Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#1 Příspěvek od chris.h »

Prosím o pomoc, vůbec si s tímto virem nevím rady. Našel mi ho NOD 32. Hlásí mi:

Operační paměť » services.exe(1600) - varianta infiltrace Win32/Rootkit.Agent.NUS trojský kůň - nelze léčit

Od té doby, co ho antivirový program našel mi vyskakují samá okna, kde musím všechno odblokovat a neustále mi přibývají v PC další viry, které sice program vyléčí, ale znovu se objevují další. A to jsem dříve na notebooku s viry problémy nemívala.
Děkuji za případnou pomoc :)

Zde uvádím log z RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by OEM at 2011-11-17 17:38:57
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 15 GB (10%) free of 148 GB
Total RAM: 1014 MB (34% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
C:\WINDOWS\tasks\PMTask.job
C:\WINDOWS\tasks\Připomenutí registrace 1.job
C:\WINDOWS\tasks\Připomenutí registrace 2.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\SmartDefrag_Startup.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\OEM\Data aplikací\Mozilla\Firefox\Profiles\6jts2rqn.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "extensions.enabledItems" - "{3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872, smartwebprinting@hp.com:4.5, {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, jqs@sun.com:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... ^YY^CZ&&q="

"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1]
"Description"=Yahoo! activeX Plug-in Bridge
"Path"=C:\Program Files\Yahoo!\Common\npyaxmpb.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll
npqtplugin.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml

C:\Documents and Settings\OEM\Data aplikací\Mozilla\Firefox\Profiles\6jts2rqn.default\extensions\
toolbar@ask.com

C:\Documents and Settings\OEM\Data aplikací\Mozilla\Firefox\Profiles\6jts2rqn.default\searchplugins\
askcom.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F}]
IObit Toolbar - C:\Program Files\IObit Toolbar\IE\4.7\iobitToolbarIE.dll [2011-09-27 1050464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
MHTBPos00 Class - C:\Program Files\Family Toolbar\tbcore3.dll [2009-05-07 2642432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-09-28 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-17 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-03-17 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-10-14 863688]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-09-28 520192]
{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - Family Toolbar - C:\Program Files\Family Toolbar\tbcore3.dll [2009-05-07 2642432]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]
{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - IObit Toolbar - C:\Program Files\IObit Toolbar\IE\4.7\iobitToolbarIE.dll [2011-09-27 1050464]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor []
"BLOG"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog []
"TPFNF7"=C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe [2007-04-09 58416]
"TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2007-03-09 66176]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-03-05 172032]
"TpShocks"=C:\WINDOWS\system32\TpShocks.exe [2007-03-29 181808]
"EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2007-03-28 243248]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-02-26 131072]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-02-26 155648]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-02-26 131072]
"TVT Scheduler Proxy"=C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2007-02-08 536576]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"ISUSPM Startup"=C:\Program Files\Common Files\Installshield\UpdateService\isuspm.exe [2005-08-11 249856]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-08-11 81920]
"AwaySch"=C:\Program Files\Lenovo\AwayTask\AwaySch.EXE [2006-11-07 91688]
"LPManager"=C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe [2007-03-22 120368]
"AMSG"=C:\Program Files\ThinkVantage\AMSG\Amsg.exe [2007-02-01 419376]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2011-08-23 887976]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-08 3076144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.894 []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-12-23 143360]
"Advanced SystemCare 4"=C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe [2011-08-09 417112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray]
C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe [2009-02-27 278016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2009-01-14 113680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ6.5\ICQ.exe silent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
C:\Program Files\PDF24\pdf24.exe [2011-04-28 220552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\Digital Imaging\bin\hpqtra08.exe [2009-05-21 275768]

C:\Documents and Settings\OEM\Nabídka Start\Programy\Po spuštění
AccuWeather.lnk - C:\Documents and Settings\OEM\Dokumenty\AccuWeather.com Stratus\AccuWeather.com Stratus.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-02-26 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\WINDOWS\system32\psqlpwd.dll [2007-03-14 89600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
C:\Program Files\Lenovo\HOTKEY\notifyf2.dll [2006-09-06 34344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
C:\Program Files\Lenovo\HOTKEY\tphklock.dll [2006-12-14 28672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Trackmania Sunrise Extreme\TmSunrise.exe"="D:\Trackmania Sunrise Extreme\TmSunrise.exe:*:Enabled:TmSunrise"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe"="C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\HPWUCli.exe"="C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\CulinatiX\SQL Anywhere 7\win32\rteng7.exe"="C:\Program Files\CulinatiX\SQL Anywhere 7\win32\rteng7.exe:*:Enabled:Adaptive Server Anywhere Database Engine"
"C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe"="C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe:*:Disabled:Adobe AIR Installer"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe"="C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe:*:Enabled:Advanced SystemCare 4"
"C:\Program Files\IObit\Advanced SystemCare 4\AutoUpdate.exe"="C:\Program Files\IObit\Advanced SystemCare 4\AutoUpdate.exe:*:Enabled:Advanced SystemCare Updater"
"C:\Documents and Settings\OEM\Dokumenty\AccuWeather.com Stratus\AccuWeather.com Stratus.exe"="C:\Documents and Settings\OEM\Dokumenty\AccuWeather.com Stratus\AccuWeather.com Stratus.exe:*:Enabled:AccuWeather.com Stratus"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Průzkumník Windows"
"C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"="C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe:*:Enabled:Search Settings"
"C:\WINDOWS\system32\msiexec.exe"="C:\WINDOWS\system32\msiexec.exe:*:Enabled:Windows® installer"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS54.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS54.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\All Users\Data aplikací\MFAData\SelfUpd\avgmfapx.exe"="C:\Documents and Settings\All Users\Data aplikací\MFAData\SelfUpd\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS8D.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS8D.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS1.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS1.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS2.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS2.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zSA.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zSA.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Dokumenty\Stažené soubory\RSIT.exe"="C:\Documents and Settings\OEM\Dokumenty\Stažené soubory\RSIT.exe:*:Enabled:RSIT"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe"="C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\HPWUCli.exe"="C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 3 months======

2011-11-17 17:38:58 ----D---- C:\Program Files\trend micro
2011-11-17 17:38:57 ----D---- C:\rsit
2011-11-17 15:59:01 ----D---- C:\Documents and Settings\OEM\Data aplikací\AVI ReComp
2011-11-17 15:58:41 ----D---- C:\Program Files\Gabest
2011-11-17 15:58:30 ----D---- C:\Program Files\Xvid
2011-11-17 15:57:49 ----D---- C:\Program Files\AviSynth 2.5
2011-11-17 15:54:44 ----D---- C:\Program Files\AVI ReComp
2011-11-17 12:48:20 ----D---- C:\Program Files\ESET
2011-11-17 12:48:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-11-17 10:09:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2011-11-08 09:54:37 ----D---- C:\Program Files\WAS
2011-10-30 19:14:12 ----D---- C:\Documents and Settings\OEM\Data aplikací\Search Settings
2011-10-30 19:13:53 ----D---- C:\Program Files\Application Updater
2011-10-30 19:13:52 ----D---- C:\Program Files\IObit Toolbar
2011-10-24 19:31:40 ----D---- C:\Documents and Settings\OEM\Data aplikací\Sonic
2011-10-24 19:31:15 ----D---- C:\Documents and Settings\OEM\Data aplikací\Leadertech
2011-09-21 17:28:17 ----D---- C:\Program Files\AoA Video Joiner
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomwave.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomtran.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomrmencoder.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomqtde.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscommpgenc.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscommpgdec.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomframe.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomflvenc.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomflvdec.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomflashenc.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomdata2.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomdata1.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomaudioencoder.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomaudiodata.dll
2011-09-21 14:23:59 ----A---- C:\WINDOWS\system32\videotrans.dll
2011-09-21 14:23:59 ----A---- C:\WINDOWS\system32\videoformat.dll
2011-09-21 14:23:59 ----A---- C:\WINDOWS\system32\videocore.dll
2011-09-21 14:23:57 ----A---- C:\WINDOWS\system32\imgscaler.dll
2011-09-21 14:23:57 ----A---- C:\WINDOWS\system32\img_utils.dll
2011-09-21 14:23:55 ----D---- C:\Program Files\Zealot Software
2011-09-21 14:23:55 ----A---- C:\WINDOWS\system32\xvid.dll
2011-09-21 14:23:55 ----A---- C:\WINDOWS\system32\divx.dll
2011-09-21 13:07:05 ----D---- C:\OutputFolder
2011-08-18 21:26:47 ----AD---- C:\Documents and Settings\OEM\Data aplikací\com.AccuWeather.air.stratus.6AF67E59E785A9A644FCA43BED05A7731922EF40.1

======List of files/folders modified in the last 3 months======

2011-11-17 17:38:58 ----AD---- C:\Program Files
2011-11-17 17:38:33 ----D---- C:\WINDOWS\Prefetch
2011-11-17 17:35:12 ----ASHD---- C:\WINDOWS\system32\dllcache
2011-11-17 17:35:07 ----AD---- C:\WINDOWS\system32
2011-11-17 16:07:52 ----AC---- C:\WINDOWS\NeroDigital.ini
2011-11-17 15:55:23 ----D---- C:\WINDOWS\Temp
2011-11-17 15:50:01 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-17 15:47:10 ----A---- C:\TPHKLOCK.TXT
2011-11-17 15:45:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-17 15:42:56 ----D---- C:\WINDOWS
2011-11-17 14:16:53 ----D---- C:\WINDOWS\system32\drivers
2011-11-17 12:49:34 ----SHD---- C:\WINDOWS\Installer
2011-11-17 12:49:30 ----HD---- C:\Config.Msi
2011-11-17 12:49:14 ----HD---- C:\WINDOWS\inf
2011-11-17 08:50:19 ----AD---- C:\Documents and Settings\OEM\Data aplikací\Media Player Classic
2011-11-17 07:42:18 ----A---- C:\WINDOWS\system32\PROCDB.INI
2011-11-17 07:41:37 ----A---- C:\WINDOWS\system32\IPSCtrl.INI
2011-11-17 07:03:02 ----A---- C:\WINDOWS\system32\bscs.ini
2011-11-17 07:02:52 ----A---- C:\WINDOWS\system32\LOCALSERVICE.INI
2011-11-17 07:02:49 ----A---- C:\WINDOWS\system32\LOCALDEVICE.INI
2011-11-16 19:59:35 ----AD---- C:\Program Files\Common Files\Lenovo
2011-11-13 06:32:42 ----D---- C:\SWSHARE
2011-11-11 23:09:20 ----AD---- C:\Program Files\Mozilla Firefox
2011-11-10 20:57:28 ----AC---- C:\WINDOWS\wincmd.ini
2011-11-10 20:53:02 ----AC---- C:\WINDOWS\wcx_ftp.ini
2011-10-30 19:13:55 ----D---- C:\WINDOWS\WinSxS
2011-10-30 19:13:52 ----D---- C:\Program Files\Common Files\Spigot
2011-10-30 10:53:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-26 07:03:09 ----A---- C:\WINDOWS\system32\REMOTEDEVICE.INI
2011-10-11 08:26:29 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-10 16:31:29 ----D---- C:\Program Files\Electronic Arts
2011-10-01 13:22:43 ----A---- C:\WINDOWS\MyHeritage.INI
2011-09-14 12:01:21 ----D---- C:\Program Files\Ask.com
2011-09-14 12:01:19 ----SD---- C:\WINDOWS\Tasks
2011-09-07 13:20:55 ----D---- C:\WINDOWS\system32\config
2011-08-28 08:29:16 ----RASH---- C:\boot.ini
2011-08-28 08:29:16 ----AC---- C:\WINDOWS\win.ini
2011-08-28 08:29:16 ----AC---- C:\WINDOWS\system.ini
2011-08-23 21:04:21 ----AD---- C:\Documents and Settings\OEM\Data aplikací\HPAppData
2011-08-23 18:33:47 ----A---- C:\WINDOWS\system32\SHORTCUT.INI
2011-08-22 11:54:41 ----D---- C:\Program Files\dm
2011-08-18 20:44:15 ----AD---- C:\Documents and Settings\OEM\Data aplikací\IObit

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BtHidBus;Bluetooth HID Bus Service; C:\WINDOWS\System32\Drivers\BtHidBus.sys [2009-01-07 20744]
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\DRIVERS\iaStor.sys [2007-02-12 277784]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-11-20 36624]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 Shockprf;Shockprf; C:\WINDOWS\System32\DRIVERS\Apsx86.sys [2007-03-02 100656]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-10-14 717296]
R0 TPDIGIMN;TPDIGIMN; C:\WINDOWS\System32\DRIVERS\ApsHM86.sys [2007-03-02 19760]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2011-08-04 103112]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-27 39936]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys [2006-10-23 17778]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwrif.sys [2007-04-12 4442]
R1 TSMAPIP;TSMAPIP; C:\WINDOWS\System32\drivers\TSMAPIP.SYS [2007-04-09 12848]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.6.0.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2007-11-20 21425]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 pmem;pmem; \??\C:\WINDOWS\System32\drivers\pmemnt.sys []
R2 PROCDD;IPS Helper Driver; C:\WINDOWS\system32\DRIVERS\PROCDD.SYS [2006-11-06 12080]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2006-11-15 32256]
R2 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2006-11-15 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2006-11-15 37376]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-02-21 12416]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys []
R2 tvtfilter;tvtfilter; C:\WINDOWS\system32\DRIVERS\tvtfilter.sys [2007-11-20 33536]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2007-03-04 146432]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-18 60800]
R3 atmeltpm;atmeltpm; C:\WINDOWS\system32\DRIVERS\atmeltpm.sys [2005-05-17 15872]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2006-03-09 152064]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2009-01-03 39304]
R3 btnetBUs;Bluetooth PAN Bus Service; C:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDAudN.sys [2007-04-27 666112]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-03-25 988032]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-03-25 210688]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-02-26 5700096]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2007-02-27 21040]
R3 IvtBtBUs;IVT Bluetooth Bus Service; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
R3 NETw4x32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-03-28 2204672]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-12-08 61824]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\WINDOWS\system32\DRIVERS\psadd.sys [2006-09-13 28224]
R3 TcUsb;TC USB Kernel Driver; C:\WINDOWS\System32\Drivers\tcusb.sys [2007-03-14 40848]
R3 TVTI2C;Lenovo SM bus driver; C:\WINDOWS\system32\DRIVERS\Tvti2c.sys [2006-09-13 35264]
R3 TVTPktFilter;TVT Packet Filter Service; C:\WINDOWS\system32\DRIVERS\tvtpktfilter.sys [2007-02-08 17664]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-10-23 20608]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2009-01-08 31880]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-03-25 731136]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-18 14848]
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys []
S3 ar56yf9i;ar56yf9i; C:\WINDOWS\system32\drivers\ar56yf9i.sys []
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2008-12-07 14088]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-03 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-10-24 117760]
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2008-10-28 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2008-10-28 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2008-10-28 21568]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2008-01-21 14856]
S4 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Filtr Compaq sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;Filtr ALI sběrnice AGP; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;Ovladač filtru AMD portu AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-09-08 962560]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
S2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe []
S2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe []
S2 BlueSoleilCS;BlueSoleilCS; C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe []
S2 BsMobileCS;BsMobileCS; C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe []
S2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe []
S2 IBMPMSVC;ThinkPad PM Service; C:\WINDOWS\system32\ibmpmsvc.exe []
S2 IPSSVC;IPS Core Service; C:\WINDOWS\system32\IPSSVC.EXE []
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf []
S2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe []
S2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe []
S2 SUService;System Update; c:\program files\lenovo\system update\suservice.exe []
S2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe []
S2 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\WINDOWS\System32\TPHDEXLG.exe []
S2 TVT Backup Protection Service;TVT Backup Protection Service; C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe []
S2 TVT Backup Service;TVT Backup Service; C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe []
S2 TVT Scheduler;TVT Scheduler; c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe []
S2 tvtnetwk;tvtnetwk; C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 BsHelpCS;BsHelpCS; C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe [2009-02-27 98407]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 HCYDLAH;HCYDLAH; C:\DOCUME~1\OEM\LOCALS~1\Temp\HCYDLAH.exe [2011-11-17 524288]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMConnectCDS;Služba Windows Media Connect; C:\Program Files\Windows Media Connect 2\wmccds.exe [2005-10-06 855552]
S4 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#2 Příspěvek od Rudy »

Stáhněte a spusťte TDSSKiller: http://support.kaspersky.com/downloads/ ... killer.zip . Ponechte pracovat a po skončení dejte log.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#3 Příspěvek od chris.h »

Nevím, jestli jsem zkopírovala správný log, ale snad jo...

18:30:16.0015 2480 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
18:30:16.0796 2480 ============================================================
18:30:16.0796 2480 Current date / time: 2011/11/17 18:30:16.0796
18:30:16.0796 2480 SystemInfo:
18:30:16.0796 2480
18:30:16.0796 2480 OS Version: 5.1.2600 ServicePack: 2.0
18:30:16.0796 2480 Product type: Workstation
18:30:16.0796 2480 ComputerName: LENOVO-551F1D3E
18:30:16.0796 2480 UserName: OEM
18:30:16.0796 2480 Windows directory: C:\WINDOWS
18:30:16.0796 2480 System windows directory: C:\WINDOWS
18:30:16.0796 2480 Processor architecture: Intel x86
18:30:16.0796 2480 Number of processors: 2
18:30:16.0796 2480 Page size: 0x1000
18:30:16.0796 2480 Boot type: Normal boot
18:30:16.0796 2480 ============================================================
18:30:24.0828 2480 Initialize success
18:30:40.0796 3288 ============================================================
18:30:40.0796 3288 Scan started
18:30:40.0796 3288 Mode: Manual;
18:30:40.0796 3288 ============================================================
18:30:45.0046 3288 Abiosdsk - ok
18:30:45.0125 3288 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
18:30:45.0140 3288 abp480n5 - ok
18:30:45.0156 3288 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys
18:30:45.0218 3288 ac97intc - ok
18:30:45.0250 3288 ACPI (fa2fbcda96d2385f773b059fe5a125a6) C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:30:45.0296 3288 ACPI - ok
18:30:45.0312 3288 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
18:30:45.0343 3288 ACPIEC - ok
18:30:45.0343 3288 Ad-Watch Connect Filter - ok
18:30:45.0375 3288 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
18:30:45.0375 3288 adpu160m - ok
18:30:45.0406 3288 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys
18:30:45.0406 3288 aec - ok
18:30:45.0453 3288 AegisP (375eb0b97e3950adef3633c27a82438b) C:\WINDOWS\system32\DRIVERS\AegisP.sys
18:30:45.0500 3288 AegisP - ok
18:30:45.0562 3288 AFD (04b0575e52a55f04f4fb84f4ae8fa752) C:\WINDOWS\System32\drivers\afd.sys
18:30:45.0562 3288 AFD - ok
18:30:45.0718 3288 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
18:30:45.0765 3288 agp440 - ok
18:30:45.0812 3288 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
18:30:45.0843 3288 agpCPQ - ok
18:30:45.0859 3288 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
18:30:45.0875 3288 Aha154x - ok
18:30:45.0890 3288 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
18:30:45.0921 3288 aic78u2 - ok
18:30:45.0937 3288 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
18:30:45.0953 3288 aic78xx - ok
18:30:45.0968 3288 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
18:30:46.0000 3288 AliIde - ok
18:30:46.0015 3288 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys
18:30:46.0046 3288 alim1541 - ok
18:30:46.0062 3288 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys
18:30:46.0078 3288 amdagp - ok
18:30:46.0109 3288 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
18:30:46.0125 3288 amsint - ok
18:30:46.0156 3288 ApfiltrService (348055c4afff8e60c01aa6bdc8c58ca7) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
18:30:46.0156 3288 ApfiltrService - ok
18:30:46.0187 3288 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
18:30:46.0234 3288 Arp1394 - ok
18:30:46.0250 3288 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
18:30:46.0296 3288 asc - ok
18:30:46.0312 3288 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
18:30:46.0328 3288 asc3350p - ok
18:30:46.0359 3288 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
18:30:46.0390 3288 asc3550 - ok
18:30:46.0421 3288 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:30:46.0453 3288 AsyncMac - ok
18:30:46.0484 3288 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
18:30:46.0515 3288 atapi - ok
18:30:46.0531 3288 Atdisk - ok
18:30:46.0562 3288 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:30:46.0578 3288 Atmarpc - ok
18:30:46.0656 3288 atmeltpm (dbf0d7e2df33b469eb55406fea759350) C:\WINDOWS\system32\DRIVERS\atmeltpm.sys
18:30:46.0656 3288 atmeltpm - ok
18:30:46.0750 3288 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
18:30:46.0781 3288 audstub - ok
18:30:46.0828 3288 b57w2k (bb1a2a73f993b623f99e03ed2f9e014c) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
18:30:46.0890 3288 b57w2k - ok
18:30:46.0890 3288 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
18:30:46.0921 3288 Beep - ok
18:30:46.0984 3288 BT (8e2d9ece59dfe7d310201e0d65d97ecb) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
18:30:47.0015 3288 BT - ok
18:30:47.0046 3288 Btcsrusb (942c602296119d758547808221c85a2c) C:\WINDOWS\system32\Drivers\btcusb.sys
18:30:47.0046 3288 Btcsrusb - ok
18:30:47.0093 3288 BthEnum (d24b8d1784c68a25060fffbe8ed34b76) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
18:30:47.0125 3288 BthEnum - ok
18:30:47.0265 3288 BtHidBus (ce441ccd98c5ecb10cb12fcaf97322ec) C:\WINDOWS\system32\Drivers\BtHidBus.sys
18:30:47.0265 3288 BtHidBus - ok
18:30:47.0281 3288 BthPan (10355270be12641b9764235da39dcf0f) C:\WINDOWS\system32\DRIVERS\bthpan.sys
18:30:47.0328 3288 BthPan - ok
18:30:47.0390 3288 BTHPORT (28d8eb74c2f2480518c59807a59cd1e2) C:\WINDOWS\system32\Drivers\BTHport.sys
18:30:47.0406 3288 BTHPORT - ok
18:30:47.0437 3288 BTHUSB (f06d4cb9918b462a84d9ac00027efc30) C:\WINDOWS\system32\Drivers\BTHUSB.sys
18:30:47.0468 3288 BTHUSB - ok
18:30:47.0515 3288 btnetBUs (d3c277a51ef9e2ec972d6221f99c0b6d) C:\WINDOWS\system32\Drivers\btnetBus.sys
18:30:47.0531 3288 btnetBUs - ok
18:30:47.0625 3288 BTNetFilter (4f26303becbb7cc5ca8ff39593124cf2) C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys
18:30:47.0625 3288 BTNetFilter - ok
18:30:47.0625 3288 BTWUSB - ok
18:30:47.0656 3288 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
18:30:47.0687 3288 cbidf - ok
18:30:47.0828 3288 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
18:30:47.0828 3288 cbidf2k - ok
18:30:47.0828 3288 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
18:30:47.0859 3288 cd20xrnt - ok
18:30:47.0890 3288 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
18:30:47.0906 3288 Cdaudio - ok
18:30:47.0937 3288 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
18:30:47.0953 3288 Cdfs - ok
18:30:47.0984 3288 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:30:48.0031 3288 Cdrom - ok
18:30:48.0046 3288 Changer - ok
18:30:48.0078 3288 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
18:30:48.0109 3288 CmBatt - ok
18:30:48.0140 3288 CmdIde (964d0f042aca51d5644779eb9d9ee40f) C:\WINDOWS\system32\DRIVERS\cmdide.sys
18:30:48.0171 3288 CmdIde - ok
18:30:48.0187 3288 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
18:30:48.0218 3288 Compbatt - ok
18:30:48.0234 3288 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
18:30:48.0265 3288 Cpqarray - ok
18:30:48.0296 3288 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
18:30:48.0343 3288 dac2w2k - ok
18:30:48.0359 3288 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
18:30:48.0390 3288 dac960nt - ok
18:30:48.0515 3288 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
18:30:48.0546 3288 Disk - ok
18:30:48.0593 3288 dmboot (e1968edec81c430108feb23ab07bdb14) C:\WINDOWS\system32\drivers\dmboot.sys
18:30:48.0656 3288 dmboot - ok
18:30:48.0687 3288 dmio (1b1520a82e396e46b9ae9fa6b03ff6c6) C:\WINDOWS\system32\drivers\dmio.sys
18:30:48.0718 3288 dmio - ok
18:30:48.0734 3288 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
18:30:48.0750 3288 dmload - ok
18:30:48.0781 3288 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
18:30:48.0796 3288 DMusic - ok
18:30:48.0828 3288 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
18:30:48.0843 3288 dpti2o - ok
18:30:48.0890 3288 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
18:30:48.0937 3288 drmkaud - ok
18:30:49.0046 3288 dtscsi - ok
18:30:49.0078 3288 E100B (866b8ee30e4504c11ae0d29ed6f8824b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
18:30:49.0156 3288 E100B - ok
18:30:49.0218 3288 eamon (9309c5c9831203436e64cf2ae605c5d7) C:\WINDOWS\system32\DRIVERS\eamon.sys
18:30:49.0218 3288 eamon - ok
18:30:49.0250 3288 ehdrv (deff87f04ab5f6dd5edf2b80853bbe10) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
18:30:49.0250 3288 ehdrv - ok
18:30:49.0281 3288 epfwtdir (06c65ac0a703cf8eea4f284d901a1550) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
18:30:49.0281 3288 epfwtdir - ok
18:30:49.0359 3288 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
18:30:49.0390 3288 Fastfat - ok
18:30:49.0531 3288 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
18:30:49.0562 3288 Fdc - ok
18:30:49.0671 3288 Fips (266dab58619b17bdf37fabbd48d875ca) C:\WINDOWS\system32\drivers\Fips.sys
18:30:49.0671 3288 Fips - ok
18:30:49.0687 3288 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:30:49.0718 3288 Flpydisk - ok
18:30:49.0734 3288 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
18:30:49.0843 3288 FltMgr - ok
18:30:49.0890 3288 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:30:49.0906 3288 Fs_Rec - ok
18:30:49.0968 3288 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:30:50.0000 3288 Ftdisk - ok
18:30:50.0125 3288 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:30:50.0187 3288 Gpc - ok
18:30:50.0250 3288 HdAudAddService (8dc8b34992131eb4b4c71b1a47fdd21c) C:\WINDOWS\system32\drivers\CHDAudN.sys
18:30:50.0265 3288 HdAudAddService - ok
18:30:50.0296 3288 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:30:50.0328 3288 HDAudBus - ok
18:30:50.0375 3288 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:30:50.0421 3288 hidusb - ok
18:30:50.0593 3288 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
18:30:50.0625 3288 hpn - ok
18:30:50.0671 3288 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
18:30:50.0687 3288 HPZid412 - ok
18:30:50.0703 3288 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
18:30:50.0734 3288 HPZipr12 - ok
18:30:50.0765 3288 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
18:30:50.0796 3288 HPZius12 - ok
18:30:50.0843 3288 HSFHWAZL (26d99cb5d30f79e4459d855af690decd) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
18:30:50.0843 3288 HSFHWAZL - ok
18:30:50.0906 3288 HSF_DPV (491b8f394e56ff31d6740f7a34540716) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
18:30:50.0953 3288 HSF_DPV - ok
18:30:51.0140 3288 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys
18:30:51.0140 3288 HTTP - ok
18:30:51.0171 3288 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys
18:30:51.0203 3288 i2omgmt - ok
18:30:51.0234 3288 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys
18:30:51.0250 3288 i2omp - ok
18:30:51.0296 3288 i8042prt (0f42de9909b5dbf2c48dd1a79d491af5) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:30:51.0328 3288 i8042prt - ok
18:30:51.0531 3288 ialm (c1c2d6940d6ec2f247b0f3c11e0a18e0) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
18:30:51.0687 3288 ialm - ok
18:30:51.0750 3288 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\WINDOWS\system32\DRIVERS\iaStor.sys
18:30:51.0750 3288 iaStor - ok
18:30:51.0890 3288 IBMPMDRV (326edb99d2b509f6c48bf723c1817292) C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
18:30:51.0890 3288 IBMPMDRV - ok
18:30:51.0921 3288 Imapi (12c59b8929121ace2f55acc86682cf12) C:\WINDOWS\system32\DRIVERS\imapi.sys
18:30:51.0953 3288 Imapi - ok
18:30:52.0031 3288 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
18:30:52.0062 3288 ini910u - ok
18:30:52.0062 3288 IntelIde (ef4fda4841001a4b98c411797db8894a) C:\WINDOWS\system32\DRIVERS\intelide.sys
18:30:52.0093 3288 IntelIde - ok
18:30:52.0125 3288 intelppm (d72a67a4ab80f7f74dc5dbbc36db12c9) C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:30:52.0156 3288 intelppm - ok
18:30:52.0171 3288 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
18:30:52.0203 3288 Ip6Fw - ok
18:30:52.0218 3288 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:30:52.0265 3288 IpFilterDriver - ok
18:30:52.0281 3288 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:30:52.0296 3288 IpInIp - ok
18:30:52.0328 3288 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:30:52.0328 3288 IpNat - ok
18:30:52.0343 3288 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:30:52.0375 3288 IPSec - ok
18:30:52.0421 3288 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
18:30:52.0453 3288 IRENUM - ok
18:30:52.0484 3288 isapnp (1091528512e4dd7ed5fddcc4df1c53d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:30:52.0515 3288 isapnp - ok
18:30:52.0640 3288 IvtBtBUs (71e1fc547cc488d5cd7bf0860c96f5af) C:\WINDOWS\system32\Drivers\IvtBtBus.sys
18:30:52.0671 3288 IvtBtBUs - ok
18:30:52.0718 3288 Kbdclass (6f877bf8dc01a550cd666f3bedb2213c) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:30:52.0750 3288 Kbdclass - ok
18:30:52.0765 3288 kbdhid (065b5a83aa78c0c7047bf22e0ab5c821) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:30:52.0796 3288 kbdhid - ok
18:30:52.0843 3288 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
18:30:52.0843 3288 kmixer - ok
18:30:52.0875 3288 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys
18:30:52.0875 3288 KSecDD - ok
18:30:52.0890 3288 lbrtfdc - ok
18:30:52.0937 3288 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
18:30:52.0937 3288 mdmxsdk - ok
18:30:53.0062 3288 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
18:30:53.0093 3288 mnmdd - ok
18:30:53.0140 3288 Modem (60210deb037846afe521ebf349964f6b) C:\WINDOWS\system32\drivers\Modem.sys
18:30:53.0171 3288 Modem - ok
18:30:53.0203 3288 Mouclass (b160ec94114715675509115986400fd9) C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:30:53.0234 3288 Mouclass - ok
18:30:53.0265 3288 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:30:53.0281 3288 mouhid - ok
18:30:53.0328 3288 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
18:30:53.0359 3288 MountMgr - ok
18:30:53.0375 3288 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
18:30:53.0406 3288 mraid35x - ok
18:30:53.0437 3288 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:30:53.0437 3288 MRxDAV - ok
18:30:53.0500 3288 MRxSmb (6f2d483b97b395544e59749c47963c6a) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:30:53.0515 3288 MRxSmb - ok
18:30:53.0640 3288 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
18:30:53.0671 3288 Msfs - ok
18:30:53.0718 3288 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:30:53.0734 3288 MSKSSRV - ok
18:30:53.0750 3288 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:30:53.0781 3288 MSPCLOCK - ok
18:30:53.0781 3288 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
18:30:53.0812 3288 MSPQM - ok
18:30:53.0843 3288 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:30:53.0859 3288 mssmbios - ok
18:30:53.0906 3288 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
18:30:53.0937 3288 Mup - ok
18:30:53.0984 3288 NDIS (bc84c4f67d0e880b0c46dc0ce2b8cbaa) C:\WINDOWS\system32\drivers\NDIS.sys
18:30:53.0984 3288 NDIS - ok
18:30:54.0015 3288 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:30:54.0015 3288 NdisTapi - ok
18:30:54.0062 3288 Ndisuio (8d3ce6b579cde8d37acc690b67dc2106) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:30:54.0093 3288 Ndisuio - ok
18:30:54.0109 3288 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:30:54.0140 3288 NdisWan - ok
18:30:54.0171 3288 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
18:30:54.0203 3288 NDProxy - ok
18:30:54.0328 3288 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
18:30:54.0343 3288 NetBIOS - ok
18:30:54.0359 3288 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
18:30:54.0421 3288 NetBT - ok
18:30:54.0546 3288 NETw4x32 (9b18806954cb7f33b538cbf090562db2) C:\WINDOWS\system32\DRIVERS\NETw4x32.sys
18:30:54.0609 3288 NETw4x32 - ok
18:30:54.0671 3288 NIC1394 (e1532ad506e0e874d1e6b4581c4f64ae) C:\WINDOWS\system32\DRIVERS\nic1394.sys
18:30:54.0671 3288 NIC1394 - ok
18:30:54.0734 3288 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
18:30:54.0750 3288 Npfs - ok
18:30:54.0781 3288 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys
18:30:54.0796 3288 Ntfs - ok
18:30:54.0812 3288 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
18:30:54.0843 3288 Null - ok
18:30:54.0921 3288 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
18:30:54.0984 3288 nv - ok
18:30:55.0140 3288 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:30:55.0171 3288 NwlnkFlt - ok
18:30:55.0187 3288 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:30:55.0218 3288 NwlnkFwd - ok
18:30:55.0265 3288 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
18:30:55.0296 3288 ohci1394 - ok
18:30:55.0343 3288 Parport (76a18caa2fefb28a4ced38d76837e86e) C:\WINDOWS\system32\DRIVERS\parport.sys
18:30:55.0375 3288 Parport - ok
18:30:55.0406 3288 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
18:30:55.0437 3288 PartMgr - ok
18:30:55.0437 3288 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
18:30:55.0468 3288 ParVdm - ok
18:30:55.0484 3288 PCI (b7979f37bb7b9df2230046134955e6e7) C:\WINDOWS\system32\DRIVERS\pci.sys
18:30:55.0515 3288 PCI - ok
18:30:55.0656 3288 PCIDump - ok
18:30:55.0671 3288 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
18:30:55.0703 3288 PCIIde - ok
18:30:55.0718 3288 Pcmcia (90505755634407d4ef4c6dea60fc1df9) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
18:30:56.0468 3288 Pcmcia - ok
18:30:56.0609 3288 PDCOMP - ok
18:30:56.0625 3288 PDFRAME - ok
18:30:56.0625 3288 PDRELI - ok
18:30:56.0640 3288 PDRFRAME - ok
18:30:56.0687 3288 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
18:30:56.0718 3288 perc2 - ok
18:30:56.0734 3288 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
18:30:56.0765 3288 perc2hib - ok
18:30:56.0828 3288 pmem (dedef40e1d05842639491365cb2c069e) C:\WINDOWS\System32\drivers\pmemnt.sys
18:30:56.0906 3288 pmem - ok
18:30:56.0953 3288 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:30:56.0984 3288 PptpMiniport - ok
18:30:57.0031 3288 PROCDD (1d80309fed4babf8ea9e7b84a394348b) C:\WINDOWS\system32\DRIVERS\PROCDD.SYS
18:30:57.0046 3288 PROCDD - ok
18:30:57.0109 3288 Processor (b6c55157fac7858b6a500fb206dda8dc) C:\WINDOWS\system32\DRIVERS\processr.sys
18:30:57.0140 3288 Processor - ok
18:30:57.0281 3288 psadd (ce5114c9d3ab67e6f6f8017c5f975292) C:\WINDOWS\system32\DRIVERS\psadd.sys
18:30:57.0281 3288 psadd - ok
18:30:57.0312 3288 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
18:30:57.0375 3288 PSched - ok
18:30:57.0375 3288 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:30:57.0406 3288 Ptilink - ok
18:30:57.0453 3288 PxHelp20 (1962166e0ceb740704f30fa55ad3d509) C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:30:57.0453 3288 PxHelp20 - ok
18:30:57.0484 3288 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
18:30:57.0531 3288 ql1080 - ok
18:30:57.0546 3288 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
18:30:57.0578 3288 Ql10wnt - ok
18:30:57.0578 3288 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
18:30:57.0609 3288 ql12160 - ok
18:30:57.0625 3288 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
18:30:57.0671 3288 ql1240 - ok
18:30:57.0687 3288 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
18:30:57.0703 3288 ql1280 - ok
18:30:57.0734 3288 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:30:57.0765 3288 RasAcd - ok
18:30:57.0781 3288 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:30:57.0828 3288 Rasl2tp - ok
18:30:57.0828 3288 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:30:57.0859 3288 RasPppoe - ok
18:30:57.0875 3288 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
18:30:57.0906 3288 Raspti - ok
18:30:57.0937 3288 Rdbss (809ca45caa9072b3176ad44579d7f688) C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:30:57.0937 3288 Rdbss - ok
18:30:57.0953 3288 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:30:57.0984 3288 RDPCDD - ok
18:30:58.0156 3288 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:30:58.0250 3288 rdpdr - ok
18:30:58.0281 3288 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
18:30:58.0281 3288 RDPWD - ok
18:30:58.0312 3288 redbook (aba13d33e1f888c9a68599a48a8840d6) C:\WINDOWS\system32\DRIVERS\redbook.sys
18:30:58.0343 3288 redbook - ok
18:30:58.0406 3288 RFCOMM (99c4b74981a1413f142a3903130088cb) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
18:30:58.0437 3288 RFCOMM - ok
18:30:58.0484 3288 rimmptsk (d85e3fa9f5b1f29bb4ed185c450d1470) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
18:30:58.0515 3288 rimmptsk - ok
18:30:58.0531 3288 rimsptsk (db8eb01c58c9fada00c70b1775278ae0) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
18:30:58.0562 3288 rimsptsk - ok
18:30:58.0718 3288 risdptsk (ace2ce73d7b04eac48fb80482e05e770) C:\WINDOWS\system32\DRIVERS\risdptsk.sys
18:30:58.0734 3288 risdptsk - ok
18:30:58.0765 3288 rismxdp (6c1f93c0760c9f79a1869d07233df39d) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
18:30:58.0812 3288 rismxdp - ok
18:30:58.0859 3288 s24trans (e2c6abcbefb1d44f6aaeb1cd5d6062d4) C:\WINDOWS\system32\DRIVERS\s24trans.sys
18:30:58.0859 3288 s24trans - ok
18:30:58.0906 3288 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:30:58.0906 3288 Secdrv - ok
18:30:58.0937 3288 Ser2pl (6ce397c482bede91a38e56a8c4a0dc6d) C:\WINDOWS\system32\DRIVERS\ser2pl.sys
18:30:58.0968 3288 Ser2pl - ok
18:30:58.0968 3288 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
18:30:59.0000 3288 serenum - ok
18:30:59.0031 3288 Serial (c1ddbc85251551a840212999da3d95f3) C:\WINDOWS\system32\DRIVERS\serial.sys
18:30:59.0062 3288 Serial - ok
18:30:59.0078 3288 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
18:30:59.0109 3288 sfdrv01 - ok
18:30:59.0140 3288 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
18:30:59.0171 3288 sfhlp02 - ok
18:30:59.0328 3288 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
18:30:59.0375 3288 Sfloppy - ok
18:30:59.0406 3288 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\WINDOWS\system32\drivers\sfvfs02.sys
18:30:59.0437 3288 sfvfs02 - ok
18:30:59.0468 3288 Shockprf (6873edc0d75e1e255208442ea3e018c1) C:\WINDOWS\system32\DRIVERS\Apsx86.sys
18:30:59.0546 3288 Shockprf - ok
18:30:59.0546 3288 Simbad - ok
18:30:59.0578 3288 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys
18:30:59.0609 3288 sisagp - ok
18:30:59.0671 3288 smihlp (350483c5a139f8a39ed3191aff39bed0) C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys
18:30:59.0671 3288 smihlp - ok
18:30:59.0687 3288 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
18:30:59.0718 3288 Sparrow - ok
18:30:59.0765 3288 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
18:30:59.0765 3288 splitter - ok
18:30:59.0968 3288 sptd (71e276f6d189413266ea22171806597b) C:\WINDOWS\system32\Drivers\sptd.sys
18:30:59.0968 3288 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
18:30:59.0968 3288 sptd ( LockedFile.Multi.Generic ) - warning
18:30:59.0968 3288 sptd - detected LockedFile.Multi.Generic (1)
18:31:00.0000 3288 sr (a74035ea526db97d9d50d2143a55f5cf) C:\WINDOWS\system32\DRIVERS\sr.sys
18:31:00.0031 3288 sr - ok
18:31:00.0078 3288 Srv (e03b4ea274c9e509cca7f9f0cec24232) C:\WINDOWS\system32\DRIVERS\srv.sys
18:31:00.0125 3288 Srv - ok
18:31:00.0171 3288 StillCam (06cda2a5a549bc455d004461e6bc5b33) C:\WINDOWS\system32\DRIVERS\serscan.sys
18:31:00.0203 3288 StillCam - ok
18:31:00.0359 3288 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
18:31:00.0390 3288 swenum - ok
18:31:00.0421 3288 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
18:31:00.0453 3288 swmidi - ok
18:31:00.0484 3288 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
18:31:00.0515 3288 symc810 - ok
18:31:00.0531 3288 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
18:31:00.0562 3288 symc8xx - ok
18:31:00.0562 3288 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
18:31:00.0593 3288 sym_hi - ok
18:31:00.0609 3288 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
18:31:00.0640 3288 sym_u3 - ok
18:31:00.0656 3288 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
18:31:00.0671 3288 sysaudio - ok
18:31:00.0734 3288 Tcpip (744e57c99232201ae98c49168b918f48) C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:31:00.0750 3288 Tcpip - ok
18:31:00.0781 3288 TcUsb (109d1f5cd9cc370a87901db3ddd533f1) C:\WINDOWS\system32\Drivers\tcusb.sys
18:31:00.0781 3288 TcUsb - ok
18:31:00.0937 3288 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
18:31:00.0984 3288 TDPIPE - ok
18:31:01.0015 3288 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
18:31:01.0046 3288 TDTCP - ok
18:31:01.0140 3288 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
18:31:01.0171 3288 TermDD - ok
18:31:01.0187 3288 TosIde (fd4fd7d6fda5c019ed86025d7be1510f) C:\WINDOWS\system32\DRIVERS\toside.sys
18:31:01.0218 3288 TosIde - ok
18:31:01.0250 3288 TPDIGIMN (9c72fdd0fa2d3be3bd5cca211fb19916) C:\WINDOWS\system32\DRIVERS\ApsHM86.sys
18:31:01.0281 3288 TPDIGIMN - ok
18:31:01.0328 3288 TPHKDRV (542770c8925e13b29b1ba63f05898058) C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys
18:31:01.0328 3288 TPHKDRV - ok
18:31:01.0375 3288 TPPWRIF (44672de6cea9569c21c4b7a8d2560750) C:\WINDOWS\system32\drivers\Tppwrif.sys
18:31:01.0390 3288 TPPWRIF - ok
18:31:01.0546 3288 TSMAPIP (ea856d91b3c088ce331e7740c72f43a3) C:\WINDOWS\system32\drivers\TSMAPIP.SYS
18:31:01.0562 3288 TSMAPIP - ok
18:31:01.0593 3288 tvtfilter (49258a02a1e8d304ed88b0f1c56b1738) C:\WINDOWS\system32\DRIVERS\tvtfilter.sys
18:31:01.0656 3288 tvtfilter - ok
18:31:01.0671 3288 TVTI2C (c254bff0a928ea7d5ccdc2522d56fd01) C:\WINDOWS\system32\DRIVERS\Tvti2c.sys
18:31:01.0703 3288 TVTI2C - ok
18:31:01.0750 3288 TVTPktFilter (0727cce3ff1a4446f4a1d507361567ab) C:\WINDOWS\system32\DRIVERS\tvtpktfilter.sys
18:31:01.0750 3288 TVTPktFilter - ok
18:31:01.0796 3288 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
18:31:01.0828 3288 Udfs - ok
18:31:01.0859 3288 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
18:31:01.0906 3288 ultra - ok
18:31:01.0953 3288 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
18:31:02.0000 3288 Update - ok
18:31:02.0203 3288 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:31:02.0250 3288 usbccgp - ok
18:31:02.0265 3288 usbehci (a45ea1550ea4b368c4fba7ca9d056bc9) C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:31:02.0296 3288 usbehci - ok
18:31:02.0343 3288 usbhub (6d46b1f89134892a862ac56b00ac11fe) C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:31:02.0375 3288 usbhub - ok
18:31:02.0421 3288 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
18:31:02.0453 3288 usbprint - ok
18:31:02.0640 3288 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:31:02.0671 3288 usbscan - ok
18:31:02.0765 3288 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:31:02.0796 3288 USBSTOR - ok
18:31:02.0968 3288 usbuhci (0ee1925590ba1abec14254d54d9870f4) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:31:03.0000 3288 usbuhci - ok
18:31:03.0109 3288 VComm (0955553090e0a88614e5b8a02af9324c) C:\WINDOWS\system32\DRIVERS\VComm.sys
18:31:03.0140 3288 VComm - ok
18:31:03.0296 3288 VcommMgr (ea0d7c68dc77b478f1c08022b8afe8ca) C:\WINDOWS\system32\Drivers\VcommMgr.sys
18:31:03.0296 3288 VcommMgr - ok
18:31:03.0453 3288 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
18:31:03.0484 3288 VgaSave - ok
18:31:03.0593 3288 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys
18:31:03.0640 3288 viaagp - ok
18:31:03.0687 3288 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
18:31:03.0718 3288 ViaIde - ok
18:31:03.0765 3288 VolSnap (cd8cce067f7e9cbd762c00bdddecaa34) C:\WINDOWS\system32\drivers\VolSnap.sys
18:31:03.0812 3288 VolSnap - ok
18:31:03.0984 3288 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:31:04.0015 3288 Wanarp - ok
18:31:04.0140 3288 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
18:31:04.0187 3288 Wdf01000 - ok
18:31:04.0234 3288 WDICA - ok
18:31:04.0421 3288 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
18:31:04.0421 3288 wdmaud - ok
18:31:04.0687 3288 winachsf (458b2e703b210683194158d639770588) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
18:31:04.0765 3288 winachsf - ok
18:31:04.0859 3288 MBR (0x1B8) (507e7d82a79f999ec2451e50872feca3) \Device\Harddisk0\DR0
18:31:04.0875 3288 \Device\Harddisk0\DR0 - ok
18:31:04.0875 3288 Boot (0x1200) (84c34d5c5fcb8782a43088a7eb373592) \Device\Harddisk0\DR0\Partition0
18:31:04.0875 3288 \Device\Harddisk0\DR0\Partition0 - ok
18:31:04.0875 3288 ============================================================
18:31:04.0875 3288 Scan finished
18:31:04.0875 3288 ============================================================
18:31:04.0890 2808 Detected object count: 1
18:31:04.0890 2808 Actual detected object count: 1
18:31:37.0750 2808 sptd ( LockedFile.Multi.Generic ) - skipped by user
18:31:37.0750 2808 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#4 Příspěvek od Rudy »

Našlo to jen sptd.sys, což je ovladač od DaemonTools. Ještě poprosím o oba logy z GMER: http://www.viry.cz/forum/viewtopic.php?f=29&t=62878 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#5 Příspěvek od chris.h »

GMER1:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-11-17 19:43:56
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0084
Running: gmer.exe; Driver: C:\DOCUME~1\OEM\LOCALS~1\Temp\uftcqpob.sys


---- System - GMER 1.0.15 ----

SSDT spsr.sys ZwEnumerateKey [0xF73DBCA2]
SSDT spsr.sys ZwEnumerateValueKey [0xF73DC030]

---- Devices - GMER 1.0.15 ----

Device \Driver\iaStor \Device\Ide\iaStor0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 86F611F8
Device \Driver\atapi \Device\Ide\IdePort0 86F611F8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1 862BD1F8
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1Port2Path0Target0Lun0 862BD1F8
Device \FileSystem\Ntfs \Ntfs 86FD21F8

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)

Device \FileSystem\Fastfat \Fat 847E21F8

AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

---- Threads - GMER 1.0.15 ----

Thread System [4:1352] 9DA013E0
Thread System [4:1356] 9DA013E0
Thread System [4:1360] 84831330
Thread System [4:1364] 84831330

---- EOF - GMER 1.0.15 ----

GMER2:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-17 20:29:03
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0084
Running: gmer.exe; Driver: C:\DOCUME~1\OEM\LOCALS~1\Temp\uftcqpob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xA39CC4B0]
SSDT spsr.sys ZwCreateKey [0xF73BD0E0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwCreateThread [0xA39CC7F0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xA39CCAB0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xA39CC5D0]
SSDT spsr.sys ZwEnumerateKey [0xF73DBCA2]
SSDT spsr.sys ZwEnumerateValueKey [0xF73DC030]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwLoadDriver [0xA39CC8B0]
SSDT spsr.sys ZwOpenKey [0xF73BD0C0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xA39CC350]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xA39CC410]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xA39CC570]
SSDT spsr.sys ZwQueryKey [0xF73DC108]
SSDT spsr.sys ZwQueryValueKey [0xF73DBF88]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwQueueApcThread [0xA39CC630]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xA39CC530]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xA39CC4F0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xA39CC670]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSystemInformation [0xA39CC870]
SSDT spsr.sys ZwSetValueKey [0xF73DC19A]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xA39CC3B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xA39CC430]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSystemDebugControl [0xA39CC830]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateProcess [0xA39CC370]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xA39CC470]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xA39CC5F0]

INT 0x62 ? 86F61BF8
INT 0x63 ? 863BDBF8
INT 0x73 ? 863BDBF8
INT 0x74 ? 863BDBF8
INT 0x83 ? 863BDBF8
INT 0x84 ? 863BDBF8
INT 0x94 ? 863BDBF8
INT 0xA4 ? 86FD3BF8
INT 0xA4 ? 863BDBF8

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwCallbackReturn + 2FB0 8050481C 12 Bytes [B0, C3, 9C, A3, 30, C4, 9C, ...]
? spsr.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload F54FC80C 5 Bytes JMP 863BD1D8
.text ar56yf9i.SYS F4E8D386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text ar56yf9i.SYS F4E8D3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ar56yf9i.SYS F4E8D3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text ar56yf9i.SYS F4E8D3C9 1 Byte [2E]
.text ar56yf9i.SYS F4E8D3C9 11 Bytes [2E, 00, 00, 00, 5A, 02, 00, ...]
.text ...
.text afd.sys 9CFE8300 1031 Bytes [08, 04, 00, 00, 00, FC, 01, ...]
.text afd.sys 9CFE8708 2575 Bytes [9C, 0F, 85, 69, 0B, 00, 00, ...]
.text afd.sys 9CFE9118 484 Bytes [93, FE, 9C, 8B, 43, 10, 8D, ...]
.text afd.sys 9CFE92FD 632 Bytes [95, FE, 9C, 90, 90, 90, 90, ...]
.text afd.sys 9CFE9576 38 Bytes [5C, 80, 28, B3, 5B, 80, 22, ...]
.text ...
.PAGE1 C:\WINDOWS\System32\drivers\afd.sys unknown last section [0x9CFF5F00, 0x100, 0xC0000040]
? C:\WINDOWS\System32\drivers\afd.sys suspicious PE modification

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1072] kernel32.dll!SetUnhandledExceptionFilter 7C84479D 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 00475550 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!DeviceIoControl 7C801625 7 Bytes JMP 00475890 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00475600 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00475770 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!IsDebuggerPresent 7C813093 6 Bytes JMP 00414F50 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] USER32.dll!ChangeDisplaySettingsExA 7E37A2DA 5 Bytes JMP 0047A650 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] USER32.dll!ChangeDisplaySettingsExW 7E3A950D 5 Bytes JMP 0047A680 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 00419860 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCloseKey 77DC6BF0 5 Bytes JMP 00419590 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueExW 77DC6FC8 5 Bytes JMP 00419980 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 00419650 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 00419830 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 00419810 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueExA 77DC7883 5 Bytes JMP 00419950 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumKeyExW 77DC79A1 5 Bytes JMP 00419760 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumValueW 77DC8081 5 Bytes JMP 004197C0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueExW 77DCD7CC 7 Bytes JMP 00419A40 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueW 77DCD8E2 5 Bytes JMP 00419920 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 00419630 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueExA 77DCEBE7 7 Bytes JMP 00419A10 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteValueA 77DCEDE5 5 Bytes JMP 004196D0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteValueW 77DCEEF1 5 Bytes JMP 00419700 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueA 77DD6F49 5 Bytes JMP 004199B0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegFlushKey 77DDB908 5 Bytes JMP 004195C0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumValueA 77DDCF4A 5 Bytes JMP 00419790 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 00419610 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteKeyW 77DE9884 5 Bytes JMP 004196A0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteKeyA 77DEC123 5 Bytes JMP 00419670 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryInfoKeyA 77DEC1B5 5 Bytes JMP 00419890 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 004197F0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumKeyExA 77DEC8C1 5 Bytes JMP 00419730 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueA 77DECC10 5 Bytes JMP 004198F0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryInfoKeyW 77DECCEF 5 Bytes JMP 004198C0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 004195F0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueW 77E25FC2 5 Bytes JMP 004199E0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ole32.dll!CoCreateInstance 774EFAC3 5 Bytes JMP 00419CB0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2824] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 012A2EC0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!SetWindowLongA 7E36D5F5 5 Bytes JMP 106AC350 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!SetWindowLongW 7E36D613 5 Bytes JMP 106AC2E2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!GetWindowInfo 7E36DE7C 5 Bytes JMP 1045E363 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!TrackPopupMenu 7E3B526E 5 Bytes JMP 1045E91C C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73BE040] spsr.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73BE13C] spsr.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73BE0BE] spsr.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73BE7FC] spsr.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73BE6D2] spsr.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73CE048] spsr.sys
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfReleaseSpinLock] 3BD44D8B
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfLowerIrql] FEA0180D
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfRaiseIrql] 8B6C769C
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KeGetCurrentIrql] 47C6B07D
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfAcquireSpinLock] 006A012F

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 86FD21F8

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)

Device \FileSystem\Fastfat \FatCdrom 847E21F8
Device \Driver\usbuhci \Device\USBPDO-0 863BC1F8
Device \Driver\usbuhci \Device\USBPDO-1 863BC1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86FD41F8
Device \Driver\dmio \Device\DmControl\DmConfig 86FD41F8
Device \Driver\dmio \Device\DmControl\DmPnP 86FD41F8
Device \Driver\dmio \Device\DmControl\DmInfo 86FD41F8
Device \Driver\usbehci \Device\USBPDO-2 864521F8
Device \Driver\usbuhci \Device\USBPDO-3 863BC1F8
Device \Driver\usbehci \Device\USBPDO-4 864521F8

AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

Device \Driver\usbuhci \Device\USBPDO-5 863BC1F8
Device \Driver\usbuhci \Device\USBPDO-6 863BC1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F621F8
Device \Driver\sptd \Device\2970688920 spsr.sys
Device \Driver\Cdrom \Device\CdRom0 862F31F8
Device \Driver\USBSTOR \Device\000000b0 8475E500
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F621F8
Device \Driver\iaStor \Device\Ide\iaStor0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 86F611F8
Device \Driver\atapi \Device\Ide\IdePort0 86F611F8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 862F31F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 849F5500
Device \Driver\NetBT \Device\NetbiosSmb 849F5500
Device \Driver\PCI_PNP0170 \Device\0000005d spsr.sys
Device \Driver\PCI_PNP0170 \Device\0000005d spsr.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{40A18DDA-0AC0-4179-AE59-846FB99DEC0B} 849F5500
Device \Driver\usbuhci \Device\USBFDO-0 863BC1F8
Device \Driver\usbuhci \Device\USBFDO-1 863BC1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{D02AAEDC-F72D-48B2-9C14-EF72D848CF68} 849F5500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8634F2E8
Device \Driver\usbehci \Device\USBFDO-2 864521F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8634F2E8
Device \Driver\usbuhci \Device\USBFDO-3 863BC1F8
Device \Driver\USBSTOR \Device\000000af 8475E500
Device \Driver\usbuhci \Device\USBFDO-4 863BC1F8
Device \Driver\Ftdisk \Device\FtControl 86F621F8
Device \Driver\usbuhci \Device\USBFDO-5 863BC1F8
Device \Driver\usbehci \Device\USBFDO-6 864521F8
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1 862BD1F8
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1Port2Path0Target0Lun0 862BD1F8
Device \FileSystem\Fastfat \Fat 847E21F8

AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)

Device \FileSystem\Cdfs \Cdfs 84AE9368

---- Modules - GMER 1.0.15 ----

Module (noname) (*** hidden *** ) 9E0D9000-9E0E7000 (57344 bytes)
Module (noname) (*** hidden *** ) 9D9FD000-9DA06000 (36864 bytes)


---- Threads - GMER 1.0.15 ----

Thread System [4:1352] 9DA013E0
Thread System [4:1356] 9DA013E0
Thread System [4:1360] 84831330
Thread System [4:1364] 84831330

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\001c26eceaed (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x35 0x94 0x33 0xDC ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x89 0x04 0x48 0x3A ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0x34 0xC1 0x31 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x74 0xDC 0x09 0x25 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0x13 0xF0 0x6D ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x7A 0xF0 0x0C 0x6A ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3F 0x2D 0x8D 0x53 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x00 0x06 0x71 0x37 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x30 0x71 0x7C 0x14 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001c26eceaed (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x35 0x94 0x33 0xDC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x89 0x04 0x48 0x3A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0x34 0xC1 0x31 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x74 0xDC 0x09 0x25 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0x13 0xF0 0x6D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x42 0x68 0xC0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3F 0x2D 0x8D 0x53 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x00 0x06 0x71 0x37 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x30 0x71 0x7C 0x14 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26eceaed
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 1042669753
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 764169717
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x35 0x94 0x33 0xDC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x89 0x04 0x48 0x3A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0x34 0xC1 0x31 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x74 0xDC 0x09 0x25 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0x13 0xF0 0x6D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x42 0x68 0xC0 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3F 0x2D 0x8D 0x53 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x00 0x06 0x71 0x37 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x30 0x71 0x7C 0x14 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109A10050400000000000F01FEC\Usage@OutlookMAPI2Intl_1029 1064372994

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\$NtUninstallKB28038$\1664086358 0 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\L 0 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\L\dtfihjfc 138368 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\loader.tlb 2632 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U 0 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@00000001 45968 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@000000c0 3072 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@000000cb 3072 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@000000cf 1536 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@80000000 23040 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@800000c0 35840 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@800000cb 24064 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@800000cf 31744 bytes
File C:\WINDOWS\$NtUninstallKB28038$\3760065385 0 bytes

---- EOF - GMER 1.0.15 ----

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#6 Příspěvek od Rudy »

Ani toto není zcela jednoznačné. Udělejte sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 a dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#7 Příspěvek od chris.h »

Status: Will be deleted when the computer is restarted (events: 1)
18.11.2011 13:38:51 Will be deleted when the computer is restarted Trojan program Backdoor.Win32.ZAccess.ang C:\WINDOWS\assembly\GAC_MSIL\Desktop.ini High
Status: Deleted (events: 6)
18.11.2011 14:30:45 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114182.ini High
18.11.2011 14:30:44 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114201.ini High
18.11.2011 14:30:45 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114272.ini High
18.11.2011 14:30:48 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114307.ini High
18.11.2011 14:30:48 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114321.ini High
18.11.2011 14:30:50 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP435\A0114346.ini High

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#8 Příspěvek od Rudy »

OK, smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#9 Příspěvek od chris.h »

Tak, NOD mi stále hlásí ten rootkit na operační paměti.

Operační paměť » services.exe(1604) - varianta infiltrace Win32/Rootkit.Agent.NUS trojský kůň - nelze léčit

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#10 Příspěvek od Rudy »

Je to rebus, tenhle šmejd jsme tu ještě neměli. Zkuste otestovat tento soubor : C: \ WINDOWS \ system32 \ spoolsv.exe na www.virustotal.com . Výsledek oznamte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#11 Příspěvek od chris.h »

File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis:
MD5: da81ec57acd4cdc3d4c51cf3d409af9f
Date first seen: 2007-09-14 17:29:17 (UTC)
Date last seen: 2011-11-05 13:20:05 (UTC)
Detection ratio: 1/43

What do you wish to do?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#12 Příspěvek od Rudy »

V jednom případě něco detekoval. Který AV a jaký virus?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#13 Příspěvek od chris.h »

eSafe 7.0.17.0 2011.11.02 Win32.Banker

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#14 Příspěvek od Rudy »

Tak to nic. Dejte ještě jeden log z ComboFix.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

chris.h
Návštěvník
Návštěvník
Příspěvky: 121
Registrován: 17 lis 2011 12:20

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

#15 Příspěvek od chris.h »

Tak hlásí mi to, že mám vypnout rezidentní štíty u NODU, ale já ani za nic nemůžu přijít na to, jak je vypnout. Pořád mi to nejde, poradíte???

Odpovědět