows API.
C:\Program Files\GoQ - NetRadio\goq.tt 23. 3. 2010 11:16 42 bytes Hidden from Windows API.
C:\WINDOWS\Temp\6bef4d21-cb8f-4b0e-b57d-18e0aefc5b16.tmp 23. 3. 2010 11:16 0 bytes Hidden from Windows API.
C:\WINDOWS\Temp\88bcaa35-c3f6-479d-a0e6-96b0182db7ad.tmp 23. 3. 2010 10:26 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\Temp\978ef2db-1302-42ee-b5cd-6f39fcc2f5ba.tmp 23. 3. 2010 11:17 0 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\Temp\ee21c3db-85e1-43bd-8918-061c294888a3.tmp 23. 3. 2010 11:13 0 bytes Visible in Windows API, but not in MFT or directory index.