CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Rootkit revealer log

 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
goal

Cadet
Cadet


Joined: Jul 23, 2006
Posts: 2
Location: USA

PostPosted: Sun Jul 23, 2006 12:26 pm    Post subject: Rootkit revealer log
Reply with quote

Hi new user.My computer has been running strangely passwords to emails have changed etc etc.
I was told to run rootkit revelaer here is the log below

HKLM\S-1-5-21-1698683601-2966927733-1597234714-1006\Software\Microsoft\MediaPlayer\Preferences\BackgroundScanCompleteDate 23/07/2006 13:02 40 bytes Data mismatch between Windows API and raw hive data.
HKLM\S-1-5-21-1698683601-2966927733-1597234714-1006\Software\Microsoft\Windows\ShellNoRoam\Bags\18\Shell\MinPos1024x768(1).x 23/07/2006 12:40 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\S-1-5-21-1698683601-2966927733-1597234714-1006\Software\Microsoft\Windows\ShellNoRoam\Bags\18\Shell\MinPos1024x768(1).y 23/07/2006 12:40 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\S-1-5-21-1698683601-2966927733-1597234714-1006\Software\Microsoft\Windows\ShellNoRoam\Bags\18\Shell\ScrollPos1024x768(1).y 23/07/2006 12:40 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System* 06/07/2006 19:08 0 bytes Key name contains embedded nulls (*)
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 12/06/2006 18:30 0 bytes Access is denied.


Is there a problem with this log? could some of your experts help

Spysweeper also found this but unable to delete.

19:23: Found System Monitor: potentially rootkit-masked files
19:23: $fspini$.dat (ID = 0)
19:23: flocker.usr (ID = 0)

I hope ive layed out the logs on this page ok!

Thanks all for help

Back to top
View users profile Send private message
AbuIbrahim

Security Expert
Special Response Team

Joined: Jan 18, 2006
Posts: 1930

1st Responder Mentors 1st Responders MVP Rootkit Experts Rootkit Responders Security Experts SRT

PostPosted: Sun Jul 23, 2006 1:10 pm    Post subject:
Reply with quote

The rootkit that you have belongs to Daemon tools. Please see:
http://www.sysinternals.com/blog/2006/02/using-rootkits-to-defeat-digital.html

Back to top
View users profile Send private message Visit posters website
goal

Cadet
Cadet


Joined: Jul 23, 2006
Posts: 2
Location: USA

PostPosted: Sun Jul 23, 2006 2:04 pm    Post subject:
Reply with quote

thanks man I have daemons tools on my pc for mounting images so nothing to worry about.


cheers

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer