Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Galates
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 08 lis 2011 21:29

Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#1 Příspěvek od Galates »

Dobrý den, nejprve bych se chtěl preventivně omluvit jestliže píšu do špatné sekce fóra, z vlastních zkušeností moderátora vím jak to vytáčí :) Žádám o pomoc proti kořenoidu.

Avast mi našel rootkit, který označil MBR: \\.\PHYSICALDRIVE0 na disku J, pod nímž je označení F (nevím přesně, co to znamená). Disk J by měla být virtuální mechanika Deamon tools pokud se nemýlím. PC reaguje normálně až na občasnou modrou smrt, kterou ale považuji za poměrně závažný problém. Rootkit nejde smazat.

log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by ADMIN at 2011-11-09 16:32:14
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 36 GB (15%) free of 233 GB
Total RAM: 1022 MB (29% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:32:20, on 9.11.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\ADMIN\Dokumenty\Stažené soubory\RSIT(1).exe
C:\Program Files\trend micro\ADMIN.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O1 - Hosts: 188.165.202.62 L2authd.lineage2.com
O1 - Hosts: 94.125.180.96 nprotect.lineage2.com
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-2000478354-1682526488-725345543-1009\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-2000478354-1682526488-725345543-1009\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'Default user')
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1965330750
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CC6887A6-1EF0-4668-9EAD-FF427347F0FC}: NameServer = 193.85.1.100,193.85.2.100,10.25.8.7,10.25.8.5
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: mdhcp32 - mdhcp32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

--
End of file - 7222 bytes

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\ADMIN\Data aplikací\Mozilla\Firefox\Profiles\a0llz3af.default

prefs.js - "browser.startup.homepage" - "http://www.igoogle.cz/"
prefs.js - "extensions.enabledItems" - "{3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13, {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, jqs@sun.com:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... id=afex&q="

"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX® Web Player
"Path"=C:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0]
"Description"=DivX® Content Upload Plugin
"Path"=C:\Program Files\DivX\DivX Content Uploader\npUpload.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
avg_igeared.xml
crawlersrch.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\ADMIN\Data aplikací\Mozilla\Firefox\Profiles\a0llz3af.default\searchplugins\
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 853672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{ED4BD629-C1B6-4399-8A34-02CCAA921DC9}
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-08-03 13892200]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-10-13 17351304]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2006-03-02 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2006-03-02 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TunngleService"=2
"MDM"=2
"idsvc"=3
"ICQ Service"=2
"eqckbdmwjwtfwvw"=2
"DAUpdaterSvc"=3
"AVG Security Toolbar Service"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mdhcp32]
mdhcp32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\Program Files\Rockstar Games\GTA2\gta2.exe"="C:\Program Files\Rockstar Games\GTA2\gta2.exe:*:Enabled:GTA2 main executable"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Warcraft III\War3.exe"="C:\Program Files\Warcraft III\War3.exe:*:Enabled:Warcraft III"
"C:\Program Files\World of Warcraft\WoW-2.0.3-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-2.0.3-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\WoW-2.0.3.6299-to-2.0.10.6448-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-2.0.3.6299-to-2.0.10.6448-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe"="C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Microsoft Games\Halo Trial\halo.exe"="C:\Program Files\Microsoft Games\Halo Trial\halo.exe:*:Enabled:Halo"
"C:\Program Files\Valve\Steam\SteamApps\titankiller222\condition zero\hl.exe"="C:\Program Files\Valve\Steam\SteamApps\titankiller222\condition zero\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD"="C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II"
"C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\age2_x1.icd"="C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\age2_x1.icd:*:Enabled:Age of Empires II Expansion"
"C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe"="C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion"
"C:\Program Files\Valve\Steam\SteamApps\titankiller222\counter-strike\hl.exe"="C:\Program Files\Valve\Steam\SteamApps\titankiller222\counter-strike\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe"="C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe:*:Enabled:Client"
"C:\Program Files\OpenTTD\openttd.exe"="C:\Program Files\OpenTTD\openttd.exe:*:Enabled:OpenTTD"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Cossacks - Napoleonic Wars\Data\engine.exe"="C:\Program Files\Cossacks - Napoleonic Wars\Data\engine.exe:*:Enabled:Cossacks 2: Napoleonic Wars"
"C:\Program Files\Starcraft\StarCraft.exe"="C:\Program Files\Starcraft\StarCraft.exe:*:Enabled:Starcraft"
"C:\Program Files\Microsoft Games\Age of Empires II\empires2.EXE"="C:\Program Files\Microsoft Games\Age of Empires II\empires2.EXE:*:Enabled:Age of Empires II"
"C:\Program Files\Valve\Steam\SteamApps\titankiller222\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Valve\Steam\SteamApps\titankiller222\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Valve\Steam\SteamApps\titankiller222\source sdk base\hl2.exe"="C:\Program Files\Valve\Steam\SteamApps\titankiller222\source sdk base\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Microsoft Games\Halo\halo.exe"="C:\Program Files\Microsoft Games\Halo\halo.exe:*:Enabled:Halo"
"C:\Program Files\DsNET Corp\aTube Catcher 1.0\smh.exe"="C:\Program Files\DsNET Corp\aTube Catcher 1.0\smh.exe:*:Enabled:Smart Media Hunter 0.7"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\War2Combat\Warcraft II BNE.exe"="C:\Program Files\War2Combat\Warcraft II BNE.exe:*:Enabled:Warcraft II Battle.net Edition"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Documents and Settings\ADMIN\Plocha\Šuplík\Halo 2\halo2.exe"="C:\Documents and Settings\ADMIN\Plocha\Šuplík\Halo 2\halo2.exe:*:Enabled:Halo 2 for Windows Vista"
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Microsoft Games\Age of Mythology\aom.exe"="C:\Program Files\Microsoft Games\Age of Mythology\aom.exe:*:Enabled:Age of Mythology"
"C:\Program Files\GMOD10\hl2.exe"="C:\Program Files\GMOD10\hl2.exe:*:Enabled:hl2"
"C:\Program Files\GOG.com\Freespace\FS.exe"="C:\Program Files\GOG.com\Freespace\FS.exe:*:Enabled:FreeSpace"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Activision\Rome - Total War\RomeTW.exe"="C:\Program Files\Activision\Rome - Total War\RomeTW.exe:*:Enabled:Rome: Total War"
"C:\Program Files\Mass Effect\Binaries\MassEffect.exe"="C:\Program Files\Mass Effect\Binaries\MassEffect.exe:*:Enabled:Mass Effect Game"
"C:\Program Files\Mass Effect\MassEffectLauncher.exe"="C:\Program Files\Mass Effect\MassEffectLauncher.exe:*:Enabled:Mass Effect Launcher"
"C:\rc\RAL.EXE"="C:\rc\RAL.EXE:*:Enabled:RAL"
"C:\Program Files\Reality Pump\The Moon Project\TheMoonProject.exe"="C:\Program Files\Reality Pump\The Moon Project\TheMoonProject.exe:*:Enabled:The Moon Project"
"K:\Quake3Arena\Quake III Arena\quake3.exe"="K:\Quake3Arena\Quake III Arena\quake3.exe:*:Enabled:quake3"
"C:\Program Files\Valve\Steam\SteamApps\titankiller222\zombie panic! source\hl2.exe"="C:\Program Files\Valve\Steam\SteamApps\titankiller222\zombie panic! source\hl2.exe:*:Enabled:Zombie Panic Source"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"C:\Program Files\GOG.com\Knights and Merchants TPR\KM_TPR.exe"="C:\Program Files\GOG.com\Knights and Merchants TPR\KM_TPR.exe:*:Enabled:KM_TPR"
"C:\Documents and Settings\ADMIN\Plocha\Šuplík\aoe 2\age2_x1.exe"="C:\Documents and Settings\ADMIN\Plocha\Šuplík\aoe 2\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\Program Files\Valve\Steam\SteamApps\common\alien swarm\swarm.exe"="C:\Program Files\Valve\Steam\SteamApps\common\alien swarm\swarm.exe:*:Enabled:Alien Swarm"
"C:\Program Files\Valve\Steam\SteamApps\common\alien swarm\srcds.exe"="C:\Program Files\Valve\Steam\SteamApps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server"
"C:\Program Files\Valve\Steam\Steam.exe"="C:\Program Files\Valve\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\THQ\Relic Entertainment\Company of Heroes Online\Game\RelicCoHOWW.exe"="C:\Program Files\THQ\Relic Entertainment\Company of Heroes Online\Game\RelicCoHOWW.exe:*:Enabled:Company of Heroes Online (THQ)"
"C:\Documents and Settings\ADMIN\Local Settings\Apps\2.0\YPO3Y721.AJB\YH3PME35.KBC\coho..tion_4fdd38d166a17713_0001.0001_2ea3ae6aea32b9ef\CoHOLauncher.exe"="C:\Documents and Settings\ADMIN\Local Settings\Apps\2.0\YPO3Y721.AJB\YH3PME35.KBC\coho..tion_4fdd38d166a17713_0001.0001_2ea3ae6aea32b9ef\CoHOLauncher.exe:*:Enabled:Company of Heroes Online (THQ)"
"C:\Documents and Settings\All Users\Dokumenty\IL-2 Sturmovik Forgotten Battles\il2fb.exe"="C:\Documents and Settings\All Users\Dokumenty\IL-2 Sturmovik Forgotten Battles\il2fb.exe:*:Enabled:il2fb"
"C:\Program Files\Reallusion\CrazyTalk for Skype\CT4Skype.exe"="C:\Program Files\Reallusion\CrazyTalk for Skype\CT4Skype.exe:*:Enabled:CrazyTalk"
"C:\Program Files\Valve\hlds.exe"="C:\Program Files\Valve\hlds.exe:*:Enabled:HLDS Launcher"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Valvenonsteam\Valve\hl.exe"="C:\Program Files\Valvenonsteam\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Games\World_of_Tanks\WorldOfTanks.exe"="C:\Games\World_of_Tanks\WorldOfTanks.exe:*:Enabled:World of Tanks"
"C:\Program Files\DsNET Corp\aTube Catcher 2.0\yct.exe"="C:\Program Files\DsNET Corp\aTube Catcher 2.0\yct.exe:*:Enabled:aTube Catcher to download and convert videos."
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Documents and Settings\ADMIN\Plocha\Empire Earth\Empire Earth.exe"="C:\Documents and Settings\ADMIN\Plocha\Empire Earth\Empire Earth.exe:*:Enabled:Empire Earth"
"C:\Program Files\Tunngle\tnglctrl.exe"="C:\Program Files\Tunngle\tnglctrl.exe:*:Enabled:Tunngle Service"
"C:\Program Files\Tunngle\tunngle.exe"="C:\Program Files\Tunngle\tunngle.exe:*:Enabled:Tunngle Client"
"C:\Program Files\Hasbro Interactive\RollerCoaster Tycoon\rct.exe"="C:\Program Files\Hasbro Interactive\RollerCoaster Tycoon\rct.exe:*:Enabled:rct"
"C:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe"="C:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe:*:Enabled:Speed"
"C:\Program Files\Team17\Worms World Party\wwp.exe"="C:\Program Files\Team17\Worms World Party\wwp.exe:*:Enabled:Worms World Party"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"C:\Documents and Settings\ADMIN\Local Settings\temp\nso10.tmp\BitComet_stats.exe"="C:\Documents and Settings\ADMIN\Local Settings\temp\nso10.tmp\BitComet_stats.exe:*:Disabled:stats Module"
"C:\Program Files\DAEMON Tools Lite\DTLite.exe"="C:\Program Files\DAEMON Tools Lite\DTLite.exe:*:Enabled:DAEMON Tools Lite"
"C:\Program Files\Microsoft Games\Halo\haloupdate.exe"="C:\Program Files\Microsoft Games\Halo\haloupdate.exe:*:Enabled:Halo Update"
"C:\Program Files\Microsoft Games\Halo\chktrust.exe"="C:\Program Files\Microsoft Games\Halo\chktrust.exe:*:Enabled:Microsoft Trust ChkTrust Utility"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Průzkumník Windows"
"C:\Documents and Settings\ADMIN\Local Settings\temp\_av_sfx.tm~a03796\avast.setup"="C:\Documents and Settings\ADMIN\Local Settings\temp\_av_sfx.tm~a03796\avast.setup:*:Enabled:avast! antivirus Update"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe:*:Enabled:avast! Antivirus"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.lhacm"=lhacm.acm
"VIDC.FPS1"=frapsvid.dll
"VIDC.FMVC"=fmcodec.dll

======List of files/folders created in the last 1 month======

2011-11-08 21:30:32 ----D---- C:\Program Files\trend micro

======List of files/folders modified in the last 1 month======

2011-11-09 16:27:20 ----D---- C:\WINDOWS\temp
2011-11-09 16:26:51 ----D---- C:\Documents and Settings\ADMIN\Data aplikací\Skype
2011-11-08 22:23:07 ----SHD---- C:\WINDOWS\Installer
2011-11-08 21:30:37 ----D---- C:\WINDOWS\Prefetch
2011-11-08 21:30:32 ----RD---- C:\Program Files
2011-11-08 21:14:15 ----D---- C:\Program Files\Warcraft III
2011-11-08 20:01:33 ----D---- C:\Program Files\Garena
2011-11-08 19:53:04 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-08 19:48:16 ----D---- C:\Program Files\OpenTTD
2011-11-08 00:24:32 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-06 12:32:23 ----D---- C:\WINDOWS\Minidump
2011-11-06 12:32:23 ----D---- C:\WINDOWS
2011-10-31 08:25:22 ----RSD---- C:\WINDOWS\assembly
2011-10-30 10:46:06 ----D---- C:\WINDOWS\system32
2011-10-30 10:46:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-21 07:01:03 ----RD---- C:\Program Files\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-04-30 691696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-09-06 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-03-02 39936]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-09-06 110552]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-01-13 4137984]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-08-03 12542592]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 a0vsqple;a0vsqple; C:\WINDOWS\system32\drivers\a0vsqple.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ADMIN\LOCALS~1\Temp\USP9.tmp []
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-07-07 17480]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-07-30 18048]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-07-30 23040]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-07-30 8192]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2004-08-03 25600]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-07-30 8192]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WsAudioDevice_383;WsAudioDevice_383; C:\WINDOWS\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2011-06-15 737016]

-----------------EOF-----------------

Díky za veškerou pomoc.
Galates

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#2 Příspěvek od chodnik74 »

Dobrý den :welcome:
Mrkneme na to ;-)



:arrow: Stáhněte SPTD
  • Vyberte si verzi svého operačního systému,jestli máte 32 bitů nebo 64 bitů
  • Stáhněte si program na plochu a spuste
  • Zvolte možnost Uninstall,poté restartujte PC (Kdyby nešlo na tlačítko Uninstall kliknou a bylo šedé,tak tento krok přeskočte
:arrow: Stáhněte Defogger
  • Stáhněte si program a uložte na plochu
  • Spuste program
  • Kliknete na tlačítko Disable,poté restartujte PC(Kdyby nešlo na tlačítko Disable kliknou a bylo šedé,tak tento krok přeskočte


:arrow: Stáhněte MBR
  • Přesuňte soubor mbr.exe na vaši Plochu
  • Stiskněte klávesovou kombinaci WIN+R( nebo start-spustit ),čímž se vám otevře okno pro zadání příkazu pro spuštění a zkopírujte a vložte sem následujíci text: %userprofile%\plocha\mbr" -t -s a dejte enter
  • Na Ploše se Vám vytvoří log s názvem mbr.txt a jeho obsah mi sem vložte

:arrow: Udělejte mi log z AswMBR
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Galates
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 08 lis 2011 21:29

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#3 Příspěvek od Galates »

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600

CreateFile("\\.\PHYSICALDRIVE0"): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!






aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-09 17:09:24
-----------------------------
17:09:24.125 OS Version: Windows 5.1.2600 Service Pack 2
17:09:24.125 Number of processors: 2 586 0x409
17:09:24.125 ComputerName: PP2 UserName:
17:09:24.671 Initialize success
17:09:24.781 AVAST engine defs: 11110300
17:09:37.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-7
17:09:37.109 Disk 0 Vendor: Size: 0MB BusType: 0
17:09:39.109 Disk 0 MBR read successfully
17:09:39.109 Disk 0 MBR scan
17:09:39.109 Disk 0 MBR:Whistler-C [Rtk]
17:09:39.125 Disk 0 Whistler@MBR code has been found
17:09:39.125 Disk 0 MBR hidden
17:09:39.125 Disk 0 MBR [Whistler] **ROOTKIT**
17:09:39.171 Disk 0 scanning C:\WINDOWS\system32\drivers
17:09:44.921 Service scanning
17:09:45.921 Modules scanning
17:09:51.546 Disk 0 trace - called modules:
17:09:51.546 ntkrnlpa.exe >>UNKNOWN [0x868c4a0a]<<
17:09:51.890 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87171ab8]
17:09:51.890 \Driver\Disk[0x871739e8] -> IRP_MJ_READ -> 0x868c4a0a
17:09:52.531 AVAST engine scan C:\WINDOWS
17:10:06.656 AVAST engine scan C:\WINDOWS\system32
17:11:36.281 AVAST engine scan C:\WINDOWS\system32\drivers
17:11:48.390 AVAST engine scan C:\Documents and Settings\ADMIN
17:31:46.531 AVAST engine scan C:\Documents and Settings\All Users
17:50:43.031 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\ADMIN\Plocha\MBR.dat"
17:50:43.031 The log file has been saved successfully to "C:\Documents and Settings\ADMIN\Plocha\aswMBR.txt"

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#4 Příspěvek od chodnik74 »

:arrow: Přesuňte MBR.exe na Vaši Plochu
  • Stiskněte klávesovou kombinaci WIN+R( nebo start-spustit ),čímž se vám otevře okno pro zadání příkazu pro spuštění a zkopírujte a vložte sem následujíci text: %userprofile%\plocha\mbr" -f a dejte enter
  • RESTARTUJTE PC...

:arrow: Stáhněte si TDSSKiller
  • Spuste program a klikněte na Start Scan
  • Pokud program najde infikekci,tak ji bude lecit (Cure), povolte léčení kliknutím na tlačítko Continue
  • Pokud program najde podezrely soubor (suspicious),bude ho chtít přeskočit (Skip), povolte přeskočení kliknutim na tlačítko Continue
  • Po dokončení skenování bude možná potřeba restartovat počítač,ten povolíte programu kliknutím na tlačítko Reboot now
  • Po restartování počítače na vás vyskočí log(pokud se tak nestane,tak ho najdete na disku,kde máte nainstalovaná systém s názvem TDSSKiller.xxxx_log.txt) a vložte mi sem jeho obsah
  • Pokud nebude program požadovat restartování počítače,klikněte na tlačítko Close a následně na Report , čímž se Vám vytvoří log a jeho obsah mu sem vložte
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Galates
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 08 lis 2011 21:29

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#5 Příspěvek od Galates »

18:47:05.0640 1232 TDSS rootkit removing tool 2.6.16.0 Nov 7 2011 16:26:51
18:47:05.0937 1232 ============================================================
18:47:05.0937 1232 Current date / time: 2011/11/09 18:47:05.0937
18:47:05.0937 1232 SystemInfo:
18:47:05.0937 1232
18:47:05.0937 1232 OS Version: 5.1.2600 ServicePack: 2.0
18:47:05.0937 1232 Product type: Workstation
18:47:05.0937 1232 ComputerName: PP2
18:47:05.0937 1232 UserName: ADMIN
18:47:05.0937 1232 Windows directory: C:\WINDOWS
18:47:05.0937 1232 System windows directory: C:\WINDOWS
18:47:05.0937 1232 Processor architecture: Intel x86
18:47:05.0937 1232 Number of processors: 2
18:47:05.0937 1232 Page size: 0x1000
18:47:05.0937 1232 Boot type: Normal boot
18:47:05.0937 1232 ============================================================
18:47:06.0718 1232 Initialize success
18:47:08.0359 1884 ============================================================
18:47:08.0359 1884 Scan started
18:47:08.0359 1884 Mode: Manual;
18:47:08.0359 1884 ============================================================
18:47:08.0984 1884 Aavmker4 (95d1de2a6613494e853a9738d5d9acd4) C:\WINDOWS\system32\drivers\Aavmker4.sys

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#6 Příspěvek od chodnik74 »

Ten log je kompletní? udělal jste vše bez problémů?
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Galates
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 08 lis 2011 21:29

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#7 Příspěvek od Galates »

Omlouvám se, špatně zkopírováno

18:47:05.0640 1232 TDSS rootkit removing tool 2.6.16.0 Nov 7 2011 16:26:51
18:47:05.0937 1232 ============================================================
18:47:05.0937 1232 Current date / time: 2011/11/09 18:47:05.0937
18:47:05.0937 1232 SystemInfo:
18:47:05.0937 1232
18:47:05.0937 1232 OS Version: 5.1.2600 ServicePack: 2.0
18:47:05.0937 1232 Product type: Workstation
18:47:05.0937 1232 ComputerName: PP2
18:47:05.0937 1232 UserName: ADMIN
18:47:05.0937 1232 Windows directory: C:\WINDOWS
18:47:05.0937 1232 System windows directory: C:\WINDOWS
18:47:05.0937 1232 Processor architecture: Intel x86
18:47:05.0937 1232 Number of processors: 2
18:47:05.0937 1232 Page size: 0x1000
18:47:05.0937 1232 Boot type: Normal boot
18:47:05.0937 1232 ============================================================
18:47:06.0718 1232 Initialize success
18:47:08.0359 1884 ============================================================
18:47:08.0359 1884 Scan started
18:47:08.0359 1884 Mode: Manual;
18:47:08.0359 1884 ============================================================
18:47:08.0984 1884 Aavmker4 (95d1de2a6613494e853a9738d5d9acd4) C:\WINDOWS\system32\drivers\Aavmker4.sys
18:47:08.0984 1884 Aavmker4 - ok
18:47:09.0015 1884 Abiosdsk - ok
18:47:09.0031 1884 abp480n5 - ok
18:47:09.0109 1884 ACPI (fa2fbcda96d2385f773b059fe5a125a6) C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:47:09.0109 1884 ACPI - ok
18:47:09.0187 1884 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
18:47:09.0187 1884 ACPIEC - ok
18:47:09.0203 1884 adpu160m - ok
18:47:09.0296 1884 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
18:47:09.0296 1884 aec - ok
18:47:09.0343 1884 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
18:47:09.0343 1884 AFD - ok
18:47:09.0359 1884 Aha154x - ok
18:47:09.0375 1884 aic78u2 - ok
18:47:09.0421 1884 aic78xx - ok
18:47:09.0468 1884 AliIde - ok
18:47:09.0515 1884 amsint - ok
18:47:09.0578 1884 asc - ok
18:47:09.0640 1884 asc3350p - ok
18:47:09.0687 1884 asc3550 - ok
18:47:09.0828 1884 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\WINDOWS\system32\drivers\aswFsBlk.sys
18:47:09.0828 1884 aswFsBlk - ok
18:47:09.0875 1884 aswMon2 (fff2dbb17a3c89f87f78d5fa72ca47fd) C:\WINDOWS\system32\drivers\aswMon2.sys
18:47:09.0875 1884 aswMon2 - ok
18:47:09.0921 1884 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\WINDOWS\system32\drivers\aswRdr.sys
18:47:09.0921 1884 aswRdr - ok
18:47:09.0968 1884 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\WINDOWS\system32\drivers\aswSnx.sys
18:47:09.0968 1884 aswSnx - ok
18:47:10.0015 1884 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\WINDOWS\system32\drivers\aswSP.sys
18:47:10.0015 1884 aswSP - ok
18:47:10.0046 1884 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\WINDOWS\system32\drivers\aswTdi.sys
18:47:10.0062 1884 aswTdi - ok
18:47:10.0109 1884 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:47:10.0109 1884 AsyncMac - ok
18:47:10.0156 1884 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
18:47:10.0156 1884 atapi - ok
18:47:10.0156 1884 Atdisk - ok
18:47:10.0203 1884 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:47:10.0203 1884 Atmarpc - ok
18:47:10.0218 1884 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
18:47:10.0234 1884 audstub - ok
18:47:10.0281 1884 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
18:47:10.0281 1884 Beep - ok
18:47:10.0296 1884 catchme - ok
18:47:10.0328 1884 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
18:47:10.0328 1884 cbidf2k - ok
18:47:10.0343 1884 cd20xrnt - ok
18:47:10.0390 1884 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
18:47:10.0390 1884 Cdaudio - ok
18:47:10.0406 1884 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
18:47:10.0406 1884 Cdfs - ok
18:47:10.0468 1884 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:47:10.0468 1884 Cdrom - ok
18:47:10.0515 1884 Changer - ok
18:47:10.0562 1884 CmdIde - ok
18:47:10.0593 1884 Cpqarray - ok
18:47:10.0625 1884 dac2w2k - ok
18:47:10.0640 1884 dac960nt - ok
18:47:10.0671 1884 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
18:47:10.0671 1884 Disk - ok
18:47:10.0734 1884 dmboot (e1968edec81c430108feb23ab07bdb14) C:\WINDOWS\system32\drivers\dmboot.sys
18:47:10.0750 1884 dmboot - ok
18:47:10.0828 1884 dmio (1b1520a82e396e46b9ae9fa6b03ff6c6) C:\WINDOWS\system32\drivers\dmio.sys
18:47:10.0828 1884 dmio - ok
18:47:10.0859 1884 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
18:47:10.0859 1884 dmload - ok
18:47:10.0921 1884 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
18:47:10.0921 1884 DMusic - ok
18:47:10.0953 1884 dpti2o - ok
18:47:11.0000 1884 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
18:47:11.0000 1884 drmkaud - ok
18:47:11.0078 1884 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
18:47:11.0078 1884 Fastfat - ok
18:47:11.0109 1884 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
18:47:11.0109 1884 Fdc - ok
18:47:11.0125 1884 Fips (266dab58619b17bdf37fabbd48d875ca) C:\WINDOWS\system32\drivers\Fips.sys
18:47:11.0125 1884 Fips - ok
18:47:11.0156 1884 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:47:11.0156 1884 Flpydisk - ok
18:47:11.0218 1884 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
18:47:11.0234 1884 FltMgr - ok
18:47:11.0250 1884 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:47:11.0250 1884 Fs_Rec - ok
18:47:11.0265 1884 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:47:11.0265 1884 Ftdisk - ok
18:47:11.0375 1884 GarenaPEngine (97590bdd20e90546045982f6ea24eb1e) C:\DOCUME~1\ADMIN\LOCALS~1\Temp\USP9.tmp
18:47:12.0921 1884 GarenaPEngine - ok
18:47:12.0984 1884 GGSAFERDriver - ok
18:47:13.0093 1884 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:47:13.0093 1884 Gpc - ok
18:47:13.0156 1884 hamachi (d30b31375c40309425c21efe75db90bb) C:\WINDOWS\system32\DRIVERS\hamachi.sys
18:47:13.0156 1884 hamachi - ok
18:47:13.0218 1884 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:47:13.0218 1884 HDAudBus - ok
18:47:13.0281 1884 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:47:13.0281 1884 HidUsb - ok
18:47:13.0312 1884 hpn - ok
18:47:13.0375 1884 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
18:47:13.0375 1884 HTTP - ok
18:47:13.0406 1884 i2omgmt - ok
18:47:13.0421 1884 i2omp - ok
18:47:13.0500 1884 i8042prt (0f42de9909b5dbf2c48dd1a79d491af5) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:47:13.0500 1884 i8042prt - ok
18:47:13.0562 1884 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
18:47:13.0562 1884 Imapi - ok
18:47:13.0609 1884 InCDFs - ok
18:47:13.0671 1884 InCDPass - ok
18:47:13.0687 1884 InCDRm - ok
18:47:13.0734 1884 ini910u - ok
18:47:14.0000 1884 IntcAzAudAddService (90e1b42e49d9e91e5accaaaaefa10ce8) C:\WINDOWS\system32\drivers\RtkHDAud.sys
18:47:14.0031 1884 IntcAzAudAddService - ok
18:47:14.0140 1884 IntelIde - ok
18:47:14.0203 1884 intelppm (10a3ac0f0df720ad3c3fd13861d50eb9) C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:47:14.0203 1884 intelppm - ok
18:47:14.0265 1884 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
18:47:14.0265 1884 Ip6Fw - ok
18:47:14.0343 1884 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:47:14.0343 1884 IpFilterDriver - ok
18:47:14.0375 1884 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:47:14.0375 1884 IpInIp - ok
18:47:14.0437 1884 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:47:14.0437 1884 IpNat - ok
18:47:14.0515 1884 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:47:14.0515 1884 IPSec - ok
18:47:14.0593 1884 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
18:47:14.0593 1884 IRENUM - ok
18:47:14.0625 1884 isapnp (1091528512e4dd7ed5fddcc4df1c53d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:47:14.0625 1884 isapnp - ok
18:47:14.0687 1884 Kbdclass (6f877bf8dc01a550cd666f3bedb2213c) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:47:14.0703 1884 Kbdclass - ok
18:47:14.0765 1884 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
18:47:14.0765 1884 kmixer - ok
18:47:14.0812 1884 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
18:47:14.0812 1884 KSecDD - ok
18:47:14.0875 1884 lbrtfdc - ok
18:47:14.0968 1884 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
18:47:14.0968 1884 mnmdd - ok
18:47:15.0015 1884 Modem (60210deb037846afe521ebf349964f6b) C:\WINDOWS\system32\drivers\Modem.sys
18:47:15.0015 1884 Modem - ok
18:47:15.0062 1884 Mouclass (b160ec94114715675509115986400fd9) C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:47:15.0078 1884 Mouclass - ok
18:47:15.0078 1884 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
18:47:15.0093 1884 MountMgr - ok
18:47:15.0093 1884 mraid35x - ok
18:47:15.0109 1884 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:47:15.0125 1884 MRxDAV - ok
18:47:15.0156 1884 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:47:15.0187 1884 MRxSmb - ok
18:47:15.0203 1884 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
18:47:15.0203 1884 Msfs - ok
18:47:15.0265 1884 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:47:15.0265 1884 MSKSSRV - ok
18:47:15.0281 1884 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:47:15.0281 1884 MSPCLOCK - ok
18:47:15.0296 1884 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
18:47:15.0296 1884 MSPQM - ok
18:47:15.0312 1884 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:47:15.0312 1884 mssmbios - ok
18:47:15.0328 1884 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
18:47:15.0328 1884 Mup - ok
18:47:15.0359 1884 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
18:47:15.0359 1884 NDIS - ok
18:47:15.0437 1884 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:47:15.0437 1884 NdisTapi - ok
18:47:15.0468 1884 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:47:15.0484 1884 Ndisuio - ok
18:47:15.0484 1884 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:47:15.0500 1884 NdisWan - ok
18:47:15.0500 1884 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
18:47:15.0515 1884 NDProxy - ok
18:47:15.0531 1884 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
18:47:15.0531 1884 NetBIOS - ok
18:47:15.0562 1884 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
18:47:15.0562 1884 NetBT - ok
18:47:15.0640 1884 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\WINDOWS\system32\drivers\ccdcmb.sys
18:47:15.0640 1884 nmwcd - ok
18:47:15.0703 1884 nmwcdc (2914ceb789964141ac6e22c6bc980c42) C:\WINDOWS\system32\drivers\ccdcmbo.sys
18:47:15.0703 1884 nmwcdc - ok
18:47:15.0718 1884 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
18:47:15.0734 1884 Npfs - ok
18:47:15.0812 1884 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys
18:47:15.0812 1884 Ntfs - ok
18:47:15.0859 1884 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
18:47:15.0859 1884 Null - ok
18:47:16.0250 1884 nv (6733e80a193fc36f41c24142b0c45c0e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
18:47:16.0546 1884 nv - ok
18:47:16.0640 1884 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:47:16.0640 1884 NwlnkFlt - ok
18:47:16.0671 1884 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:47:16.0671 1884 NwlnkFwd - ok
18:47:16.0750 1884 Parport (76a18caa2fefb28a4ced38d76837e86e) C:\WINDOWS\system32\DRIVERS\parport.sys
18:47:16.0750 1884 Parport - ok
18:47:16.0765 1884 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
18:47:16.0765 1884 PartMgr - ok
18:47:16.0796 1884 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
18:47:16.0796 1884 ParVdm - ok
18:47:16.0828 1884 PCI (b7979f37bb7b9df2230046134955e6e7) C:\WINDOWS\system32\DRIVERS\pci.sys
18:47:16.0828 1884 PCI - ok
18:47:16.0843 1884 PCIDump - ok
18:47:16.0890 1884 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
18:47:16.0890 1884 PCIIde - ok
18:47:16.0953 1884 Pcmcia (90505755634407d4ef4c6dea60fc1df9) C:\WINDOWS\system32\drivers\Pcmcia.sys
18:47:16.0953 1884 Pcmcia - ok
18:47:16.0984 1884 PDCOMP - ok
18:47:17.0031 1884 PDFRAME - ok
18:47:17.0062 1884 PDRELI - ok
18:47:17.0109 1884 PDRFRAME - ok
18:47:17.0140 1884 perc2 - ok
18:47:17.0187 1884 perc2hib - ok
18:47:17.0234 1884 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:47:17.0234 1884 PptpMiniport - ok
18:47:17.0250 1884 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
18:47:17.0250 1884 PSched - ok
18:47:17.0265 1884 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:47:17.0265 1884 Ptilink - ok
18:47:17.0281 1884 ql1080 - ok
18:47:17.0312 1884 Ql10wnt - ok
18:47:17.0328 1884 ql12160 - ok
18:47:17.0343 1884 ql1240 - ok
18:47:17.0390 1884 ql1280 - ok
18:47:17.0421 1884 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:47:17.0421 1884 RasAcd - ok
18:47:17.0500 1884 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:47:17.0500 1884 Rasl2tp - ok
18:47:17.0531 1884 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:47:17.0531 1884 RasPppoe - ok
18:47:17.0578 1884 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
18:47:17.0578 1884 Raspti - ok
18:47:17.0640 1884 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:47:17.0640 1884 Rdbss - ok
18:47:17.0671 1884 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:47:17.0671 1884 RDPCDD - ok
18:47:17.0750 1884 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
18:47:17.0750 1884 RDPWD - ok
18:47:17.0843 1884 redbook (aba13d33e1f888c9a68599a48a8840d6) C:\WINDOWS\system32\DRIVERS\redbook.sys
18:47:17.0843 1884 redbook - ok
18:47:17.0906 1884 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
18:47:17.0906 1884 rtl8139 - ok
18:47:18.0000 1884 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:47:18.0000 1884 Secdrv - ok
18:47:18.0062 1884 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
18:47:18.0062 1884 serenum - ok
18:47:18.0078 1884 Serial (c1ddbc85251551a840212999da3d95f3) C:\WINDOWS\system32\DRIVERS\serial.sys
18:47:18.0078 1884 Serial - ok
18:47:18.0140 1884 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
18:47:18.0140 1884 Sfloppy - ok
18:47:18.0156 1884 Simbad - ok
18:47:18.0187 1884 Sparrow - ok
18:47:18.0234 1884 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
18:47:18.0234 1884 splitter - ok
18:47:18.0265 1884 sptd - ok
18:47:18.0343 1884 sr (a74035ea526db97d9d50d2143a55f5cf) C:\WINDOWS\system32\DRIVERS\sr.sys
18:47:18.0343 1884 sr - ok
18:47:18.0390 1884 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
18:47:18.0406 1884 Srv - ok
18:47:18.0468 1884 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
18:47:18.0468 1884 swenum - ok
18:47:18.0546 1884 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
18:47:18.0546 1884 swmidi - ok
18:47:18.0578 1884 symc810 - ok
18:47:18.0625 1884 symc8xx - ok
18:47:18.0656 1884 sym_hi - ok
18:47:18.0703 1884 sym_u3 - ok
18:47:18.0750 1884 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
18:47:18.0750 1884 sysaudio - ok
18:47:18.0796 1884 tap0901t (b7aee68d2e867cbf69b649b18fcedbbb) C:\WINDOWS\system32\DRIVERS\tap0901t.sys
18:47:18.0796 1884 tap0901t - ok
18:47:18.0890 1884 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:47:18.0890 1884 Tcpip - ok
18:47:18.0937 1884 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
18:47:18.0953 1884 TDPIPE - ok
18:47:18.0984 1884 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
18:47:18.0984 1884 TDTCP - ok
18:47:19.0000 1884 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
18:47:19.0015 1884 TermDD - ok
18:47:19.0046 1884 TosIde - ok
18:47:19.0140 1884 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
18:47:19.0140 1884 Udfs - ok
18:47:19.0156 1884 ultra - ok
18:47:19.0250 1884 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys
18:47:19.0265 1884 Update - ok
18:47:19.0328 1884 upperdev (e526a166e6acafd0a9b3841d3941669e) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
18:47:19.0328 1884 upperdev - ok
18:47:19.0390 1884 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:47:19.0390 1884 usbehci - ok
18:47:19.0453 1884 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:47:19.0453 1884 usbhub - ok
18:47:19.0484 1884 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys
18:47:19.0484 1884 usbohci - ok
18:47:19.0546 1884 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:47:19.0562 1884 usbscan - ok
18:47:19.0593 1884 usbser (49106ee29074e6a3d3ac9e24c6d791d8) C:\WINDOWS\system32\drivers\usbser.sys
18:47:19.0593 1884 usbser - ok
18:47:19.0656 1884 UsbserFilt (6f3e3c6811b930d2414552a2e4a40f36) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
18:47:19.0656 1884 UsbserFilt - ok
18:47:19.0734 1884 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:47:19.0734 1884 USBSTOR - ok
18:47:19.0812 1884 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
18:47:19.0812 1884 VgaSave - ok
18:47:19.0843 1884 ViaIde - ok
18:47:19.0859 1884 VolSnap (cd8cce067f7e9cbd762c00bdddecaa34) C:\WINDOWS\system32\drivers\VolSnap.sys
18:47:19.0859 1884 VolSnap - ok
18:47:19.0953 1884 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:47:19.0953 1884 Wanarp - ok
18:47:20.0031 1884 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
18:47:20.0046 1884 Wdf01000 - ok
18:47:20.0078 1884 WDICA - ok
18:47:20.0156 1884 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
18:47:20.0156 1884 wdmaud - ok
18:47:20.0281 1884 WsAudioDevice_383 (85ece26f326c2d07ba77a60343468272) C:\WINDOWS\system32\drivers\WsAudioDevice_383.sys
18:47:20.0281 1884 WsAudioDevice_383 - ok
18:47:20.0343 1884 MBR (0x1B8) (9c603bc3977968c891de319283e1e7af) \Device\Harddisk0\DR0
18:47:20.0343 1884 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected
18:47:20.0343 1884 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a (0)
18:47:20.0343 1884 Boot (0x1200) (8fbd63c449d3108e9c235028b0245111) \Device\Harddisk0\DR0\Partition0
18:47:20.0343 1884 \Device\Harddisk0\DR0\Partition0 - ok
18:47:20.0390 1884 Boot (0x1200) (3503f5fbbda753949168206ce6aaab2b) \Device\Harddisk0\DR0\Partition1
18:47:20.0390 1884 \Device\Harddisk0\DR0\Partition1 - ok
18:47:20.0390 1884 ============================================================
18:47:20.0390 1884 Scan finished
18:47:20.0390 1884 ============================================================
18:47:20.0406 4060 Detected object count: 1
18:47:20.0406 4060 Actual detected object count: 1
18:47:27.0843 4060 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - will be cured on reboot
18:47:27.0843 4060 \Device\Harddisk0\DR0 - ok
18:47:27.0843 4060 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - User select action: Cure
18:47:35.0546 1040 Deinitialize success

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#8 Příspěvek od chodnik74 »

Výborně :) rootkit se zdal a odešel :) můžete preventivně udělat po restartování pc znovu log z TDSSKilleru :) Jak se chová PC?
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Galates
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 08 lis 2011 21:29

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#9 Příspěvek od Galates »

Lord TDSSKiller říká, že vše ok :) PC šlape normálně, pokud bude ještě modrá smrt tak napíšu.

Moc díky za pomoc, podpořím nějakou tou korunou toto skvělé fórum :)

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#10 Příspěvek od chodnik74 »

Ještě dočistíme od používaných programů:

:arrow: Obrázek OTC
  • Spustíme,zmáčkneme CleanUp a potvrdíme YES :) Program uklidí a následně restartuje
:arrow: ObrázekT-Cleaner
  • Spustíme,zmáčkneme klávesu A a potvrdíme ENTER(některé antiviry mohou detekovat utilitu jako vir-jedá se o falešný poplach,proto IGNOROVAT nebo dočasně vypnout antivir )
  • po použití T-Cleaner smažte ;-)
Zbytek smazat :)


Za podporu fora děkuju jméném celého týmu fora viry.cz :| Kdyby byli problémy, ozvěte se.. :)

P.S. Odinstalujte ICQ Toolbar a pokud chcete, vložte mi po odinstalování log z RSITu a uděláme údržbu pc :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Galates
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 08 lis 2011 21:29

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#11 Příspěvek od Galates »

Vše jsem udělal i se zbavil toolbaru.

Čištěním PC bych Vás nechtěl zdržovat, mám tam hodně bordelu který si odstraním sám a pak kdyžtak napíšu. Ale děkuju za nabídku :wink:

Hodně zdravu při lovu dalších kořínků,
Galates

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: Žádost o pomoc proti Rootkitu MBR: \\.\PHYSICALDRIVE0

#12 Příspěvek od chodnik74 »

Dobře, nezbývá se s vámi rozloučit a popřát hezký zbytek večera :bye: Příště jsme tu opět pro vás ;-)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Odpovědět