pomalé nabíhání windows při startu
Napsal: 05 dub 2010 11:47
Zdravím je možné že je tam nějaký neřád,udělal jsem scan z rootkit reveleer a supery
HKU\.DEFAULT\Control Panel\International 8.6.2009 8:34 0 bytes Security mismatch.
HKU\.DEFAULT\Control Panel\International\Geo 8.6.2009 8:34 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Console 24.3.2010 16:13 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Control Panel\International 1.1.2010 1:01 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Control Panel\International\Geo 8.6.2009 8:34 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY* 31.8.2009 10:59 0 bytes Key name contains embedded nulls (*)
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\License information* 30.1.2010 18:31 0 bytes Key name contains embedded nulls (*)
HKU\S-1-5-18\Control Panel\International 8.6.2009 8:34 0 bytes Security mismatch.
HKU\S-1-5-18\Control Panel\International\Geo 8.6.2009 8:34 0 bytes Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC* 17.10.2008 23:28 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 17.10.2008 23:28 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\swearware\backup\winsock2 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018 20.7.2009 13:28 0 bytes Security mismatch.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \cache 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \logs 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \settings 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \temporary 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\cache 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\logs 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\settings 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\temporary 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKR7 5.4.2010 12:18 1.63 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRF 5.4.2010 12:27 20.82 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRG 5.4.2010 12:27 35 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRH 5.4.2010 12:27 43 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRI 5.4.2010 12:29 436 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRJ 5.4.2010 12:29 43 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRK 5.4.2010 12:29 1.11 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRL 5.4.2010 12:29 35 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRM 5.4.2010 12:29 29.39 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRN 5.4.2010 12:29 2.57 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRO 5.4.2010 12:29 632 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRP 5.4.2010 12:29 1.17 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRQ 5.4.2010 12:29 1.19 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRR 5.4.2010 12:29 1.12 KB Hidden from Windows API.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/05/2010 at 02:24 PM
Application Version : 4.34.1000
Core Rules Database Version : 4769
Trace Rules Database Version: 2581
Scan type : Complete Scan
Total Scan Time : 00:48:31
Memory items scanned : 616
Memory threats detected : 0
Registry items scanned : 5151
Registry threats detected : 6
File items scanned : 14310
File threats detected : 1
Trojan.Agent/Gen
HKLM\System\ControlSet001\Services\utexnjq5
C:\WINDOWS\SYSTEM32\DRIVERS\UTEXNJQ5.SYS
HKLM\System\ControlSet001\Enum\Root\LEGACY_utexnjq5
HKLM\System\ControlSet006\Services\utexnjq5
HKLM\System\ControlSet006\Enum\Root\LEGACY_utexnjq5
HKLM\System\CurrentControlSet\Services\utexnjq5
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_utexnjq5
HKU\.DEFAULT\Control Panel\International 8.6.2009 8:34 0 bytes Security mismatch.
HKU\.DEFAULT\Control Panel\International\Geo 8.6.2009 8:34 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Console 24.3.2010 16:13 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Control Panel\International 1.1.2010 1:01 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Control Panel\International\Geo 8.6.2009 8:34 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY* 31.8.2009 10:59 0 bytes Key name contains embedded nulls (*)
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\License information* 30.1.2010 18:31 0 bytes Key name contains embedded nulls (*)
HKU\S-1-5-18\Control Panel\International 8.6.2009 8:34 0 bytes Security mismatch.
HKU\S-1-5-18\Control Panel\International\Geo 8.6.2009 8:34 0 bytes Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC* 17.10.2008 23:28 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 17.10.2008 23:28 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\swearware\backup\winsock2 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017 20.7.2009 13:28 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018 20.7.2009 13:28 0 bytes Security mismatch.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \cache 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \logs 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \settings 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher \temporary 22.12.2008 19:24 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\cache 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\logs 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\settings 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Data aplikací\Sports Interactive\Installer Launcher\temporary 22.12.2008 20:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKR7 5.4.2010 12:18 1.63 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRF 5.4.2010 12:27 20.82 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRG 5.4.2010 12:27 35 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRH 5.4.2010 12:27 43 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRI 5.4.2010 12:29 436 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRJ 5.4.2010 12:29 43 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRK 5.4.2010 12:29 1.11 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRL 5.4.2010 12:29 35 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRM 5.4.2010 12:29 29.39 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRN 5.4.2010 12:29 2.57 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRO 5.4.2010 12:29 632 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRP 5.4.2010 12:29 1.17 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRQ 5.4.2010 12:29 1.19 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Program Files\cache\opr0IKRR 5.4.2010 12:29 1.12 KB Hidden from Windows API.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/05/2010 at 02:24 PM
Application Version : 4.34.1000
Core Rules Database Version : 4769
Trace Rules Database Version: 2581
Scan type : Complete Scan
Total Scan Time : 00:48:31
Memory items scanned : 616
Memory threats detected : 0
Registry items scanned : 5151
Registry threats detected : 6
File items scanned : 14310
File threats detected : 1
Trojan.Agent/Gen
HKLM\System\ControlSet001\Services\utexnjq5
C:\WINDOWS\SYSTEM32\DRIVERS\UTEXNJQ5.SYS
HKLM\System\ControlSet001\Enum\Root\LEGACY_utexnjq5
HKLM\System\ControlSet006\Services\utexnjq5
HKLM\System\ControlSet006\Enum\Root\LEGACY_utexnjq5
HKLM\System\CurrentControlSet\Services\utexnjq5
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_utexnjq5