Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Veľa vírusov - súrne

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
-Matthew-
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 led 2012 15:35

Re: Veľa vírusov - súrne

#16 Příspěvek od -Matthew- »

Po spustení PC neseká, ani sa nezobrazujú okná s infiltráciami. :) Log:


ComboFix 12-01-30.02 - Martin 31.01.2012 21:24:26.10.4 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.421.1033.18.3326.2996 [GMT 1:00]
Running from: c:\documents and settings\Martin\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Martin\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
file zipped: c:\documents and settings\Martin\Application Data\Vumemz.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Martin\Application Data\A43.exe
c:\documents and settings\Martin\Application Data\B.exe
c:\documents and settings\Martin\Application Data\Vumemz.exe
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
.
((((((((((((((((((((((((( Files Created from 2011-12-28 to 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 14:29 . 2012-01-31 14:29 -------- d-----w- C:\rsit
2012-01-02 15:37 . 2012-01-02 15:37 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-02 15:37 . 2012-01-02 15:37 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-02 15:37 . 2012-01-02 15:37 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-02 15:37 . 2012-01-02 15:37 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-31 20:34 . 2009-05-07 12:19 16608 ----a-w- c:\windows\gdrv.sys
2011-12-21 15:38 . 2011-12-02 21:01 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 14:24 . 2010-12-20 18:51 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-02 15:37 . 2011-04-29 14:36 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-28 09:18 . CB75214525D36F923D3948DA3CD1562D . 1390080 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2008-04-28 . A55B8899D2EA2E800061BCFD456E34DC . 547328 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
.
[-] 2008-03-20 . F92D8964B5286DE225BD2B6BF89764BE . 578560 . . [5.1.2600.5508] . . c:\windows\system32\user32.dll
.
[-] 2008-08-18 . 4A90F51B778FA0157F60D206E8B37D2A . 1616384 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-04-13 . 18B0915F58A5342AB0F3D01D57261E32 . 267264 . . [5.1.2600.5512] . . c:\windows\regedit.exe
.
[-] 2008-03-20 . 31653CDF039C3F415B8D33F2D133E6AB . 1287168 . . [5.1.2600.5508] . . c:\windows\system32\ole32.dll
.
[-] 2008-04-28 . B5E8782D4AF1B3756F38E11E7C157BBE . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
[-] 2008-04-26 . BC298B78B311397B421D4D52B44B49EC . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
[-] 2008-04-28 . A913E1FF4C0BDA15FC542430182EB7B6 . 368640 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll
.
.
[-] 2011-07-12 . 83199EF88D691E730B80666E29F90D58 . 17408 . . [6.0.6002.18005] . . c:\windows\system32\midimap.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-01-31_16.08.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-31 20:34 . 2012-01-31 20:34 16384 c:\windows\temp\Perflib_Perfdata_7fc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ESET"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-03-31 2145000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Visual Task Tips"="c:\program files\Windows7\VisualTaskTips\VisualTaskTips.exe" [2007-09-05 36352]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-27 16875008]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"D-Link AirPlus XtremeG DWL-G122"="c:\program files\D-Link\AirPlus XtremeG DWL-G122\AirGCFG.exe" [2008-12-18 1556480]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-18 76304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
.
c:\documents and settings\Martin\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2011-7-12 0]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-31 809488]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-18 22:30 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TPSvc]
TPSvc.dll [BU]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnalogClock]
2005-11-05 06:10 480256 ----a-w- c:\program files\Windows7\Analog Clock\AnalogClock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pie Dock]
2007-09-02 06:12 586240 ----a-w- c:\program files\Windows7\Windows 7 Pie Dock\Windows 7 Pie Dock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ------r- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TopDesk]
2007-06-20 08:21 1912832 ----a-w- c:\program files\Windows7\TopDesk\topdesk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UberIcon]
2006-05-21 03:43 180224 ----a-w- c:\program files\Windows7\UberIcon\UberIcon Manager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Viena Explorer]
2006-11-18 10:31 581632 ----a-w- c:\program files\Windows7\Vienna Explorer\Vienna Explorer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"StarWindServiceAE"=2 (0x2)
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"gupdate1c9cf1520895eca"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\game.dat"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\FlatOut2\\FlatOut2.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\patchget.dat"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Hry\\WoW\\WotLK\\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Hry\\WoW\\WotLK\\Launcher.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Programy\\Internet\\Fake IP\\FakeIP\\DC_IS.EXE"=
"c:\\Program Files\\ACSPMonitor\\ASMonitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\EA GAMES\\Command and Conquer Generals\\game.dat"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Pyro Studios\\Imperial Glory\\ImperialGlory.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Hry\\Stronghold Crusader\\Stronghold Crusader.exe"=
"c:\\Program Files\\keyclone\\keyclone.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [7.5.2009 16:48 685816]
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [7.12.2009 16:59 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [12.5.2010 17:01 59280]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [31.3.2010 7:22 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [31.3.2010 7:23 95872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [31.3.2010 7:23 810120]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [7.5.2009 13:19 80392]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [20.12.2010 19:51 652360]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [21.12.2009 14:46 4096]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [20.12.2010 19:51 20464]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [24.5.2009 10:12 47360]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [7.12.2009 16:59 61328]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [19.8.2010 22:56 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [19.8.2010 22:56 8456]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 wip0202;Wippien Network Adapter;c:\windows\system32\drivers\wip0202.sys [22.9.2011 10:50 23904]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11.7.2008 1:28 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10.7.2008 1:49 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11.7.2008 1:28 369688]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do programu Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Martin\Application Data\Mozilla\Firefox\Profiles\prrbkrkl.default\
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-PService - c:\documents and settings\Martin\Application Data\B.exe
HKLM-Run-PService - c:\documents and settings\Martin\Application Data\B.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-31 21:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\SETUPAPI.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\system32\sfc_os.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
.
- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(3140)
c:\program files\Windows7\VisualTaskTips\VttHooks.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msctfime.ime
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2012-01-31 21:40:24 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-31 20:40
ComboFix2.txt 2012-01-31 16:10
.
Pre-Run: 279 320 260 608 bytes free
Post-Run: 279 295 672 320 bytes free
.
- - End Of File - - 8EECDDFC9EABB5A6ACAC8517A8D6A6FC

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Veľa vírusov - súrne

#17 Příspěvek od vyosek »

vyosek píše::arrow: Nasledujici soubory otestujte na VirusTotalu (viz muj podpis)
  • c:\windows\system32\winlogon.exe
    c:\windows\regedit.exe
    c:\windows\system32\comres.dll
    c:\windows\explorer.exe
  • Kliknete na Choose file
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Kliknete na Scan It
  • Pokud na Vas vyskoci obrazovka jako je nize, tak kliknete na ReAnalyse
    Obrázek
  • Vysledek analyzy sem vlozte (jako odkaz)
Snad nam vt jiz pujde
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.


Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Veľa vírusov - súrne

#19 Příspěvek od vyosek »

Tak, ted jeste TDSSKiller
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

-Matthew-
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 led 2012 15:35

Re: Veľa vírusov - súrne

#20 Příspěvek od -Matthew- »

TDSKiller log


22:45:51.0390 3352 TDSS rootkit removing tool 2.7.8.0 Jan 30 2012 16:39:36
22:45:51.0500 3352 ============================================================
22:45:51.0500 3352 Current date / time: 2012/01/31 22:45:51.0500
22:45:51.0500 3352 SystemInfo:
22:45:51.0500 3352
22:45:51.0500 3352 OS Version: 5.1.2600 ServicePack: 3.0
22:45:51.0500 3352 Product type: Workstation
22:45:51.0500 3352 ComputerName: XPWINDOWS7
22:45:51.0500 3352 UserName: Martin
22:45:51.0500 3352 Windows directory: C:\WINDOWS
22:45:51.0500 3352 System windows directory: C:\WINDOWS
22:45:51.0500 3352 Processor architecture: Intel x86
22:45:51.0500 3352 Number of processors: 4
22:45:51.0500 3352 Page size: 0x1000
22:45:51.0500 3352 Boot type: Normal boot
22:45:51.0500 3352 ============================================================
22:45:53.0031 3352 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0CADE00 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
22:45:53.0046 3352 \Device\Harddisk0\DR0:
22:45:53.0046 3352 MBR used
22:45:53.0046 3352 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x681C44F7
22:45:53.0062 3352 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x681C4575, BlocksNum 0xC54144C
22:45:53.0218 3352 Initialize success
22:45:53.0218 3352 ============================================================
22:46:12.0609 1840 ============================================================
22:46:12.0609 1840 Scan started
22:46:12.0609 1840 Mode: Manual; SigCheck; TDLFS;
22:46:12.0609 1840 ============================================================
22:46:12.0968 1840 Abiosdsk - ok
22:46:12.0984 1840 abp480n5 - ok
22:46:13.0015 1840 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:46:13.0453 1840 ACPI - ok
22:46:13.0484 1840 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
22:46:13.0593 1840 ACPIEC - ok
22:46:13.0593 1840 adpu160m - ok
22:46:13.0640 1840 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
22:46:13.0765 1840 aec - ok
22:46:13.0796 1840 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
22:46:13.0812 1840 AFD - ok
22:46:13.0828 1840 Aha154x - ok
22:46:13.0828 1840 aic78u2 - ok
22:46:13.0843 1840 aic78xx - ok
22:46:13.0843 1840 AliIde - ok
22:46:13.0859 1840 amsint - ok
22:46:13.0890 1840 ANIO (920298c7aef97d8168d219d35975d295) C:\WINDOWS\system32\ANIO.SYS
22:46:13.0890 1840 ANIO ( UnsignedFile.Multi.Generic ) - warning
22:46:13.0890 1840 ANIO - detected UnsignedFile.Multi.Generic (1)
22:46:13.0906 1840 asc - ok
22:46:13.0906 1840 asc3350p - ok
22:46:13.0906 1840 asc3550 - ok
22:46:13.0953 1840 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:46:14.0046 1840 AsyncMac - ok
22:46:14.0062 1840 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:46:14.0140 1840 atapi - ok
22:46:14.0140 1840 Atdisk - ok
22:46:14.0156 1840 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:46:14.0250 1840 Atmarpc - ok
22:46:14.0281 1840 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:46:14.0359 1840 audstub - ok
22:46:14.0375 1840 bbcap (709fbe6eced1c3259d2b50bb0520b765) C:\WINDOWS\system32\DRIVERS\bbcap.sys
22:46:14.0390 1840 bbcap - ok
22:46:14.0421 1840 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:46:14.0500 1840 Beep - ok
22:46:14.0515 1840 catchme - ok
22:46:14.0562 1840 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:46:14.0656 1840 cbidf2k - ok
22:46:14.0656 1840 cd20xrnt - ok
22:46:14.0671 1840 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:46:14.0750 1840 Cdaudio - ok
22:46:14.0781 1840 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
22:46:14.0859 1840 Cdfs - ok
22:46:14.0890 1840 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:46:14.0968 1840 Cdrom - ok
22:46:14.0968 1840 Changer - ok
22:46:14.0984 1840 CmdIde - ok
22:46:15.0000 1840 Cpqarray - ok
22:46:15.0000 1840 dac2w2k - ok
22:46:15.0015 1840 dac960nt - ok
22:46:15.0031 1840 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
22:46:15.0125 1840 Disk - ok
22:46:15.0156 1840 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
22:46:15.0281 1840 dmboot - ok
22:46:15.0281 1840 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
22:46:15.0375 1840 dmio - ok
22:46:15.0390 1840 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:46:15.0468 1840 dmload - ok
22:46:15.0500 1840 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
22:46:15.0578 1840 DMusic - ok
22:46:15.0593 1840 dpti2o - ok
22:46:15.0593 1840 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
22:46:15.0671 1840 drmkaud - ok
22:46:15.0703 1840 eamon (797798ed835628109811b4c8a6e1b668) C:\WINDOWS\system32\DRIVERS\eamon.sys
22:46:15.0734 1840 eamon - ok
22:46:15.0750 1840 ehdrv (d56f9592ea30e6f049af0c7f1062cd48) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
22:46:15.0781 1840 ehdrv - ok
22:46:15.0781 1840 epfwtdir (2f70747c739550e7f0de9430f17e093b) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
22:46:15.0828 1840 epfwtdir - ok
22:46:15.0859 1840 epmntdrv (f07ba56b0235f15eff8f10dc6389c42e) C:\WINDOWS\system32\epmntdrv.sys
22:46:15.0859 1840 epmntdrv ( UnsignedFile.Multi.Generic ) - warning
22:46:15.0859 1840 epmntdrv - detected UnsignedFile.Multi.Generic (1)
22:46:15.0906 1840 EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\WINDOWS\system32\EuGdiDrv.sys
22:46:15.0906 1840 EuGdiDrv ( UnsignedFile.Multi.Generic ) - warning
22:46:15.0906 1840 EuGdiDrv - detected UnsignedFile.Multi.Generic (1)
22:46:15.0937 1840 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
22:46:16.0046 1840 Fastfat - ok
22:46:16.0125 1840 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
22:46:16.0203 1840 Fdc - ok
22:46:16.0234 1840 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
22:46:16.0328 1840 Fips - ok
22:46:16.0343 1840 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
22:46:16.0421 1840 Flpydisk - ok
22:46:16.0437 1840 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:46:16.0515 1840 FltMgr - ok
22:46:16.0531 1840 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:46:16.0625 1840 Fs_Rec - ok
22:46:16.0625 1840 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:46:16.0718 1840 Ftdisk - ok
22:46:16.0718 1840 gdrv (5c230948dd6652228f88ca7ae6cb276c) C:\WINDOWS\gdrv.sys
22:46:16.0734 1840 gdrv - ok
22:46:16.0750 1840 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
22:46:16.0750 1840 giveio ( UnsignedFile.Multi.Generic ) - warning
22:46:16.0750 1840 giveio - detected UnsignedFile.Multi.Generic (1)
22:46:16.0781 1840 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:46:16.0859 1840 Gpc - ok
22:46:16.0875 1840 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
22:46:16.0875 1840 hamachi - ok
22:46:16.0890 1840 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:46:16.0968 1840 HDAudBus - ok
22:46:17.0000 1840 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:46:17.0078 1840 hidusb - ok
22:46:17.0078 1840 hpn - ok
22:46:17.0093 1840 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
22:46:17.0187 1840 HTTP - ok
22:46:17.0203 1840 i2omgmt - ok
22:46:17.0203 1840 i2omp - ok
22:46:17.0218 1840 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:46:17.0312 1840 Imapi - ok
22:46:17.0328 1840 ini910u - ok
22:46:17.0421 1840 IntcAzAudAddService (557e20484a095d949912883f5ab29e88) C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:46:17.0546 1840 IntcAzAudAddService - ok
22:46:17.0562 1840 IntelIde - ok
22:46:17.0578 1840 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:46:17.0671 1840 intelppm - ok
22:46:17.0703 1840 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:46:17.0781 1840 Ip6Fw - ok
22:46:17.0796 1840 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:46:17.0859 1840 IpFilterDriver - ok
22:46:17.0875 1840 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:46:17.0953 1840 IpInIp - ok
22:46:17.0968 1840 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:46:18.0031 1840 IpNat - ok
22:46:18.0046 1840 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:46:18.0140 1840 IPSec - ok
22:46:18.0171 1840 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:46:18.0218 1840 IRENUM - ok
22:46:18.0234 1840 is3srv (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\drivers\is3srv.sys
22:46:18.0234 1840 is3srv - ok
22:46:18.0250 1840 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:46:18.0328 1840 isapnp - ok
22:46:18.0359 1840 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:46:18.0437 1840 Kbdclass - ok
22:46:18.0453 1840 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:46:18.0546 1840 kbdhid - ok
22:46:18.0562 1840 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
22:46:18.0656 1840 kmixer - ok
22:46:18.0656 1840 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
22:46:18.0734 1840 KSecDD - ok
22:46:18.0750 1840 lbrtfdc - ok
22:46:18.0781 1840 LHidFilt (8b30311241f97b35167afe68d79e8530) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
22:46:18.0781 1840 LHidFilt - ok
22:46:18.0796 1840 LMouFilt (48d7422a6c4eec886b56ac534cfa3acf) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
22:46:18.0812 1840 LMouFilt - ok
22:46:18.0828 1840 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys
22:46:18.0843 1840 MBAMProtector - ok
22:46:18.0859 1840 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:46:18.0937 1840 mnmdd - ok
22:46:18.0968 1840 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
22:46:19.0062 1840 Modem - ok
22:46:19.0062 1840 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:46:19.0156 1840 Mouclass - ok
22:46:19.0171 1840 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:46:19.0250 1840 mouhid - ok
22:46:19.0250 1840 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
22:46:19.0328 1840 MountMgr - ok
22:46:19.0328 1840 mraid35x - ok
22:46:19.0359 1840 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:46:19.0437 1840 MRxDAV - ok
22:46:19.0453 1840 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:46:19.0484 1840 MRxSmb - ok
22:46:19.0500 1840 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
22:46:19.0578 1840 Msfs - ok
22:46:19.0593 1840 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:46:19.0687 1840 MSKSSRV - ok
22:46:19.0703 1840 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:46:19.0781 1840 mssmbios - ok
22:46:19.0796 1840 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
22:46:19.0875 1840 Mup - ok
22:46:19.0875 1840 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
22:46:19.0953 1840 NDIS - ok
22:46:19.0968 1840 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:46:20.0046 1840 NdisTapi - ok
22:46:20.0062 1840 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:46:20.0156 1840 Ndisuio - ok
22:46:20.0171 1840 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:46:20.0250 1840 NdisWan - ok
22:46:20.0250 1840 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
22:46:20.0328 1840 NDProxy - ok
22:46:20.0343 1840 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:46:20.0421 1840 NetBIOS - ok
22:46:20.0421 1840 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:46:20.0531 1840 NetBT - ok
22:46:20.0578 1840 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
22:46:20.0671 1840 Npfs - ok
22:46:20.0687 1840 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
22:46:20.0765 1840 Ntfs - ok
22:46:20.0781 1840 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:46:20.0859 1840 Null - ok
22:46:21.0000 1840 nv (406ddab2b05d94d4818e97ff050d1bc6) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:46:21.0250 1840 nv - ok
22:46:21.0281 1840 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:46:21.0359 1840 NwlnkFlt - ok
22:46:21.0359 1840 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:46:21.0453 1840 NwlnkFwd - ok
22:46:21.0484 1840 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
22:46:21.0578 1840 Parport - ok
22:46:21.0578 1840 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
22:46:21.0656 1840 PartMgr - ok
22:46:21.0671 1840 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
22:46:21.0765 1840 ParVdm - ok
22:46:21.0796 1840 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
22:46:21.0890 1840 PCI - ok
22:46:21.0890 1840 PCIDump - ok
22:46:21.0906 1840 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:46:21.0984 1840 PCIIde - ok
22:46:22.0015 1840 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
22:46:22.0140 1840 Pcmcia - ok
22:46:22.0156 1840 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
22:46:22.0156 1840 pcouffin ( UnsignedFile.Multi.Generic ) - warning
22:46:22.0156 1840 pcouffin - detected UnsignedFile.Multi.Generic (1)
22:46:22.0171 1840 PDCOMP - ok
22:46:22.0171 1840 PDFRAME - ok
22:46:22.0187 1840 PDRELI - ok
22:46:22.0187 1840 PDRFRAME - ok
22:46:22.0203 1840 perc2 - ok
22:46:22.0203 1840 perc2hib - ok
22:46:22.0234 1840 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:46:22.0312 1840 PptpMiniport - ok
22:46:22.0328 1840 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
22:46:22.0406 1840 PSched - ok
22:46:22.0406 1840 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:46:22.0484 1840 Ptilink - ok
22:46:22.0484 1840 ql1080 - ok
22:46:22.0500 1840 Ql10wnt - ok
22:46:22.0500 1840 ql12160 - ok
22:46:22.0515 1840 ql1240 - ok
22:46:22.0515 1840 ql1280 - ok
22:46:22.0531 1840 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:46:22.0609 1840 RasAcd - ok
22:46:22.0625 1840 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:46:22.0703 1840 Rasl2tp - ok
22:46:22.0718 1840 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:46:22.0796 1840 RasPppoe - ok
22:46:22.0796 1840 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:46:22.0875 1840 Raspti - ok
22:46:22.0890 1840 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:46:23.0015 1840 Rdbss - ok
22:46:23.0031 1840 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:46:23.0125 1840 RDPCDD - ok
22:46:23.0125 1840 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:46:23.0218 1840 rdpdr - ok
22:46:23.0250 1840 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
22:46:23.0328 1840 RDPWD - ok
22:46:23.0328 1840 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
22:46:23.0421 1840 redbook - ok
22:46:23.0468 1840 RsFx0102 (fedd2710b75be3ecf078adace790c423) C:\WINDOWS\system32\DRIVERS\RsFx0102.sys
22:46:23.0484 1840 RsFx0102 - ok
22:46:23.0484 1840 rt2500usb - ok
22:46:23.0515 1840 RT73 (cb20f16afdba63707fb971e0922edec1) C:\WINDOWS\system32\DRIVERS\Dr71WU.sys
22:46:23.0515 1840 RT73 ( UnsignedFile.Multi.Generic ) - warning
22:46:23.0515 1840 RT73 - detected UnsignedFile.Multi.Generic (1)
22:46:23.0531 1840 RTLE8023xp (eeb84629064abcb6198864d25bf15b1a) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
22:46:23.0593 1840 RTLE8023xp - ok
22:46:23.0609 1840 s116bus (815445f4676cc96bc9aeec303c727e19) C:\WINDOWS\system32\DRIVERS\s116bus.sys
22:46:23.0625 1840 s116bus - ok
22:46:23.0625 1840 s116mdfl (333d1e0743e6de1779c3c418ac601c3a) C:\WINDOWS\system32\DRIVERS\s116mdfl.sys
22:46:23.0640 1840 s116mdfl - ok
22:46:23.0640 1840 s116mdm (50d6e5b021e9ec7553ab8a3553cc1b6b) C:\WINDOWS\system32\DRIVERS\s116mdm.sys
22:46:23.0656 1840 s116mdm - ok
22:46:23.0671 1840 s116mgmt (1589aa53e43f8d193a7d4d580d3ffa95) C:\WINDOWS\system32\DRIVERS\s116mgmt.sys
22:46:23.0671 1840 s116mgmt - ok
22:46:23.0687 1840 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:46:23.0734 1840 Secdrv - ok
22:46:23.0750 1840 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
22:46:23.0843 1840 serenum - ok
22:46:23.0843 1840 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
22:46:23.0921 1840 Serial - ok
22:46:23.0953 1840 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:46:24.0046 1840 Sfloppy - ok
22:46:24.0046 1840 Simbad - ok
22:46:24.0062 1840 Sparrow - ok
22:46:24.0109 1840 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\WINDOWS\system32\speedfan.sys
22:46:24.0109 1840 speedfan ( UnsignedFile.Multi.Generic ) - warning
22:46:24.0109 1840 speedfan - detected UnsignedFile.Multi.Generic (1)
22:46:24.0125 1840 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
22:46:24.0203 1840 splitter - ok
22:46:24.0250 1840 sptd (d390675b8ce45e5fb359338e5e649329) C:\WINDOWS\system32\Drivers\sptd.sys
22:46:24.0250 1840 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d390675b8ce45e5fb359338e5e649329
22:46:24.0250 1840 sptd ( LockedFile.Multi.Generic ) - warning
22:46:24.0250 1840 sptd - detected LockedFile.Multi.Generic (1)
22:46:24.0265 1840 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
22:46:24.0312 1840 sr - ok
22:46:24.0328 1840 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys
22:46:24.0343 1840 Srv - ok
22:46:24.0375 1840 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:46:24.0468 1840 swenum - ok
22:46:24.0468 1840 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
22:46:24.0546 1840 swmidi - ok
22:46:24.0562 1840 symc810 - ok
22:46:24.0562 1840 symc8xx - ok
22:46:24.0562 1840 sym_hi - ok
22:46:24.0578 1840 sym_u3 - ok
22:46:24.0593 1840 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
22:46:24.0671 1840 sysaudio - ok
22:46:24.0671 1840 szkg5 (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\DRIVERS\szkg.sys
22:46:24.0687 1840 szkg5 - ok
22:46:24.0687 1840 szkgfs (410a02a920fa9daeec56364e839597c1) C:\WINDOWS\system32\drivers\szkgfs.sys
22:46:24.0703 1840 szkgfs - ok
22:46:24.0734 1840 tap0901 (98a1e6bc9f766b0b0a5bf00af847ef20) C:\WINDOWS\system32\DRIVERS\tap0901.sys
22:46:24.0734 1840 tap0901 ( UnsignedFile.Multi.Generic ) - warning
22:46:24.0734 1840 tap0901 - detected UnsignedFile.Multi.Generic (1)
22:46:24.0781 1840 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:46:24.0828 1840 Tcpip - ok
22:46:24.0859 1840 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:46:24.0921 1840 TDPIPE - ok
22:46:24.0953 1840 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
22:46:25.0031 1840 TDTCP - ok
22:46:25.0031 1840 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:46:25.0156 1840 TermDD - ok
22:46:25.0156 1840 TosIde - ok
22:46:25.0218 1840 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
22:46:25.0312 1840 Udfs - ok
22:46:25.0312 1840 ultra - ok
22:46:25.0359 1840 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
22:46:25.0437 1840 Update - ok
22:46:25.0468 1840 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:46:25.0546 1840 usbccgp - ok
22:46:25.0578 1840 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:46:25.0656 1840 usbehci - ok
22:46:25.0671 1840 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:46:25.0781 1840 usbhub - ok
22:46:25.0812 1840 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:46:25.0906 1840 USBSTOR - ok
22:46:25.0906 1840 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:46:26.0000 1840 usbuhci - ok
22:46:26.0000 1840 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
22:46:26.0093 1840 VgaSave - ok
22:46:26.0109 1840 ViaIde - ok
22:46:26.0125 1840 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
22:46:26.0218 1840 VolSnap - ok
22:46:26.0234 1840 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:46:26.0312 1840 Wanarp - ok
22:46:26.0343 1840 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
22:46:26.0375 1840 Wdf01000 - ok
22:46:26.0375 1840 WDICA - ok
22:46:26.0406 1840 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
22:46:26.0484 1840 wdmaud - ok
22:46:26.0515 1840 wip0202 (277366120cd28bf9a757c739713422af) C:\WINDOWS\system32\DRIVERS\wip0202.sys
22:46:26.0531 1840 wip0202 - ok
22:46:26.0562 1840 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
22:46:26.0578 1840 WpdUsb - ok
22:46:26.0625 1840 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
22:46:26.0703 1840 WS2IFSL - ok
22:46:26.0718 1840 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:46:26.0734 1840 WudfPf - ok
22:46:26.0765 1840 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:46:26.0765 1840 WudfRd - ok
22:46:26.0781 1840 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
22:46:26.0812 1840 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - infected
22:46:26.0812 1840 \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0)
22:46:26.0921 1840 Boot (0x1200) (7922af791e009c098b531721fd8f5c01) \Device\Harddisk0\DR0\Partition0
22:46:26.0921 1840 \Device\Harddisk0\DR0\Partition0 - ok
22:46:26.0921 1840 Boot (0x1200) (ddc475b82c10e2932c9aa4a361fda8f6) \Device\Harddisk0\DR0\Partition1
22:46:26.0921 1840 \Device\Harddisk0\DR0\Partition1 - ok
22:46:26.0921 1840 ============================================================
22:46:26.0921 1840 Scan finished
22:46:26.0921 1840 ============================================================
22:46:27.0031 1284 Detected object count: 10
22:46:27.0031 1284 Actual detected object count: 10
22:46:43.0015 1284 ANIO ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0015 1284 ANIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0015 1284 epmntdrv ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0015 1284 epmntdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0015 1284 EuGdiDrv ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0015 1284 EuGdiDrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0015 1284 giveio ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0015 1284 giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0015 1284 pcouffin ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0015 1284 pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0015 1284 RT73 ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0015 1284 RT73 ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0031 1284 speedfan ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0031 1284 speedfan ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0031 1284 sptd ( LockedFile.Multi.Generic ) - skipped by user
22:46:43.0031 1284 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
22:46:43.0031 1284 tap0901 ( UnsignedFile.Multi.Generic ) - skipped by user
22:46:43.0031 1284 tap0901 ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:46:43.0031 1284 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - skipped by user
22:46:43.0031 1284 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - User select action: Skip

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Veľa vírusov - súrne

#21 Příspěvek od vyosek »

Znovu TDSSKiller a u polozky Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) zvolte Cure - log pak opet sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

-Matthew-
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 led 2012 15:35

Re: Veľa vírusov - súrne

#22 Příspěvek od -Matthew- »

17:08:35.0765 2452 TDSS rootkit removing tool 2.7.8.0 Jan 30 2012 16:39:36
17:08:40.0015 2452 ============================================================
17:08:40.0015 2452 Current date / time: 2012/02/01 17:08:40.0015
17:08:40.0015 2452 SystemInfo:
17:08:40.0015 2452
17:08:40.0015 2452 OS Version: 5.1.2600 ServicePack: 3.0
17:08:40.0015 2452 Product type: Workstation
17:08:40.0015 2452 ComputerName: XPWINDOWS7
17:08:40.0015 2452 UserName: Martin
17:08:40.0015 2452 Windows directory: C:\WINDOWS
17:08:40.0015 2452 System windows directory: C:\WINDOWS
17:08:40.0015 2452 Processor architecture: Intel x86
17:08:40.0015 2452 Number of processors: 4
17:08:40.0015 2452 Page size: 0x1000
17:08:40.0015 2452 Boot type: Normal boot
17:08:40.0015 2452 ============================================================
17:08:41.0437 2452 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0CADE00 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
17:08:41.0578 2452 \Device\Harddisk0\DR0:
17:08:41.0578 2452 MBR used
17:08:41.0578 2452 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x681C44F7
17:08:41.0593 2452 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x681C4575, BlocksNum 0xC54144C
17:08:41.0671 2452 Initialize success
17:08:41.0671 2452 ============================================================
17:09:08.0281 3620 ============================================================
17:09:08.0281 3620 Scan started
17:09:08.0281 3620 Mode: Manual; SigCheck; TDLFS;
17:09:08.0281 3620 ============================================================
17:09:08.0562 3620 Abiosdsk - ok
17:09:08.0562 3620 abp480n5 - ok
17:09:08.0593 3620 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:09:09.0687 3620 ACPI - ok
17:09:09.0718 3620 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
17:09:09.0843 3620 ACPIEC - ok
17:09:09.0843 3620 adpu160m - ok
17:09:09.0890 3620 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:09:10.0000 3620 aec - ok
17:09:10.0046 3620 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
17:09:10.0125 3620 AFD - ok
17:09:10.0125 3620 Aha154x - ok
17:09:10.0125 3620 aic78u2 - ok
17:09:10.0140 3620 aic78xx - ok
17:09:10.0140 3620 AliIde - ok
17:09:10.0156 3620 amsint - ok
17:09:10.0187 3620 ANIO (920298c7aef97d8168d219d35975d295) C:\WINDOWS\system32\ANIO.SYS
17:09:10.0203 3620 ANIO ( UnsignedFile.Multi.Generic ) - warning
17:09:10.0203 3620 ANIO - detected UnsignedFile.Multi.Generic (1)
17:09:10.0203 3620 asc - ok
17:09:10.0218 3620 asc3350p - ok
17:09:10.0218 3620 asc3550 - ok
17:09:10.0250 3620 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:09:10.0328 3620 AsyncMac - ok
17:09:10.0359 3620 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:09:10.0437 3620 atapi - ok
17:09:10.0437 3620 Atdisk - ok
17:09:10.0453 3620 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:09:10.0531 3620 Atmarpc - ok
17:09:10.0562 3620 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:09:10.0625 3620 audstub - ok
17:09:10.0656 3620 bbcap (709fbe6eced1c3259d2b50bb0520b765) C:\WINDOWS\system32\DRIVERS\bbcap.sys
17:09:10.0687 3620 bbcap - ok
17:09:10.0718 3620 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:09:10.0796 3620 Beep - ok
17:09:10.0796 3620 catchme - ok
17:09:10.0843 3620 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:09:10.0953 3620 cbidf2k - ok
17:09:10.0968 3620 cd20xrnt - ok
17:09:10.0968 3620 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:09:11.0046 3620 Cdaudio - ok
17:09:11.0078 3620 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:09:11.0156 3620 Cdfs - ok
17:09:11.0171 3620 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:09:11.0250 3620 Cdrom - ok
17:09:11.0250 3620 Changer - ok
17:09:11.0265 3620 CmdIde - ok
17:09:11.0265 3620 Cpqarray - ok
17:09:11.0281 3620 dac2w2k - ok
17:09:11.0281 3620 dac960nt - ok
17:09:11.0328 3620 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:09:11.0390 3620 Disk - ok
17:09:11.0421 3620 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
17:09:11.0531 3620 dmboot - ok
17:09:11.0546 3620 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
17:09:11.0625 3620 dmio - ok
17:09:11.0640 3620 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:09:11.0718 3620 dmload - ok
17:09:11.0750 3620 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:09:11.0828 3620 DMusic - ok
17:09:11.0828 3620 dpti2o - ok
17:09:11.0843 3620 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:09:11.0921 3620 drmkaud - ok
17:09:11.0937 3620 eamon (797798ed835628109811b4c8a6e1b668) C:\WINDOWS\system32\DRIVERS\eamon.sys
17:09:11.0984 3620 eamon - ok
17:09:11.0984 3620 ehdrv (d56f9592ea30e6f049af0c7f1062cd48) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
17:09:12.0000 3620 ehdrv - ok
17:09:12.0015 3620 epfwtdir (2f70747c739550e7f0de9430f17e093b) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
17:09:12.0015 3620 epfwtdir - ok
17:09:12.0062 3620 epmntdrv (f07ba56b0235f15eff8f10dc6389c42e) C:\WINDOWS\system32\epmntdrv.sys
17:09:12.0109 3620 epmntdrv ( UnsignedFile.Multi.Generic ) - warning
17:09:12.0109 3620 epmntdrv - detected UnsignedFile.Multi.Generic (1)
17:09:12.0156 3620 EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\WINDOWS\system32\EuGdiDrv.sys
17:09:12.0156 3620 EuGdiDrv ( UnsignedFile.Multi.Generic ) - warning
17:09:12.0156 3620 EuGdiDrv - detected UnsignedFile.Multi.Generic (1)
17:09:12.0187 3620 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:09:12.0281 3620 Fastfat - ok
17:09:12.0296 3620 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
17:09:12.0375 3620 Fdc - ok
17:09:12.0375 3620 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
17:09:12.0453 3620 Fips - ok
17:09:12.0468 3620 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
17:09:12.0546 3620 Flpydisk - ok
17:09:12.0578 3620 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
17:09:12.0656 3620 FltMgr - ok
17:09:12.0656 3620 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:09:12.0734 3620 Fs_Rec - ok
17:09:12.0750 3620 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:09:12.0828 3620 Ftdisk - ok
17:09:12.0843 3620 gdrv (5c230948dd6652228f88ca7ae6cb276c) C:\WINDOWS\gdrv.sys
17:09:12.0859 3620 gdrv - ok
17:09:12.0875 3620 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
17:09:12.0875 3620 giveio ( UnsignedFile.Multi.Generic ) - warning
17:09:12.0875 3620 giveio - detected UnsignedFile.Multi.Generic (1)
17:09:12.0890 3620 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:09:12.0968 3620 Gpc - ok
17:09:13.0000 3620 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
17:09:13.0015 3620 hamachi - ok
17:09:13.0031 3620 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
17:09:13.0109 3620 HDAudBus - ok
17:09:13.0125 3620 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:09:13.0203 3620 hidusb - ok
17:09:13.0218 3620 hpn - ok
17:09:13.0234 3620 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
17:09:13.0312 3620 HTTP - ok
17:09:13.0328 3620 i2omgmt - ok
17:09:13.0328 3620 i2omp - ok
17:09:13.0343 3620 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:09:13.0406 3620 Imapi - ok
17:09:13.0421 3620 ini910u - ok
17:09:13.0515 3620 IntcAzAudAddService (557e20484a095d949912883f5ab29e88) C:\WINDOWS\system32\drivers\RtkHDAud.sys
17:09:13.0734 3620 IntcAzAudAddService - ok
17:09:13.0734 3620 IntelIde - ok
17:09:13.0781 3620 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:09:13.0859 3620 intelppm - ok
17:09:13.0890 3620 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
17:09:13.0968 3620 Ip6Fw - ok
17:09:13.0968 3620 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:09:14.0046 3620 IpFilterDriver - ok
17:09:14.0046 3620 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:09:14.0125 3620 IpInIp - ok
17:09:14.0156 3620 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:09:14.0234 3620 IpNat - ok
17:09:14.0250 3620 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:09:14.0328 3620 IPSec - ok
17:09:14.0375 3620 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:09:14.0406 3620 IRENUM - ok
17:09:14.0421 3620 is3srv (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\drivers\is3srv.sys
17:09:14.0437 3620 is3srv - ok
17:09:14.0437 3620 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:09:14.0515 3620 isapnp - ok
17:09:14.0546 3620 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:09:14.0625 3620 Kbdclass - ok
17:09:14.0625 3620 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
17:09:14.0703 3620 kbdhid - ok
17:09:14.0734 3620 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:09:14.0812 3620 kmixer - ok
17:09:14.0812 3620 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
17:09:14.0890 3620 KSecDD - ok
17:09:14.0906 3620 lbrtfdc - ok
17:09:14.0937 3620 LHidFilt (8b30311241f97b35167afe68d79e8530) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
17:09:14.0937 3620 LHidFilt - ok
17:09:14.0953 3620 LMouFilt (48d7422a6c4eec886b56ac534cfa3acf) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
17:09:14.0968 3620 LMouFilt - ok
17:09:15.0000 3620 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys
17:09:15.0015 3620 MBAMProtector - ok
17:09:15.0031 3620 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:09:15.0109 3620 mnmdd - ok
17:09:15.0140 3620 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
17:09:15.0234 3620 Modem - ok
17:09:15.0250 3620 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:09:15.0312 3620 Mouclass - ok
17:09:15.0328 3620 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:09:15.0406 3620 mouhid - ok
17:09:15.0406 3620 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:09:15.0484 3620 MountMgr - ok
17:09:15.0484 3620 mraid35x - ok
17:09:15.0515 3620 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:09:15.0609 3620 MRxDAV - ok
17:09:15.0625 3620 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:09:15.0656 3620 MRxSmb - ok
17:09:15.0671 3620 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:09:15.0750 3620 Msfs - ok
17:09:15.0765 3620 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:09:15.0843 3620 MSKSSRV - ok
17:09:15.0843 3620 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:09:15.0921 3620 mssmbios - ok
17:09:15.0937 3620 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
17:09:16.0015 3620 Mup - ok
17:09:16.0015 3620 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:09:16.0093 3620 NDIS - ok
17:09:16.0125 3620 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:09:16.0187 3620 NdisTapi - ok
17:09:16.0203 3620 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:09:16.0281 3620 Ndisuio - ok
17:09:16.0296 3620 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:09:16.0375 3620 NdisWan - ok
17:09:16.0375 3620 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
17:09:16.0453 3620 NDProxy - ok
17:09:16.0453 3620 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:09:16.0531 3620 NetBIOS - ok
17:09:16.0562 3620 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:09:16.0640 3620 NetBT - ok
17:09:16.0671 3620 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:09:16.0750 3620 Npfs - ok
17:09:16.0765 3620 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:09:16.0859 3620 Ntfs - ok
17:09:16.0890 3620 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:09:16.0953 3620 Null - ok
17:09:17.0093 3620 nv (406ddab2b05d94d4818e97ff050d1bc6) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
17:09:17.0343 3620 nv - ok
17:09:17.0375 3620 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:09:17.0453 3620 NwlnkFlt - ok
17:09:17.0453 3620 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:09:17.0531 3620 NwlnkFwd - ok
17:09:17.0546 3620 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
17:09:17.0625 3620 Parport - ok
17:09:17.0625 3620 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:09:17.0703 3620 PartMgr - ok
17:09:17.0718 3620 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
17:09:17.0812 3620 ParVdm - ok
17:09:17.0828 3620 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
17:09:17.0906 3620 PCI - ok
17:09:17.0906 3620 PCIDump - ok
17:09:17.0921 3620 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:09:17.0984 3620 PCIIde - ok
17:09:18.0031 3620 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:09:18.0140 3620 Pcmcia - ok
17:09:18.0171 3620 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
17:09:18.0171 3620 pcouffin ( UnsignedFile.Multi.Generic ) - warning
17:09:18.0171 3620 pcouffin - detected UnsignedFile.Multi.Generic (1)
17:09:18.0171 3620 PDCOMP - ok
17:09:18.0187 3620 PDFRAME - ok
17:09:18.0187 3620 PDRELI - ok
17:09:18.0187 3620 PDRFRAME - ok
17:09:18.0203 3620 perc2 - ok
17:09:18.0203 3620 perc2hib - ok
17:09:18.0234 3620 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:09:18.0296 3620 PptpMiniport - ok
17:09:18.0312 3620 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:09:18.0390 3620 PSched - ok
17:09:18.0406 3620 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:09:18.0468 3620 Ptilink - ok
17:09:18.0484 3620 ql1080 - ok
17:09:18.0484 3620 Ql10wnt - ok
17:09:18.0500 3620 ql12160 - ok
17:09:18.0500 3620 ql1240 - ok
17:09:18.0515 3620 ql1280 - ok
17:09:18.0515 3620 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:09:18.0593 3620 RasAcd - ok
17:09:18.0593 3620 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:09:18.0671 3620 Rasl2tp - ok
17:09:18.0687 3620 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:09:18.0765 3620 RasPppoe - ok
17:09:18.0765 3620 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:09:18.0843 3620 Raspti - ok
17:09:18.0859 3620 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:09:18.0921 3620 Rdbss - ok
17:09:18.0937 3620 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:09:19.0000 3620 RDPCDD - ok
17:09:19.0015 3620 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
17:09:19.0093 3620 rdpdr - ok
17:09:19.0109 3620 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
17:09:19.0187 3620 RDPWD - ok
17:09:19.0203 3620 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:09:19.0281 3620 redbook - ok
17:09:19.0312 3620 RsFx0102 (fedd2710b75be3ecf078adace790c423) C:\WINDOWS\system32\DRIVERS\RsFx0102.sys
17:09:19.0328 3620 RsFx0102 - ok
17:09:19.0328 3620 rt2500usb - ok
17:09:19.0359 3620 RT73 (cb20f16afdba63707fb971e0922edec1) C:\WINDOWS\system32\DRIVERS\Dr71WU.sys
17:09:19.0375 3620 RT73 ( UnsignedFile.Multi.Generic ) - warning
17:09:19.0375 3620 RT73 - detected UnsignedFile.Multi.Generic (1)
17:09:19.0390 3620 RTLE8023xp (eeb84629064abcb6198864d25bf15b1a) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
17:09:19.0421 3620 RTLE8023xp - ok
17:09:19.0453 3620 s116bus (815445f4676cc96bc9aeec303c727e19) C:\WINDOWS\system32\DRIVERS\s116bus.sys
17:09:19.0453 3620 s116bus - ok
17:09:19.0468 3620 s116mdfl (333d1e0743e6de1779c3c418ac601c3a) C:\WINDOWS\system32\DRIVERS\s116mdfl.sys
17:09:19.0468 3620 s116mdfl - ok
17:09:19.0468 3620 s116mdm (50d6e5b021e9ec7553ab8a3553cc1b6b) C:\WINDOWS\system32\DRIVERS\s116mdm.sys
17:09:19.0484 3620 s116mdm - ok
17:09:19.0500 3620 s116mgmt (1589aa53e43f8d193a7d4d580d3ffa95) C:\WINDOWS\system32\DRIVERS\s116mgmt.sys
17:09:19.0500 3620 s116mgmt - ok
17:09:19.0515 3620 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:09:19.0546 3620 Secdrv - ok
17:09:19.0562 3620 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:09:19.0625 3620 serenum - ok
17:09:19.0640 3620 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
17:09:19.0718 3620 Serial - ok
17:09:19.0750 3620 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:09:19.0812 3620 Sfloppy - ok
17:09:19.0828 3620 Simbad - ok
17:09:19.0828 3620 Sparrow - ok
17:09:19.0859 3620 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\WINDOWS\system32\speedfan.sys
17:09:19.0859 3620 speedfan ( UnsignedFile.Multi.Generic ) - warning
17:09:19.0859 3620 speedfan - detected UnsignedFile.Multi.Generic (1)
17:09:19.0875 3620 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:09:19.0953 3620 splitter - ok
17:09:19.0968 3620 sptd (d390675b8ce45e5fb359338e5e649329) C:\WINDOWS\system32\Drivers\sptd.sys
17:09:19.0968 3620 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d390675b8ce45e5fb359338e5e649329
17:09:19.0968 3620 sptd ( LockedFile.Multi.Generic ) - warning
17:09:19.0968 3620 sptd - detected LockedFile.Multi.Generic (1)
17:09:20.0000 3620 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
17:09:20.0031 3620 sr - ok
17:09:20.0062 3620 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys
17:09:20.0093 3620 Srv - ok
17:09:20.0125 3620 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:09:20.0218 3620 swenum - ok
17:09:20.0218 3620 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:09:20.0296 3620 swmidi - ok
17:09:20.0296 3620 symc810 - ok
17:09:20.0312 3620 symc8xx - ok
17:09:20.0312 3620 sym_hi - ok
17:09:20.0328 3620 sym_u3 - ok
17:09:20.0343 3620 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:09:20.0421 3620 sysaudio - ok
17:09:20.0437 3620 szkg5 (8fe4ecc7877fcfe4e59414708898073d) C:\WINDOWS\system32\DRIVERS\szkg.sys
17:09:20.0437 3620 szkg5 - ok
17:09:20.0453 3620 szkgfs (410a02a920fa9daeec56364e839597c1) C:\WINDOWS\system32\drivers\szkgfs.sys
17:09:20.0453 3620 szkgfs - ok
17:09:20.0484 3620 tap0901 (98a1e6bc9f766b0b0a5bf00af847ef20) C:\WINDOWS\system32\DRIVERS\tap0901.sys
17:09:20.0484 3620 tap0901 ( UnsignedFile.Multi.Generic ) - warning
17:09:20.0484 3620 tap0901 - detected UnsignedFile.Multi.Generic (1)
17:09:20.0531 3620 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:09:20.0593 3620 Tcpip - ok
17:09:20.0609 3620 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:09:20.0687 3620 TDPIPE - ok
17:09:20.0718 3620 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:09:20.0796 3620 TDTCP - ok
17:09:20.0812 3620 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:09:20.0875 3620 TermDD - ok
17:09:20.0890 3620 TosIde - ok
17:09:20.0937 3620 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:09:21.0015 3620 Udfs - ok
17:09:21.0031 3620 ultra - ok
17:09:21.0062 3620 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:09:21.0140 3620 Update - ok
17:09:21.0156 3620 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:09:21.0234 3620 usbccgp - ok
17:09:21.0265 3620 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:09:21.0328 3620 usbehci - ok
17:09:21.0343 3620 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:09:21.0421 3620 usbhub - ok
17:09:21.0437 3620 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:09:21.0515 3620 USBSTOR - ok
17:09:21.0515 3620 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:09:21.0593 3620 usbuhci - ok
17:09:21.0593 3620 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:09:21.0671 3620 VgaSave - ok
17:09:21.0671 3620 ViaIde - ok
17:09:21.0687 3620 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
17:09:21.0765 3620 VolSnap - ok
17:09:21.0781 3620 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:09:21.0843 3620 Wanarp - ok
17:09:21.0875 3620 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
17:09:21.0890 3620 Wdf01000 - ok
17:09:21.0890 3620 WDICA - ok
17:09:21.0906 3620 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:09:21.0984 3620 wdmaud - ok
17:09:22.0015 3620 wip0202 (277366120cd28bf9a757c739713422af) C:\WINDOWS\system32\DRIVERS\wip0202.sys
17:09:22.0031 3620 wip0202 - ok
17:09:22.0062 3620 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
17:09:22.0093 3620 WpdUsb - ok
17:09:22.0125 3620 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
17:09:22.0203 3620 WS2IFSL - ok
17:09:22.0218 3620 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:09:22.0234 3620 WudfPf - ok
17:09:22.0250 3620 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:09:22.0265 3620 WudfRd - ok
17:09:22.0265 3620 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
17:09:22.0296 3620 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - infected
17:09:22.0296 3620 \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0)
17:09:22.0406 3620 Boot (0x1200) (7922af791e009c098b531721fd8f5c01) \Device\Harddisk0\DR0\Partition0
17:09:22.0406 3620 \Device\Harddisk0\DR0\Partition0 - ok
17:09:22.0406 3620 Boot (0x1200) (ddc475b82c10e2932c9aa4a361fda8f6) \Device\Harddisk0\DR0\Partition1
17:09:22.0421 3620 \Device\Harddisk0\DR0\Partition1 - ok
17:09:22.0421 3620 ============================================================
17:09:22.0421 3620 Scan finished
17:09:22.0421 3620 ============================================================
17:09:22.0515 0988 Detected object count: 10
17:09:22.0515 0988 Actual detected object count: 10
17:10:09.0968 0988 ANIO ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 ANIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 epmntdrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 epmntdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 EuGdiDrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 EuGdiDrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 giveio ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 pcouffin ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 RT73 ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 RT73 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 speedfan ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 speedfan ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 sptd ( LockedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
17:10:09.0968 0988 tap0901 ( UnsignedFile.Multi.Generic ) - skipped by user
17:10:09.0968 0988 tap0901 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:10:10.0109 0988 \Device\Harddisk0\DR0\# - copied to quarantine
17:10:10.0109 0988 \Device\Harddisk0\DR0 - copied to quarantine
17:10:10.0125 0988 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - will be cured on reboot
17:10:10.0171 0988 \Device\Harddisk0\DR0 - ok
17:10:10.0171 0988 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - User select action: Cure
17:10:34.0656 2432 Deinitialize success

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Veľa vírusov - súrne

#23 Příspěvek od vyosek »

:arrow: Stahnete aswMBR http://public.avast.com/%7Egmerek/aswMBR.exe a ulozte jej na plochu.
  • Utilitu spustte a prikazte ji, at skenuje - klik na Scan
  • Kliknutim na Save log ulozte log aswMBR na plochu
  • Obsah logu aswMBR mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

-Matthew-
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 led 2012 15:35

Re: Veľa vírusov - súrne

#24 Příspěvek od -Matthew- »

Kde by sa ten log mal uložiť? Po kliknutí na "Save log" sa nič nedeje, nie je na ploche ani v C/ ako iné logy.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Veľa vírusov - súrne

#25 Příspěvek od vyosek »

Sken se jiz dokoncil? mel by byt vedle aswMBR pripadne se i otevrit :?:

:arrow: Stahnete SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte z uvedene stranky verzi dle sveho operacniho systemu (32(x86)bit ci 64(x64)bit)
  • Ulozte na plochu a spustte
  • Zvolte moznost Uninstall a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete Defogger http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Ulozte na plochu a spustte
  • Kliknete na Disable a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete MBR na plochu http://www2.gmer.net/mbr/mbr.exe ale nespoustejte

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    "%userprofile%\Desktop\mbr" -t -s
  • Kliknete na OK
  • Na plose se Vam vytvori log s nazvem mbr.txt, jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

-Matthew-
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 led 2012 15:35

Re: Veľa vírusov - súrne

#26 Příspěvek od -Matthew- »

Všetky kroky šli ako mali, tu je log:


Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST31000333AS rev.CC1H -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-16

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8ADB4AB8]
3 CLASSPNP[0xB8118FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000078[0x8AF0C360]
5 ACPI[0xB7F7F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IdeDeviceP2T0L0-16[0x8AE741B0]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
user & kernel MBR OK
copy of MBR has been found in sector 1953520065

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Veľa vírusov - súrne

#27 Příspěvek od vyosek »

Jeste jeden skript pro ComboFix - postup stejny - vytvorit CFScript a pretahnout nad CF

Kód: Vybrat vše

KillAll::

Mia::
c:\windows\system32\drivers\i8042prt.sys

Restore::
c:\windows\system32\drivers\i8042prt.sys

ClearJavaCache::

Reboot::
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

-Matthew-
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 led 2012 15:35

Re: Veľa vírusov - súrne

#28 Příspěvek od -Matthew- »

ComboFix 12-01-30.02 - Martin 01.02.2012 18:14:21.11.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.421.1033.18.3326.2536 [GMT 1:00]
Running from: c:\documents and settings\Martin\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Martin\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\i8042prt.sys . . . is infected!!
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
.
((((((((((((((((((((((((( Files Created from 2012-01-01 to 2012-02-01 )))))))))))))))))))))))))))))))
.
.
2012-02-01 16:10 . 2012-02-01 16:10 -------- d-----w- C:\TDSSKiller_Quarantine
2012-01-31 14:29 . 2012-01-31 14:29 -------- d-----w- C:\rsit
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-01 17:22 . 2009-05-07 12:19 16608 ----a-w- c:\windows\gdrv.sys
2011-12-21 15:38 . 2011-12-02 21:01 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 14:24 . 2010-12-20 18:51 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-02 15:37 . 2011-04-29 14:36 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-28 09:18 . CB75214525D36F923D3948DA3CD1562D . 1390080 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2008-04-28 . A55B8899D2EA2E800061BCFD456E34DC . 547328 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
.
[-] 2008-03-20 . F92D8964B5286DE225BD2B6BF89764BE . 578560 . . [5.1.2600.5508] . . c:\windows\system32\user32.dll
.
[-] 2008-08-18 . 4A90F51B778FA0157F60D206E8B37D2A . 1616384 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-04-13 . 18B0915F58A5342AB0F3D01D57261E32 . 267264 . . [5.1.2600.5512] . . c:\windows\regedit.exe
.
[-] 2008-03-20 . 31653CDF039C3F415B8D33F2D133E6AB . 1287168 . . [5.1.2600.5508] . . c:\windows\system32\ole32.dll
.
[-] 2008-04-28 . B5E8782D4AF1B3756F38E11E7C157BBE . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
[-] 2008-04-26 . BC298B78B311397B421D4D52B44B49EC . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
[-] 2008-04-28 . A913E1FF4C0BDA15FC542430182EB7B6 . 368640 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll
.
.
[-] 2011-07-12 . 83199EF88D691E730B80666E29F90D58 . 17408 . . [6.0.6002.18005] . . c:\windows\system32\midimap.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-01-31_16.08.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-01 17:22 . 2012-02-01 17:22 16384 c:\windows\temp\Perflib_Perfdata_7d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ESET"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-03-31 2145000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Visual Task Tips"="c:\program files\Windows7\VisualTaskTips\VisualTaskTips.exe" [2007-09-05 36352]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-27 16875008]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"D-Link AirPlus XtremeG DWL-G122"="c:\program files\D-Link\AirPlus XtremeG DWL-G122\AirGCFG.exe" [2008-12-18 1556480]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-18 76304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
.
c:\documents and settings\Martin\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2011-7-12 0]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-31 809488]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-18 22:30 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TPSvc]
TPSvc.dll [BU]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnalogClock]
2005-11-05 06:10 480256 ----a-w- c:\program files\Windows7\Analog Clock\AnalogClock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pie Dock]
2007-09-02 06:12 586240 ----a-w- c:\program files\Windows7\Windows 7 Pie Dock\Windows 7 Pie Dock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ------r- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TopDesk]
2007-06-20 08:21 1912832 ----a-w- c:\program files\Windows7\TopDesk\topdesk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UberIcon]
2006-05-21 03:43 180224 ----a-w- c:\program files\Windows7\UberIcon\UberIcon Manager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Viena Explorer]
2006-11-18 10:31 581632 ----a-w- c:\program files\Windows7\Vienna Explorer\Vienna Explorer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"StarWindServiceAE"=2 (0x2)
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"gupdate1c9cf1520895eca"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\game.dat"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\FlatOut2\\FlatOut2.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\patchget.dat"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Hry\\WoW\\WotLK\\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Hry\\WoW\\WotLK\\Launcher.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Programy\\Internet\\Fake IP\\FakeIP\\DC_IS.EXE"=
"c:\\Program Files\\ACSPMonitor\\ASMonitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\EA GAMES\\Command and Conquer Generals\\game.dat"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Pyro Studios\\Imperial Glory\\ImperialGlory.exe"=
"c:\\Documents and Settings\\Martin\\Desktop\\Hry\\Stronghold Crusader\\Stronghold Crusader.exe"=
"c:\\Program Files\\keyclone\\keyclone.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [7.12.2009 16:59 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [12.5.2010 17:01 59280]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [31.3.2010 7:22 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [31.3.2010 7:23 95872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [31.3.2010 7:23 810120]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [7.5.2009 13:19 80392]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [20.12.2010 19:51 652360]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [21.12.2009 14:46 4096]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [20.12.2010 19:51 20464]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [24.5.2009 10:12 47360]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [7.12.2009 16:59 61328]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [19.8.2010 22:56 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [19.8.2010 22:56 8456]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 wip0202;Wippien Network Adapter;c:\windows\system32\drivers\wip0202.sys [22.9.2011 10:50 23904]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11.7.2008 1:28 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10.7.2008 1:49 242712]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11.7.2008 1:28 369688]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do programu Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Martin\Application Data\Mozilla\Firefox\Profiles\prrbkrkl.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-01 18:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\SETUPAPI.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\system32\sfc_os.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
.
- - - - - - - > 'lsass.exe'(836)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(2144)
c:\program files\Windows7\VisualTaskTips\VttHooks.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msctfime.ime
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2012-02-01 18:27:27 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-01 17:27
ComboFix2.txt 2012-01-31 20:40
ComboFix3.txt 2012-01-31 16:10
.
Pre-Run: 278 924 181 504 bytes free
Post-Run: 278 904 524 800 bytes free
.
- - End Of File - - 9607F7A252286C5AE3C2EBC4CAE439D1

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Veľa vírusov - súrne

#29 Příspěvek od vyosek »

Co nas pacient? Mate po ruce instalacni CD od windows :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

-Matthew-
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 led 2012 15:35

Re: Veľa vírusov - súrne

#30 Příspěvek od -Matthew- »

vyosek píše:Co nas pacient? Mate po ruce instalacni CD od windows :???:
Tak čo sa týka PC tak ide úplne v pohode, žiadne infiltrácie nezobrazuje ani nič podobne. :)

Ale ohladom toho CD bude asi problém, PC som nepreinštaloval už asi 2 a pol roka, možno aj 3.. takže budem musieť ho pohladať, naozaj neviem či ho budem mať ešte, pretože sme medzitým aj prestavali dom a s celou mojou zbierkou CD a DVD robil poriadok syn a žena, takže nie som si istý, či bude, keďže polovica tejto zbierky je už vyhodená. :cry:

Nie je ešte niečo v poriadku alebo čo sa vám nezdá na tom? Potrebujeme súrne to CD?

Odpovědět