Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Trojan & Malware & Rootkit

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
McLovin
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 29 úno 2012 21:35

Trojan & Malware & Rootkit

#1 Příspěvek od McLovin »

Zdravím. Surfoval som na nete na všelijakých pofidérnych stránkach lebo som hľadal jeden film a zrazu mi preblikla BSOD a notebook sa reštartoval... Po reštarte mi potom Avast hlásil trojana (dal ho do truhly), ale teraz mi ho hlási každú chvíľu...

Dal som spraviť test priečinku Documents and Settings, kde hlási tie hrozby a našlo to dva rootkity a dvoch trojanov. Dal som ich odstrániť ale stále mi tu vyhadzuje to isté...

Obrázek

Logfile of random's system information tool 1.09 (written by random/random)
Run by Roman at 2012-02-28 20:33:20
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 976 MB (5%) free of 20 GB
Total RAM: 1022 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:33:32, on 28.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS.0\explorer.exe
C:\WINDOWS.0\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS.0\system32\rundll32.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\AllMyNotes Organizer\AllMyNotes.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Noční obloha\vesmir.exe
C:\PROGRA~1\DUMETE~1\DUMeter.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe
C:\Program Files\DU Meter\DUMeterSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS.0\system32\nvsvc32.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
D:\RSIT.exe
C:\Program Files\trend micro\Roman.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\vShare.tv plugin\BarLcher.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: VShareToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Bonus.SSR.FR10] "C:\Program Files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [AllMyNotes] C:\Program Files\AllMyNotes Organizer\AllMyNotes.exe -autostartup
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Vesmír na dlani.lnk = ?
O4 - Global Startup: Windchill ProductPoint Client Manager.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Roman\Desktop\PartyPoker.lnk
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Roman\Desktop\PartyPoker.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Unibet - {000168A3-4EF2-49DD-B7BD-595E8C394B31} - C:\Microgaming\Poker\unibetpokerMPP\MPPoker.exe (HKCU)
O20 - Winlogon Notify: Antiwpa - antiwpa.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS.0\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS.0\system32\browseui.dll
O23 - Service: ABBYY FineReader 10 CE Licensing Service (ABBYY.Licensing.FineReader.Corporate.10.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

--
End of file - 7479 bytes

======Scheduled tasks folder======

C:\WINDOWS.0\tasks\RealUpgradeLogonTaskS-1-5-21-329068152-813497703-1417001333-1003.job
C:\WINDOWS.0\tasks\RealUpgradeScheduledTaskS-1-5-21-329068152-813497703-1417001333-1003.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\9iqm5760.default

prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}:0.3.8.1, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, jqs@sun.com:1.0, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS.0\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pages.tvunetworks.com/WebPlayer]
"Description"=TVU Web Player Plugin
"Path"=C:\WINDOWS.0\system32\TVUAx\npTVUAx.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13]
"Description"=15.0.1.13
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19]
"Description"=Veetle TV Core
"Path"=C:\Program Files\Veetle\plugins\npVeetle.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files\Veetle\Player\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
nprjplug.dll
nprpjplug.dll
npvsharetvplg.dll
nsjsrealplayerplugin.xpt
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\9iqm5760.default\extensions\
customizable-shortcuts@timtaubert.de
firefox@tvunetworks.com
superstart@enjoyfreeware.org
vshare@toolbar
{5384767E-00D9-40E9-B72F-9CC39D655D6F}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-01-04 425680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}]
IE5BarLauncherBHO Class - C:\Program Files\vShare.tv plugin\BarLcher.dll [2011-09-22 177712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - VShareToolBar - C:\Program Files\vShare.tv plugin\BarLcher.dll [2011-09-22 177712]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS.0\system32\NvCpl.dll [2006-07-20 7581696]
"RTHDCPL"=C:\WINDOWS.0\RTHDCPL.EXE [2006-09-22 16236032]
"SkyTel"=C:\WINDOWS.0\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS.0\ALCMTR.EXE [2005-05-03 69632]
"AzMixerSel"=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [2005-06-11 53248]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-05-10 3459712]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2010-03-09 15872]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"Bonus.SSR.FR10"=C:\Program Files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe [2009-12-20 941320]
"TkBellExe"=C:\Program Files\Real\RealPlayer\update\realsched.exe [2012-01-04 296056]
"KernelFaultCheck"=C:\WINDOWS.0\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS.0\system32\ctfmon.exe [2008-04-14 15360]
"AllMyNotes"=C:\Program Files\AllMyNotes Organizer\AllMyNotes.exe [2011-05-12 2705672]
"DU Meter"=C:\Program Files\DU Meter\DUMeter.exe [2009-03-13 1216931]
"Rainlendar2"=C:\Program Files\Rainlendar2\Rainlendar2.exe [2011-08-12 2433024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
C:\Program Files\QIP 2010\qip.exe [2010-10-12 5810128]

C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Startup
Windchill ProductPoint Client Manager.lnk - C:\WINDOWS.0\Installer\{D27AB79F-B1B3-49E1-97E7-94E30882F01F}\_112AFB1E788558580027CB.exe

C:\Documents and Settings\Roman\Start Menu\Programs\Startup
Vesmír na dlani.lnk - C:\Program Files\Noční obloha\vesmir.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa]
C:\WINDOWS.0\system32\antiwpa.dll [2003-05-25 60416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"D:\ApexDC\ApexDC\ApexDC.exe"="D:\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC++"
"D:\HRY\Vietcong\vietcong.exe"="D:\HRY\Vietcong\vietcong.exe:*:Enabled:vietcong"
"F:\ApexDC\ApexDC\ApexDC.exe"="F:\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC++"
"C:3\ApexDC\ApexDC\ApexDC.exe"="C:3\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:6\ApexDC\ApexDC\ApexDC.exe"="C:6\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"E:\Revolt\Revolt (full game)+Hamachi_by_punksoul\Revolt (full game)+Hamachi\REVOLT - FULL GAME\revolt.exe"="E:\Revolt\Revolt (full game)+Hamachi_by_punksoul\Revolt (full game)+Hamachi\REVOLT - FULL GAME\revolt.exe:*:Disabled:revolt"
"C:\WINDOWS.0\system32\dplaysvr.exe"="C:\WINDOWS.0\system32\dplaysvr.exe:*:Disabled:Microsoft DirectPlay Helper"
"C:3\Flatout 2\FlatOut 2\flatout2.exe"="C:3\Flatout 2\FlatOut 2\flatout2.exe:*:Enabled:flatout2.exe"
"D:3\ApexDC\ApexDC\ApexDC.exe"="D:3\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:\Program Files\QIP 2010\qip.exe"="C:\Program Files\QIP 2010\qip.exe:*:Enabled:QIP 2010"
"E:\FIFA11\Game\fifa.exe"="E:\FIFA11\Game\fifa.exe:*:Enabled:FIFA 11"
"C:\Documents and Settings\Roman\Application Data\GameRanger\GameRanger\GameRanger.exe"="C:\Documents and Settings\Roman\Application Data\GameRanger\GameRanger\GameRanger.exe:*:Enabled:GameRanger"
"G:\ApexDC\ApexDC\ApexDC.exe"="G:\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC++"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Frankie Dettori Racing - Melbourne Cup Challenge\Racing.exe"="C:\Program Files\Frankie Dettori Racing - Melbourne Cup Challenge\Racing.exe:*:Enabled:Frankie Dettori Racing - Melbourne Cup Challenge"
"C:\Program Files\proeWildfire 5.0\i486_nt\obj\xtop.exe"="C:\Program Files\proeWildfire 5.0\i486_nt\obj\xtop.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC"
"C:\Program Files\proeWildfire 5.0\i486_nt\obj\pro_comm_msg.exe"="C:\Program Files\proeWildfire 5.0\i486_nt\obj\pro_comm_msg.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC"
"C:\Program Files\proeWildfire 5.0\i486_nt\nms\nmsd.exe"="C:\Program Files\proeWildfire 5.0\i486_nt\nms\nmsd.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC"
"C:9\ApexDC\ApexDC\ApexDC.exe"="C:9\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:\Program Files\proeWildfire 4.0\i486_nt\nms\nmsd.exe"="C:\Program Files\proeWildfire 4.0\i486_nt\nms\nmsd.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC"
"C:\Program Files\proeWildfire 4.0\i486_nt\obj\pro_comm_msg.exe"="C:\Program Files\proeWildfire 4.0\i486_nt\obj\pro_comm_msg.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC"
"C:\Program Files\proeWildfire 4.0\i486_nt\obj\xtop.exe"="C:\Program Files\proeWildfire 4.0\i486_nt\obj\xtop.exe:*:Enabled:Pro/ENGINEER Wildfire from PTC"
"D:5\ApexDC\ApexDC\ApexDC.exe"="D:5\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:0\ApexDC\ApexDC\ApexDC.exe"="C:0\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"D:2\ApexDC\ApexDC\ApexDC.exe"="D:2\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:\Program Files\FrostWire\FrostWire.exe"="C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\WWTExplorer.exe"="C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\WWTExplorer.exe:*:Enabled:WorldWide Telescope"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
"D:0\ApexDC\ApexDC\ApexDC.exe"="D:0\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"H:\ApexDC\ApexDC\ApexDC.exe"="H:\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC++"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\ApexDC++\ApexDC.exe"="C:\Program Files\ApexDC++\ApexDC.exe:*:Enabled:ApexDC++"
"X:\ApexDC\ApexDC\ApexDC.exe"="X:\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC++"
"C:\Program Files\Java\jre6\launch4j-tmp\Jubler.exe"="C:\Program Files\Java\jre6\launch4j-tmp\Jubler.exe:*:Enabled:Java(TM) Platform SE binary"
"C:5\ApexDC\ApexDC\ApexDC.exe"="C:5\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:8\ApexDC\ApexDC\ApexDC.exe"="C:8\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"D:4\ApexDC\ApexDC\ApexDC.exe"="D:4\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:4\ApexDC\ApexDC\ApexDC.exe"="C:4\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"X:\ApexDC++\ApexDC.exe"="X:\ApexDC++\ApexDC.exe:*:Enabled:ApexDC++"
"E:\Install\ApexDC\ApexDC\ApexDC.exe"="E:\Install\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC++"
"C:\Program Files\Mozilla Firefox\plugin-container.exe"="C:\Program Files\Mozilla Firefox\plugin-container.exe:*:Enabled:Plugin Container for Firefox"
"D:\HRY\Pocket Tanks Deluxe\pockettanks.exe"="D:\HRY\Pocket Tanks Deluxe\pockettanks.exe:*:Enabled:Pocket Tanks"
"C:\Program Files\StreamTorrent 1.0\StreamTorrent.exe"="C:\Program Files\StreamTorrent 1.0\StreamTorrent.exe:*:Enabled:StreamTorrent Media Player"
"C:\Program Files\Doxxbet\pokerclient\Doxxbet.exe"="C:\Program Files\Doxxbet\pokerclient\Doxxbet.exe:*:Enabled:Poker Client Software"
"C:1\ApexDC\ApexDC\ApexDC.exe"="C:1\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:7\ApexDC\ApexDC\ApexDC.exe"="C:7\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"C:2\ApexDC\ApexDC\ApexDC.exe"="C:2\ApexDC\ApexDC\ApexDC.exe:*:Enabled:ApexDC.exe"
"F:\ApexDC++\ApexDC.exe"="F:\ApexDC++\ApexDC.exe:*:Enabled:ApexDC++"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"F:\ApexDC\ApexDC.exe"="F:\ApexDC\ApexDC.exe:*:Enabled:ApexDC++"
"C:\Program Files\Veetle\Player\VeetleNet.exe"="C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet"
"X:\VirtuaTennis\Virtua Tennis\vtennis\VIRTUA_TENNIS_PC.exe"="X:\VirtuaTennis\Virtua Tennis\vtennis\VIRTUA_TENNIS_PC.exe:*:Enabled:VIRTUA_TENNIS_PC"
"C:\WINDOWS.0\system32\dpnsvr.exe"="C:\WINDOWS.0\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Veetle\Player\VeetleNet.exe"="C:\Program Files\Veetle\Player\VeetleNet.exe:*:Enabled:VeetleNet"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS.0\system32\iac25_32.ax
"vidc.iv50"=C:\PROGRA~1\SPlayer\ir50_32.dll
"msacm.l3acm"=C:\WINDOWS.0\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter"=ac3filter.acm
"VIDC.CSM0"=CSMX.dll

======File associations======

.scr - open - "C:\WINDOWS.0\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2012-02-28 20:33:20 ----D---- C:\rsit

======List of files/folders modified in the last 1 month======

2012-02-28 20:33:27 ----D---- C:\WINDOWS.0\Prefetch
2012-02-28 20:33:25 ----D---- C:\Program Files\trend micro
2012-02-28 20:29:34 ----D---- C:\WINDOWS.0\system32
2012-02-28 20:29:34 ----A---- C:\WINDOWS.0\system32\PerfStringBackup.INI
2012-02-28 20:25:36 ----D---- C:\WINDOWS.0\Temp
2012-02-28 20:24:44 ----D---- C:\WINDOWS.0
2012-02-28 20:21:57 ----D---- C:\Program Files\Mozilla Firefox
2012-02-28 16:42:13 ----D---- C:\Program Files\ABBYY FineReader 10
2012-02-27 22:35:07 ----D---- C:\Documents and Settings\Roman\Application Data\AIMP
2012-02-26 22:11:09 ----D---- C:\WINDOWS.0\system32\CatRoot2
2012-02-23 10:57:38 ----D---- C:\Documents and Settings\Roman\Application Data\Microgaming
2012-02-20 21:06:44 ----D---- C:\bwinPoker JPC
2012-02-18 19:40:14 ----D---- C:\Program Files\PokerStars
2012-02-16 10:40:41 ----D---- C:\Program Files\PartyGaming
2012-02-15 00:54:04 ----D---- C:\Documents and Settings\Roman\Application Data\vlc
2012-02-13 15:12:19 ----D---- C:\Program Files\Foxit Software
2012-02-05 08:05:38 ----A---- C:\WINDOWS.0\SchedLgU.Txt
2012-02-02 20:12:38 ----D---- C:\Program Files\Opera

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\WINDOWS.0\System32\Drivers\sptd.sys [2010-11-14 436792]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS.0\system32\drivers\Aavmker4.sys [2011-05-10 30808]
R1 aswRdr;aswRdr; C:\WINDOWS.0\system32\drivers\aswRdr.sys [2011-05-10 25432]
R1 aswSnx;aswSnx; C:\WINDOWS.0\system32\drivers\aswSnx.sys [2011-05-10 441176]
R1 aswSP;aswSP; C:\WINDOWS.0\system32\drivers\aswSP.sys [2011-05-10 307928]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS.0\system32\drivers\aswTdi.sys [2011-05-10 49240]
R1 intelppm;Intel Processor Driver; C:\WINDOWS.0\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS.0\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS.0\system32\drivers\aswFsBlk.sys [2011-05-10 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS.0\system32\drivers\aswMon2.sys [2011-05-10 102616]
R2 cpuz135;cpuz135; \??\C:\WINDOWS.0\system32\drivers\cpuz135_x32.sys []
R3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver; \??\C:\Program Files\DU Meter\DUM_XP32.SYS []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS.0\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS.0\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS.0\system32\drivers\RtkHDAud.sys [2006-09-22 4381696]
R3 mouhid;Mouse HID Driver; C:\WINDOWS.0\system32\DRIVERS\mouhid.sys [2001-08-18 12160]
R3 NETw3x32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows XP 32 Bit; C:\WINDOWS.0\system32\DRIVERS\NETw3x32.sys [2006-09-26 1709696]
R3 nv;nv; C:\WINDOWS.0\system32\DRIVERS\nv4_mini.sys [2006-07-20 3685152]
R3 sdbus;sdbus; C:\WINDOWS.0\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS.0\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS.0\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS.0\system32\DRIVERS\yk51x86.sys [2006-08-07 248832]
S3 a6zmbfs5;a6zmbfs5; C:\WINDOWS.0\system32\drivers\a6zmbfs5.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS.0\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS.0\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS.0\System32\Drivers\BTHport.sys [2008-04-13 273024]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS.0\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS.0\system32\drivers\mbamswissarmy.sys []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS.0\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS.0\system32\DRIVERS\sffdisk.sys [2008-04-13 11904]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS.0\system32\DRIVERS\sffp_sd.sys [2008-04-13 11008]
S3 usbscan;USB Scanner Driver; C:\WINDOWS.0\system32\DRIVERS\usbscan.sys [2008-04-13 15104]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-05-10 42184]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS.0\system32\svchost.exe [2008-04-14 14336]
R2 DUMeterSvc;DU Meter Service; C:\Program Files\DU Meter\DUMeterSvc.exe [2009-03-13 552052]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS.0\system32\nvsvc32.exe [2006-07-20 143426]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-10-25 85096]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS.0\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Poradí mi niekto čo s tým :?:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trojan & Malware & Rootkit

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Stahnete MBRScan http://eric71.geekstogo.com/tools/MbrScan.exe
  • Ulozte nejlepe na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na MBRScan pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Report
  • Po chvilce se objevi log do souboru MBRScan.txt, ten sem vlozte
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

McLovin
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 29 úno 2012 21:35

Re: Trojan & Malware & Rootkit

#3 Příspěvek od McLovin »

Kód: Vybrat vše

MBRScan v1.1.1

OS             : Windows XP Home Service Pack 3 (32 bit)
PROCESSOR      : x86 Family 6 Model 15 Stepping 2, GenuineIntel
BOOT           : Normal Boot
DATE           : 2012/02/29 (ISO 8601) at 21:51:37
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __FUJITSU MHW2120BH (00000012)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : YES
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

DISK           : Device\Harddisk1\DR4 __My Book 1110 (1032)
BUS_TYPE       : (0x07)  USB
USE_PIO        : NO
MAX_TRANSFER   : 64 Kb
ALIGNMENT_MASK : byte aligned
________________________________________________________________________________

Device\Harddisk0\DR0	111.8 Go  [Fixed] ==> XP MBR Code

MBR_MD5   : 240BD2102F3D0689BF3F64DB1FEE1CEA
MBR_SHA1  : D3DF1B12DD5AE824CC544F303DA1F3E5DD1A560B

Device\Harddisk0\Partition1	19.53 Go  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	48.83 Go  	0x0E FAT16 [LBA] 
Device\Harddisk0\Partition3	43.42 Go  	0x0E FAT16 [LBA] 
________________________________________________________________________________

Device\Harddisk1\DR4	465.1 Go  [Fixed] ==> XP MBR Code ....

MBR_MD5   : 0BC224B1BC55972869EBB5A144502484
MBR_SHA1  : 0F86A03D7E0B2A099FF6E11E8569FEED586979A0

Device\Harddisk1\Partition1	50.00 Go  	0x07 NTFS / HPFS
Device\Harddisk1\Partition2	200.0 Go  	0x07 NTFS / HPFS
Device\Harddisk1\Partition3	215.1 Go  	0x07 NTFS / HPFS
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\WINDOWS.0\System32\Drivers\dump_atapi.sys => Invisible on the disk
ADDRESS : 0xF4466000
SIZE    : 96.0 Ko

DRIVER  : C:\WINDOWS.0\System32\Drivers\dump_WMILIB.SYS => Invisible on the disk
ADDRESS : 0xF7D82000
SIZE    : 8.0 Ko

SystemStartOptions : NOEXECUTE=OPTIN  FASTDETECT

________________________________________________________________________________

_______MBR   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C   3À.м.|ûP.P.ü¾.|
0x00000010   BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04   ¿..PW¹å.ó¤Ë½¾.±.
0x00000020   38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5   8n.|.u..Å.âôÍ..õ
0x00000030   83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B   .Æ.It.8,tö.µ.´..
0x00000040   F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88   ð¬<.tü»..´.Í.ëò.
0x00000050   4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B   N.èF.s*þF..~..t.
0x00000060   80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83   .~..t..¶.uÒ.F...
0x00000070   46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB   F...V..è!.s..¶.ë
0x00000080   BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0   ¼.>þ}Uªt..~..tÈ.
0x00000090   B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56   ·.ë©.ü.W.õË¿...V
0x000000A0   00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC   .´.Í.r#.Á$?..Þ.ü
0x000000B0   43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56   C÷ã.Ñ.Ö±.ÒîB÷â9V
0x000000C0   0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C   .w#r.9F.s.¸..».|
0x000000D0   8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A   .N..V.Í.sQOtN2ä.
0x000000E0   56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD   V.Í.ëä.V.`»ªU´AÍ
0x000000F0   13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60   .r6.ûUªu0öÁ.t+a`
0x00000100   6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A   j.j..v..v.j.h.|j
0x00000110   01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B   .j.´B.ôÍ.aas.Ot.
0x00000120   32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 49 6E 76 61   2ä.V.Í.ëÖaùÃInva
0x00000130   6C 69 64 20 70 61 72 74 69 74 69 6F 6E 20 74 61   lid partition ta
0x00000140   62 6C 65 00 45 72 72 6F 72 20 6C 6F 61 64 69 6E   ble.Error loadin
0x00000150   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x00000160   65 6D 00 4D 69 73 73 69 6E 67 20 6F 70 65 72 61   em.Missing opera
0x00000170   74 69 6E 67 20 73 79 73 74 65 6D 00 00 00 00 00   ting system.....
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 2C 44 63 77 0B 78 0B 00 00 80 01   .....,Dcw.x.....
0x000001C0   01 00 07 FE FF FF 3F 00 00 00 37 16 71 02 00 FE   ...þ..?...7.q..þ
0x000001D0   FF FF 0F FE FF FF 76 16 71 02 8A E2 87 0B 00 00   ...þ..v.q..â....
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

_______MBR   \Device\Harddisk1\DR4  

0x00000000   33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C   3À.м.|ûP.P.ü¾.|
0x00000010   BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04   ¿..PW¹å.ó¤Ë½¾.±.
0x00000020   38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5   8n.|.u..Å.âôÍ..õ
0x00000030   83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B   .Æ.It.8,tö.µ.´..
0x00000040   F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88   ð¬<.tü»..´.Í.ëò.
0x00000050   4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B   N.èF.s*þF..~..t.
0x00000060   80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83   .~..t..¶.uÒ.F...
0x00000070   46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB   F...V..è!.s..¶.ë
0x00000080   BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0   ¼.>þ}Uªt..~..tÈ.
0x00000090   B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56   ·.ë©.ü.W.õË¿...V
0x000000A0   00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC   .´.Í.r#.Á$?..Þ.ü
0x000000B0   43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56   C÷ã.Ñ.Ö±.ÒîB÷â9V
0x000000C0   0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C   .w#r.9F.s.¸..».|
0x000000D0   8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A   .N..V.Í.sQOtN2ä.
0x000000E0   56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD   V.Í.ëä.V.`»ªU´AÍ
0x000000F0   13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60   .r6.ûUªu0öÁ.t+a`
0x00000100   6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A   j.j..v..v.j.h.|j
0x00000110   01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B   .j.´B.ôÍ.aas.Ot.
0x00000120   32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 49 6E 76 61   2ä.V.Í.ëÖaùÃInva
0x00000130   6C 69 64 20 70 61 72 74 69 74 69 6F 6E 20 74 61   lid partition ta
0x00000140   62 6C 65 00 45 72 72 6F 72 20 6C 6F 61 64 69 6E   ble.Error loadin
0x00000150   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x00000160   65 6D 00 4D 69 73 73 69 6E 67 20 6F 70 65 72 61   em.Missing opera
0x00000170   74 69 6E 67 20 73 79 73 74 65 6D 00 00 00 00 00   ting system.....
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 2C 44 63 A0 87 04 00 00 00 00 01   .....,Dc........
0x000001C0   01 00 0F FE FF FF 3F 00 00 00 ED 36 23 3A 00 00   ...þ..?...í6#:..
0x000001D0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª
21:53:44.0521 1456 TDSS rootkit removing tool 2.7.17.0 Feb 29 2012 14:02:24
21:53:44.0646 1456 ============================================================
21:53:44.0646 1456 Current date / time: 2012/02/29 21:53:44.0646
21:53:44.0646 1456 SystemInfo:
21:53:44.0646 1456
21:53:44.0646 1456 OS Version: 5.1.2600 ServicePack: 3.0
21:53:44.0646 1456 Product type: Workstation
21:53:44.0646 1456 ComputerName: ROMAN
21:53:44.0678 1456 UserName: Roman
21:53:44.0678 1456 Windows directory: C:\WINDOWS.0
21:53:44.0678 1456 System windows directory: C:\WINDOWS.0
21:53:44.0678 1456 Processor architecture: Intel x86
21:53:44.0678 1456 Number of processors: 2
21:53:44.0678 1456 Page size: 0x1000
21:53:44.0678 1456 Boot type: Normal boot
21:53:44.0678 1456 ============================================================
21:53:46.0537 1456 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:53:46.0537 1456 Drive \Device\Harddisk1\DR4 - Size: 0x7446E00000 (465.11 Gb), SectorSize: 0x200, Cylinders: 0xED2B, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:53:46.0553 1456 \Device\Harddisk0\DR0:
21:53:46.0553 1456 MBR used
21:53:46.0553 1456 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2711637
21:53:46.0568 1456 \Device\Harddisk0\DR0\Partition1: MBR, Type 0xE, StartLBA 0x27116B5, BlocksNum 0x61A7927
21:53:46.0599 1456 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xE, StartLBA 0x88B901B, BlocksNum 0x56D68E5
21:53:46.0599 1456 \Device\Harddisk1\DR4:
21:53:46.0599 1456 MBR used
21:53:46.0599 1456 \Device\Harddisk1\DR4\Partition0: MBR, Type 0x7, StartLBA 0x7E, BlocksNum 0x63FE6FD
21:53:46.0615 1456 \Device\Harddisk1\DR4\Partition1: MBR, Type 0x7, StartLBA 0x63FE7BB, BlocksNum 0x190001B8
21:53:46.0615 1456 \Device\Harddisk1\DR4\Partition2: MBR, Type 0x7, StartLBA 0x1F3FE9B2, BlocksNum 0x1AE34D7A
21:53:47.0459 1456 Initialize success
21:53:47.0459 1456 ============================================================
21:54:16.0334 2072 ============================================================
21:54:16.0334 2072 Scan started
21:54:16.0334 2072 Mode: Manual; SigCheck; TDLFS;
21:54:16.0334 2072 ============================================================
21:54:16.0787 2072 Aavmker4 (3f6884eff406238d39aaa892218f1df7) C:\WINDOWS.0\system32\drivers\Aavmker4.sys
21:54:17.0131 2072 Aavmker4 - ok
21:54:17.0224 2072 Abiosdsk - ok
21:54:17.0256 2072 abp480n5 - ok
21:54:17.0303 2072 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS.0\system32\DRIVERS\ACPI.sys
21:54:18.0021 2072 ACPI - ok
21:54:18.0131 2072 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS.0\system32\DRIVERS\ACPIEC.sys
21:54:18.0271 2072 ACPIEC - ok
21:54:18.0303 2072 adpu160m - ok
21:54:18.0349 2072 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS.0\system32\drivers\aec.sys
21:54:18.0474 2072 aec - ok
21:54:18.0506 2072 AFD (322d0e36693d6e24a2398bee62a268cd) C:\WINDOWS.0\System32\drivers\afd.sys
21:54:18.0631 2072 AFD - ok
21:54:18.0646 2072 Aha154x - ok
21:54:18.0646 2072 aic78u2 - ok
21:54:18.0662 2072 aic78xx - ok
21:54:18.0678 2072 AliIde - ok
21:54:18.0693 2072 amsint - ok
21:54:18.0693 2072 asc - ok
21:54:18.0709 2072 asc3350p - ok
21:54:18.0724 2072 asc3550 - ok
21:54:18.0787 2072 aswFsBlk (7f08d9c504b015d81a8abd75c80028c5) C:\WINDOWS.0\system32\drivers\aswFsBlk.sys
21:54:18.0787 2072 aswFsBlk - ok
21:54:19.0068 2072 aswMon2 (c2181ef6b54752273a0759a968c59279) C:\WINDOWS.0\system32\drivers\aswMon2.sys
21:54:19.0068 2072 aswMon2 - ok
21:54:19.0099 2072 aswRdr (ac48bdd4cd5d44af33087c06d6e9511c) C:\WINDOWS.0\system32\drivers\aswRdr.sys
21:54:19.0115 2072 aswRdr - ok
21:54:19.0162 2072 aswSnx (b64134316fcd1f20e0f10ef3e65bd522) C:\WINDOWS.0\system32\drivers\aswSnx.sys
21:54:19.0193 2072 aswSnx - ok
21:54:19.0224 2072 aswSP (d6788e3211afa9951ed7a4d617f68a4f) C:\WINDOWS.0\system32\drivers\aswSP.sys
21:54:19.0240 2072 aswSP - ok
21:54:19.0240 2072 aswTdi (4d100c45517809439c7b6dd98997fa00) C:\WINDOWS.0\system32\drivers\aswTdi.sys
21:54:19.0256 2072 aswTdi - ok
21:54:19.0287 2072 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS.0\system32\DRIVERS\asyncmac.sys
21:54:19.0428 2072 AsyncMac - ok
21:54:19.0443 2072 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS.0\system32\DRIVERS\atapi.sys
21:54:19.0584 2072 atapi - ok
21:54:19.0678 2072 Atdisk - ok
21:54:19.0709 2072 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS.0\system32\DRIVERS\atmarpc.sys
21:54:19.0849 2072 Atmarpc - ok
21:54:19.0896 2072 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS.0\system32\DRIVERS\audstub.sys
21:54:20.0053 2072 audstub - ok
21:54:20.0115 2072 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS.0\system32\drivers\Beep.sys
21:54:20.0256 2072 Beep - ok
21:54:20.0303 2072 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS.0\system32\DRIVERS\BthEnum.sys
21:54:20.0443 2072 BthEnum - ok
21:54:20.0506 2072 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS.0\system32\DRIVERS\bthpan.sys
21:54:20.0662 2072 BthPan - ok
21:54:20.0693 2072 BTHPORT (10b85171b90c449f8da71c2640b797e9) C:\WINDOWS.0\system32\Drivers\BTHport.sys
21:54:20.0834 2072 BTHPORT - ok
21:54:20.0912 2072 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS.0\system32\Drivers\BTHUSB.sys
21:54:21.0037 2072 BTHUSB - ok
21:54:21.0084 2072 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS.0\system32\drivers\cbidf2k.sys
21:54:21.0224 2072 cbidf2k - ok
21:54:21.0256 2072 cd20xrnt - ok
21:54:21.0303 2072 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS.0\system32\drivers\Cdaudio.sys
21:54:21.0443 2072 Cdaudio - ok
21:54:21.0506 2072 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS.0\system32\drivers\Cdfs.sys
21:54:21.0662 2072 Cdfs - ok
21:54:21.0740 2072 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS.0\system32\DRIVERS\cdrom.sys
21:54:21.0896 2072 Cdrom - ok
21:54:21.0990 2072 Changer - ok
21:54:22.0053 2072 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS.0\system32\DRIVERS\CmBatt.sys
21:54:22.0209 2072 CmBatt - ok
21:54:22.0240 2072 CmdIde - ok
21:54:22.0287 2072 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS.0\system32\DRIVERS\compbatt.sys
21:54:22.0412 2072 Compbatt - ok
21:54:22.0428 2072 Cpqarray - ok
21:54:22.0521 2072 cpuz135 (c2eb4539a4f6ab6edd01bdc191619975) C:\WINDOWS.0\system32\drivers\cpuz135_x32.sys
21:54:22.0521 2072 cpuz135 - ok
21:54:22.0537 2072 dac2w2k - ok
21:54:22.0553 2072 dac960nt - ok
21:54:22.0599 2072 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS.0\system32\DRIVERS\disk.sys
21:54:22.0740 2072 Disk - ok
21:54:22.0834 2072 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS.0\system32\drivers\dmboot.sys
21:54:23.0021 2072 dmboot - ok
21:54:23.0068 2072 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS.0\system32\drivers\dmio.sys
21:54:23.0209 2072 dmio - ok
21:54:23.0240 2072 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS.0\system32\drivers\dmload.sys
21:54:23.0396 2072 dmload - ok
21:54:23.0459 2072 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS.0\system32\drivers\DMusic.sys
21:54:23.0599 2072 DMusic - ok
21:54:23.0615 2072 dpti2o - ok
21:54:23.0678 2072 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS.0\system32\drivers\drmkaud.sys
21:54:23.0818 2072 drmkaud - ok
21:54:23.0896 2072 DUMeterDrv (24f97aca2946fbaa46e38babdef766c0) C:\Program Files\DU Meter\DUM_XP32.SYS
21:54:23.0912 2072 DUMeterDrv - ok
21:54:23.0990 2072 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS.0\system32\drivers\Fastfat.sys
21:54:24.0146 2072 Fastfat - ok
21:54:24.0209 2072 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS.0\system32\drivers\Fdc.sys
21:54:24.0349 2072 Fdc - ok
21:54:24.0365 2072 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS.0\system32\drivers\Fips.sys
21:54:24.0506 2072 Fips - ok
21:54:24.0537 2072 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS.0\system32\drivers\Flpydisk.sys
21:54:24.0662 2072 Flpydisk - ok
21:54:24.0693 2072 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS.0\system32\DRIVERS\fltMgr.sys
21:54:24.0834 2072 FltMgr - ok
21:54:24.0881 2072 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS.0\system32\drivers\Fs_Rec.sys
21:54:25.0006 2072 Fs_Rec - ok
21:54:25.0084 2072 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS.0\system32\DRIVERS\ftdisk.sys
21:54:25.0224 2072 Ftdisk - ok
21:54:25.0271 2072 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS.0\system32\DRIVERS\msgpc.sys
21:54:25.0412 2072 Gpc - ok
21:54:25.0459 2072 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS.0\system32\DRIVERS\HDAudBus.sys
21:54:25.0599 2072 HDAudBus - ok
21:54:25.0631 2072 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS.0\system32\DRIVERS\hidusb.sys
21:54:25.0771 2072 hidusb - ok
21:54:25.0787 2072 hpn - ok
21:54:25.0818 2072 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS.0\system32\Drivers\HTTP.sys
21:54:25.0959 2072 HTTP - ok
21:54:25.0990 2072 i2omgmt - ok
21:54:26.0021 2072 i2omp - ok
21:54:26.0068 2072 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS.0\system32\DRIVERS\i8042prt.sys
21:54:26.0209 2072 i8042prt - ok
21:54:26.0271 2072 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS.0\system32\DRIVERS\imapi.sys
21:54:26.0412 2072 Imapi - ok
21:54:26.0443 2072 ini910u - ok
21:54:26.0631 2072 IntcAzAudAddService (1b717caf195ad09a67a7904140b2c6fb) C:\WINDOWS.0\system32\drivers\RtkHDAud.sys
21:54:26.0974 2072 IntcAzAudAddService - ok
21:54:27.0037 2072 IntelIde - ok
21:54:27.0084 2072 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS.0\system32\DRIVERS\intelppm.sys
21:54:27.0224 2072 intelppm - ok
21:54:27.0271 2072 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS.0\system32\DRIVERS\Ip6Fw.sys
21:54:27.0412 2072 Ip6Fw - ok
21:54:27.0474 2072 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS.0\system32\DRIVERS\ipfltdrv.sys
21:54:27.0615 2072 IpFilterDriver - ok
21:54:27.0646 2072 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS.0\system32\DRIVERS\ipinip.sys
21:54:27.0771 2072 IpInIp - ok
21:54:27.0803 2072 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS.0\system32\DRIVERS\ipnat.sys
21:54:27.0943 2072 IpNat - ok
21:54:28.0037 2072 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS.0\system32\DRIVERS\ipsec.sys
21:54:28.0162 2072 IPSec - ok
21:54:28.0209 2072 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS.0\system32\DRIVERS\irenum.sys
21:54:28.0256 2072 IRENUM - ok
21:54:28.0303 2072 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS.0\system32\DRIVERS\isapnp.sys
21:54:28.0428 2072 isapnp - ok
21:54:28.0459 2072 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS.0\system32\DRIVERS\kbdclass.sys
21:54:28.0599 2072 Kbdclass - ok
21:54:28.0631 2072 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS.0\system32\drivers\kmixer.sys
21:54:28.0771 2072 kmixer - ok
21:54:28.0912 2072 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS.0\system32\drivers\KSecDD.sys
21:54:29.0084 2072 KSecDD - ok
21:54:29.0146 2072 lbrtfdc - ok
21:54:29.0162 2072 MBAMSwissArmy - ok
21:54:29.0193 2072 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS.0\system32\drivers\mnmdd.sys
21:54:29.0334 2072 mnmdd - ok
21:54:29.0412 2072 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS.0\system32\drivers\Modem.sys
21:54:29.0553 2072 Modem - ok
21:54:29.0599 2072 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS.0\system32\DRIVERS\mouclass.sys
21:54:29.0771 2072 Mouclass - ok
21:54:29.0803 2072 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS.0\system32\DRIVERS\mouhid.sys
21:54:29.0943 2072 mouhid - ok
21:54:29.0974 2072 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS.0\system32\drivers\MountMgr.sys
21:54:30.0115 2072 MountMgr - ok
21:54:30.0178 2072 mraid35x - ok
21:54:30.0209 2072 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS.0\system32\DRIVERS\mrxdav.sys
21:54:30.0349 2072 MRxDAV - ok
21:54:30.0412 2072 MRxSmb (68755f0ff16070178b54674fe5b847b0) C:\WINDOWS.0\system32\DRIVERS\mrxsmb.sys
21:54:30.0553 2072 MRxSmb - ok
21:54:30.0615 2072 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS.0\system32\drivers\Msfs.sys
21:54:30.0756 2072 Msfs - ok
21:54:30.0803 2072 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS.0\system32\drivers\MSKSSRV.sys
21:54:30.0943 2072 MSKSSRV - ok
21:54:30.0943 2072 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS.0\system32\drivers\MSPCLOCK.sys
21:54:31.0068 2072 MSPCLOCK - ok
21:54:31.0068 2072 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS.0\system32\drivers\MSPQM.sys
21:54:31.0256 2072 MSPQM - ok
21:54:31.0349 2072 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS.0\system32\DRIVERS\mssmbios.sys
21:54:31.0474 2072 mssmbios - ok
21:54:31.0506 2072 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS.0\system32\drivers\Mup.sys
21:54:31.0631 2072 Mup - ok
21:54:31.0646 2072 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS.0\system32\drivers\NDIS.sys
21:54:31.0771 2072 NDIS - ok
21:54:31.0803 2072 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS.0\system32\DRIVERS\ndistapi.sys
21:54:31.0943 2072 NdisTapi - ok
21:54:31.0959 2072 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS.0\system32\DRIVERS\ndisuio.sys
21:54:32.0084 2072 Ndisuio - ok
21:54:32.0099 2072 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS.0\system32\DRIVERS\ndiswan.sys
21:54:32.0240 2072 NdisWan - ok
21:54:32.0271 2072 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS.0\system32\drivers\NDProxy.sys
21:54:32.0396 2072 NDProxy - ok
21:54:32.0396 2072 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS.0\system32\DRIVERS\netbios.sys
21:54:32.0537 2072 NetBIOS - ok
21:54:32.0599 2072 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS.0\system32\DRIVERS\netbt.sys
21:54:32.0740 2072 NetBT - ok
21:54:32.0849 2072 NETw3x32 (e2f396f71a793a04839dbb6af304a026) C:\WINDOWS.0\system32\DRIVERS\NETw3x32.sys
21:54:33.0021 2072 NETw3x32 - ok
21:54:33.0037 2072 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS.0\system32\drivers\Npfs.sys
21:54:33.0178 2072 Npfs - ok
21:54:33.0209 2072 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS.0\system32\drivers\Ntfs.sys
21:54:33.0349 2072 Ntfs - ok
21:54:33.0412 2072 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS.0\system32\drivers\Null.sys
21:54:33.0537 2072 Null - ok
21:54:33.0724 2072 nv (59e5d945934ec2e7eaa22af81813dabf) C:\WINDOWS.0\system32\DRIVERS\nv4_mini.sys
21:54:33.0990 2072 nv - ok
21:54:34.0115 2072 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS.0\system32\DRIVERS\nwlnkflt.sys
21:54:34.0240 2072 NwlnkFlt - ok
21:54:34.0271 2072 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS.0\system32\DRIVERS\nwlnkfwd.sys
21:54:34.0412 2072 NwlnkFwd - ok
21:54:34.0459 2072 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS.0\system32\drivers\Parport.sys
21:54:34.0599 2072 Parport - ok
21:54:34.0615 2072 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS.0\system32\drivers\PartMgr.sys
21:54:34.0740 2072 PartMgr - ok
21:54:34.0756 2072 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS.0\system32\drivers\ParVdm.sys
21:54:34.0896 2072 ParVdm - ok
21:54:34.0928 2072 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS.0\system32\DRIVERS\pci.sys
21:54:35.0068 2072 PCI - ok
21:54:35.0068 2072 PCIDump - ok
21:54:35.0099 2072 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS.0\system32\DRIVERS\pciide.sys
21:54:35.0224 2072 PCIIde - ok
21:54:35.0318 2072 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS.0\system32\DRIVERS\pcmcia.sys
21:54:35.0474 2072 Pcmcia - ok
21:54:35.0474 2072 PDCOMP - ok
21:54:35.0490 2072 PDFRAME - ok
21:54:35.0506 2072 PDRELI - ok
21:54:35.0506 2072 PDRFRAME - ok
21:54:35.0521 2072 perc2 - ok
21:54:35.0537 2072 perc2hib - ok
21:54:35.0599 2072 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS.0\system32\DRIVERS\raspptp.sys
21:54:35.0724 2072 PptpMiniport - ok
21:54:35.0740 2072 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS.0\system32\DRIVERS\psched.sys
21:54:35.0881 2072 PSched - ok
21:54:35.0943 2072 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS.0\system32\DRIVERS\ptilink.sys
21:54:36.0068 2072 Ptilink - ok
21:54:36.0084 2072 ql1080 - ok
21:54:36.0099 2072 Ql10wnt - ok
21:54:36.0099 2072 ql12160 - ok
21:54:36.0131 2072 ql1240 - ok
21:54:36.0131 2072 ql1280 - ok
21:54:36.0146 2072 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS.0\system32\DRIVERS\rasacd.sys
21:54:36.0271 2072 RasAcd - ok
21:54:36.0334 2072 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS.0\system32\DRIVERS\rasl2tp.sys
21:54:36.0459 2072 Rasl2tp - ok
21:54:36.0490 2072 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS.0\system32\DRIVERS\raspppoe.sys
21:54:36.0615 2072 RasPppoe - ok
21:54:36.0662 2072 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS.0\system32\DRIVERS\raspti.sys
21:54:36.0787 2072 Raspti - ok
21:54:36.0818 2072 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS.0\system32\DRIVERS\rdbss.sys
21:54:36.0959 2072 Rdbss - ok
21:54:36.0990 2072 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS.0\system32\DRIVERS\RDPCDD.sys
21:54:37.0115 2072 RDPCDD - ok
21:54:37.0178 2072 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS.0\system32\DRIVERS\rdpdr.sys
21:54:37.0318 2072 rdpdr - ok
21:54:37.0365 2072 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS.0\system32\drivers\RDPWD.sys
21:54:37.0506 2072 RDPWD - ok
21:54:37.0568 2072 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS.0\system32\DRIVERS\redbook.sys
21:54:37.0693 2072 redbook - ok
21:54:37.0740 2072 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS.0\system32\DRIVERS\rfcomm.sys
21:54:37.0896 2072 RFCOMM - ok
21:54:37.0974 2072 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS.0\system32\DRIVERS\sdbus.sys
21:54:38.0115 2072 sdbus - ok
21:54:38.0162 2072 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS.0\system32\DRIVERS\secdrv.sys
21:54:38.0224 2072 Secdrv - ok
21:54:38.0271 2072 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS.0\system32\drivers\Serial.sys
21:54:38.0396 2072 Serial - ok
21:54:38.0490 2072 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS.0\system32\DRIVERS\sffdisk.sys
21:54:38.0599 2072 sffdisk - ok
21:54:38.0615 2072 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS.0\system32\DRIVERS\sffp_sd.sys
21:54:38.0756 2072 sffp_sd - ok
21:54:38.0771 2072 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS.0\system32\drivers\Sfloppy.sys
21:54:38.0881 2072 Sfloppy - ok
21:54:38.0912 2072 Simbad - ok
21:54:38.0928 2072 Sparrow - ok
21:54:38.0959 2072 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS.0\system32\drivers\splitter.sys
21:54:39.0099 2072 splitter - ok
21:54:39.0146 2072 sptd (a199171385be17973fd800fa91f8f78a) C:\WINDOWS.0\system32\Drivers\sptd.sys
21:54:39.0146 2072 Suspicious file (NoAccess): C:\WINDOWS.0\system32\Drivers\sptd.sys. md5: a199171385be17973fd800fa91f8f78a
21:54:39.0146 2072 sptd ( LockedFile.Multi.Generic ) - warning
21:54:39.0146 2072 sptd - detected LockedFile.Multi.Generic (1)
21:54:39.0178 2072 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS.0\system32\DRIVERS\sr.sys
21:54:39.0240 2072 sr - ok
21:54:39.0303 2072 Srv (5252605079810904e31c332e241cd59b) C:\WINDOWS.0\system32\DRIVERS\srv.sys
21:54:39.0443 2072 Srv - ok
21:54:39.0521 2072 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS.0\system32\DRIVERS\swenum.sys
21:54:39.0646 2072 swenum - ok
21:54:39.0693 2072 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS.0\system32\drivers\swmidi.sys
21:54:39.0818 2072 swmidi - ok
21:54:39.0834 2072 symc810 - ok
21:54:39.0834 2072 symc8xx - ok
21:54:39.0849 2072 sym_hi - ok
21:54:39.0865 2072 sym_u3 - ok
21:54:39.0896 2072 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS.0\system32\drivers\sysaudio.sys
21:54:40.0021 2072 sysaudio - ok
21:54:40.0084 2072 Tcpip (93ea8d04ec73a85db02eb8805988f733) C:\WINDOWS.0\system32\DRIVERS\tcpip.sys
21:54:40.0271 2072 Tcpip - ok
21:54:40.0318 2072 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS.0\system32\drivers\TDPIPE.sys
21:54:40.0474 2072 TDPIPE - ok
21:54:40.0506 2072 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS.0\system32\drivers\TDTCP.sys
21:54:40.0646 2072 TDTCP - ok
21:54:40.0709 2072 TermDD (88155247177638048422893737429d9e) C:\WINDOWS.0\system32\DRIVERS\termdd.sys
21:54:40.0834 2072 TermDD - ok
21:54:40.0849 2072 TosIde - ok
21:54:40.0912 2072 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS.0\system32\drivers\Udfs.sys
21:54:41.0037 2072 Udfs - ok
21:54:41.0068 2072 ultra - ok
21:54:41.0131 2072 UnlockerDriver5 (d0cb75386d9e89c864d808d64ec9160f) C:\Program Files\Unlocker\UnlockerDriver5.sys
21:54:41.0146 2072 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - warning
21:54:41.0146 2072 UnlockerDriver5 - detected UnsignedFile.Multi.Generic (1)
21:54:41.0193 2072 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS.0\system32\DRIVERS\update.sys
21:54:41.0318 2072 Update - ok
21:54:41.0396 2072 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS.0\system32\DRIVERS\usbehci.sys
21:54:41.0521 2072 usbehci - ok
21:54:41.0584 2072 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS.0\system32\DRIVERS\usbhub.sys
21:54:41.0724 2072 usbhub - ok
21:54:41.0803 2072 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS.0\system32\DRIVERS\usbscan.sys
21:54:41.0928 2072 usbscan - ok
21:54:41.0974 2072 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS.0\system32\DRIVERS\USBSTOR.SYS
21:54:42.0099 2072 usbstor - ok
21:54:42.0131 2072 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS.0\system32\DRIVERS\usbuhci.sys
21:54:42.0256 2072 usbuhci - ok
21:54:42.0271 2072 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS.0\System32\drivers\vga.sys
21:54:42.0396 2072 VgaSave - ok
21:54:42.0396 2072 ViaIde - ok
21:54:42.0428 2072 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS.0\system32\drivers\VolSnap.sys
21:54:42.0553 2072 VolSnap - ok
21:54:42.0631 2072 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS.0\system32\DRIVERS\wanarp.sys
21:54:42.0756 2072 Wanarp - ok
21:54:42.0771 2072 WDICA - ok
21:54:42.0803 2072 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS.0\system32\drivers\wdmaud.sys
21:54:42.0928 2072 wdmaud - ok
21:54:42.0974 2072 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS.0\system32\DRIVERS\wmiacpi.sys
21:54:43.0084 2072 WmiAcpi - ok
21:54:43.0146 2072 yukonwxp (05d48e56ea2612d39a4e7f0ecc17b917) C:\WINDOWS.0\system32\DRIVERS\yk51x86.sys
21:54:43.0178 2072 yukonwxp - ok
21:54:43.0209 2072 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
21:54:43.0521 2072 \Device\Harddisk0\DR0 - ok
21:54:43.0553 2072 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR4
21:54:43.0709 2072 \Device\Harddisk1\DR4 - ok
21:54:43.0709 2072 Boot (0x1200) (7ca3c44fd1198a2d0444897b9674df61) \Device\Harddisk0\DR0\Partition0
21:54:43.0709 2072 \Device\Harddisk0\DR0\Partition0 - ok
21:54:43.0709 2072 Boot (0x1200) (91fcbc6b141d1bb9db16b716ccd088dc) \Device\Harddisk0\DR0\Partition1
21:54:43.0709 2072 \Device\Harddisk0\DR0\Partition1 - ok
21:54:43.0756 2072 Boot (0x1200) (16a0e0e91c04ec1fe82f1add2dfec39c) \Device\Harddisk0\DR0\Partition2
21:54:43.0756 2072 \Device\Harddisk0\DR0\Partition2 - ok
21:54:43.0756 2072 Boot (0x1200) (84d990b877118016e1dce8ea6fd79fcc) \Device\Harddisk1\DR4\Partition0
21:54:43.0756 2072 \Device\Harddisk1\DR4\Partition0 - ok
21:54:43.0771 2072 Boot (0x1200) (65e5de9e4910173c835afdc43c737f2a) \Device\Harddisk1\DR4\Partition1
21:54:43.0787 2072 \Device\Harddisk1\DR4\Partition1 - ok
21:54:43.0803 2072 Boot (0x1200) (e5e164676135d9e48b0b414b41f72f75) \Device\Harddisk1\DR4\Partition2
21:54:43.0803 2072 \Device\Harddisk1\DR4\Partition2 - ok
21:54:43.0803 2072 ============================================================
21:54:43.0803 2072 Scan finished
21:54:43.0803 2072 ============================================================
21:54:43.0928 3528 Detected object count: 2
21:54:43.0928 3528 Actual detected object count: 2
21:55:08.0849 3528 sptd ( LockedFile.Multi.Generic ) - skipped by user
21:55:08.0849 3528 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
21:55:08.0849 3528 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - skipped by user
21:55:08.0849 3528 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:55:17.0443 3988 Deinitialize success

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trojan & Malware & Rootkit

#4 Příspěvek od vyosek »

Tak tohle bychom meli OK, mrknem dale kde se skryvaji :)

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

McLovin
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 29 úno 2012 21:35

Re: Trojan & Malware & Rootkit

#5 Příspěvek od McLovin »

RogueKiller V7.2.1 [02/29/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operačný systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spustené v : Normálny režim
Užívateľ: Roman [Práva Správcu]
Mode: Kontrola -- Date: 02/29/2012 22:04:16

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrov: 6 ¤¤¤
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> FOUND
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> FOUND
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač: [NAHRATÉ] ¤¤¤

¤¤¤ Nákaza : ZeroAccess ¤¤¤
[ZeroAccess] (LOCKED) windir\NtUpdateKBxxxx present!

¤¤¤ Súbor HOSTS: ¤¤¤
ÿþ1

¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHW2120BH +++++
--- User ---
[MBR] 240bd2102f3d0689bf3f64db1fee1cea
[BSP] a8abf93d554bd9e02f150bfa1a4379d3 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 20002 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 40965750 | Size: 94460 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: WD My Book 1110 USB Device +++++
--- User ---
[MBR] 0bc224b1bc55972869ebb5a144502484
[BSP] 80800248c3ad43dc24815dfff0d27317 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 63 | Size: 476262 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončené : << RKreport[1].txt >>
RKreport[1].txt



Po dokončení mi otvorilo v prehliadači aj túto stránku

Kód: Vybrat vše

http://tigzyrk.blogspot.com/2011/09/rootkit-zeroaccess-max.html

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trojan & Malware & Rootkit

#6 Příspěvek od vyosek »

:arrow: No jo, je tam mrcha, ale jeho starsi verze

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

McLovin
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 29 úno 2012 21:35

Re: Trojan & Malware & Rootkit

#7 Příspěvek od McLovin »

Po dokončení skenu a reštarte pokračoval CF normálne ďalej, niečo vymazal a po následnom reštarte mi už bohužiaľ nenabehol Windows, respektíve chcel aktiváciu - mal som na výber "áno" alebo "nie". V oboch prípadoch sa dostnem maximálne po prihlasovaciu obrazovku, potom si zas vypýta aktiváciu a toto sa opakuje stále dookola. CF asi vymazal aj niečo čím som crackol Windows. Tento problém som už mal aj predtým, takže budem musieť asi naformátovať disk a nahodiť nový Windows.

Len sa chcem spýtať, či ten vírus mi tam neostane náhodou aj potom, lebo chcem sformátovať iba partíciu C a partície D, E nie. Neskôr sem ešte hodím aj log z CF keď ho nájdem - cez Hirens Boot CD by som sa k súborom na disku mal dostať.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trojan & Malware & Rootkit

#8 Příspěvek od vyosek »

tema ukoncuji, jelikoz toto neni muj problem ze win nenabehli z duvodu smazani cracku...ja predpokladal, ze windows jsou legalni - nelegalnim SW se nezabyvame - viz pravidla fora

Pomoc s neleegalnim SW bude odmitnuta :!:

:closed:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět