
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
nelze se dostat na stranky antiviru a antivir se neaktulizuj
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
nelze se dostat na stranky antiviru a antivir se neaktulizuj
Dobrý den,
mám od zname na odvirovani NTB a problem je, že se nedokazu dostat na zadne stranky antiviru, http://www.microsoft.com, http://www.grisoft.cz, eset.cz a další...
moc prosím o radu co tím...
dočetl jsem se že sem musím vložit log z hijack tak zde je:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:44:37, on 12.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\eISIS\servers\postgresql\bin\pg_ctl.exe
c:\eISIS\servers\tomcat\bin\tomcat5.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
C:\Program Files\Firebird\bin\fbguard.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Firebird\bin\fbserver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=66022
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Kooperativa - PDF Server.lnk = C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: eISIS PostgreSQL Database Server (eISISPostgreSQL) - PostgreSQL Global Development Group - c:\eISIS\servers\postgresql\bin\pg_ctl.exe
O23 - Service: eISIS Tomcat (eISISTomcat) - Apache Software Foundation - c:\eISIS\servers\tomcat\bin\tomcat5.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
--
End of file - 8672 bytes
mockrat děkuji
mám od zname na odvirovani NTB a problem je, že se nedokazu dostat na zadne stranky antiviru, http://www.microsoft.com, http://www.grisoft.cz, eset.cz a další...
moc prosím o radu co tím...
dočetl jsem se že sem musím vložit log z hijack tak zde je:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:44:37, on 12.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\eISIS\servers\postgresql\bin\pg_ctl.exe
c:\eISIS\servers\tomcat\bin\tomcat5.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
C:\Program Files\Firebird\bin\fbguard.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Firebird\bin\fbserver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
c:\eISIS\servers\postgresql\bin\postgres.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=66022
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Kooperativa - PDF Server.lnk = C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: eISIS PostgreSQL Database Server (eISISPostgreSQL) - PostgreSQL Global Development Group - c:\eISIS\servers\postgresql\bin\pg_ctl.exe
O23 - Service: eISIS Tomcat (eISISTomcat) - Apache Software Foundation - c:\eISIS\servers\tomcat\bin\tomcat5.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
--
End of file - 8672 bytes
mockrat děkuji
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: nelze se dostat na stranky antiviru a antivir se neaktul
zdravim.
vloz sem log z RSIT.
http://forum.viry.cz/viewtopic.php?f=13&t=105895
Zle si cital,dočetl jsem se že sem musím vložit log z hijack tak zde je:

http://forum.viry.cz/viewtopic.php?f=13&t=105895
Re: nelze se dostat na stranky antiviru a antivir se neaktul
omlouvám se 
Logfile of random's system information tool 1.09 (written by random/random)
Run by Asus at 2012-02-12 16:04:01
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 2 GB (3%) free of 74 GB
Total RAM: 1015 MB (31% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\MpIdleTask.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-07-15 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"AsusACPIServer"=C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe [2009-04-16 630784]
"AsusEPCMonitor"=C:\Program Files\EeePC\ACPI\AsEPCMon.exe [2009-03-13 98304]
"AsusTray"=C:\Program Files\EeePC\ACPI\AsTray.exe [2009-04-16 118784]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe []
"snp2uvc"=C:\WINDOWS\vsnp2uvc.exe []
"LiveUpdate"=C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [2009-06-25 712704]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-04-27 17881088]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2009-07-27 397312]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Documents and Settings\Asus\Nabídka Start\Programy\Po spuštění
Kooperativa - PDF Server.lnk - C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Documents and Settings\Asus\Local Settings\Temp\7ZipSfx.000\jre\bin\javaw.exe"="C:\Documents and Settings\Asus\Local Settings\Temp\7ZipSfx.000\jre\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\SIMS\RACER\racer.exe"="C:\SIMS\RACER\racer.exe:*:Enabled:racer"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Games\Paintball2\paintball2.exe"="C:\Games\Paintball2\paintball2.exe:*:Enabled:paintball2"
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe"="C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe:*:Enabled:Kalk_ziv"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-02-12 16:04:05 ----DC---- C:\Program Files\trend micro
2012-02-12 16:04:01 ----DC---- C:\rsit
2012-02-12 15:19:13 ----DC---- C:\Program Files\ESET
2012-02-12 15:15:49 ----AC---- C:\WINDOWS\ntbtlog.txt
2012-02-12 14:43:34 ----DC---- C:\Program Files\HijackThis
2012-02-12 14:36:07 ----AC---- C:\WINDOWS\system32\hidserv.dll
2012-02-09 13:29:09 ----DC---- C:\Program Files\Microsoft Security Client
2012-02-09 12:55:07 ----DC---- C:\WINDOWS\system32\Atheros_L1e
2012-02-09 12:52:10 ----AC---- C:\WINDOWS\system32\drivers\l1c51x86.sys
2012-01-28 12:04:11 ----DC---- C:\eISIS
======List of files/folders modified in the last 1 month======
2012-02-12 16:04:05 ----DC---- C:\Program Files
2012-02-12 16:03:40 ----DC---- C:\WINDOWS\Temp
2012-02-12 16:03:40 ----DC---- C:\WINDOWS\Prefetch
2012-02-12 16:00:47 ----SDC---- C:\WINDOWS\Tasks
2012-02-12 15:56:20 ----DC---- C:\WINDOWS\system32\CatRoot2
2012-02-12 15:54:57 ----DC---- C:\WINDOWS\system32
2012-02-12 15:19:15 ----SDC---- C:\WINDOWS\Downloaded Program Files
2012-02-12 15:16:45 ----DC---- C:\Documents and Settings
2012-02-12 15:15:49 ----DC---- C:\WINDOWS
2012-02-12 15:15:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-02-12 14:36:15 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-02-12 14:35:54 ----HDC---- C:\WINDOWS\inf
2012-02-09 13:29:57 ----SHDC---- C:\WINDOWS\Installer
2012-02-09 13:29:33 ----DC---- C:\WINDOWS\system32\drivers
2012-02-09 13:29:29 ----SDC---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-02-09 13:27:21 ----DC---- C:\Program Files\Norton Internet Security
2012-02-09 13:27:17 ----SHD---- C:\System Volume Information
2012-02-09 13:27:16 ----DC---- C:\Program Files\Google
2012-02-09 13:27:16 ----DC---- C:\Program Files\Common Files
2012-02-09 13:26:22 ----DC---- C:\Documents and Settings\All Users\Data aplikací\Norton
2012-02-09 12:59:37 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-02-09 12:55:04 ----HDC---- C:\Program Files\InstallShield Installation Information
2012-01-24 14:36:56 ----DC---- C:\Program Files\Simulace_PCS
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\drivers\iaStor.sys [2008-09-12 327192]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-04-27 5074944]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1c51x86.sys [2009-03-02 38912]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2009-07-10 1015424]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2009-03-13 1759616]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 uvclf;uvclf; C:\WINDOWS\system32\DRIVERS\uvclf.sys [2008-11-19 39040]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 eISISPostgreSQL;eISIS PostgreSQL Database Server; c:\eISIS\servers\postgresql\bin\pg_ctl.exe [2008-01-04 79948]
R2 eISISTomcat;eISIS Tomcat; c:\eISIS\servers\tomcat\bin\tomcat5.exe [2007-08-24 57344]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-25 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-25 135664]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------

Logfile of random's system information tool 1.09 (written by random/random)
Run by Asus at 2012-02-12 16:04:01
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 2 GB (3%) free of 74 GB
Total RAM: 1015 MB (31% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\MpIdleTask.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-07-15 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"AsusACPIServer"=C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe [2009-04-16 630784]
"AsusEPCMonitor"=C:\Program Files\EeePC\ACPI\AsEPCMon.exe [2009-03-13 98304]
"AsusTray"=C:\Program Files\EeePC\ACPI\AsTray.exe [2009-04-16 118784]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe []
"snp2uvc"=C:\WINDOWS\vsnp2uvc.exe []
"LiveUpdate"=C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [2009-06-25 712704]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-04-27 17881088]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2009-07-27 397312]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Documents and Settings\Asus\Nabídka Start\Programy\Po spuštění
Kooperativa - PDF Server.lnk - C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Documents and Settings\Asus\Local Settings\Temp\7ZipSfx.000\jre\bin\javaw.exe"="C:\Documents and Settings\Asus\Local Settings\Temp\7ZipSfx.000\jre\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\SIMS\RACER\racer.exe"="C:\SIMS\RACER\racer.exe:*:Enabled:racer"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Games\Paintball2\paintball2.exe"="C:\Games\Paintball2\paintball2.exe:*:Enabled:paintball2"
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe"="C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe:*:Enabled:Kalk_ziv"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-02-12 16:04:05 ----DC---- C:\Program Files\trend micro
2012-02-12 16:04:01 ----DC---- C:\rsit
2012-02-12 15:19:13 ----DC---- C:\Program Files\ESET
2012-02-12 15:15:49 ----AC---- C:\WINDOWS\ntbtlog.txt
2012-02-12 14:43:34 ----DC---- C:\Program Files\HijackThis
2012-02-12 14:36:07 ----AC---- C:\WINDOWS\system32\hidserv.dll
2012-02-09 13:29:09 ----DC---- C:\Program Files\Microsoft Security Client
2012-02-09 12:55:07 ----DC---- C:\WINDOWS\system32\Atheros_L1e
2012-02-09 12:52:10 ----AC---- C:\WINDOWS\system32\drivers\l1c51x86.sys
2012-01-28 12:04:11 ----DC---- C:\eISIS
======List of files/folders modified in the last 1 month======
2012-02-12 16:04:05 ----DC---- C:\Program Files
2012-02-12 16:03:40 ----DC---- C:\WINDOWS\Temp
2012-02-12 16:03:40 ----DC---- C:\WINDOWS\Prefetch
2012-02-12 16:00:47 ----SDC---- C:\WINDOWS\Tasks
2012-02-12 15:56:20 ----DC---- C:\WINDOWS\system32\CatRoot2
2012-02-12 15:54:57 ----DC---- C:\WINDOWS\system32
2012-02-12 15:19:15 ----SDC---- C:\WINDOWS\Downloaded Program Files
2012-02-12 15:16:45 ----DC---- C:\Documents and Settings
2012-02-12 15:15:49 ----DC---- C:\WINDOWS
2012-02-12 15:15:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-02-12 14:36:15 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-02-12 14:35:54 ----HDC---- C:\WINDOWS\inf
2012-02-09 13:29:57 ----SHDC---- C:\WINDOWS\Installer
2012-02-09 13:29:33 ----DC---- C:\WINDOWS\system32\drivers
2012-02-09 13:29:29 ----SDC---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-02-09 13:27:21 ----DC---- C:\Program Files\Norton Internet Security
2012-02-09 13:27:17 ----SHD---- C:\System Volume Information
2012-02-09 13:27:16 ----DC---- C:\Program Files\Google
2012-02-09 13:27:16 ----DC---- C:\Program Files\Common Files
2012-02-09 13:26:22 ----DC---- C:\Documents and Settings\All Users\Data aplikací\Norton
2012-02-09 12:59:37 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-02-09 12:55:04 ----HDC---- C:\Program Files\InstallShield Installation Information
2012-01-24 14:36:56 ----DC---- C:\Program Files\Simulace_PCS
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\drivers\iaStor.sys [2008-09-12 327192]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-04-27 5074944]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1c51x86.sys [2009-03-02 38912]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2009-07-10 1015424]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2009-03-13 1759616]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 uvclf;uvclf; C:\WINDOWS\system32\DRIVERS\uvclf.sys [2008-11-19 39040]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 eISISPostgreSQL;eISIS PostgreSQL Database Server; c:\eISIS\servers\postgresql\bin\pg_ctl.exe [2008-01-04 79948]
R2 eISISTomcat;eISIS Tomcat; c:\eISIS\servers\tomcat\bin\tomcat5.exe [2007-08-24 57344]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-25 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-25 135664]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: nelze se dostat na stranky antiviru a antivir se neaktul
jinak nedostal jsem se ani na stranku ke stazeni RSIT 

- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: nelze se dostat na stranky antiviru a antivir se neaktul
Ok tak vteda skus ci nemas nastavene v IE,proxy.
NAVOD
Ak mas zrus, a pokracuj RogueKiller.
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
Spust
Vyber polozku Prehľadať (Scan) a potom Zmazať (Deletion) a nasledne Sprava (Report) - otvorí sa log, ten sem vloz.
NAVOD
Ak mas zrus, a pokracuj RogueKiller.
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
Spust
Vyber polozku Prehľadať (Scan) a potom Zmazať (Deletion) a nasledne Sprava (Report) - otvorí sa log, ten sem vloz.
Re: nelze se dostat na stranky antiviru a antivir se neaktul
RogueKiller V7.0.4 [02/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Asus [Admin rights]
Mode: Remove -- Date : 02/12/2012 17:33:41
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST9160314AS +++++
--- User ---
[MBR] 9ee5cd48f8a9122385325ccc5a3706fe
[BSP] eb3131951ee8d2cc9a6e3dd5741c54e3 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 73790 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 151123455 | Size: 73782 Mo
2 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 302230845 | Size: 5004 Mo
3 - [XXXXXX] UNKNOWN (0xef) [VISIBLE] Offset (sectors): 312480315 | Size: 47 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt
jinak stále stejné ... nejde mi se dostat treba ani na to viruscasino co jsi odkazal ... jinak v nouzovym rezimu se dostanu kamkoliv ... v proxy nic neni
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Asus [Admin rights]
Mode: Remove -- Date : 02/12/2012 17:33:41
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST9160314AS +++++
--- User ---
[MBR] 9ee5cd48f8a9122385325ccc5a3706fe
[BSP] eb3131951ee8d2cc9a6e3dd5741c54e3 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 73790 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 151123455 | Size: 73782 Mo
2 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 302230845 | Size: 5004 Mo
3 - [XXXXXX] UNKNOWN (0xef) [VISIBLE] Offset (sectors): 312480315 | Size: 47 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt
jinak stále stejné ... nejde mi se dostat treba ani na to viruscasino co jsi odkazal ... jinak v nouzovym rezimu se dostanu kamkoliv ... v proxy nic neni
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: nelze se dostat na stranky antiviru a antivir se neaktul
ok, zostan v nudzovom rezime.
http://support.kaspersky.com/downloads/ ... killer.exe
Stiahni a spust, report log vloz sem.
http://support.kaspersky.com/downloads/ ... killer.exe
Stiahni a spust, report log vloz sem.
Re: nelze se dostat na stranky antiviru a antivir se neaktul
17:59:27.0437 1352 TDSS rootkit removing tool 2.7.11.0 Feb 9 2012 10:12:57
17:59:27.0515 1352 ============================================================
17:59:27.0515 1352 Current date / time: 2012/02/12 17:59:27.0515
17:59:27.0515 1352 SystemInfo:
17:59:27.0515 1352
17:59:27.0515 1352 OS Version: 5.1.2600 ServicePack: 3.0
17:59:27.0515 1352 Product type: Workstation
17:59:27.0515 1352 ComputerName: N-WMOWLZRITS9B8
17:59:27.0515 1352 UserName: Administrator
17:59:27.0515 1352 Windows directory: C:\WINDOWS
17:59:27.0515 1352 System windows directory: C:\WINDOWS
17:59:27.0515 1352 Processor architecture: Intel x86
17:59:27.0515 1352 Number of processors: 2
17:59:27.0515 1352 Page size: 0x1000
17:59:27.0515 1352 Boot type: Safe boot with network
17:59:27.0515 1352 ============================================================
17:59:29.0281 1352 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:59:29.0281 1352 \Device\Harddisk0\DR0:
17:59:29.0281 1352 MBR used
17:59:29.0281 1352 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x901F5C0
17:59:29.0281 1352 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x901F5FF, BlocksNum 0x901B73E
17:59:29.0359 1352 Initialize success
17:59:29.0359 1352 ============================================================
17:59:31.0687 1448 ============================================================
17:59:31.0687 1448 Scan started
17:59:31.0687 1448 Mode: Manual;
17:59:31.0687 1448 ============================================================
17:59:32.0500 1448 Abiosdsk - ok
17:59:32.0531 1448 abp480n5 - ok
17:59:32.0562 1448 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:59:32.0578 1448 ACPI - ok
17:59:32.0625 1448 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
17:59:32.0640 1448 ACPIEC - ok
17:59:32.0656 1448 adpu160m - ok
17:59:32.0734 1448 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:59:32.0734 1448 aec - ok
17:59:32.0796 1448 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
17:59:32.0796 1448 AFD - ok
17:59:32.0812 1448 Aha154x - ok
17:59:32.0843 1448 aic78u2 - ok
17:59:32.0859 1448 aic78xx - ok
17:59:32.0921 1448 AliIde - ok
17:59:33.0031 1448 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys
17:59:33.0093 1448 Ambfilt - ok
17:59:33.0109 1448 amsint - ok
17:59:33.0171 1448 asc - ok
17:59:33.0203 1448 asc3350p - ok
17:59:33.0234 1448 asc3550 - ok
17:59:33.0328 1448 AsusACPI (12415a4b61ded200fe9932b47a35fa42) C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys
17:59:33.0328 1448 AsusACPI - ok
17:59:33.0390 1448 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:59:33.0390 1448 AsyncMac - ok
17:59:33.0421 1448 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys
17:59:33.0437 1448 atapi - ok
17:59:33.0437 1448 Atdisk - ok
17:59:33.0484 1448 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:59:33.0484 1448 Atmarpc - ok
17:59:33.0531 1448 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:59:33.0531 1448 audstub - ok
17:59:33.0593 1448 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:59:33.0593 1448 Beep - ok
17:59:33.0671 1448 btaudio - ok
17:59:33.0718 1448 BTDriver - ok
17:59:33.0750 1448 BTWDNDIS - ok
17:59:33.0781 1448 BTWUSB - ok
17:59:33.0843 1448 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:59:33.0843 1448 cbidf2k - ok
17:59:33.0890 1448 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:59:33.0890 1448 CCDECODE - ok
17:59:33.0906 1448 cd20xrnt - ok
17:59:33.0937 1448 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:59:33.0937 1448 Cdaudio - ok
17:59:33.0984 1448 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:59:33.0984 1448 Cdfs - ok
17:59:34.0015 1448 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:59:34.0015 1448 Cdrom - ok
17:59:34.0031 1448 Changer - ok
17:59:34.0125 1448 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
17:59:34.0125 1448 CmBatt - ok
17:59:34.0140 1448 CmdIde - ok
17:59:34.0171 1448 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
17:59:34.0171 1448 Compbatt - ok
17:59:34.0234 1448 Cpqarray - ok
17:59:34.0265 1448 dac2w2k - ok
17:59:34.0296 1448 dac960nt - ok
17:59:34.0343 1448 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:59:34.0343 1448 Disk - ok
17:59:34.0421 1448 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
17:59:34.0453 1448 dmboot - ok
17:59:34.0500 1448 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
17:59:34.0500 1448 dmio - ok
17:59:34.0531 1448 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:59:34.0531 1448 dmload - ok
17:59:34.0593 1448 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:59:34.0593 1448 DMusic - ok
17:59:34.0640 1448 dpti2o - ok
17:59:34.0687 1448 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:59:34.0687 1448 drmkaud - ok
17:59:34.0812 1448 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:59:34.0828 1448 Fastfat - ok
17:59:34.0875 1448 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
17:59:34.0875 1448 Fdc - ok
17:59:34.0906 1448 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
17:59:34.0906 1448 Fips - ok
17:59:34.0984 1448 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
17:59:34.0984 1448 Flpydisk - ok
17:59:35.0031 1448 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
17:59:35.0046 1448 FltMgr - ok
17:59:35.0093 1448 fssfltr (960f5e5e4e1f720465311ac68a99c2df) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
17:59:35.0109 1448 fssfltr - ok
17:59:35.0140 1448 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:59:35.0140 1448 Fs_Rec - ok
17:59:35.0187 1448 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:59:35.0203 1448 Ftdisk - ok
17:59:35.0234 1448 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:59:35.0234 1448 Gpc - ok
17:59:35.0328 1448 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
17:59:35.0328 1448 HDAudBus - ok
17:59:35.0375 1448 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:59:35.0375 1448 HidUsb - ok
17:59:35.0421 1448 hpn - ok
17:59:35.0500 1448 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:59:35.0515 1448 HTTP - ok
17:59:35.0546 1448 i2omgmt - ok
17:59:35.0562 1448 i2omp - ok
17:59:35.0625 1448 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:59:35.0640 1448 i8042prt - ok
17:59:35.0812 1448 ialm (0f68e2ec713f132ffb19e45415b09679) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
17:59:35.0968 1448 ialm - ok
17:59:36.0031 1448 iaStor (8ef427c54497c5f8a7a645990e4278c7) C:\WINDOWS\system32\drivers\iaStor.sys
17:59:36.0031 1448 iaStor - ok
17:59:36.0093 1448 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:59:36.0093 1448 Imapi - ok
17:59:36.0140 1448 ini910u - ok
17:59:36.0406 1448 IntcAzAudAddService (9037c8bd3e896d7f2803a171fdeaeef4) C:\WINDOWS\system32\drivers\RtkHDAud.sys
17:59:36.0562 1448 IntcAzAudAddService - ok
17:59:36.0578 1448 IntelIde - ok
17:59:36.0625 1448 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:59:36.0640 1448 intelppm - ok
17:59:36.0671 1448 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
17:59:36.0671 1448 Ip6Fw - ok
17:59:36.0703 1448 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:59:36.0703 1448 IpFilterDriver - ok
17:59:36.0718 1448 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:59:36.0718 1448 IpInIp - ok
17:59:36.0765 1448 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:59:36.0781 1448 IpNat - ok
17:59:36.0796 1448 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:59:36.0812 1448 IPSec - ok
17:59:36.0843 1448 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:59:36.0843 1448 IRENUM - ok
17:59:36.0906 1448 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:59:36.0906 1448 isapnp - ok
17:59:36.0968 1448 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:59:36.0968 1448 Kbdclass - ok
17:59:37.0015 1448 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:59:37.0031 1448 kmixer - ok
17:59:37.0093 1448 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:59:37.0093 1448 KSecDD - ok
17:59:37.0140 1448 L1c (6c8658587e91ea25b0fd2e71781ad228) C:\WINDOWS\system32\DRIVERS\l1c51x86.sys
17:59:37.0140 1448 L1c - ok
17:59:37.0187 1448 lbrtfdc - ok
17:59:37.0296 1448 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:59:37.0312 1448 mnmdd - ok
17:59:37.0343 1448 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
17:59:37.0359 1448 Modem - ok
17:59:37.0437 1448 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys
17:59:37.0500 1448 Monfilt - ok
17:59:37.0546 1448 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:59:37.0546 1448 Mouclass - ok
17:59:37.0609 1448 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:59:37.0609 1448 mouhid - ok
17:59:37.0687 1448 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:59:37.0687 1448 MountMgr - ok
17:59:37.0765 1448 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
17:59:37.0765 1448 MpFilter - ok
17:59:37.0781 1448 mraid35x - ok
17:59:37.0843 1448 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:59:37.0859 1448 MRxDAV - ok
17:59:37.0937 1448 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:59:37.0953 1448 MRxSmb - ok
17:59:38.0046 1448 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:59:38.0046 1448 Msfs - ok
17:59:38.0109 1448 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:59:38.0109 1448 MSKSSRV - ok
17:59:38.0140 1448 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:59:38.0140 1448 MSPCLOCK - ok
17:59:38.0171 1448 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:59:38.0171 1448 MSPQM - ok
17:59:38.0187 1448 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:59:38.0187 1448 mssmbios - ok
17:59:38.0218 1448 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
17:59:38.0218 1448 MSTEE - ok
17:59:38.0265 1448 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
17:59:38.0281 1448 Mup - ok
17:59:38.0312 1448 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:59:38.0312 1448 NABTSFEC - ok
17:59:38.0406 1448 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:59:38.0406 1448 NDIS - ok
17:59:38.0453 1448 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:59:38.0453 1448 NdisIP - ok
17:59:38.0500 1448 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:59:38.0500 1448 NdisTapi - ok
17:59:38.0546 1448 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:59:38.0546 1448 Ndisuio - ok
17:59:38.0640 1448 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:59:38.0656 1448 NdisWan - ok
17:59:38.0718 1448 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:59:38.0718 1448 NDProxy - ok
17:59:38.0765 1448 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:59:38.0781 1448 NetBIOS - ok
17:59:38.0843 1448 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:59:38.0859 1448 NetBT - ok
17:59:38.0953 1448 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:59:38.0953 1448 Npfs - ok
17:59:39.0031 1448 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:59:39.0062 1448 Ntfs - ok
17:59:39.0125 1448 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:59:39.0125 1448 Null - ok
17:59:39.0156 1448 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:59:39.0171 1448 NwlnkFlt - ok
17:59:39.0187 1448 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:59:39.0187 1448 NwlnkFwd - ok
17:59:39.0250 1448 Suspicious service (NoAccess): ouxhxq
17:59:39.0296 1448 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\drivers\Parport.sys
17:59:39.0296 1448 Parport - ok
17:59:39.0312 1448 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:59:39.0312 1448 PartMgr - ok
17:59:39.0359 1448 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
17:59:39.0359 1448 ParVdm - ok
17:59:39.0406 1448 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
17:59:39.0406 1448 PCI - ok
17:59:39.0421 1448 PCIDump - ok
17:59:39.0453 1448 PCIIde - ok
17:59:39.0515 1448 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:59:39.0515 1448 Pcmcia - ok
17:59:39.0531 1448 PDCOMP - ok
17:59:39.0562 1448 PDFRAME - ok
17:59:39.0593 1448 PDRELI - ok
17:59:39.0625 1448 PDRFRAME - ok
17:59:39.0640 1448 perc2 - ok
17:59:39.0671 1448 perc2hib - ok
17:59:39.0828 1448 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:59:39.0828 1448 PptpMiniport - ok
17:59:39.0859 1448 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:59:39.0859 1448 PSched - ok
17:59:39.0890 1448 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:59:39.0890 1448 Ptilink - ok
17:59:39.0906 1448 ql1080 - ok
17:59:39.0937 1448 Ql10wnt - ok
17:59:39.0968 1448 ql12160 - ok
17:59:39.0984 1448 ql1240 - ok
17:59:40.0015 1448 ql1280 - ok
17:59:40.0046 1448 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:59:40.0046 1448 RasAcd - ok
17:59:40.0078 1448 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:59:40.0078 1448 Rasl2tp - ok
17:59:40.0125 1448 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:59:40.0125 1448 RasPppoe - ok
17:59:40.0187 1448 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:59:40.0187 1448 Raspti - ok
17:59:40.0234 1448 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:59:40.0234 1448 Rdbss - ok
17:59:40.0265 1448 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:59:40.0265 1448 RDPCDD - ok
17:59:40.0343 1448 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
17:59:40.0359 1448 RDPWD - ok
17:59:40.0406 1448 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:59:40.0406 1448 redbook - ok
17:59:40.0546 1448 RT80x86 (97b59ce2cfbb0884a16ddd8f1781812b) C:\WINDOWS\system32\DRIVERS\RT2860.sys
17:59:40.0593 1448 RT80x86 - ok
17:59:40.0718 1448 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:59:40.0718 1448 Secdrv - ok
17:59:40.0796 1448 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\drivers\Serial.sys
17:59:40.0812 1448 Serial - ok
17:59:40.0906 1448 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:59:40.0906 1448 Sfloppy - ok
17:59:40.0953 1448 Simbad - ok
17:59:41.0000 1448 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:59:41.0000 1448 SLIP - ok
17:59:41.0187 1448 SNP2UVC (473f35e2a378b854731e67c377a3bea7) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
17:59:41.0250 1448 SNP2UVC - ok
17:59:41.0281 1448 Sparrow - ok
17:59:41.0359 1448 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:59:41.0359 1448 splitter - ok
17:59:41.0406 1448 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
17:59:41.0421 1448 sr - ok
17:59:41.0484 1448 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
17:59:41.0500 1448 Srv - ok
17:59:41.0578 1448 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:59:41.0578 1448 streamip - ok
17:59:41.0609 1448 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:59:41.0609 1448 swenum - ok
17:59:41.0656 1448 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:59:41.0671 1448 swmidi - ok
17:59:41.0687 1448 symc810 - ok
17:59:41.0718 1448 symc8xx - ok
17:59:41.0750 1448 sym_hi - ok
17:59:41.0765 1448 sym_u3 - ok
17:59:41.0812 1448 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:59:41.0828 1448 sysaudio - ok
17:59:41.0921 1448 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:59:41.0953 1448 Tcpip - ok
17:59:42.0000 1448 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:59:42.0000 1448 TDPIPE - ok
17:59:42.0015 1448 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:59:42.0015 1448 TDTCP - ok
17:59:42.0062 1448 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:59:42.0078 1448 TermDD - ok
17:59:42.0125 1448 TosIde - ok
17:59:42.0218 1448 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:59:42.0218 1448 Udfs - ok
17:59:42.0234 1448 ultra - ok
17:59:42.0312 1448 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:59:42.0328 1448 Update - ok
17:59:42.0375 1448 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:59:42.0375 1448 usbccgp - ok
17:59:42.0421 1448 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:59:42.0421 1448 usbehci - ok
17:59:42.0484 1448 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:59:42.0484 1448 usbhub - ok
17:59:42.0546 1448 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
17:59:42.0546 1448 usbprint - ok
17:59:42.0593 1448 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:59:42.0593 1448 usbscan - ok
17:59:42.0625 1448 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:59:42.0640 1448 usbstor - ok
17:59:42.0671 1448 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:59:42.0671 1448 usbuhci - ok
17:59:42.0734 1448 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
17:59:42.0750 1448 usbvideo - ok
17:59:42.0812 1448 uvclf (c019889035cdc1a06f2febc93cbb6897) C:\WINDOWS\system32\DRIVERS\uvclf.sys
17:59:42.0812 1448 uvclf - ok
17:59:42.0828 1448 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:59:42.0828 1448 VgaSave - ok
17:59:42.0859 1448 ViaIde - ok
17:59:42.0921 1448 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
17:59:42.0921 1448 VolSnap - ok
17:59:43.0015 1448 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:59:43.0031 1448 Wanarp - ok
17:59:43.0109 1448 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
17:59:43.0125 1448 Wdf01000 - ok
17:59:43.0140 1448 WDICA - ok
17:59:43.0218 1448 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:59:43.0218 1448 wdmaud - ok
17:59:43.0500 1448 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:59:43.0500 1448 WSTCODEC - ok
17:59:43.0562 1448 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:59:43.0578 1448 WudfPf - ok
17:59:43.0593 1448 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:59:43.0609 1448 WudfRd - ok
17:59:43.0750 1448 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
17:59:43.0968 1448 \Device\Harddisk0\DR0 - ok
17:59:43.0984 1448 Boot (0x1200) (b9b5c2effce87b74ea37c28109aed26d) \Device\Harddisk0\DR0\Partition0
17:59:43.0984 1448 \Device\Harddisk0\DR0\Partition0 - ok
17:59:44.0046 1448 Boot (0x1200) (d56a3b990eaa43c9bf7798a85cb5e097) \Device\Harddisk0\DR0\Partition1
17:59:44.0046 1448 \Device\Harddisk0\DR0\Partition1 - ok
17:59:44.0046 1448 ============================================================
17:59:44.0046 1448 Scan finished
17:59:44.0046 1448 ============================================================
17:59:44.0093 1440 Detected object count: 0
17:59:44.0093 1440 Actual detected object count: 0
nez jsi napsal tak jsem si vsiml, ze se mi spustil MS essentials security a povedlo se mu najít Conficker.C (coz podle wikipedie je presne muj problem) ... dokonce to vypada, ze ho i odstranil, na stranky esetu jsem se dostal
17:59:27.0515 1352 ============================================================
17:59:27.0515 1352 Current date / time: 2012/02/12 17:59:27.0515
17:59:27.0515 1352 SystemInfo:
17:59:27.0515 1352
17:59:27.0515 1352 OS Version: 5.1.2600 ServicePack: 3.0
17:59:27.0515 1352 Product type: Workstation
17:59:27.0515 1352 ComputerName: N-WMOWLZRITS9B8
17:59:27.0515 1352 UserName: Administrator
17:59:27.0515 1352 Windows directory: C:\WINDOWS
17:59:27.0515 1352 System windows directory: C:\WINDOWS
17:59:27.0515 1352 Processor architecture: Intel x86
17:59:27.0515 1352 Number of processors: 2
17:59:27.0515 1352 Page size: 0x1000
17:59:27.0515 1352 Boot type: Safe boot with network
17:59:27.0515 1352 ============================================================
17:59:29.0281 1352 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:59:29.0281 1352 \Device\Harddisk0\DR0:
17:59:29.0281 1352 MBR used
17:59:29.0281 1352 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x901F5C0
17:59:29.0281 1352 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x901F5FF, BlocksNum 0x901B73E
17:59:29.0359 1352 Initialize success
17:59:29.0359 1352 ============================================================
17:59:31.0687 1448 ============================================================
17:59:31.0687 1448 Scan started
17:59:31.0687 1448 Mode: Manual;
17:59:31.0687 1448 ============================================================
17:59:32.0500 1448 Abiosdsk - ok
17:59:32.0531 1448 abp480n5 - ok
17:59:32.0562 1448 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:59:32.0578 1448 ACPI - ok
17:59:32.0625 1448 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
17:59:32.0640 1448 ACPIEC - ok
17:59:32.0656 1448 adpu160m - ok
17:59:32.0734 1448 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:59:32.0734 1448 aec - ok
17:59:32.0796 1448 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
17:59:32.0796 1448 AFD - ok
17:59:32.0812 1448 Aha154x - ok
17:59:32.0843 1448 aic78u2 - ok
17:59:32.0859 1448 aic78xx - ok
17:59:32.0921 1448 AliIde - ok
17:59:33.0031 1448 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys
17:59:33.0093 1448 Ambfilt - ok
17:59:33.0109 1448 amsint - ok
17:59:33.0171 1448 asc - ok
17:59:33.0203 1448 asc3350p - ok
17:59:33.0234 1448 asc3550 - ok
17:59:33.0328 1448 AsusACPI (12415a4b61ded200fe9932b47a35fa42) C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys
17:59:33.0328 1448 AsusACPI - ok
17:59:33.0390 1448 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:59:33.0390 1448 AsyncMac - ok
17:59:33.0421 1448 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys
17:59:33.0437 1448 atapi - ok
17:59:33.0437 1448 Atdisk - ok
17:59:33.0484 1448 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:59:33.0484 1448 Atmarpc - ok
17:59:33.0531 1448 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:59:33.0531 1448 audstub - ok
17:59:33.0593 1448 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:59:33.0593 1448 Beep - ok
17:59:33.0671 1448 btaudio - ok
17:59:33.0718 1448 BTDriver - ok
17:59:33.0750 1448 BTWDNDIS - ok
17:59:33.0781 1448 BTWUSB - ok
17:59:33.0843 1448 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:59:33.0843 1448 cbidf2k - ok
17:59:33.0890 1448 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:59:33.0890 1448 CCDECODE - ok
17:59:33.0906 1448 cd20xrnt - ok
17:59:33.0937 1448 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:59:33.0937 1448 Cdaudio - ok
17:59:33.0984 1448 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:59:33.0984 1448 Cdfs - ok
17:59:34.0015 1448 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:59:34.0015 1448 Cdrom - ok
17:59:34.0031 1448 Changer - ok
17:59:34.0125 1448 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
17:59:34.0125 1448 CmBatt - ok
17:59:34.0140 1448 CmdIde - ok
17:59:34.0171 1448 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
17:59:34.0171 1448 Compbatt - ok
17:59:34.0234 1448 Cpqarray - ok
17:59:34.0265 1448 dac2w2k - ok
17:59:34.0296 1448 dac960nt - ok
17:59:34.0343 1448 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:59:34.0343 1448 Disk - ok
17:59:34.0421 1448 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
17:59:34.0453 1448 dmboot - ok
17:59:34.0500 1448 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
17:59:34.0500 1448 dmio - ok
17:59:34.0531 1448 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:59:34.0531 1448 dmload - ok
17:59:34.0593 1448 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:59:34.0593 1448 DMusic - ok
17:59:34.0640 1448 dpti2o - ok
17:59:34.0687 1448 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:59:34.0687 1448 drmkaud - ok
17:59:34.0812 1448 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:59:34.0828 1448 Fastfat - ok
17:59:34.0875 1448 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
17:59:34.0875 1448 Fdc - ok
17:59:34.0906 1448 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
17:59:34.0906 1448 Fips - ok
17:59:34.0984 1448 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
17:59:34.0984 1448 Flpydisk - ok
17:59:35.0031 1448 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
17:59:35.0046 1448 FltMgr - ok
17:59:35.0093 1448 fssfltr (960f5e5e4e1f720465311ac68a99c2df) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
17:59:35.0109 1448 fssfltr - ok
17:59:35.0140 1448 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:59:35.0140 1448 Fs_Rec - ok
17:59:35.0187 1448 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:59:35.0203 1448 Ftdisk - ok
17:59:35.0234 1448 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:59:35.0234 1448 Gpc - ok
17:59:35.0328 1448 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
17:59:35.0328 1448 HDAudBus - ok
17:59:35.0375 1448 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:59:35.0375 1448 HidUsb - ok
17:59:35.0421 1448 hpn - ok
17:59:35.0500 1448 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:59:35.0515 1448 HTTP - ok
17:59:35.0546 1448 i2omgmt - ok
17:59:35.0562 1448 i2omp - ok
17:59:35.0625 1448 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:59:35.0640 1448 i8042prt - ok
17:59:35.0812 1448 ialm (0f68e2ec713f132ffb19e45415b09679) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
17:59:35.0968 1448 ialm - ok
17:59:36.0031 1448 iaStor (8ef427c54497c5f8a7a645990e4278c7) C:\WINDOWS\system32\drivers\iaStor.sys
17:59:36.0031 1448 iaStor - ok
17:59:36.0093 1448 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:59:36.0093 1448 Imapi - ok
17:59:36.0140 1448 ini910u - ok
17:59:36.0406 1448 IntcAzAudAddService (9037c8bd3e896d7f2803a171fdeaeef4) C:\WINDOWS\system32\drivers\RtkHDAud.sys
17:59:36.0562 1448 IntcAzAudAddService - ok
17:59:36.0578 1448 IntelIde - ok
17:59:36.0625 1448 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:59:36.0640 1448 intelppm - ok
17:59:36.0671 1448 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
17:59:36.0671 1448 Ip6Fw - ok
17:59:36.0703 1448 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:59:36.0703 1448 IpFilterDriver - ok
17:59:36.0718 1448 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:59:36.0718 1448 IpInIp - ok
17:59:36.0765 1448 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:59:36.0781 1448 IpNat - ok
17:59:36.0796 1448 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:59:36.0812 1448 IPSec - ok
17:59:36.0843 1448 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:59:36.0843 1448 IRENUM - ok
17:59:36.0906 1448 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:59:36.0906 1448 isapnp - ok
17:59:36.0968 1448 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:59:36.0968 1448 Kbdclass - ok
17:59:37.0015 1448 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:59:37.0031 1448 kmixer - ok
17:59:37.0093 1448 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:59:37.0093 1448 KSecDD - ok
17:59:37.0140 1448 L1c (6c8658587e91ea25b0fd2e71781ad228) C:\WINDOWS\system32\DRIVERS\l1c51x86.sys
17:59:37.0140 1448 L1c - ok
17:59:37.0187 1448 lbrtfdc - ok
17:59:37.0296 1448 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:59:37.0312 1448 mnmdd - ok
17:59:37.0343 1448 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
17:59:37.0359 1448 Modem - ok
17:59:37.0437 1448 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys
17:59:37.0500 1448 Monfilt - ok
17:59:37.0546 1448 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:59:37.0546 1448 Mouclass - ok
17:59:37.0609 1448 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:59:37.0609 1448 mouhid - ok
17:59:37.0687 1448 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:59:37.0687 1448 MountMgr - ok
17:59:37.0765 1448 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
17:59:37.0765 1448 MpFilter - ok
17:59:37.0781 1448 mraid35x - ok
17:59:37.0843 1448 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:59:37.0859 1448 MRxDAV - ok
17:59:37.0937 1448 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:59:37.0953 1448 MRxSmb - ok
17:59:38.0046 1448 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:59:38.0046 1448 Msfs - ok
17:59:38.0109 1448 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:59:38.0109 1448 MSKSSRV - ok
17:59:38.0140 1448 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:59:38.0140 1448 MSPCLOCK - ok
17:59:38.0171 1448 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:59:38.0171 1448 MSPQM - ok
17:59:38.0187 1448 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:59:38.0187 1448 mssmbios - ok
17:59:38.0218 1448 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
17:59:38.0218 1448 MSTEE - ok
17:59:38.0265 1448 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
17:59:38.0281 1448 Mup - ok
17:59:38.0312 1448 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:59:38.0312 1448 NABTSFEC - ok
17:59:38.0406 1448 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:59:38.0406 1448 NDIS - ok
17:59:38.0453 1448 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:59:38.0453 1448 NdisIP - ok
17:59:38.0500 1448 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:59:38.0500 1448 NdisTapi - ok
17:59:38.0546 1448 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:59:38.0546 1448 Ndisuio - ok
17:59:38.0640 1448 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:59:38.0656 1448 NdisWan - ok
17:59:38.0718 1448 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:59:38.0718 1448 NDProxy - ok
17:59:38.0765 1448 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:59:38.0781 1448 NetBIOS - ok
17:59:38.0843 1448 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:59:38.0859 1448 NetBT - ok
17:59:38.0953 1448 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:59:38.0953 1448 Npfs - ok
17:59:39.0031 1448 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:59:39.0062 1448 Ntfs - ok
17:59:39.0125 1448 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:59:39.0125 1448 Null - ok
17:59:39.0156 1448 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:59:39.0171 1448 NwlnkFlt - ok
17:59:39.0187 1448 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:59:39.0187 1448 NwlnkFwd - ok
17:59:39.0250 1448 Suspicious service (NoAccess): ouxhxq
17:59:39.0296 1448 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\drivers\Parport.sys
17:59:39.0296 1448 Parport - ok
17:59:39.0312 1448 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:59:39.0312 1448 PartMgr - ok
17:59:39.0359 1448 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
17:59:39.0359 1448 ParVdm - ok
17:59:39.0406 1448 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
17:59:39.0406 1448 PCI - ok
17:59:39.0421 1448 PCIDump - ok
17:59:39.0453 1448 PCIIde - ok
17:59:39.0515 1448 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:59:39.0515 1448 Pcmcia - ok
17:59:39.0531 1448 PDCOMP - ok
17:59:39.0562 1448 PDFRAME - ok
17:59:39.0593 1448 PDRELI - ok
17:59:39.0625 1448 PDRFRAME - ok
17:59:39.0640 1448 perc2 - ok
17:59:39.0671 1448 perc2hib - ok
17:59:39.0828 1448 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:59:39.0828 1448 PptpMiniport - ok
17:59:39.0859 1448 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:59:39.0859 1448 PSched - ok
17:59:39.0890 1448 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:59:39.0890 1448 Ptilink - ok
17:59:39.0906 1448 ql1080 - ok
17:59:39.0937 1448 Ql10wnt - ok
17:59:39.0968 1448 ql12160 - ok
17:59:39.0984 1448 ql1240 - ok
17:59:40.0015 1448 ql1280 - ok
17:59:40.0046 1448 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:59:40.0046 1448 RasAcd - ok
17:59:40.0078 1448 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:59:40.0078 1448 Rasl2tp - ok
17:59:40.0125 1448 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:59:40.0125 1448 RasPppoe - ok
17:59:40.0187 1448 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:59:40.0187 1448 Raspti - ok
17:59:40.0234 1448 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:59:40.0234 1448 Rdbss - ok
17:59:40.0265 1448 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:59:40.0265 1448 RDPCDD - ok
17:59:40.0343 1448 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
17:59:40.0359 1448 RDPWD - ok
17:59:40.0406 1448 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:59:40.0406 1448 redbook - ok
17:59:40.0546 1448 RT80x86 (97b59ce2cfbb0884a16ddd8f1781812b) C:\WINDOWS\system32\DRIVERS\RT2860.sys
17:59:40.0593 1448 RT80x86 - ok
17:59:40.0718 1448 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:59:40.0718 1448 Secdrv - ok
17:59:40.0796 1448 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\drivers\Serial.sys
17:59:40.0812 1448 Serial - ok
17:59:40.0906 1448 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:59:40.0906 1448 Sfloppy - ok
17:59:40.0953 1448 Simbad - ok
17:59:41.0000 1448 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:59:41.0000 1448 SLIP - ok
17:59:41.0187 1448 SNP2UVC (473f35e2a378b854731e67c377a3bea7) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
17:59:41.0250 1448 SNP2UVC - ok
17:59:41.0281 1448 Sparrow - ok
17:59:41.0359 1448 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:59:41.0359 1448 splitter - ok
17:59:41.0406 1448 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
17:59:41.0421 1448 sr - ok
17:59:41.0484 1448 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
17:59:41.0500 1448 Srv - ok
17:59:41.0578 1448 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:59:41.0578 1448 streamip - ok
17:59:41.0609 1448 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:59:41.0609 1448 swenum - ok
17:59:41.0656 1448 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:59:41.0671 1448 swmidi - ok
17:59:41.0687 1448 symc810 - ok
17:59:41.0718 1448 symc8xx - ok
17:59:41.0750 1448 sym_hi - ok
17:59:41.0765 1448 sym_u3 - ok
17:59:41.0812 1448 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:59:41.0828 1448 sysaudio - ok
17:59:41.0921 1448 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:59:41.0953 1448 Tcpip - ok
17:59:42.0000 1448 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:59:42.0000 1448 TDPIPE - ok
17:59:42.0015 1448 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:59:42.0015 1448 TDTCP - ok
17:59:42.0062 1448 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:59:42.0078 1448 TermDD - ok
17:59:42.0125 1448 TosIde - ok
17:59:42.0218 1448 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:59:42.0218 1448 Udfs - ok
17:59:42.0234 1448 ultra - ok
17:59:42.0312 1448 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:59:42.0328 1448 Update - ok
17:59:42.0375 1448 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:59:42.0375 1448 usbccgp - ok
17:59:42.0421 1448 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:59:42.0421 1448 usbehci - ok
17:59:42.0484 1448 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:59:42.0484 1448 usbhub - ok
17:59:42.0546 1448 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
17:59:42.0546 1448 usbprint - ok
17:59:42.0593 1448 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:59:42.0593 1448 usbscan - ok
17:59:42.0625 1448 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:59:42.0640 1448 usbstor - ok
17:59:42.0671 1448 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:59:42.0671 1448 usbuhci - ok
17:59:42.0734 1448 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
17:59:42.0750 1448 usbvideo - ok
17:59:42.0812 1448 uvclf (c019889035cdc1a06f2febc93cbb6897) C:\WINDOWS\system32\DRIVERS\uvclf.sys
17:59:42.0812 1448 uvclf - ok
17:59:42.0828 1448 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:59:42.0828 1448 VgaSave - ok
17:59:42.0859 1448 ViaIde - ok
17:59:42.0921 1448 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
17:59:42.0921 1448 VolSnap - ok
17:59:43.0015 1448 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:59:43.0031 1448 Wanarp - ok
17:59:43.0109 1448 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
17:59:43.0125 1448 Wdf01000 - ok
17:59:43.0140 1448 WDICA - ok
17:59:43.0218 1448 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:59:43.0218 1448 wdmaud - ok
17:59:43.0500 1448 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:59:43.0500 1448 WSTCODEC - ok
17:59:43.0562 1448 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:59:43.0578 1448 WudfPf - ok
17:59:43.0593 1448 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:59:43.0609 1448 WudfRd - ok
17:59:43.0750 1448 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
17:59:43.0968 1448 \Device\Harddisk0\DR0 - ok
17:59:43.0984 1448 Boot (0x1200) (b9b5c2effce87b74ea37c28109aed26d) \Device\Harddisk0\DR0\Partition0
17:59:43.0984 1448 \Device\Harddisk0\DR0\Partition0 - ok
17:59:44.0046 1448 Boot (0x1200) (d56a3b990eaa43c9bf7798a85cb5e097) \Device\Harddisk0\DR0\Partition1
17:59:44.0046 1448 \Device\Harddisk0\DR0\Partition1 - ok
17:59:44.0046 1448 ============================================================
17:59:44.0046 1448 Scan finished
17:59:44.0046 1448 ============================================================
17:59:44.0093 1440 Detected object count: 0
17:59:44.0093 1440 Actual detected object count: 0
nez jsi napsal tak jsem si vsiml, ze se mi spustil MS essentials security a povedlo se mu najít Conficker.C (coz podle wikipedie je presne muj problem) ... dokonce to vypada, ze ho i odstranil, na stranky esetu jsem se dostal
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: nelze se dostat na stranky antiviru a antivir se neaktul
No conficker urcite neodstranil, takze spravis vsetko ako napisem
1:Stiahnuť nástroj KidoKiller a uloz na disk C:\
http://support.kaspersky.com/downloads/utils/kk.zip
Pripojte všetky vymeniteľné média,ktoré používate cez USB.
Otvorte príkazový riadok a zadáme príkaz cd\ [enter]
Zadať cestu k súboru kk.exe. C:\kk.exe -a [enter]
Počkajte až do konca skenovania a dezinfekcie .
2:Stiahnuť na plochu FixDownadup
http://download.viry.cz/removers/FixDownadup.exe
Spustime FixDownadup
Počkajte až do konca skenovania a dezinfekcie .
Nainštalujeme Microsoft záplaty,podla operačného systému
http://www.microsoft.com/technet/securi ... 8-067.mspx
Stiahnite si prosím USBFIX a uložte ho na plochu.
http://www.commentcamarche.net/download ... 838-usbfix
2: Pripojte Všetky vymeniteľné médiá, ktoré používate cez USB.
3: Spustite USBFix (win7 a Vista pravý klik spustiť Ako správca.)
4: Stlačte gombík (Suppression, Deletion)
5: Po pripojení Všetkých vymeniteľných médii, ktorý používate cez USB, dajte OK
6: Pri analýze plocha zmizne, je to normálne
7: Správa bude vytvorená v tejto ceste: C:\USBFix.txt
Vloz sem
Stiahnes combofix na plochu, podla navodu spust, log vloz sem,
http://www.bleepingcomputer.com/combofi ... t-combofix
Vsetko rob v nudzovom rezime a nezabudni pripojit vsetko co sa pouziva cez USB.
Podrobny Navod
1:Stiahnuť nástroj KidoKiller a uloz na disk C:\
http://support.kaspersky.com/downloads/utils/kk.zip
Pripojte všetky vymeniteľné média,ktoré používate cez USB.
Otvorte príkazový riadok a zadáme príkaz cd\ [enter]
Zadať cestu k súboru kk.exe. C:\kk.exe -a [enter]
Počkajte až do konca skenovania a dezinfekcie .
2:Stiahnuť na plochu FixDownadup
http://download.viry.cz/removers/FixDownadup.exe
Spustime FixDownadup
Počkajte až do konca skenovania a dezinfekcie .
Nainštalujeme Microsoft záplaty,podla operačného systému
http://www.microsoft.com/technet/securi ... 8-067.mspx
Stiahnite si prosím USBFIX a uložte ho na plochu.
http://www.commentcamarche.net/download ... 838-usbfix
2: Pripojte Všetky vymeniteľné médiá, ktoré používate cez USB.
3: Spustite USBFix (win7 a Vista pravý klik spustiť Ako správca.)
4: Stlačte gombík (Suppression, Deletion)
5: Po pripojení Všetkých vymeniteľných médii, ktorý používate cez USB, dajte OK
6: Pri analýze plocha zmizne, je to normálne
7: Správa bude vytvorená v tejto ceste: C:\USBFix.txt
Vloz sem
Stiahnes combofix na plochu, podla navodu spust, log vloz sem,
http://www.bleepingcomputer.com/combofi ... t-combofix
Vsetko rob v nudzovom rezime a nezabudni pripojit vsetko co sa pouziva cez USB.
Podrobny Navod
Re: nelze se dostat na stranky antiviru a antivir se neaktul
USBFIX ... nemam co pripojit, dostal jsem jen NTB ... nicmene diky te aktulizaci z MS by mel byt system vuci tomuto viru chranen ne?
############################## | UsbFix V 7.081 | [Deletion]
User: Administrator (Administrator) # N-WMOWLZRITS9B8
Updated 05/02/2012 by El Desaparecido
Started at 19:03:56 | 12/02/2012
Website: http://eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.html
Contact: contact@eldesaparecido.com
PC: ASUSTeK Computer INC. (1001HA) (X86-based PC) # Notebook
CPU: Intel(R) Atom(TM) CPU N270 @ 1.60GHz (1599)
RAM -> [ Total : 1015 | Free : 555 ]
BIOS: BIOS Date: 02/26/10 09:16:31 Ver: 08.00.12
BOOT: Fail-safe with network boot
OS: Microsoft Windows XP Home Edition (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 72 Gb (2 Mb free - 3%) [] # NTFS
D:\ -> Fixed drive # 72 Gb (71 Mb free - 99%) [] # NTFS
################## | Active Processes |
C:\WINDOWS\System32\smss.exe (384)
C:\WINDOWS\system32\winlogon.exe (636)
C:\WINDOWS\system32\services.exe (680)
C:\WINDOWS\system32\lsass.exe (692)
C:\WINDOWS\system32\svchost.exe (848)
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (976)
C:\WINDOWS\system32\svchost.exe (1096)
C:\WINDOWS\Explorer.EXE (1436)
C:\Program Files\Internet Explorer\iexplore.exe (1984)
C:\Program Files\Internet Explorer\iexplore.exe (136)
C:\WINDOWS\system32\ctfmon.exe (212)
C:\WINDOWS\system32\notepad.exe (1856)
C:\Program Files\Internet Explorer\iexplore.exe (1076)
C:\UsbFix\Go.exe (2008)
################## | Stopped processes |
Stopped! C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (976)
Stopped! C:\WINDOWS\Explorer.EXE (1436)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (1984)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (136)
Stopped! C:\WINDOWS\system32\ctfmon.exe (212)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (1076)
################## | Files # Infected Folders |
Deleted ! C:\Recycler\S-1-5-21-1482476501-329068152-299502267-1003
Deleted ! C:\Recycler\S-1-5-21-2227039031-492925597-1573675636-1005
Deleted ! D:\Recycler\S-1-5-21-2227039031-492925597-1573675636-1005
Deleted ! C:\KK.exe
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[26/01/2011 - 14:00:57 | DC ] C:\Aplikace
[02/11/2010 - 14:31:14 | DC ] C:\AXAKalkulacka
[12/07/2010 - 17:46:54 | C | 211] C:\boot.ini
[14/04/2008 - 13:00:00 | C | 4952] C:\Bootfont.bin
[12/02/2012 - 15:16:45 | DC ] C:\Documents and Settings
[04/03/2011 - 14:42:49 | DC ] C:\DUKE3D
[04/03/2011 - 14:45:27 | DC ] C:\DUKE3DHO
[28/01/2012 - 12:19:48 | DC ] C:\eISIS
[08/10/2011 - 15:48:33 | C | 23022] C:\fftrlog.txt
[04/03/2011 - 14:47:34 | DC ] C:\Games
[14/08/2011 - 14:57:28 | DC ] C:\GEN
[01/09/2009 - 21:59:28 | DC ] C:\Intel
[01/09/2009 - 21:39:42 | C | 0] C:\IO.SYS
[12/02/2012 - 18:26:13 | DC ] C:\kk
[12/02/2012 - 18:24:36 | C | 164352] C:\kk.zip
[01/09/2009 - 21:39:42 | C | 0] C:\MSDOS.SYS
[01/09/2009 - 22:40:37 | RHDC ] C:\MSOCache
[14/04/2008 - 13:00:00 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 250576] C:\ntldr
[12/02/2012 - 18:22:58 | ASH | 1598029824] C:\pagefile.sys
[12/02/2012 - 16:04:05 | DC ] C:\Program Files
[12/02/2012 - 19:05:46 | SHDC ] C:\RECYCLER
[12/02/2012 - 16:04:11 | DC ] C:\rsit
[01/03/2011 - 15:39:32 | DC ] C:\SIMS
[09/02/2012 - 13:27:17 | SHD ] C:\System Volume Information
[12/02/2012 - 18:02:45 | C | 47000] C:\TDSSKiller.2.7.11.0_12.02.2012_17.59.27_log.txt
[04/03/2011 - 13:52:29 | DC ] C:\TEMP
[08/11/2011 - 21:36:42 | DC ] C:\TiskProRadost
[12/02/2012 - 19:05:46 | DC ] C:\UsbFix
[12/02/2012 - 19:05:47 | AC | 2364] C:\UsbFix.txt
[12/02/2012 - 19:01:54 | DC ] C:\WINDOWS
[20/09/2010 - 20:22:59 | D ] D:\17591be43ec7552f26fe86f047cb7d23
[12/02/2012 - 16:03:40 | D ] D:\Filmy
[12/02/2012 - 19:05:46 | SHD ] D:\RECYCLER
[09/02/2012 - 13:27:17 | SHD ] D:\System Volume Information
################## | Vaccin |
############################## | UsbFix V 7.081 | [Deletion]
User: Administrator (Administrator) # N-WMOWLZRITS9B8
Updated 05/02/2012 by El Desaparecido
Started at 19:03:56 | 12/02/2012
Website: http://eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.html
Contact: contact@eldesaparecido.com
PC: ASUSTeK Computer INC. (1001HA) (X86-based PC) # Notebook
CPU: Intel(R) Atom(TM) CPU N270 @ 1.60GHz (1599)
RAM -> [ Total : 1015 | Free : 555 ]
BIOS: BIOS Date: 02/26/10 09:16:31 Ver: 08.00.12
BOOT: Fail-safe with network boot
OS: Microsoft Windows XP Home Edition (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 72 Gb (2 Mb free - 3%) [] # NTFS
D:\ -> Fixed drive # 72 Gb (71 Mb free - 99%) [] # NTFS
################## | Active Processes |
C:\WINDOWS\System32\smss.exe (384)
C:\WINDOWS\system32\winlogon.exe (636)
C:\WINDOWS\system32\services.exe (680)
C:\WINDOWS\system32\lsass.exe (692)
C:\WINDOWS\system32\svchost.exe (848)
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (976)
C:\WINDOWS\system32\svchost.exe (1096)
C:\WINDOWS\Explorer.EXE (1436)
C:\Program Files\Internet Explorer\iexplore.exe (1984)
C:\Program Files\Internet Explorer\iexplore.exe (136)
C:\WINDOWS\system32\ctfmon.exe (212)
C:\WINDOWS\system32\notepad.exe (1856)
C:\Program Files\Internet Explorer\iexplore.exe (1076)
C:\UsbFix\Go.exe (2008)
################## | Stopped processes |
Stopped! C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (976)
Stopped! C:\WINDOWS\Explorer.EXE (1436)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (1984)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (136)
Stopped! C:\WINDOWS\system32\ctfmon.exe (212)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (1076)
################## | Files # Infected Folders |
Deleted ! C:\Recycler\S-1-5-21-1482476501-329068152-299502267-1003
Deleted ! C:\Recycler\S-1-5-21-2227039031-492925597-1573675636-1005
Deleted ! D:\Recycler\S-1-5-21-2227039031-492925597-1573675636-1005
Deleted ! C:\KK.exe
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[26/01/2011 - 14:00:57 | DC ] C:\Aplikace
[02/11/2010 - 14:31:14 | DC ] C:\AXAKalkulacka
[12/07/2010 - 17:46:54 | C | 211] C:\boot.ini
[14/04/2008 - 13:00:00 | C | 4952] C:\Bootfont.bin
[12/02/2012 - 15:16:45 | DC ] C:\Documents and Settings
[04/03/2011 - 14:42:49 | DC ] C:\DUKE3D
[04/03/2011 - 14:45:27 | DC ] C:\DUKE3DHO
[28/01/2012 - 12:19:48 | DC ] C:\eISIS
[08/10/2011 - 15:48:33 | C | 23022] C:\fftrlog.txt
[04/03/2011 - 14:47:34 | DC ] C:\Games
[14/08/2011 - 14:57:28 | DC ] C:\GEN
[01/09/2009 - 21:59:28 | DC ] C:\Intel
[01/09/2009 - 21:39:42 | C | 0] C:\IO.SYS
[12/02/2012 - 18:26:13 | DC ] C:\kk
[12/02/2012 - 18:24:36 | C | 164352] C:\kk.zip
[01/09/2009 - 21:39:42 | C | 0] C:\MSDOS.SYS
[01/09/2009 - 22:40:37 | RHDC ] C:\MSOCache
[14/04/2008 - 13:00:00 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 250576] C:\ntldr
[12/02/2012 - 18:22:58 | ASH | 1598029824] C:\pagefile.sys
[12/02/2012 - 16:04:05 | DC ] C:\Program Files
[12/02/2012 - 19:05:46 | SHDC ] C:\RECYCLER
[12/02/2012 - 16:04:11 | DC ] C:\rsit
[01/03/2011 - 15:39:32 | DC ] C:\SIMS
[09/02/2012 - 13:27:17 | SHD ] C:\System Volume Information
[12/02/2012 - 18:02:45 | C | 47000] C:\TDSSKiller.2.7.11.0_12.02.2012_17.59.27_log.txt
[04/03/2011 - 13:52:29 | DC ] C:\TEMP
[08/11/2011 - 21:36:42 | DC ] C:\TiskProRadost
[12/02/2012 - 19:05:46 | DC ] C:\UsbFix
[12/02/2012 - 19:05:47 | AC | 2364] C:\UsbFix.txt
[12/02/2012 - 19:01:54 | DC ] C:\WINDOWS
[20/09/2010 - 20:22:59 | D ] D:\17591be43ec7552f26fe86f047cb7d23
[12/02/2012 - 16:03:40 | D ] D:\Filmy
[12/02/2012 - 19:05:46 | SHD ] D:\RECYCLER
[09/02/2012 - 13:27:17 | SHD ] D:\System Volume Information
################## | Vaccin |
Re: nelze se dostat na stranky antiviru a antivir se neaktul
combofix:
ComboFix 12-02-12.01 - Administrator 12.02.2012 19:25:53.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.589 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Asus\WINDOWS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-12 do 2012-02-12 )))))))))))))))))))))))))))))))
.
.
2012-02-12 18:03 . 2012-02-12 18:05 -------- dc----w- C:\UsbFix
2012-02-12 17:24 . 2012-02-12 17:26 -------- dc----w- C:\kk
2012-02-12 17:14 . 2012-02-12 17:14 -------- dc----w- c:\windows\LastGood
2012-02-12 16:56 . 2012-01-31 12:44 237072 -c----w- c:\windows\system32\MpSigStub.exe
2012-02-12 16:55 . 2009-08-06 18:23 274288 -c--a-w- c:\windows\system32\mucltui.dll
2012-02-12 16:55 . 2009-08-06 18:23 215920 -c--a-w- c:\windows\system32\muweb.dll
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- c:\program files\trend micro
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- C:\rsit
2012-02-12 14:30 . 2012-01-17 03:39 6557240 -c--a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BAB36321-02FE-4630-B036-811D141F089C}\mpengine.dll
2012-02-12 14:19 . 2012-02-12 14:19 -------- dc----w- c:\program files\ESET
2012-02-12 14:16 . 2012-02-12 14:17 -------- dc----w- c:\documents and settings\Administrator
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\hidserv.dll
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2012-02-12 13:33 . 2012-02-12 13:33 -------- dc----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:36 . 2012-02-09 12:36 -------- dc----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:29 . 2012-02-09 12:30 -------- dc----w- c:\program files\Microsoft Security Client
2012-02-09 11:55 . 2012-02-09 11:55 -------- dc----w- c:\windows\system32\Atheros_L1e
2012-02-09 11:52 . 2009-03-02 20:03 38912 -c--a-w- c:\windows\system32\drivers\l1c51x86.sys
2012-01-28 11:04 . 2012-01-28 11:19 -------- dc----w- C:\eISIS
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-12 17:24 . 2012-02-12 17:24 164352 -c----w- C:\kk.zip
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2009-07-27 397312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"LiveUpdate"="c:\program files\Asus\LiveUpdate\LiveUpdate.exe" [2009-06-25 712704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-9-1 376832]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 -c--a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 16:53 3885408 -c--a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Kooperativa\\KalkZiv\\Kalk_ziv.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7565:TCP"= 7565:TCP:xoiys
.
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [9.2.2012 12:52 38912]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [1.9.2009 22:02 1015424]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 eISISPostgreSQL;eISIS PostgreSQL Database Server;c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data" --> c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data [?]
S2 eISISTomcat;eISIS Tomcat;c:\eisis\servers\tomcat\bin\tomcat5.exe [28.1.2012 12:07 57344]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S2 ouxhxq;Network Universal;c:\windows\system32\svchost.exe -k netsvcs [1.9.2009 23:26 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [1.9.2009 22:01 1684736]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [12.8.2009 7:57 39040]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
2012-02-12 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-SynAsusAcpi - c:\program files\Synaptics\SynTP\SynAsusAcpi.exe
HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe
HKLM-RunOnce-<NO NAME> - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-12 19:33
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ouxhxq]
"ServiceDll"="c:\windows\system32\whyknfyf.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2227039031-492925597-1573675636-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,07,e1,00,9d,07,e5,44,a6,79,31,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,07,e1,00,9d,07,e5,44,a6,79,31,\
.
Celkový čas: 2012-02-12 19:35:54
ComboFix-quarantined-files.txt 2012-02-12 18:35
.
Před spuštěním: 2 213 933 056
Po spuštění: 2 213 695 488
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 20C2CFBDC706F105E431CFBE5BDC99AA
ComboFix 12-02-12.01 - Administrator 12.02.2012 19:25:53.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.589 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Asus\WINDOWS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-12 do 2012-02-12 )))))))))))))))))))))))))))))))
.
.
2012-02-12 18:03 . 2012-02-12 18:05 -------- dc----w- C:\UsbFix
2012-02-12 17:24 . 2012-02-12 17:26 -------- dc----w- C:\kk
2012-02-12 17:14 . 2012-02-12 17:14 -------- dc----w- c:\windows\LastGood
2012-02-12 16:56 . 2012-01-31 12:44 237072 -c----w- c:\windows\system32\MpSigStub.exe
2012-02-12 16:55 . 2009-08-06 18:23 274288 -c--a-w- c:\windows\system32\mucltui.dll
2012-02-12 16:55 . 2009-08-06 18:23 215920 -c--a-w- c:\windows\system32\muweb.dll
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- c:\program files\trend micro
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- C:\rsit
2012-02-12 14:30 . 2012-01-17 03:39 6557240 -c--a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BAB36321-02FE-4630-B036-811D141F089C}\mpengine.dll
2012-02-12 14:19 . 2012-02-12 14:19 -------- dc----w- c:\program files\ESET
2012-02-12 14:16 . 2012-02-12 14:17 -------- dc----w- c:\documents and settings\Administrator
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\hidserv.dll
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2012-02-12 13:33 . 2012-02-12 13:33 -------- dc----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:36 . 2012-02-09 12:36 -------- dc----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:29 . 2012-02-09 12:30 -------- dc----w- c:\program files\Microsoft Security Client
2012-02-09 11:55 . 2012-02-09 11:55 -------- dc----w- c:\windows\system32\Atheros_L1e
2012-02-09 11:52 . 2009-03-02 20:03 38912 -c--a-w- c:\windows\system32\drivers\l1c51x86.sys
2012-01-28 11:04 . 2012-01-28 11:19 -------- dc----w- C:\eISIS
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-12 17:24 . 2012-02-12 17:24 164352 -c----w- C:\kk.zip
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2009-07-27 397312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"LiveUpdate"="c:\program files\Asus\LiveUpdate\LiveUpdate.exe" [2009-06-25 712704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-9-1 376832]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 -c--a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 16:53 3885408 -c--a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Kooperativa\\KalkZiv\\Kalk_ziv.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7565:TCP"= 7565:TCP:xoiys
.
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [9.2.2012 12:52 38912]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [1.9.2009 22:02 1015424]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 eISISPostgreSQL;eISIS PostgreSQL Database Server;c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data" --> c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data [?]
S2 eISISTomcat;eISIS Tomcat;c:\eisis\servers\tomcat\bin\tomcat5.exe [28.1.2012 12:07 57344]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S2 ouxhxq;Network Universal;c:\windows\system32\svchost.exe -k netsvcs [1.9.2009 23:26 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [1.9.2009 22:01 1684736]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [12.8.2009 7:57 39040]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
2012-02-12 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-SynAsusAcpi - c:\program files\Synaptics\SynTP\SynAsusAcpi.exe
HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe
HKLM-RunOnce-<NO NAME> - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-12 19:33
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ouxhxq]
"ServiceDll"="c:\windows\system32\whyknfyf.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2227039031-492925597-1573675636-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,07,e1,00,9d,07,e5,44,a6,79,31,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,07,e1,00,9d,07,e5,44,a6,79,31,\
.
Celkový čas: 2012-02-12 19:35:54
ComboFix-quarantined-files.txt 2012-02-12 18:35
.
Před spuštěním: 2 213 933 056
Po spuštění: 2 213 695 488
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 20C2CFBDC706F105E431CFBE5BDC99AA
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: nelze se dostat na stranky antiviru a antivir se neaktul
Ano aj nie, pretoze ak kamaratka pripoji fotak, USB kluc a co ja viem co vsetko ma, PC sa okamzite infikuje, pretoze tento smejd sa siri cez USB, vymenitelne media a vsetko tieto vymenitelne media su infikovane.
Pri tejto akcii je nutné mať ComboFix na ploche.
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log
Pri tejto akcii je nutné mať ComboFix na ploche.
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Kód: Vybrat vše
KILLALL::
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7565:TCP"=-
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ouxhxq]
"ServiceDll"=-
Driver::
xoiys
ouxhxq
Rootkit::
c:\windows\system32\whyknfyf.dll
RegLock::
[HKEY_USERS\S-1-5-21-2227039031-492925597-1573675636-500\Software\Microsoft\Internet Explorer\User Preferences]
ClearJavaCache::
Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log
Re: nelze se dostat na stranky antiviru a antivir se neaktul
ComboFix 12-02-12.01 - Administrator 12.02.2012 20:07:18.2.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.621 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_OUXHXQ
-------\Service_ouxhxq
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-12 do 2012-02-12 )))))))))))))))))))))))))))))))
.
.
2012-02-12 18:54 . 2012-02-12 19:55 133208 -c--a-w- c:\windows\system32\drivers\58979658.sys
2012-02-12 18:03 . 2012-02-12 18:05 -------- dc----w- C:\UsbFix
2012-02-12 17:24 . 2012-02-12 17:26 -------- dc----w- C:\kk
2012-02-12 16:56 . 2012-01-31 12:44 237072 -c----w- c:\windows\system32\MpSigStub.exe
2012-02-12 16:55 . 2009-08-06 18:23 274288 -c--a-w- c:\windows\system32\mucltui.dll
2012-02-12 16:55 . 2009-08-06 18:23 215920 -c--a-w- c:\windows\system32\muweb.dll
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- c:\program files\trend micro
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- C:\rsit
2012-02-12 14:30 . 2012-01-17 03:39 6557240 -c--a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BAB36321-02FE-4630-B036-811D141F089C}\mpengine.dll
2012-02-12 14:19 . 2012-02-12 14:19 -------- dc----w- c:\program files\ESET
2012-02-12 14:16 . 2012-02-12 14:17 -------- dc----w- c:\documents and settings\Administrator
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\hidserv.dll
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2012-02-12 13:33 . 2012-02-12 13:33 -------- dc----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:36 . 2012-02-09 12:36 -------- dc----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:29 . 2012-02-09 12:30 -------- dc----w- c:\program files\Microsoft Security Client
2012-02-09 11:55 . 2012-02-09 11:55 -------- dc----w- c:\windows\system32\Atheros_L1e
2012-02-09 11:52 . 2009-03-02 20:03 38912 -c--a-w- c:\windows\system32\drivers\l1c51x86.sys
2012-01-28 11:04 . 2012-01-28 11:19 -------- dc----w- C:\eISIS
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-12 17:24 . 2012-02-12 17:24 164352 -c----w- C:\kk.zip
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-12_18.33.06 )))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2009-07-27 397312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"LiveUpdate"="c:\program files\Asus\LiveUpdate\LiveUpdate.exe" [2009-06-25 712704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\Administrator\Nabídka Start\Programy\Po spuštění\
_uninst_.lnk - c:\documents and settings\Administrator\Local Settings\temp\_uninst_.bat [N/A]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-9-1 376832]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 -c--a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 16:53 3885408 -c--a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Kooperativa\\KalkZiv\\Kalk_ziv.exe"=
.
R0 58979658;58979658;c:\windows\system32\drivers\58979658.sys [12.2.2012 19:54 133208]
R2 eISISPostgreSQL;eISIS PostgreSQL Database Server;c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data" --> c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data [?]
R2 eISISTomcat;eISIS Tomcat;c:\eisis\servers\tomcat\bin\tomcat5.exe [28.1.2012 12:07 57344]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [9.2.2012 12:52 38912]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [1.9.2009 22:02 1015424]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [1.9.2009 22:01 1684736]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [12.8.2009 7:57 39040]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09e0c124-3649-11e1-8618-1c4bd62e6ad2}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4244e211-e69d-11df-8219-485b395c707a}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66986489-442e-11e0-82e1-485b395c707a}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce2c3954-2f10-11e1-8601-1c4bd62e6ad2}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9e5dd4e-34f1-11e0-82b3-485b395c707a}]
\Shell\AutoRun\command - E:\SETUP.EXE
\Shell\configure\command - E:\SETUP.EXE
\Shell\install\command - E:\SETUP.EXE
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
2012-02-12 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-12 20:17
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(600)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\eisis\servers\postgresql\bin\pg_ctl.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\program files\Firebird\bin\fbguard.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\program files\Firebird\bin\fbserver.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
c:\program files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
.
**************************************************************************
.
Celkový čas: 2012-02-12 20:21:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-02-12 19:21
ComboFix2.txt 2012-02-12 18:35
.
Před spuštěním: 1 397 747 712
Po spuštění: 1 227 214 848
.
- - End Of File - - 0282B28B24A7A3E00EEF41282DEA1DAA
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.621 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_OUXHXQ
-------\Service_ouxhxq
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-12 do 2012-02-12 )))))))))))))))))))))))))))))))
.
.
2012-02-12 18:54 . 2012-02-12 19:55 133208 -c--a-w- c:\windows\system32\drivers\58979658.sys
2012-02-12 18:03 . 2012-02-12 18:05 -------- dc----w- C:\UsbFix
2012-02-12 17:24 . 2012-02-12 17:26 -------- dc----w- C:\kk
2012-02-12 16:56 . 2012-01-31 12:44 237072 -c----w- c:\windows\system32\MpSigStub.exe
2012-02-12 16:55 . 2009-08-06 18:23 274288 -c--a-w- c:\windows\system32\mucltui.dll
2012-02-12 16:55 . 2009-08-06 18:23 215920 -c--a-w- c:\windows\system32\muweb.dll
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- c:\program files\trend micro
2012-02-12 15:04 . 2012-02-12 15:04 -------- dc----w- C:\rsit
2012-02-12 14:30 . 2012-01-17 03:39 6557240 -c--a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BAB36321-02FE-4630-B036-811D141F089C}\mpengine.dll
2012-02-12 14:19 . 2012-02-12 14:19 -------- dc----w- c:\program files\ESET
2012-02-12 14:16 . 2012-02-12 14:17 -------- dc----w- c:\documents and settings\Administrator
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\hidserv.dll
2012-02-12 13:36 . 2008-04-14 07:51 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2012-02-12 13:33 . 2012-02-12 13:33 -------- dc----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:36 . 2012-02-09 12:36 -------- dc----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\PCHealth
2012-02-09 12:29 . 2012-02-09 12:30 -------- dc----w- c:\program files\Microsoft Security Client
2012-02-09 11:55 . 2012-02-09 11:55 -------- dc----w- c:\windows\system32\Atheros_L1e
2012-02-09 11:52 . 2009-03-02 20:03 38912 -c--a-w- c:\windows\system32\drivers\l1c51x86.sys
2012-01-28 11:04 . 2012-01-28 11:19 -------- dc----w- C:\eISIS
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-12 17:24 . 2012-02-12 17:24 164352 -c----w- C:\kk.zip
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-12_18.33.06 )))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2009-07-27 397312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"LiveUpdate"="c:\program files\Asus\LiveUpdate\LiveUpdate.exe" [2009-06-25 712704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\Administrator\Nabídka Start\Programy\Po spuštění\
_uninst_.lnk - c:\documents and settings\Administrator\Local Settings\temp\_uninst_.bat [N/A]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-9-1 376832]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 -c--a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 16:53 3885408 -c--a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Kooperativa\\KalkZiv\\Kalk_ziv.exe"=
.
R0 58979658;58979658;c:\windows\system32\drivers\58979658.sys [12.2.2012 19:54 133208]
R2 eISISPostgreSQL;eISIS PostgreSQL Database Server;c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data" --> c:\eisis\servers\postgresql\bin\pg_ctl.exe runservice -N eISISPostgreSQL -D c:\eisis\data\db\data [?]
R2 eISISTomcat;eISIS Tomcat;c:\eisis\servers\tomcat\bin\tomcat5.exe [28.1.2012 12:07 57344]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [9.2.2012 12:52 38912]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [1.9.2009 22:02 1015424]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [1.9.2009 22:01 1684736]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [25.2.2011 17:24 135664]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [12.8.2009 7:57 39040]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09e0c124-3649-11e1-8618-1c4bd62e6ad2}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4244e211-e69d-11df-8219-485b395c707a}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66986489-442e-11e0-82e1-485b395c707a}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce2c3954-2f10-11e1-8601-1c4bd62e6ad2}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9e5dd4e-34f1-11e0-82b3-485b395c707a}]
\Shell\AutoRun\command - E:\SETUP.EXE
\Shell\configure\command - E:\SETUP.EXE
\Shell\install\command - E:\SETUP.EXE
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-25 16:24]
.
2012-02-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
2012-02-12 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-12 20:17
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(600)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\eisis\servers\postgresql\bin\pg_ctl.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\program files\Firebird\bin\fbguard.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\program files\Firebird\bin\fbserver.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
c:\program files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
c:\eisis\servers\postgresql\bin\postgres.exe
.
**************************************************************************
.
Celkový čas: 2012-02-12 20:21:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-02-12 19:21
ComboFix2.txt 2012-02-12 18:35
.
Před spuštěním: 1 397 747 712
Po spuštění: 1 227 214 848
.
- - End Of File - - 0282B28B24A7A3E00EEF41282DEA1DAA
- stell
- VIP in memoriam
- Příspěvky: 5175
- Registrován: 09 pro 2007 09:27
- Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: nelze se dostat na stranky antiviru a antivir se neaktul
Ok, Conficker odkryl karty.
Zopakuj akcius USBFIXOM, log loz sem,,
Zopakuj akciu s combofixom, vytvor novy CFScript.txt.>.log vloz sem.
Zopakuj akcius USBFIXOM, log loz sem,,
Zopakuj akciu s combofixom, vytvor novy CFScript.txt.>.log vloz sem.
Kód: Vybrat vše
KILLALL::
Driver::
58979658
ahaezedrn
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4244e211-e69d-11df-8219-485b395c707a}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66986489-442e-11e0-82e1-485b395c707a}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce2c3954-2f10-11e1-8601-1c4bd62e6ad2}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9e5dd4e-34f1-11e0-82b3-485b395c707a}]
Re: nelze se dostat na stranky antiviru a antivir se neaktul
USBFIX - (ted jdu na combo)
############################## | UsbFix V 7.081 | [Deletion]
User: Asus (Administrator) # N-WMOWLZRITS9B8
Updated 05/02/2012 by El Desaparecido
Started at 20:54:03 | 12/02/2012
Website: http://eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.html
Contact: contact@eldesaparecido.com
PC: ASUSTeK Computer INC. (1001HA) (X86-based PC) # Notebook
CPU: Intel(R) Atom(TM) CPU N270 @ 1.60GHz (1599)
RAM -> [ Total : 1015 | Free : 275 ]
BIOS: BIOS Date: 02/26/10 09:16:31 Ver: 08.00.12
BOOT: Normal boot
OS: Microsoft Windows XP Home Edition (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 72 Gb (908 Mb free - 1%) [] # NTFS
D:\ -> Fixed drive # 72 Gb (71 Mb free - 99%) [] # NTFS
################## | Active Processes |
C:\WINDOWS\System32\smss.exe (648)
C:\WINDOWS\system32\winlogon.exe (720)
C:\WINDOWS\system32\services.exe (764)
C:\WINDOWS\system32\lsass.exe (776)
C:\WINDOWS\system32\svchost.exe (936)
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (1044)
C:\WINDOWS\System32\svchost.exe (1116)
C:\WINDOWS\system32\spoolsv.exe (1504)
c:\eISIS\servers\postgresql\bin\pg_ctl.exe (1980)
c:\eISIS\servers\tomcat\bin\tomcat5.exe (2016)
c:\eISIS\servers\postgresql\bin\postgres.exe (2024)
C:\Program Files\Firebird\bin\fbguard.exe (180)
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (384)
C:\WINDOWS\system32\svchost.exe (604)
c:\eISIS\servers\postgresql\bin\postgres.exe (1856)
c:\eISIS\servers\postgresql\bin\postgres.exe (1876)
C:\Program Files\Firebird\bin\fbserver.exe (1400)
C:\WINDOWS\system32\igfxsrvc.exe (444)
C:\WINDOWS\system32\hkcmd.exe (592)
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (2064)
C:\Program Files\EeePC\ACPI\AsEPCMon.exe (2072)
C:\Program Files\EeePC\ACPI\AsTray.exe (2088)
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (2128)
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2144)
C:\WINDOWS\RTHDCPL.EXE (1352)
C:\Program Files\Microsoft Security Client\msseces.exe (2200)
C:\WINDOWS\system32\igfxext.exe (2420)
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (2564)
C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe (2632)
C:\WINDOWS\system32\wuauclt.exe (3860)
c:\eISIS\servers\postgresql\bin\postgres.exe (3916)
c:\eISIS\servers\postgresql\bin\postgres.exe (3804)
C:\WINDOWS\explorer.exe (600)
c:\eISIS\servers\postgresql\bin\postgres.exe (2112)
c:\eISIS\servers\postgresql\bin\postgres.exe (2796)
C:\WINDOWS\system32\notepad.exe (2968)
C:\Program Files\Internet Explorer\iexplore.exe (3964)
C:\Program Files\Internet Explorer\iexplore.exe (3452)
C:\WINDOWS\system32\ctfmon.exe (2772)
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe (2560)
C:\UsbFix\Go.exe (5836)
################## | Stopped processes |
Stopped! C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (1044)
Stopped! C:\WINDOWS\system32\spoolsv.exe (1504)
Stopped! c:\eISIS\servers\postgresql\bin\pg_ctl.exe (1980)
Stopped! c:\eISIS\servers\tomcat\bin\tomcat5.exe (2016)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (2024)
Stopped! C:\Program Files\Firebird\bin\fbguard.exe (180)
Stopped! C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (384)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (1856)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (1876)
Stopped! C:\Program Files\Firebird\bin\fbserver.exe (1400)
Stopped! C:\WINDOWS\system32\igfxsrvc.exe (444)
Stopped! C:\WINDOWS\system32\hkcmd.exe (592)
Stopped! C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (2064)
Stopped! C:\Program Files\EeePC\ACPI\AsEPCMon.exe (2072)
Stopped! C:\Program Files\EeePC\ACPI\AsTray.exe (2088)
Stopped! C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (2128)
Stopped! C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2144)
Stopped! C:\WINDOWS\RTHDCPL.EXE (1352)
Stopped! C:\Program Files\Microsoft Security Client\msseces.exe (2200)
Stopped! C:\WINDOWS\system32\igfxext.exe (2420)
Stopped! C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (2564)
Stopped! C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe (2632)
Stopped! C:\WINDOWS\system32\wuauclt.exe (3860)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (3916)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (3804)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (2112)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (3964)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (3452)
Stopped! C:\WINDOWS\system32\ctfmon.exe (2772)
Stopped! C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe (2560)
################## | Files # Infected Folders |
Deleted ! C:\DOCUME~1\Asus\LOCALS~1\Temp\AutoRun.exe
Deleted ! D:\Recycler\S-1-5-21-2227039031-492925597-1573675636-1005
Deleted ! D:\Recycler\S-1-5-21-2227039031-492925597-1573675636-500
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{09e0c124-3649-11e1-8618-1c4bd62e6ad2}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{4244e211-e69d-11df-8219-485b395c707a}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{66986489-442e-11e0-82e1-485b395c707a}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{ce2c3954-2f10-11e1-8601-1c4bd62e6ad2}
################## | Listing |
[26/01/2011 - 14:00:57 | DC ] C:\Aplikace
[12/02/2012 - 19:10:53 | RADC ] C:\Autorun.inf
[02/11/2010 - 14:31:14 | DC ] C:\AXAKalkulacka
[12/07/2010 - 17:46:54 | C | 211] C:\Boot.bak
[12/02/2012 - 19:23:06 | C | 327] C:\boot.ini
[14/04/2008 - 13:00:00 | C | 4952] C:\Bootfont.bin
[12/02/2012 - 19:23:05 | DC ] C:\cmdcons
[03/08/2004 - 23:00:04 | C | 261312] C:\cmldr
[12/02/2012 - 20:21:54 | C | 12353] C:\ComboFix.txt
[12/02/2012 - 15:16:45 | DC ] C:\Documents and Settings
[04/03/2011 - 14:42:49 | DC ] C:\DUKE3D
[04/03/2011 - 14:45:27 | DC ] C:\DUKE3DHO
[28/01/2012 - 12:19:48 | DC ] C:\eISIS
[08/10/2011 - 15:48:33 | C | 23022] C:\fftrlog.txt
[04/03/2011 - 14:47:34 | DC ] C:\Games
[14/08/2011 - 14:57:28 | DC ] C:\GEN
[01/09/2009 - 21:59:28 | DC ] C:\Intel
[01/09/2009 - 21:39:42 | C | 0] C:\IO.SYS
[12/02/2012 - 18:26:13 | DC ] C:\kk
[12/02/2012 - 18:24:36 | C | 164352] C:\kk.zip
[01/09/2009 - 21:39:42 | C | 0] C:\MSDOS.SYS
[01/09/2009 - 22:40:37 | RDC ] C:\MSOCache
[14/04/2008 - 13:00:00 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 250576] C:\ntldr
[12/02/2012 - 20:15:58 | ASH | 1598029824] C:\pagefile.sys
[12/02/2012 - 16:04:05 | DC ] C:\Program Files
[12/02/2012 - 20:24:21 | DC ] C:\Qoobox
[12/02/2012 - 20:59:59 | SHDC ] C:\RECYCLER
[12/02/2012 - 16:04:11 | DC ] C:\rsit
[01/03/2011 - 15:39:32 | DC ] C:\SIMS
[12/02/2012 - 19:55:29 | SHD ] C:\System Volume Information
[12/02/2012 - 18:02:45 | C | 47000] C:\TDSSKiller.2.7.11.0_12.02.2012_17.59.27_log.txt
[04/03/2011 - 13:52:29 | DC ] C:\TEMP
[08/11/2011 - 21:36:42 | DC ] C:\TiskProRadost
[12/02/2012 - 21:00:00 | DC ] C:\UsbFix
[12/02/2012 - 21:04:33 | AC | 7562] C:\UsbFix.txt
[12/02/2012 - 20:22:43 | DC ] C:\WINDOWS
[20/09/2010 - 20:22:59 | D ] D:\17591be43ec7552f26fe86f047cb7d23
[12/02/2012 - 16:03:40 | D ] D:\Filmy
[12/02/2012 - 21:00:00 | SHD ] D:\RECYCLER
[09/02/2012 - 13:27:17 | SHD ] D:\System Volume Information
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_N-WMOWLZRITS9B8.zip
http://eldesaparecido.com/upload.html
Thank you for your contribution.
################## | E.O.F |
############################## | UsbFix V 7.081 | [Deletion]
User: Asus (Administrator) # N-WMOWLZRITS9B8
Updated 05/02/2012 by El Desaparecido
Started at 20:54:03 | 12/02/2012
Website: http://eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.html
Contact: contact@eldesaparecido.com
PC: ASUSTeK Computer INC. (1001HA) (X86-based PC) # Notebook
CPU: Intel(R) Atom(TM) CPU N270 @ 1.60GHz (1599)
RAM -> [ Total : 1015 | Free : 275 ]
BIOS: BIOS Date: 02/26/10 09:16:31 Ver: 08.00.12
BOOT: Normal boot
OS: Microsoft Windows XP Home Edition (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 72 Gb (908 Mb free - 1%) [] # NTFS
D:\ -> Fixed drive # 72 Gb (71 Mb free - 99%) [] # NTFS
################## | Active Processes |
C:\WINDOWS\System32\smss.exe (648)
C:\WINDOWS\system32\winlogon.exe (720)
C:\WINDOWS\system32\services.exe (764)
C:\WINDOWS\system32\lsass.exe (776)
C:\WINDOWS\system32\svchost.exe (936)
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (1044)
C:\WINDOWS\System32\svchost.exe (1116)
C:\WINDOWS\system32\spoolsv.exe (1504)
c:\eISIS\servers\postgresql\bin\pg_ctl.exe (1980)
c:\eISIS\servers\tomcat\bin\tomcat5.exe (2016)
c:\eISIS\servers\postgresql\bin\postgres.exe (2024)
C:\Program Files\Firebird\bin\fbguard.exe (180)
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (384)
C:\WINDOWS\system32\svchost.exe (604)
c:\eISIS\servers\postgresql\bin\postgres.exe (1856)
c:\eISIS\servers\postgresql\bin\postgres.exe (1876)
C:\Program Files\Firebird\bin\fbserver.exe (1400)
C:\WINDOWS\system32\igfxsrvc.exe (444)
C:\WINDOWS\system32\hkcmd.exe (592)
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (2064)
C:\Program Files\EeePC\ACPI\AsEPCMon.exe (2072)
C:\Program Files\EeePC\ACPI\AsTray.exe (2088)
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (2128)
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2144)
C:\WINDOWS\RTHDCPL.EXE (1352)
C:\Program Files\Microsoft Security Client\msseces.exe (2200)
C:\WINDOWS\system32\igfxext.exe (2420)
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (2564)
C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe (2632)
C:\WINDOWS\system32\wuauclt.exe (3860)
c:\eISIS\servers\postgresql\bin\postgres.exe (3916)
c:\eISIS\servers\postgresql\bin\postgres.exe (3804)
C:\WINDOWS\explorer.exe (600)
c:\eISIS\servers\postgresql\bin\postgres.exe (2112)
c:\eISIS\servers\postgresql\bin\postgres.exe (2796)
C:\WINDOWS\system32\notepad.exe (2968)
C:\Program Files\Internet Explorer\iexplore.exe (3964)
C:\Program Files\Internet Explorer\iexplore.exe (3452)
C:\WINDOWS\system32\ctfmon.exe (2772)
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe (2560)
C:\UsbFix\Go.exe (5836)
################## | Stopped processes |
Stopped! C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (1044)
Stopped! C:\WINDOWS\system32\spoolsv.exe (1504)
Stopped! c:\eISIS\servers\postgresql\bin\pg_ctl.exe (1980)
Stopped! c:\eISIS\servers\tomcat\bin\tomcat5.exe (2016)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (2024)
Stopped! C:\Program Files\Firebird\bin\fbguard.exe (180)
Stopped! C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (384)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (1856)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (1876)
Stopped! C:\Program Files\Firebird\bin\fbserver.exe (1400)
Stopped! C:\WINDOWS\system32\igfxsrvc.exe (444)
Stopped! C:\WINDOWS\system32\hkcmd.exe (592)
Stopped! C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (2064)
Stopped! C:\Program Files\EeePC\ACPI\AsEPCMon.exe (2072)
Stopped! C:\Program Files\EeePC\ACPI\AsTray.exe (2088)
Stopped! C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (2128)
Stopped! C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2144)
Stopped! C:\WINDOWS\RTHDCPL.EXE (1352)
Stopped! C:\Program Files\Microsoft Security Client\msseces.exe (2200)
Stopped! C:\WINDOWS\system32\igfxext.exe (2420)
Stopped! C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (2564)
Stopped! C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe (2632)
Stopped! C:\WINDOWS\system32\wuauclt.exe (3860)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (3916)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (3804)
Stopped! c:\eISIS\servers\postgresql\bin\postgres.exe (2112)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (3964)
Stopped! C:\Program Files\Internet Explorer\iexplore.exe (3452)
Stopped! C:\WINDOWS\system32\ctfmon.exe (2772)
Stopped! C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe (2560)
################## | Files # Infected Folders |
Deleted ! C:\DOCUME~1\Asus\LOCALS~1\Temp\AutoRun.exe
Deleted ! D:\Recycler\S-1-5-21-2227039031-492925597-1573675636-1005
Deleted ! D:\Recycler\S-1-5-21-2227039031-492925597-1573675636-500
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{09e0c124-3649-11e1-8618-1c4bd62e6ad2}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{4244e211-e69d-11df-8219-485b395c707a}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{66986489-442e-11e0-82e1-485b395c707a}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{ce2c3954-2f10-11e1-8601-1c4bd62e6ad2}
################## | Listing |
[26/01/2011 - 14:00:57 | DC ] C:\Aplikace
[12/02/2012 - 19:10:53 | RADC ] C:\Autorun.inf
[02/11/2010 - 14:31:14 | DC ] C:\AXAKalkulacka
[12/07/2010 - 17:46:54 | C | 211] C:\Boot.bak
[12/02/2012 - 19:23:06 | C | 327] C:\boot.ini
[14/04/2008 - 13:00:00 | C | 4952] C:\Bootfont.bin
[12/02/2012 - 19:23:05 | DC ] C:\cmdcons
[03/08/2004 - 23:00:04 | C | 261312] C:\cmldr
[12/02/2012 - 20:21:54 | C | 12353] C:\ComboFix.txt
[12/02/2012 - 15:16:45 | DC ] C:\Documents and Settings
[04/03/2011 - 14:42:49 | DC ] C:\DUKE3D
[04/03/2011 - 14:45:27 | DC ] C:\DUKE3DHO
[28/01/2012 - 12:19:48 | DC ] C:\eISIS
[08/10/2011 - 15:48:33 | C | 23022] C:\fftrlog.txt
[04/03/2011 - 14:47:34 | DC ] C:\Games
[14/08/2011 - 14:57:28 | DC ] C:\GEN
[01/09/2009 - 21:59:28 | DC ] C:\Intel
[01/09/2009 - 21:39:42 | C | 0] C:\IO.SYS
[12/02/2012 - 18:26:13 | DC ] C:\kk
[12/02/2012 - 18:24:36 | C | 164352] C:\kk.zip
[01/09/2009 - 21:39:42 | C | 0] C:\MSDOS.SYS
[01/09/2009 - 22:40:37 | RDC ] C:\MSOCache
[14/04/2008 - 13:00:00 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 250576] C:\ntldr
[12/02/2012 - 20:15:58 | ASH | 1598029824] C:\pagefile.sys
[12/02/2012 - 16:04:05 | DC ] C:\Program Files
[12/02/2012 - 20:24:21 | DC ] C:\Qoobox
[12/02/2012 - 20:59:59 | SHDC ] C:\RECYCLER
[12/02/2012 - 16:04:11 | DC ] C:\rsit
[01/03/2011 - 15:39:32 | DC ] C:\SIMS
[12/02/2012 - 19:55:29 | SHD ] C:\System Volume Information
[12/02/2012 - 18:02:45 | C | 47000] C:\TDSSKiller.2.7.11.0_12.02.2012_17.59.27_log.txt
[04/03/2011 - 13:52:29 | DC ] C:\TEMP
[08/11/2011 - 21:36:42 | DC ] C:\TiskProRadost
[12/02/2012 - 21:00:00 | DC ] C:\UsbFix
[12/02/2012 - 21:04:33 | AC | 7562] C:\UsbFix.txt
[12/02/2012 - 20:22:43 | DC ] C:\WINDOWS
[20/09/2010 - 20:22:59 | D ] D:\17591be43ec7552f26fe86f047cb7d23
[12/02/2012 - 16:03:40 | D ] D:\Filmy
[12/02/2012 - 21:00:00 | SHD ] D:\RECYCLER
[09/02/2012 - 13:27:17 | SHD ] D:\System Volume Information
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_N-WMOWLZRITS9B8.zip
http://eldesaparecido.com/upload.html
Thank you for your contribution.
################## | E.O.F |