Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu(IRCBot)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Prosím o kontrolu(IRCBot)

#1 Příspěvek od Driver3 »

Dobrý den,
prosím Vás o kontrolu :)


Object "Backdoor (IRCBot) Trojans Spyware/Adware" found in File System! Action Taken: Entries Removed.
Object "AntiSpyware Pro XP Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed.
** Scanning may fail! File Locked [SUSPICIOUS]: C:\Documents and Settings\Inna\Local Settings\temp\Bunndle\BunndleOfferManager.dll (????)

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#2 Příspěvek od Driver3 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Inna at 2012-07-09 01:04:22
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 41 GB (79%) free of 51 GB
Total RAM: 3582 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:04:23, on 9.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\JulaPan.Exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Inna\Local Settings\Temp\mwavscan.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\RSIT\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HiJackThis\Inna.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JulaPan] JulaPan.Exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: AutorunsDisabled
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microso ... 0481329328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0481310937
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan ... stubie.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A8AA0C00-BDF9-4109-B0C6-7FF3E249E4D8}: NameServer = 194.228.41.113 160.218.161.54
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe

--
End of file - 5442 bytes

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.257 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.5.1]
"Description"=
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandasecurity.com/activescan]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll
npwachk.dll

C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

C:\Documents and Settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default\searchplugins\
askcom.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04 453504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04 157576]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"JulaPan"=C:\WINDOWS\system32\JulaPan.Exe [2008-06-24 421888]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-03-11 6749512]
"AdslTaskBar"=stmctrl.dll,TaskBar []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-12-05 98304]
"ThreatFire"=C:\Program Files\ThreatFire\TFTray.exe [2010-01-14 378128]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2012-04-04 462408]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\36X Raid Configurer]
C:\WINDOWS\system32\xRaidSetup.exe [2007-11-19 1966080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeARM.exe]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALCMTR.EXE]
C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
C:\WINDOWS\ALCWZRD.EXE [2008-06-19 2808832]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneVI]
C:\Program Files\GIGABYTE\ET6\ETcall.exe [2007-07-26 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\PROGRA~1\Eraser\Eraser.exe [2012-05-22 980920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Inna\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2012-01-17 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetLimiter]
C:\Program Files\NetLimiter\NetLimiter.exe [2004-03-31 823296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2008-07-23 16804864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2008-06-18 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2012-06-20 74752]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
AutorunsDisabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2011-05-04 551296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2011-12-06 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Opera2\opera.exe"="C:\Program Files\Opera2\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe"="C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe:*:Enabled:Opera Internet Browser - Plugin wrapper"
"C:\Documents and Settings\Inna\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Inna\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FFDS"=C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"msacm.l3codecp"=
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-07-09 00:46:36 ----AD---- C:\WINDOWS\rundll16.exe
2012-07-09 00:46:36 ----AD---- C:\WINDOWS\logo1_.exe
2012-07-06 13:16:28 ----D---- C:\Program Files\Auslogics
2012-07-01 22:41:26 ----D---- C:\Documents and Settings\Inna\Data aplikací\Dropbox
2012-07-01 01:55:04 ----SHD---- C:\RECYCLER
2012-07-01 01:35:06 ----A---- C:\ComboFix.txt
2012-07-01 01:11:05 ----A---- C:\Boot.bak
2012-07-01 01:11:01 ----RASHD---- C:\cmdcons
2012-07-01 01:08:23 ----A---- C:\WINDOWS\zip.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\SWXCACLS.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\SWSC.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\SWREG.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\sed.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\PEV.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\NIRCMD.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\MBR.exe
2012-07-01 01:08:23 ----A---- C:\WINDOWS\grep.exe
2012-07-01 01:07:47 ----D---- C:\ComboFix
2012-07-01 01:06:57 ----AD---- C:\Qoobox
2012-07-01 01:06:33 ----D---- C:\WINDOWS\erdnt
2012-06-30 23:52:41 ----A---- C:\Documents and Settings\All Users\Data aplikací\restart.txt
2012-06-30 23:42:50 ----D---- C:\Program Files\AntiVir PersonalEdition Classic
2012-06-30 14:21:22 ----D---- C:\rsit
2012-06-30 00:03:39 ----D---- C:\Program Files\RSIT
2012-06-29 20:55:01 ----D---- C:\Program Files\NeroCDSpeed
2012-06-29 19:17:00 ----D---- C:\Documents and Settings\Inna\Data aplikací\ImgBurn
2012-06-29 18:50:43 ----D---- C:\Program Files\ImgBurn
2012-06-29 09:00:32 ----D---- C:\Documents and Settings\Inna\Data aplikací\Malwarebytes
2012-06-29 09:00:21 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-06-29 09:00:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-06-29 09:00:21 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-06-28 12:46:41 ----D---- C:\Program Files\OTMovelt
2012-06-27 20:50:39 ----D---- C:\Documents and Settings\Inna\Data aplikací\SUPERAntiSpyware.com
2012-06-27 20:50:02 ----D---- C:\Program Files\SUPERAntiSpyware
2012-06-27 20:50:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2012-06-26 21:23:38 ----AD---- C:\WINDOWS\VDLL.DLL
2012-06-26 21:23:38 ----AD---- C:\WINDOWS\system32\runouce.exe
2012-06-26 21:23:38 ----AD---- C:\WINDOWS\RUNDL132.EXE
2012-06-26 21:23:38 ----AD---- C:\WINDOWS\logo_1.exe
2012-06-26 20:59:32 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-06-26 20:59:18 ----A---- C:\WINDOWS\system32\msvcr80.dll
2012-06-26 20:59:17 ----A---- C:\WINDOWS\system32\msvcp80.dll
2012-06-26 20:59:16 ----A---- C:\WINDOWS\system32\msvcp90.dll
2012-06-26 20:59:15 ----A---- C:\WINDOWS\system32\msvcr90.dll
2012-06-26 20:59:14 ----A---- C:\WINDOWS\system32\eEmpty.exe
2012-06-26 20:59:12 ----A---- C:\WINDOWS\system32\TASKMGR.COM
2012-06-26 20:59:12 ----A---- C:\WINDOWS\system32\T.COM
2012-06-26 20:59:12 ----A---- C:\WINDOWS\REGEDIT.COM
2012-06-26 20:59:12 ----A---- C:\WINDOWS\R.COM
2012-06-26 20:59:10 ----D---- C:\Program Files\Common Files\MicroWorld
2012-06-26 20:59:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2012-06-26 14:49:50 ----D---- C:\Program Files\Wireshark
2012-06-26 14:37:37 ----D---- C:\Documents and Settings\Inna\Data aplikací\Online Solutions
2012-06-26 14:30:12 ----D---- C:\Program Files\Common Files\Java
2012-06-26 14:29:48 ----D---- C:\Program Files\Oracle
2012-06-26 14:29:43 ----D---- C:\Documents and Settings\Inna\Data aplikací\Oracle
2012-06-26 13:47:02 ----D---- C:\Program Files\Online Solutions
2012-06-26 13:47:02 ----D---- C:\Program Files\Common Files\Online Solutions Shared
2012-06-25 12:02:32 ----D---- C:\Documents and Settings\Inna\Data aplikací\xrecode2
2012-06-25 12:02:30 ----D---- C:\Program Files\xrecode II
2012-06-24 15:28:15 ----D---- C:\Documents and Settings\Inna\Data aplikací\CUE Tools
2012-06-24 15:27:28 ----D---- C:\Program Files\Cue_Tools
2012-06-23 22:44:43 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-06-23 22:44:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Mozilla
2012-06-23 22:32:02 ----A---- C:\WINDOWS\system32\npdeployJava1.dll
2012-06-23 22:32:02 ----A---- C:\WINDOWS\system32\javaws.exe
2012-06-23 22:32:02 ----A---- C:\WINDOWS\system32\javaw.exe
2012-06-23 22:32:02 ----A---- C:\WINDOWS\system32\java.exe
2012-06-23 22:13:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2685939$
2012-06-23 22:13:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2709162$
2012-06-23 22:10:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2707511$
2012-06-23 22:10:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2718704$
2012-06-23 22:05:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-06-23 22:05:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-06-23 22:05:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2012-06-23 21:57:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2695962$
2012-06-23 21:57:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2012-06-23 20:56:39 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2012-06-23 19:28:05 ----D---- C:\Program Files\Eraser
2012-06-23 12:35:39 ----D---- C:\Documents and Settings\Inna\Data aplikací\TrueCrypt
2012-06-23 12:33:36 ----A---- C:\WINDOWS\system32\drivers\truecrypt.sys
2012-06-23 12:33:34 ----D---- C:\Program Files\TrueCrypt

======List of files/folders modified in the last 1 month======

2012-07-09 00:46:36 ----D---- C:\WINDOWS
2012-07-09 00:46:19 ----D---- C:\WINDOWS\system32\drivers
2012-07-09 00:46:04 ----D---- C:\WINDOWS\Temp
2012-07-09 00:41:32 ----D---- C:\WINDOWS\system32\CatRoot2
2012-07-09 00:39:46 ----D---- C:\WINDOWS\system32\Restore
2012-07-09 00:33:08 ----D---- C:\WINDOWS\Prefetch
2012-07-09 00:33:08 ----A---- C:\WINDOWS\win.ini
2012-07-08 23:05:46 ----D---- C:\Documents and Settings\Inna\Data aplikací\uTorrent
2012-07-08 20:36:27 ----D---- C:\Program Files\ThreatFire
2012-07-08 16:12:28 ----D---- C:\Documents and Settings\Inna\Data aplikací\foobar2000
2012-07-08 02:09:49 ----D---- C:\Program Files\JonDo
2012-07-08 01:44:35 ----D---- C:\Documents and Settings\Inna\Data aplikací\JonDo
2012-07-07 22:26:57 ----D---- C:\WINDOWS\SoftwareDistribution
2012-07-07 12:34:52 ----D---- C:\Program Files\PeerGuardian2
2012-07-06 23:36:26 ----D---- C:\Program Files\uTorrent
2012-07-06 19:39:50 ----D---- C:\WINDOWS\system32\config
2012-07-06 13:21:23 ----D---- C:\Program Files\Opera
2012-07-06 13:16:28 ----RD---- C:\Program Files
2012-07-03 18:12:35 ----D---- C:\Documents and Settings\Inna\Data aplikací\Media Player Classic
2012-07-01 14:45:51 ----D---- C:\Program Files\FreeRapid-0.86u1
2012-07-01 12:27:47 ----SHD---- C:\WINDOWS\Installer
2012-07-01 12:27:47 ----D---- C:\WINDOWS\system32
2012-07-01 12:24:39 ----HD---- C:\WINDOWS\inf
2012-07-01 12:23:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-07-01 12:23:23 ----SHD---- C:\System Volume Information
2012-07-01 01:33:28 ----SD---- C:\WINDOWS\Tasks
2012-07-01 01:28:39 ----A---- C:\WINDOWS\system.ini
2012-07-01 01:27:35 ----D---- C:\WINDOWS\system32\drivers\etc
2012-07-01 01:21:12 ----D---- C:\WINDOWS\AppPatch
2012-07-01 01:21:11 ----D---- C:\Program Files\Common Files
2012-07-01 01:11:06 ----RASH---- C:\boot.ini
2012-07-01 00:00:44 ----D---- C:\WINDOWS\system32\CatRoot
2012-06-29 22:16:56 ----D---- C:\Documents and Settings\Inna\Data aplikací\Opera
2012-06-29 15:22:58 ----D---- C:\WINDOWS\EHome
2012-06-29 15:22:58 ----D---- C:\Documents and Settings\Inna\Data aplikací\ArcSoft
2012-06-29 15:22:52 ----HD---- C:\Program Files\InstallShield Installation Information
2012-06-29 15:20:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\SlySoft
2012-06-29 15:20:18 ----D---- C:\Program Files\SlySoft
2012-06-28 12:17:45 ----D---- C:\Program Files\CCleaner
2012-06-27 11:53:10 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-06-26 14:29:27 ----D---- C:\Program Files\Java
2012-06-25 00:35:00 ----D---- C:\Program Files\Mozilla Firefox
2012-06-23 22:58:01 ----D---- C:\WINDOWS\Microsoft.NET
2012-06-23 22:57:47 ----RSD---- C:\WINDOWS\assembly
2012-06-23 22:49:22 ----D---- C:\Documents and Settings\Inna\Data aplikací\Winamp
2012-06-23 22:49:13 ----D---- C:\WINDOWS\Debug
2012-06-23 22:38:34 ----D---- C:\Program Files\Winamp
2012-06-23 22:38:29 ----D---- C:\Program Files\Winamp Detect
2012-06-23 22:28:42 ----D---- C:\Program Files\Common Files\Adobe AIR
2012-06-23 22:21:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-06-23 22:17:13 ----D---- C:\Program Files\Internet Explorer
2012-06-23 22:13:28 ----HD---- C:\WINDOWS\$hf_mig$
2012-06-23 22:12:57 ----D---- C:\WINDOWS\WinSxS
2012-06-23 22:10:01 ----D---- C:\WINDOWS\system32\XPSViewer
2012-06-23 21:55:57 ----D---- C:\WINDOWS\Help
2012-06-23 21:55:33 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-06-23 19:32:12 ----D---- C:\Program Files\Common Files\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2012-03-11 97760]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2008-07-31 79960]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 pavboot;pavboot; C:\WINDOWS\system32\drivers\pavboot.sys [2009-06-30 28552]
R0 TfFsMon;TfFsMon; C:\WINDOWS\system32\drivers\TfFsMon.sys [2010-01-14 51984]
R0 TfSysMon;TfSysMon; C:\WINDOWS\system32\drivers\TfSysMon.sys [2010-01-14 59664]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2012-03-11 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2012-03-11 31704]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2012-06-23 231760]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2011-12-06 7490560]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdXP3.sys [2011-12-20 100368]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 JULA_01;Service for Juli@ 1; C:\WINDOWS\system32\drivers\JulaWdm.sys [2008-06-24 22912]
R3 JULA_AA;Service for Juli@ Audio Driver (EWDM); C:\WINDOWS\system32\drivers\Jula.sys [2008-06-24 29600]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 Stmatm;ATM/ADSL miniport; C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-08-12 60255]
R3 TaurusUsb;ADSL Modem USB Service; C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-12-23 549421]
R3 TfNetMon;TfNetMon; \??\C:\WINDOWS\system32\drivers\TfNetMon.sys []
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 ATITool;ATITool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\ATITool.sys [2005-05-31 28160]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-05-21 93696]
S3 etdrv;etdrv; \??\C:\WINDOWS\etdrv.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-24 4749824]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2005-08-02 32512]
S3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
S3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-06-16 109184]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2011-01-15 30208]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-06-29 477240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2011-08-12 116608]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-03-11 1983232]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [2012-05-04 161664]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R2 ThreatFire;ThreatFire; C:\Program Files\ThreatFire\TFService.exe [2010-01-14 70928]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-25 113120]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2005-08-02 86016]
S3 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S4 ADExchange;ArcSoft Exchange Service; C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2011-09-16 39528]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2011-12-06 643072]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu(IRCBot)

#3 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#4 Příspěvek od Driver3 »

Tady je ta zpráva,děkuji za pomoc


RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Inna [Práva správce]
Mód: Kontrola -- Datum: 07/09/2012 13:16:00

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 6 ¤¤¤
[BLACKLIST DLL] HKLM\[...]\Run : AdslTaskBar (rundll32.exe stmctrl.dll,TaskBar) -> FOUND
[PROXY FF] JonDoFox\ 127.0.0.1:4001 -> FOUND
[PROXY FF] se8ddhvg.default\ 127.0.0.1:4001 -> FOUND
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤
SSDT[41] : NtCreateKey @ 0x80623FD6 -> HOOKED (TfSysMon.sys @ 0xB9EC4A1C)
SSDT[63] : NtDeleteKey @ 0x80624472 -> HOOKED (TfSysMon.sys @ 0xB9EC4C10)
SSDT[65] : NtDeleteValueKey @ 0x80624642 -> HOOKED (TfSysMon.sys @ 0xB9EC4CB6)
SSDT[119] : NtOpenKey @ 0x806253B4 -> HOOKED (TfSysMon.sys @ 0xB9EC490C)
SSDT[247] : NtSetValueKey @ 0x80622548 -> HOOKED (TfSysMon.sys @ 0xB9EC4E52)
SSDT[257] : NtTerminateProcess @ 0x805D22D8 -> HOOKED (TfSysMon.sys @ 0xB9EC6B30)

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD6401AALS-00L3B2 +++++
--- User ---
[MBR] 19475971a7e98fc13a846af3ae25175c
[BSP] 5193c8bfbfc430d59657c8fd6f8b4fbd : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 51199 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 104856255 | Size: 559278 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu(IRCBot)

#5 Příspěvek od vyosek »

:arrow: Spustte znovu RogueKiller
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost Prohledat a pote Smazat a nasledne Zprava - otevre se log, ten sem vlozte
  • Pak kliknete na Oprava Host a Zprava - otevre se log, ten sem vlozte
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#6 Příspěvek od Driver3 »

Ahoj,používám Windows XP Home Edition.Tedˇ,když se pokouším spustit RogueKiller,tak mi to píše hlášku:Systém Windows nemá přístup k určenému zařízení,cestě nebo souboru.K přístupu k položce pravděpodobně nemáte patřičná oprávnění.



Systém běží pod správcem počítače chráněný heslem.
C:\Program Files\RogueKiller\RogueKiller.exe.......z tohoto adresáře nelze rozběhnout....mám zkusit ten prográmek spustit z jiného umístění?Dík.

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#7 Příspěvek od Driver3 »

Už vím proč nejde spusit Comodo Firewall mi ho zablokoval,zkouším v nastavení najít,kde přesně se dá ta blokace programu dá zrušit,kdyby někdo věděl kde,tak vás prosím o radu,dík.

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#8 Příspěvek od Driver3 »

Už jsem to odblokoval,takže jdu na ten Scan :thumbsup:

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#9 Příspěvek od Driver3 »

Takže první zpráva z RogueKiller:


RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Inna [Práva správce]
Mód: Odebrat -- Datum: 07/09/2012 14:40:45

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 7 ¤¤¤
[BLACKLIST DLL] HKLM\[...]\Run : AdslTaskBar (rundll32.exe stmctrl.dll,TaskBar) -> DELETED
[PROXY FF] JonDoFox\ 127.0.0.1:4001 -> NOT REMOVED, USE PROXYFIX
[PROXY FF] se8ddhvg.default\ 127.0.0.1:4001 -> NOT REMOVED, USE PROXYFIX
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{A8AA0C00-BDF9-4109-B0C6-7FF3E249E4D8} : NameServer (194.228.41.113 160.218.161.54) -> NOT REMOVED, USE DNSFIX
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> REPLACED (0)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤
SSDT[41] : NtCreateKey @ 0x80623FD6 -> HOOKED (TfSysMon.sys @ 0xB9EC4A1C)
SSDT[63] : NtDeleteKey @ 0x80624472 -> HOOKED (TfSysMon.sys @ 0xB9EC4C10)
SSDT[65] : NtDeleteValueKey @ 0x80624642 -> HOOKED (TfSysMon.sys @ 0xB9EC4CB6)
SSDT[119] : NtOpenKey @ 0x806253B4 -> HOOKED (TfSysMon.sys @ 0xB9EC490C)
SSDT[247] : NtSetValueKey @ 0x80622548 -> HOOKED (TfSysMon.sys @ 0xB9EC4E52)
SSDT[257] : NtTerminateProcess @ 0x805D22D8 -> HOOKED (TfSysMon.sys @ 0xB9EC6B30)

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD6401AALS-00L3B2 +++++
--- User ---
[MBR] 19475971a7e98fc13a846af3ae25175c
[BSP] 5193c8bfbfc430d59657c8fd6f8b4fbd : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 51199 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 104856255 | Size: 559278 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#10 Příspěvek od Driver3 »

a druhá zpráva:


RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Inna [Práva správce]
Mód: Oprava HOSTS -- Datum: 07/09/2012 14:42:35

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost


¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost

Dokončeno : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#11 Příspěvek od Driver3 »

TDSSKiller log:

14:45:23.0375 3008 TDSS rootkit removing tool 2.7.45.0 Jul 9 2012 12:46:35
14:45:25.0375 3008 ============================================================
14:45:25.0375 3008 Current date / time: 2012/07/09 14:45:25.0375
14:45:25.0375 3008 SystemInfo:
14:45:25.0375 3008
14:45:25.0375 3008 OS Version: 5.1.2600 ServicePack: 3.0
14:45:25.0375 3008 Product type: Workstation
14:45:25.0375 3008 ComputerName: UNDURRAG-2115CA
14:45:25.0375 3008 UserName: Inna
14:45:25.0375 3008 Windows directory: C:\WINDOWS
14:45:25.0375 3008 System windows directory: C:\WINDOWS
14:45:25.0375 3008 Processor architecture: Intel x86
14:45:25.0375 3008 Number of processors: 2
14:45:25.0375 3008 Page size: 0x1000
14:45:25.0375 3008 Boot type: Normal boot
14:45:25.0375 3008 ============================================================
14:45:27.0000 3008 Drive \Device\Harddisk0\DR0 - Size: 0x950AF4DE00 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
14:45:27.0000 3008 ============================================================
14:45:27.0000 3008 \Device\Harddisk0\DR0:
14:45:27.0000 3008 MBR partitions:
14:45:27.0000 3008 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x63FFA80
14:45:27.0015 3008 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x63FFAFE, BlocksNum 0x444573C3
14:45:27.0015 3008 ============================================================
14:45:27.0031 3008 D: <-> \Device\Harddisk0\DR0\Partition1
14:45:27.0046 3008 C: <-> \Device\Harddisk0\DR0\Partition0
14:45:27.0046 3008 ============================================================
14:45:27.0046 3008 Initialize success
14:45:27.0046 3008 ============================================================
14:46:03.0640 3900 ============================================================
14:46:03.0640 3900 Scan started
14:46:03.0640 3900 Mode: Manual; SigCheck; TDLFS;
14:46:03.0640 3900 ============================================================
14:46:03.0781 3900 !SASCORE (c0393eb99a6c72c6bef9bfc4a72b33a6) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
14:46:03.0937 3900 !SASCORE - ok
14:46:04.0015 3900 Abiosdsk - ok
14:46:04.0015 3900 abp480n5 - ok
14:46:04.0031 3900 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:46:04.0468 3900 ACPI - ok
14:46:04.0484 3900 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
14:46:04.0546 3900 ACPIEC - ok
14:46:04.0593 3900 ADExchange (9e100616b5075228bfed1cc5738aad8b) C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe
14:46:04.0656 3900 ADExchange - ok
14:46:04.0671 3900 adpu160m - ok
14:46:04.0687 3900 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
14:46:04.0765 3900 aec - ok
14:46:04.0796 3900 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
14:46:04.0812 3900 AFD - ok
14:46:04.0828 3900 Aha154x - ok
14:46:04.0828 3900 aic78u2 - ok
14:46:04.0828 3900 aic78xx - ok
14:46:04.0859 3900 Alerter (e0a6fa244b8624d78fe5ff6f56a33bae) C:\WINDOWS\system32\alrsvc.dll
14:46:04.0937 3900 Alerter - ok
14:46:04.0953 3900 ALG (88842de939a827577bf24243699ac80a) C:\WINDOWS\System32\alg.exe
14:46:05.0015 3900 ALG - ok
14:46:05.0015 3900 AliIde - ok
14:46:05.0031 3900 amsint - ok
14:46:05.0031 3900 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
14:46:05.0109 3900 Arp1394 - ok
14:46:05.0109 3900 asc - ok
14:46:05.0125 3900 asc3350p - ok
14:46:05.0125 3900 asc3550 - ok
14:46:05.0171 3900 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
14:46:05.0187 3900 aspnet_state - ok
14:46:05.0203 3900 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
14:46:05.0265 3900 AsyncMac - ok
14:46:05.0281 3900 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
14:46:05.0343 3900 atapi - ok
14:46:05.0343 3900 Atdisk - ok
14:46:05.0390 3900 Ati HotKey Poller (944e535926628fb2fa33435eb848f94e) C:\WINDOWS\system32\Ati2evxx.exe
14:46:05.0453 3900 Ati HotKey Poller - ok
14:46:05.0781 3900 ati2mtag (0997918a56a6e09ddf7bdfc0ebe8a99d) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
14:46:05.0921 3900 ati2mtag - ok
14:46:06.0000 3900 AtiHDAudioService (bd9ca8136738040d3257363ed12be693) C:\WINDOWS\system32\drivers\AtihdXP3.sys
14:46:06.0000 3900 AtiHDAudioService - ok
14:46:06.0015 3900 AtiHdmiService (41c8f0eda10da14378d304c20ba6e558) C:\WINDOWS\system32\drivers\AtiHdmi.sys
14:46:06.0062 3900 AtiHdmiService - ok
14:46:06.0078 3900 ATITool (1294314049f7cc8bf8ffa11d51458d35) C:\WINDOWS\system32\DRIVERS\ATITool.sys
14:46:06.0093 3900 ATITool ( UnsignedFile.Multi.Generic ) - warning
14:46:06.0093 3900 ATITool - detected UnsignedFile.Multi.Generic (1)
14:46:06.0093 3900 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
14:46:06.0171 3900 Atmarpc - ok
14:46:06.0187 3900 AudioSrv (de31b88962a8645dba5a37b993e7b0f1) C:\WINDOWS\System32\audiosrv.dll
14:46:06.0250 3900 AudioSrv - ok
14:46:06.0265 3900 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
14:46:06.0328 3900 audstub - ok
14:46:06.0343 3900 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
14:46:06.0421 3900 Beep - ok
14:46:06.0437 3900 BITS (19395d092fd85ddc2d9c7729cf5a2ac8) C:\WINDOWS\system32\qmgr.dll
14:46:06.0515 3900 BITS - ok
14:46:06.0531 3900 Browser (249276d3ef1e74b992299cb96099e4d7) C:\WINDOWS\System32\browser.dll
14:46:06.0593 3900 Browser - ok
14:46:06.0609 3900 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
14:46:06.0687 3900 cbidf2k - ok
14:46:06.0687 3900 cd20xrnt - ok
14:46:06.0687 3900 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
14:46:06.0750 3900 Cdaudio - ok
14:46:06.0781 3900 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
14:46:06.0843 3900 Cdfs - ok
14:46:06.0843 3900 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
14:46:06.0906 3900 Cdrom - ok
14:46:06.0921 3900 Changer - ok
14:46:06.0921 3900 CiSvc (e390dc1d7c461d7d56ec53402f329928) C:\WINDOWS\system32\cisvc.exe
14:46:06.0984 3900 CiSvc - ok
14:46:07.0000 3900 ClipSrv (064507a8dfa8c5c7e2ffddd3e6f424fa) C:\WINDOWS\system32\clipsrv.exe
14:46:07.0062 3900 ClipSrv - ok
14:46:07.0109 3900 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:46:07.0140 3900 clr_optimization_v2.0.50727_32 - ok
14:46:07.0250 3900 cmdAgent (907324001ae25ac5959c91eaa34cabae) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
14:46:07.0328 3900 cmdAgent - ok
14:46:07.0421 3900 cmdGuard (bee235831f8e3f0baaca18b39d285cf5) C:\WINDOWS\system32\DRIVERS\cmdguard.sys
14:46:07.0437 3900 cmdGuard - ok
14:46:07.0437 3900 cmdHlp (de548946f36cab62fec2e6aa0149a619) C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
14:46:07.0453 3900 cmdHlp - ok
14:46:07.0453 3900 CmdIde - ok
14:46:07.0468 3900 COMSysApp - ok
14:46:07.0484 3900 Cpqarray - ok
14:46:07.0484 3900 CryptSvc (f3ab0933cbd166d271992f411c27ccaf) C:\WINDOWS\System32\cryptsvc.dll
14:46:07.0546 3900 CryptSvc - ok
14:46:07.0546 3900 dac2w2k - ok
14:46:07.0546 3900 dac960nt - ok
14:46:07.0593 3900 DcomLaunch (be27674d1cbc3214aec84b4336a38bbf) C:\WINDOWS\system32\rpcss.dll
14:46:07.0625 3900 DcomLaunch - ok
14:46:07.0656 3900 Dhcp (8c9a53e285ac5e6704844d0459ec85be) C:\WINDOWS\System32\dhcpcsvc.dll
14:46:07.0718 3900 Dhcp - ok
14:46:07.0734 3900 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
14:46:07.0796 3900 Disk - ok
14:46:07.0796 3900 dmadmin - ok
14:46:07.0843 3900 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
14:46:07.0921 3900 dmboot - ok
14:46:07.0937 3900 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
14:46:08.0000 3900 dmio - ok
14:46:08.0000 3900 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
14:46:08.0078 3900 dmload - ok
14:46:08.0093 3900 dmserver (2bfefe9e865655a76982f050450b9591) C:\WINDOWS\System32\dmserver.dll
14:46:08.0156 3900 dmserver - ok
14:46:08.0171 3900 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
14:46:08.0234 3900 DMusic - ok
14:46:08.0250 3900 Dnscache (dfaa406bf19f4ee806a6f8d4342137f7) C:\WINDOWS\System32\dnsrslvr.dll
14:46:08.0296 3900 Dnscache - ok
14:46:08.0312 3900 Dot3svc (4a3e2bd20157a0946751229e92eb8621) C:\WINDOWS\System32\dot3svc.dll
14:46:08.0390 3900 Dot3svc - ok
14:46:08.0390 3900 dpti2o - ok
14:46:08.0390 3900 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
14:46:08.0453 3900 drmkaud - ok
14:46:08.0468 3900 EapHost (0887d9c2be8d940778cad1e3b85f2a41) C:\WINDOWS\System32\eapsvc.dll
14:46:08.0531 3900 EapHost - ok
14:46:08.0546 3900 ERSvc (a2a4912798f2be706abadd3d30800d16) C:\WINDOWS\System32\ersvc.dll
14:46:08.0609 3900 ERSvc - ok
14:46:08.0625 3900 etdrv (3af0ae042afe486b22644cd3fbebf2e2) C:\WINDOWS\etdrv.sys
14:46:08.0625 3900 etdrv - ok
14:46:08.0640 3900 Eventlog (9ef697af07bb8dd82c3b02ca953a95b7) C:\WINDOWS\system32\services.exe
14:46:08.0671 3900 Eventlog - ok
14:46:08.0687 3900 EventSystem (a371f11ef07653591c8de26afb13ce7f) C:\WINDOWS\system32\es.dll
14:46:08.0734 3900 EventSystem - ok
14:46:08.0750 3900 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
14:46:08.0812 3900 Fastfat - ok
14:46:08.0843 3900 FastUserSwitchingCompatibility (ee9a2b9ea968a792a053c9d1a86bf870) C:\WINDOWS\System32\shsvcs.dll
14:46:08.0875 3900 FastUserSwitchingCompatibility - ok
14:46:08.0890 3900 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
14:46:08.0953 3900 Fdc - ok
14:46:08.0968 3900 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
14:46:09.0031 3900 Fips - ok
14:46:09.0046 3900 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
14:46:09.0109 3900 Flpydisk - ok
14:46:09.0125 3900 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
14:46:09.0187 3900 FltMgr - ok
14:46:09.0234 3900 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
14:46:09.0250 3900 FontCache3.0.0.0 - ok
14:46:09.0265 3900 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
14:46:09.0328 3900 Fs_Rec - ok
14:46:09.0343 3900 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
14:46:09.0406 3900 Ftdisk - ok
14:46:09.0421 3900 gdrv (c6e3105b8c68c35cc1eb26a00fd1a8c6) C:\WINDOWS\gdrv.sys
14:46:09.0437 3900 gdrv - ok
14:46:09.0437 3900 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
14:46:09.0515 3900 Gpc - ok
14:46:09.0531 3900 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
14:46:09.0593 3900 HDAudBus - ok
14:46:09.0625 3900 helpsvc (fcfe31fb75f8a6295b6b0af87a626282) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
14:46:09.0687 3900 helpsvc - ok
14:46:09.0703 3900 HidServ (00e25ee90166b3e1be6e74aebf858306) C:\WINDOWS\System32\hidserv.dll
14:46:09.0765 3900 HidServ - ok
14:46:09.0781 3900 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
14:46:09.0843 3900 hidusb - ok
14:46:09.0859 3900 hkmsvc (7a6b320928f86bc851530d63c82965d9) C:\WINDOWS\System32\kmsvc.dll
14:46:09.0921 3900 hkmsvc - ok
14:46:09.0921 3900 hpn - ok
14:46:09.0953 3900 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
14:46:09.0984 3900 HTTP - ok
14:46:10.0000 3900 HTTPFilter (58fe2f2da3bc5573f4a35b3760d3125f) C:\WINDOWS\System32\w3ssl.dll
14:46:10.0062 3900 HTTPFilter - ok
14:46:10.0062 3900 i2omgmt - ok
14:46:10.0078 3900 i2omp - ok
14:46:10.0078 3900 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\drivers\i8042prt.sys
14:46:10.0140 3900 i8042prt - ok
14:46:10.0187 3900 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
14:46:10.0187 3900 IDriverT ( UnsignedFile.Multi.Generic ) - warning
14:46:10.0187 3900 IDriverT - detected UnsignedFile.Multi.Generic (1)
14:46:10.0234 3900 idsvc (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:46:10.0281 3900 idsvc - ok
14:46:10.0281 3900 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
14:46:10.0343 3900 Imapi - ok
14:46:10.0359 3900 ImapiService (f7b93aafad33b2320954c17e26c8d361) C:\WINDOWS\system32\imapi.exe
14:46:10.0421 3900 ImapiService - ok
14:46:10.0437 3900 ini910u - ok
14:46:10.0453 3900 Inspect (f89849cf13805ef49da64a8a63193af7) C:\WINDOWS\system32\DRIVERS\inspect.sys
14:46:10.0468 3900 Inspect - ok
14:46:10.0671 3900 IntcAzAudAddService (4aaa8312732655f93a254d1fa695eb79) C:\WINDOWS\system32\drivers\RtkHDAud.sys
14:46:10.0781 3900 IntcAzAudAddService - ok
14:46:10.0859 3900 IntelIde - ok
14:46:10.0875 3900 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
14:46:10.0937 3900 intelppm - ok
14:46:10.0937 3900 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
14:46:11.0015 3900 Ip6Fw - ok
14:46:11.0031 3900 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
14:46:11.0093 3900 IpFilterDriver - ok
14:46:11.0109 3900 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
14:46:11.0171 3900 IpInIp - ok
14:46:11.0203 3900 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
14:46:11.0265 3900 IpNat - ok
14:46:11.0281 3900 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
14:46:11.0343 3900 IPSec - ok
14:46:11.0359 3900 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
14:46:11.0421 3900 IRENUM - ok
14:46:11.0437 3900 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
14:46:11.0500 3900 isapnp - ok
14:46:11.0562 3900 JavaQuickStarterService (c2c1660ddcc9bd67eb98d6d5f91c107f) C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
14:46:11.0578 3900 JavaQuickStarterService - ok
14:46:11.0593 3900 JRAID (b07084095f8c03aadb9811c9df14b5e4) C:\WINDOWS\system32\DRIVERS\jraid.sys
14:46:11.0609 3900 JRAID - ok
14:46:11.0625 3900 JULA_01 (c85db3f30f55687fb72e9d757ac0bffb) C:\WINDOWS\system32\drivers\JulaWdm.sys
14:46:11.0640 3900 JULA_01 ( UnsignedFile.Multi.Generic ) - warning
14:46:11.0640 3900 JULA_01 - detected UnsignedFile.Multi.Generic (1)
14:46:11.0640 3900 JULA_AA (ab32d25297e2cec111a9b661049bb841) C:\WINDOWS\system32\drivers\Jula.sys
14:46:11.0640 3900 JULA_AA ( UnsignedFile.Multi.Generic ) - warning
14:46:11.0640 3900 JULA_AA - detected UnsignedFile.Multi.Generic (1)
14:46:11.0656 3900 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
14:46:11.0703 3900 Kbdclass - ok
14:46:11.0718 3900 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
14:46:11.0781 3900 kbdhid - ok
14:46:11.0796 3900 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
14:46:11.0859 3900 kmixer - ok
14:46:11.0875 3900 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
14:46:11.0906 3900 KSecDD - ok
14:46:11.0937 3900 lanmanserver (3428e8f86f8add36b42fb23542c7b3e4) C:\WINDOWS\System32\srvsvc.dll
14:46:11.0953 3900 lanmanserver - ok
14:46:11.0968 3900 lanmanworkstation (936c1d110232d23b621cb0196e4f80f0) C:\WINDOWS\System32\wkssvc.dll
14:46:12.0000 3900 lanmanworkstation - ok
14:46:12.0000 3900 lbrtfdc - ok
14:46:12.0015 3900 LmHosts (0ab159f536e3e8f7f07113702a07cca5) C:\WINDOWS\System32\lmhsvc.dll
14:46:12.0078 3900 LmHosts - ok
14:46:12.0078 3900 MBAMProtector (fb097bbc1a18f044bd17bd2fccf97865) C:\WINDOWS\system32\drivers\mbam.sys
14:46:12.0093 3900 MBAMProtector - ok
14:46:12.0125 3900 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
14:46:12.0156 3900 MBAMService - ok
14:46:12.0171 3900 Messenger (221cd1c815b8a6b79389c3f5d1018de8) C:\WINDOWS\System32\msgsvc.dll
14:46:12.0250 3900 Messenger - ok
14:46:12.0250 3900 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
14:46:12.0328 3900 mnmdd - ok
14:46:12.0328 3900 mnmsrvc (9a57d046f88f4b69751b11fd40088a61) C:\WINDOWS\system32\mnmsrvc.exe
14:46:12.0390 3900 mnmsrvc - ok
14:46:12.0421 3900 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
14:46:12.0484 3900 Modem - ok
14:46:12.0484 3900 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
14:46:12.0562 3900 Mouclass - ok
14:46:12.0578 3900 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
14:46:12.0656 3900 mouhid - ok
14:46:12.0656 3900 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
14:46:12.0718 3900 MountMgr - ok
14:46:12.0734 3900 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:46:12.0750 3900 MozillaMaintenance - ok
14:46:12.0750 3900 mraid35x - ok
14:46:12.0765 3900 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
14:46:12.0828 3900 MRxDAV - ok
14:46:12.0859 3900 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
14:46:12.0906 3900 MRxSmb - ok
14:46:12.0921 3900 MSDTC (6db4d1521caba9a5ffab54ade0ae867d) C:\WINDOWS\system32\msdtc.exe
14:46:12.0984 3900 MSDTC - ok
14:46:12.0984 3900 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
14:46:13.0046 3900 Msfs - ok
14:46:13.0046 3900 MSIServer - ok
14:46:13.0062 3900 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
14:46:13.0125 3900 MSKSSRV - ok
14:46:13.0140 3900 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
14:46:13.0203 3900 MSPCLOCK - ok
14:46:13.0203 3900 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
14:46:13.0265 3900 MSPQM - ok
14:46:13.0281 3900 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
14:46:13.0343 3900 mssmbios - ok
14:46:13.0359 3900 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
14:46:13.0375 3900 Mup - ok
14:46:13.0406 3900 napagent (6ea362e9db03d44f6b996f4d8be237e9) C:\WINDOWS\System32\qagentrt.dll
14:46:13.0468 3900 napagent - ok
14:46:13.0484 3900 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
14:46:13.0546 3900 NDIS - ok
14:46:13.0562 3900 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
14:46:13.0578 3900 NdisTapi - ok
14:46:13.0593 3900 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
14:46:13.0656 3900 Ndisuio - ok
14:46:13.0671 3900 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
14:46:13.0734 3900 NdisWan - ok
14:46:13.0750 3900 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
14:46:13.0765 3900 NDProxy - ok
14:46:13.0781 3900 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
14:46:13.0843 3900 NetBIOS - ok
14:46:13.0859 3900 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
14:46:13.0937 3900 NetBT - ok
14:46:13.0953 3900 NetDDE (933de774986ec85e48210c44ab431de6) C:\WINDOWS\system32\netdde.exe
14:46:14.0015 3900 NetDDE - ok
14:46:14.0015 3900 NetDDEdsdm (933de774986ec85e48210c44ab431de6) C:\WINDOWS\system32\netdde.exe
14:46:14.0078 3900 NetDDEdsdm - ok
14:46:14.0109 3900 Netlogon (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
14:46:14.0171 3900 Netlogon - ok
14:46:14.0187 3900 Netman (72e1e9e2977be08bdeedb6d8fd9d4d40) C:\WINDOWS\System32\netman.dll
14:46:14.0265 3900 Netman - ok
14:46:14.0312 3900 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:46:14.0312 3900 NetTcpPortSharing - ok
14:46:14.0328 3900 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
14:46:14.0390 3900 NIC1394 - ok
14:46:14.0421 3900 Nla (39ee7c3bfbc64ba87cc8cf67386e814c) C:\WINDOWS\System32\mswsock.dll
14:46:14.0453 3900 Nla - ok
14:46:14.0453 3900 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
14:46:14.0515 3900 nm - ok
14:46:14.0546 3900 NPF (d21fee8db254ba762656878168ac1db6) C:\WINDOWS\system32\drivers\npf.sys
14:46:14.0546 3900 NPF ( UnsignedFile.Multi.Generic ) - warning
14:46:14.0546 3900 NPF - detected UnsignedFile.Multi.Generic (1)
14:46:14.0578 3900 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
14:46:14.0640 3900 Npfs - ok
14:46:14.0656 3900 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
14:46:14.0718 3900 Ntfs - ok
14:46:14.0734 3900 NtLmSsp (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
14:46:14.0796 3900 NtLmSsp - ok
14:46:14.0828 3900 NtmsSvc (023dd70573d644f3d9c8b1258a7bfd08) C:\WINDOWS\system32\ntmssvc.dll
14:46:14.0890 3900 NtmsSvc - ok
14:46:14.0906 3900 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
14:46:14.0968 3900 Null - ok
14:46:14.0984 3900 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
14:46:15.0046 3900 NwlnkFlt - ok
14:46:15.0062 3900 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
14:46:15.0140 3900 NwlnkFwd - ok
14:46:15.0140 3900 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
14:46:15.0203 3900 ohci1394 - ok
14:46:15.0218 3900 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
14:46:15.0281 3900 Parport - ok
14:46:15.0281 3900 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
14:46:15.0343 3900 PartMgr - ok
14:46:15.0359 3900 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
14:46:15.0421 3900 ParVdm - ok
14:46:15.0421 3900 pavboot (3adb8bd6154a3ef87496e8fce9c22493) C:\WINDOWS\system32\drivers\pavboot.sys
14:46:15.0437 3900 pavboot - ok
14:46:15.0437 3900 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
14:46:15.0500 3900 PCI - ok
14:46:15.0515 3900 PCIDump - ok
14:46:15.0515 3900 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
14:46:15.0578 3900 PCIIde - ok
14:46:15.0593 3900 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
14:46:15.0656 3900 Pcmcia - ok
14:46:15.0656 3900 PDCOMP - ok
14:46:15.0656 3900 PDFRAME - ok
14:46:15.0656 3900 PDRELI - ok
14:46:15.0671 3900 PDRFRAME - ok
14:46:15.0671 3900 perc2 - ok
14:46:15.0671 3900 perc2hib - ok
14:46:15.0703 3900 PlugPlay (9ef697af07bb8dd82c3b02ca953a95b7) C:\WINDOWS\system32\services.exe
14:46:15.0718 3900 PlugPlay - ok
14:46:15.0718 3900 PolicyAgent (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
14:46:15.0781 3900 PolicyAgent - ok
14:46:15.0796 3900 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
14:46:15.0859 3900 PptpMiniport - ok
14:46:15.0859 3900 ProtectedStorage (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
14:46:15.0921 3900 ProtectedStorage - ok
14:46:15.0937 3900 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
14:46:16.0000 3900 PSched - ok
14:46:16.0000 3900 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\WINDOWS\system32\DRIVERS\psi_mf.sys
14:46:16.0015 3900 PSI - ok
14:46:16.0015 3900 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
14:46:16.0093 3900 Ptilink - ok
14:46:16.0093 3900 ql1080 - ok
14:46:16.0093 3900 Ql10wnt - ok
14:46:16.0109 3900 ql12160 - ok
14:46:16.0109 3900 ql1240 - ok
14:46:16.0109 3900 ql1280 - ok
14:46:16.0125 3900 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
14:46:16.0187 3900 RasAcd - ok
14:46:16.0218 3900 RasAuto (2b5e44ea009f2f374b980e1e9a70635d) C:\WINDOWS\System32\rasauto.dll
14:46:16.0281 3900 RasAuto - ok
14:46:16.0281 3900 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
14:46:16.0343 3900 Rasl2tp - ok
14:46:16.0359 3900 RasMan (d57554c664b64604bd1ee13ea2c07e77) C:\WINDOWS\System32\rasmans.dll
14:46:16.0437 3900 RasMan - ok
14:46:16.0437 3900 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
14:46:16.0500 3900 RasPppoe - ok
14:46:16.0500 3900 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
14:46:16.0578 3900 Raspti - ok
14:46:16.0593 3900 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
14:46:16.0656 3900 Rdbss - ok
14:46:16.0671 3900 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
14:46:16.0734 3900 RDPCDD - ok
14:46:16.0765 3900 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys
14:46:16.0796 3900 RDPWD - ok
14:46:16.0828 3900 RDSessMgr (c0d9d9711cb74ee9bc66353d8cbdab0e) C:\WINDOWS\system32\sessmgr.exe
14:46:16.0890 3900 RDSessMgr - ok
14:46:16.0906 3900 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
14:46:16.0968 3900 redbook - ok
14:46:16.0984 3900 RemoteAccess (127c26b5371651043450e52542099aba) C:\WINDOWS\System32\mprdim.dll
14:46:17.0046 3900 RemoteAccess - ok
14:46:17.0093 3900 rpcapd (67c607857ccd6ebffe768dad5b2ca239) C:\Program Files\WinPcap\rpcapd.exe
14:46:17.0109 3900 rpcapd ( UnsignedFile.Multi.Generic ) - warning
14:46:17.0109 3900 rpcapd - detected UnsignedFile.Multi.Generic (1)
14:46:17.0125 3900 RpcLocator (718b3bdc0bc3c2f7d065a53d26202af9) C:\WINDOWS\system32\locator.exe
14:46:17.0187 3900 RpcLocator - ok
14:46:17.0218 3900 RpcSs (be27674d1cbc3214aec84b4336a38bbf) C:\WINDOWS\System32\rpcss.dll
14:46:17.0234 3900 RpcSs - ok
14:46:17.0250 3900 RSVP (09ab2e71e58b078038e3bfdba7ffc984) C:\WINDOWS\system32\rsvp.exe
14:46:17.0328 3900 RSVP - ok
14:46:17.0343 3900 RTLE8023xp (eeb84629064abcb6198864d25bf15b1a) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
14:46:17.0375 3900 RTLE8023xp - ok
14:46:17.0390 3900 SamSs (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
14:46:17.0453 3900 SamSs - ok
14:46:17.0468 3900 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
14:46:17.0484 3900 SASDIFSV - ok
14:46:17.0515 3900 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
14:46:17.0515 3900 SASKUTIL - ok
14:46:17.0531 3900 SCardSvr (410046e401eb11e1e6749e9deea41d4a) C:\WINDOWS\System32\SCardSvr.exe
14:46:17.0609 3900 SCardSvr - ok
14:46:17.0625 3900 Schedule (3ff232a7731621b8902d81d42418c93c) C:\WINDOWS\system32\schedsvc.dll
14:46:17.0687 3900 Schedule - ok
14:46:17.0718 3900 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
14:46:17.0781 3900 Secdrv - ok
14:46:17.0796 3900 seclogon (477e2c3cc5e4a0d635bcb0ea8dcac3c6) C:\WINDOWS\System32\seclogon.dll
14:46:17.0859 3900 seclogon - ok
14:46:17.0921 3900 Secunia PSI Agent (5b66db4877bbac9f7493aa8d84421e49) C:\Program Files\Secunia\PSI\PSIA.exe
14:46:17.0968 3900 Secunia PSI Agent - ok
14:46:17.0968 3900 SENS (a530b75c10c23c9ab28fdb6ce719e21f) C:\WINDOWS\system32\sens.dll
14:46:18.0031 3900 SENS - ok
14:46:18.0046 3900 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
14:46:18.0109 3900 serenum - ok
14:46:18.0125 3900 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
14:46:18.0187 3900 Serial - ok
14:46:18.0203 3900 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
14:46:18.0250 3900 Sfloppy - ok
14:46:18.0281 3900 SharedAccess (f58faca9621d2db01bd0927d9a0a208e) C:\WINDOWS\System32\ipnathlp.dll
14:46:18.0359 3900 SharedAccess - ok
14:46:18.0375 3900 ShellHWDetection (ee9a2b9ea968a792a053c9d1a86bf870) C:\WINDOWS\System32\shsvcs.dll
14:46:18.0390 3900 ShellHWDetection - ok
14:46:18.0390 3900 Simbad - ok
14:46:18.0406 3900 Sparrow - ok
14:46:18.0406 3900 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
14:46:18.0468 3900 splitter - ok
14:46:18.0484 3900 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
14:46:18.0515 3900 Spooler - ok
14:46:18.0546 3900 sptd (0022cfff1a41e5ce3a764050a7ddf22a) C:\WINDOWS\System32\Drivers\sptd.sys
14:46:18.0562 3900 sptd - ok
14:46:18.0578 3900 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
14:46:18.0640 3900 sr - ok
14:46:18.0656 3900 srservice (35b91147124f64ac8081a2edb9ea4dee) C:\WINDOWS\system32\srsvc.dll
14:46:18.0734 3900 srservice - ok
14:46:18.0750 3900 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
14:46:18.0781 3900 Srv - ok
14:46:18.0781 3900 SSDPSRV (becd5271dc4e3b7c3d035f790fcbc1e5) C:\WINDOWS\System32\ssdpsrv.dll
14:46:18.0843 3900 SSDPSRV - ok
14:46:18.0875 3900 stisvc (c1cdd9275f6a115bb0ae1d55d8d27ba6) C:\WINDOWS\system32\wiaservc.dll
14:46:18.0937 3900 stisvc - ok
14:46:18.0953 3900 Stmatm (2fc0c3d5615395585abdb16660efbc3a) C:\WINDOWS\system32\DRIVERS\stmatm.sys
14:46:18.0968 3900 Stmatm ( UnsignedFile.Multi.Generic ) - warning
14:46:18.0968 3900 Stmatm - detected UnsignedFile.Multi.Generic (1)
14:46:18.0984 3900 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
14:46:19.0031 3900 swenum - ok
14:46:19.0046 3900 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
14:46:19.0109 3900 swmidi - ok
14:46:19.0109 3900 SwPrv - ok
14:46:19.0125 3900 symc810 - ok
14:46:19.0125 3900 symc8xx - ok
14:46:19.0125 3900 sym_hi - ok
14:46:19.0125 3900 sym_u3 - ok
14:46:19.0140 3900 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
14:46:19.0203 3900 sysaudio - ok
14:46:19.0218 3900 SysmonLog (ce06f01b88ace199a1bf460cac29c110) C:\WINDOWS\system32\smlogsvc.exe
14:46:19.0281 3900 SysmonLog - ok
14:46:19.0312 3900 TapiSrv (c2546cd7a398476f9df5614b2ae160e8) C:\WINDOWS\System32\tapisrv.dll
14:46:19.0375 3900 TapiSrv - ok
14:46:19.0421 3900 TaurusUsb (22826eedaaaefbb0b95e33cd24314375) C:\WINDOWS\system32\DRIVERS\torususb.sys
14:46:19.0437 3900 TaurusUsb ( UnsignedFile.Multi.Generic ) - warning
14:46:19.0437 3900 TaurusUsb - detected UnsignedFile.Multi.Generic (1)
14:46:19.0484 3900 Tcpip (4afb3b0919649f95c1964aa1fad27d73) C:\WINDOWS\system32\DRIVERS\tcpip.sys
14:46:19.0484 3900 Tcpip ( UnsignedFile.Multi.Generic ) - warning
14:46:19.0484 3900 Tcpip - detected UnsignedFile.Multi.Generic (1)
14:46:19.0500 3900 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
14:46:19.0562 3900 TDPIPE - ok
14:46:19.0578 3900 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
14:46:19.0640 3900 TDTCP - ok
14:46:19.0656 3900 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
14:46:19.0718 3900 TermDD - ok
14:46:19.0734 3900 TermService (a75dd6fc3dbee4fff5ebc9f2c28bb66e) C:\WINDOWS\System32\termsrv.dll
14:46:19.0812 3900 TermService - ok
14:46:19.0843 3900 TfFsMon (95746e5b1473432f3d9458940dba6e3a) C:\WINDOWS\system32\drivers\TfFsMon.sys
14:46:19.0859 3900 TfFsMon - ok
14:46:19.0859 3900 TfNetMon (02ffdd873e31c5c2d57ca87d11ec36af) C:\WINDOWS\system32\drivers\TfNetMon.sys
14:46:19.0875 3900 TfNetMon - ok
14:46:19.0875 3900 TfSysMon (f8bd92251ab439383c051ce907d78cce) C:\WINDOWS\system32\drivers\TfSysMon.sys
14:46:19.0890 3900 TfSysMon - ok
14:46:19.0937 3900 Themes (ee9a2b9ea968a792a053c9d1a86bf870) C:\WINDOWS\System32\shsvcs.dll
14:46:19.0953 3900 Themes - ok
14:46:19.0968 3900 ThreatFire - ok
14:46:19.0984 3900 TosIde - ok
14:46:19.0984 3900 TrkWks (38853304ccb938d30e0c4cde8d2c2a8a) C:\WINDOWS\system32\trkwks.dll
14:46:20.0046 3900 TrkWks - ok
14:46:20.0078 3900 truecrypt (ed5e4ce36c54f55e7698642e94d32ec7) C:\WINDOWS\system32\drivers\truecrypt.sys
14:46:20.0093 3900 truecrypt - ok
14:46:20.0109 3900 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
14:46:20.0171 3900 Udfs - ok
14:46:20.0171 3900 ultra - ok
14:46:20.0187 3900 UMWdf (ab0a7ca90d9e3d6a193905dc1715ded0) C:\WINDOWS\system32\wdfmgr.exe
14:46:20.0203 3900 UMWdf - ok
14:46:20.0234 3900 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
14:46:20.0312 3900 Update - ok
14:46:20.0343 3900 upnphost (651bd90dcee5b7bdc74a2eb7c9266f9e) C:\WINDOWS\System32\upnphost.dll
14:46:20.0406 3900 upnphost - ok
14:46:20.0421 3900 UPS (20a0f6a11959e92908717d09e87d670d) C:\WINDOWS\System32\ups.exe
14:46:20.0484 3900 UPS - ok
14:46:20.0484 3900 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
14:46:20.0546 3900 usbccgp - ok
14:46:20.0578 3900 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
14:46:20.0625 3900 usbehci - ok
14:46:20.0640 3900 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
14:46:20.0703 3900 usbhub - ok
14:46:20.0703 3900 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:46:20.0765 3900 USBSTOR - ok
14:46:20.0781 3900 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
14:46:20.0843 3900 usbuhci - ok
14:46:20.0875 3900 VClone (fce98c43b5c5db8e0da8ea0e2b45e044) C:\WINDOWS\system32\DRIVERS\VClone.sys
14:46:20.0875 3900 VClone ( UnsignedFile.Multi.Generic ) - warning
14:46:20.0875 3900 VClone - detected UnsignedFile.Multi.Generic (1)
14:46:20.0875 3900 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
14:46:20.0937 3900 VgaSave - ok
14:46:20.0953 3900 ViaIde - ok
14:46:20.0968 3900 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
14:46:21.0031 3900 VolSnap - ok
14:46:21.0062 3900 VSS (d6ba1a63d9e00933f1cd2a885573afb2) C:\WINDOWS\System32\vssvc.exe
14:46:21.0125 3900 VSS - ok
14:46:21.0140 3900 W32Time (fa4e1cdba256787f2149f4aad07bc91f) C:\WINDOWS\system32\w32time.dll
14:46:21.0203 3900 W32Time - ok
14:46:21.0218 3900 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
14:46:21.0281 3900 Wanarp - ok
14:46:21.0281 3900 WDICA - ok
14:46:21.0296 3900 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
14:46:21.0359 3900 wdmaud - ok
14:46:21.0375 3900 WebClient (47ae51048a82dfa1cd6b51d369f7e169) C:\WINDOWS\System32\webclnt.dll
14:46:21.0453 3900 WebClient - ok
14:46:21.0484 3900 winmgmt (e488332126e3b1182d2b8a0c35408ec6) C:\WINDOWS\system32\wbem\WMIsvc.dll
14:46:21.0546 3900 winmgmt - ok
14:46:21.0578 3900 WmdmPmSN (140ef97b64f560fd78643cae2cdad838) C:\WINDOWS\system32\MsPMSNSv.dll
14:46:21.0609 3900 WmdmPmSN - ok
14:46:21.0625 3900 WmiApSrv (23f6f03272f7e5679f1f050aed5acee6) C:\WINDOWS\system32\wbem\wmiapsrv.exe
14:46:21.0687 3900 WmiApSrv - ok
14:46:21.0703 3900 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
14:46:21.0765 3900 WS2IFSL - ok
14:46:21.0781 3900 wscsvc (4c86d5faf78194995af9cc1075f65dd3) C:\WINDOWS\system32\wscsvc.dll
14:46:21.0843 3900 wscsvc - ok
14:46:21.0859 3900 wuauserv (c1364564800ee9784192145324a23308) C:\WINDOWS\system32\wuauserv.dll
14:46:21.0921 3900 wuauserv - ok
14:46:21.0953 3900 WZCSVC (a27d4ba7264c0bf52f32d10405bea1d4) C:\WINDOWS\System32\wzcsvc.dll
14:46:22.0046 3900 WZCSVC - ok
14:46:22.0062 3900 xmlprov (eaa4bb9edb3fb10cf8979fe65e63658f) C:\WINDOWS\System32\xmlprov.dll
14:46:22.0125 3900 xmlprov - ok
14:46:22.0140 3900 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
14:46:22.0484 3900 \Device\Harddisk0\DR0 - ok
14:46:22.0484 3900 Boot (0x1200) (948c5cc54d968eb692cfd8026126e225) \Device\Harddisk0\DR0\Partition0
14:46:22.0484 3900 \Device\Harddisk0\DR0\Partition0 - ok
14:46:22.0484 3900 Boot (0x1200) (52fe7f5f8c3bc6e11d3b868cf5ce7a72) \Device\Harddisk0\DR0\Partition1
14:46:22.0484 3900 \Device\Harddisk0\DR0\Partition1 - ok
14:46:22.0484 3900 ============================================================
14:46:22.0484 3900 Scan finished
14:46:22.0484 3900 ============================================================
14:46:22.0593 3064 Detected object count: 10
14:46:22.0593 3064 Actual detected object count: 10
14:46:59.0812 3064 ATITool ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0812 3064 ATITool ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0812 3064 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0812 3064 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0812 3064 JULA_01 ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0812 3064 JULA_01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0812 3064 JULA_AA ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0812 3064 JULA_AA ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0812 3064 NPF ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0812 3064 NPF ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0812 3064 rpcapd ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0812 3064 rpcapd ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0812 3064 Stmatm ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0812 3064 Stmatm ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0828 3064 TaurusUsb ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0828 3064 TaurusUsb ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0828 3064 Tcpip ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0828 3064 Tcpip ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:46:59.0828 3064 VClone ( UnsignedFile.Multi.Generic ) - skipped by user
14:46:59.0828 3064 VClone ( UnsignedFile.Multi.Generic ) - User select action: Skip

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#12 Příspěvek od Driver3 »

Děkuju

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu(IRCBot)

#13 Příspěvek od vyosek »

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Driver3
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 26 čer 2012 20:58

Re: Prosím o kontrolu(IRCBot)

#14 Příspěvek od Driver3 »

ComboFix 12-07-08.02 - Inna 09.07.2012 21:26:29.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3582.3068 [GMT 2:00]
Spuštěný z: c:\documents and settings\Inna\Plocha\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\regedit.com
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\taskmgr.com
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-09 do 2012-07-09 )))))))))))))))))))))))))))))))
.
.
2012-07-09 12:44 . 2012-07-09 12:44 -------- d-----w- c:\program files\TDSSKiller
2012-07-09 12:21 . 2012-07-09 12:22 -------- d-----w- C:\RG
2012-07-09 11:11 . 2012-07-09 11:11 -------- d-----w- c:\program files\RogueKiller
2012-07-06 11:16 . 2012-07-06 11:16 -------- d-----w- c:\program files\Auslogics
2012-07-01 20:41 . 2012-07-01 20:42 -------- d-----w- c:\documents and settings\Inna\Data aplikací\Dropbox
2012-06-30 12:21 . 2012-06-30 12:21 -------- d-----w- C:\rsit
2012-06-29 22:03 . 2012-06-29 22:03 -------- d-----w- c:\program files\RSIT
2012-06-29 18:55 . 2012-06-29 18:55 -------- d-----w- c:\program files\NeroCDSpeed
2012-06-29 17:17 . 2012-06-29 18:22 -------- d-----w- c:\documents and settings\Inna\Data aplikací\ImgBurn
2012-06-29 16:50 . 2012-06-29 16:50 -------- d-----w- c:\program files\ImgBurn
2012-06-29 07:00 . 2012-06-29 07:00 -------- d-----w- c:\documents and settings\Inna\Data aplikací\Malwarebytes
2012-06-29 07:00 . 2012-06-29 07:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-06-29 07:00 . 2012-06-29 07:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-06-29 07:00 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-28 10:46 . 2012-06-29 06:50 -------- d-----w- c:\program files\OTMovelt
2012-06-27 18:50 . 2012-06-27 18:50 -------- d-----w- c:\documents and settings\Inna\Data aplikací\SUPERAntiSpyware.com
2012-06-27 18:50 . 2012-06-27 18:50 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-06-27 18:50 . 2012-06-27 18:50 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2012-06-26 19:23 . 2012-06-26 19:23 -------- d---a-w- c:\windows\VDLL.DLL
2012-06-26 19:23 . 2012-06-26 19:23 -------- d---a-w- c:\windows\system32\runouce.exe
2012-06-26 19:23 . 2012-06-26 19:23 -------- d---a-w- c:\windows\RUNDL132.EXE
2012-06-26 19:23 . 2012-06-26 19:23 -------- d---a-w- c:\windows\logo_1.exe
2012-06-26 19:10 . 2012-06-26 19:10 -------- d-sh--w- c:\documents and settings\Inna\IECompatCache
2012-06-26 18:59 . 2012-06-26 18:59 632064 ----a-w- c:\windows\system32\msvcr80.dll
2012-06-26 18:59 . 2012-06-26 18:59 554240 ----a-w- c:\windows\system32\msvcp80.dll
2012-06-26 18:59 . 2012-06-26 18:59 572928 ----a-w- c:\windows\system32\msvcp90.dll
2012-06-26 18:59 . 2012-06-26 18:59 655872 ----a-w- c:\windows\system32\msvcr90.dll
2012-06-26 18:59 . 2012-06-26 18:59 34048 ----a-w- c:\windows\system32\eEmpty.exe
2012-06-26 18:59 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2012-06-26 18:59 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2012-06-26 18:59 . 2012-06-26 18:59 -------- d-----w- c:\program files\Common Files\MicroWorld
2012-06-26 18:59 . 2012-06-26 18:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MicroWorld
2012-06-26 18:42 . 2012-06-26 18:42 -------- d-----w- c:\documents and settings\Inna\Local Settings\Data aplikací\Sun
2012-06-26 12:49 . 2012-06-26 12:50 -------- d-----w- c:\program files\Wireshark
2012-06-26 12:37 . 2012-06-26 12:37 -------- d-----w- c:\documents and settings\Inna\Data aplikací\Online Solutions
2012-06-26 12:30 . 2012-06-26 12:30 -------- d-----w- c:\program files\Common Files\Java
2012-06-26 12:29 . 2012-06-26 12:29 -------- d-----w- c:\program files\Oracle
2012-06-26 12:29 . 2012-06-26 12:29 -------- d-----w- c:\documents and settings\Inna\Data aplikací\Oracle
2012-06-26 11:47 . 2012-06-26 11:47 -------- d-----w- c:\program files\Online Solutions
2012-06-26 11:47 . 2012-06-26 11:47 -------- d-----w- c:\program files\Common Files\Online Solutions Shared
2012-06-25 10:02 . 2012-06-25 10:09 -------- d-----w- c:\documents and settings\Inna\Data aplikací\xrecode2
2012-06-25 10:02 . 2012-06-25 10:02 -------- d-----w- c:\program files\xrecode II
2012-06-24 13:28 . 2012-06-24 13:28 -------- d-----w- c:\documents and settings\Inna\Data aplikací\CUE Tools
2012-06-24 13:27 . 2012-06-24 13:27 -------- d-----w- c:\program files\Cue_Tools
2012-06-23 20:44 . 2012-06-25 09:00 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-06-23 20:44 . 2012-06-24 22:34 85472 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-06-23 20:44 . 2012-06-24 22:34 157608 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-06-23 20:44 . 2012-06-24 22:34 113120 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-06-23 20:44 . 2012-06-01 15:39 770384 ----a-w- c:\program files\Mozilla Firefox\msvcr100.dll
2012-06-23 20:44 . 2012-06-01 15:39 421200 ----a-w- c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-23 20:32 . 2012-05-04 17:29 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-06-23 20:32 . 2012-05-04 17:29 772504 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-06-23 20:03 . 2012-05-11 14:44 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2012-06-23 19:55 . 2012-06-02 13:19 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-23 18:56 . 2008-04-13 17:45 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2012-06-23 18:32 . 2012-06-23 18:32 -------- d-----w- c:\documents and settings\Inna\Local Settings\Data aplikací\Eraser 6
2012-06-23 17:28 . 2012-06-23 17:28 -------- d-----w- c:\program files\Eraser
2012-06-23 10:35 . 2012-06-23 11:13 -------- d-----w- c:\documents and settings\Inna\Data aplikací\TrueCrypt
2012-06-23 10:33 . 2012-06-23 10:33 231760 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2012-06-23 10:33 . 2012-06-23 10:33 -------- d-----w- c:\program files\TrueCrypt
2012-06-20 16:14 . 2012-06-20 16:14 12800 ----a-w- c:\program files\Mozilla Firefox\plugins\npwachk.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-29 17:30 . 2011-12-14 22:09 477240 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-06-27 09:53 . 2012-03-31 13:21 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-27 09:53 . 2011-12-14 06:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-26 19:24 . 2012-06-26 19:23 4375385 ----a-w- c:\windows\REGBK00.ZIP
2012-06-04 15:35 . 2011-12-14 03:18 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-04 15:35 . 2009-08-06 18:23 222448 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 13:19 . 2011-12-14 04:20 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2011-12-14 04:20 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2011-12-14 03:18 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2011-12-14 03:18 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2011-12-14 04:20 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2011-12-14 04:20 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2011-12-14 03:18 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2011-12-14 03:18 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2006-03-02 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2011-12-14 03:18 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2011-12-14 03:18 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2012-01-18 14:57 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2012-01-18 14:57 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2006-03-02 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2006-03-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 13:55 . 2006-03-02 12:00 1863168 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 14:44 . 2006-03-02 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2006-03-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-03-02 12:00 385024 ------w- c:\windows\system32\html.iec
2012-05-05 03:14 . 2006-03-02 12:00 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-17 15:45 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-04 17:29 . 2012-01-02 10:19 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-02 13:46 . 2011-12-14 03:17 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-24 22:34 . 2012-06-23 20:44 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2006-03-02 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748_0$\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2012-06-30_23.28.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-09 19:22 . 2012-07-09 19:22 16384 c:\windows\Temp\Perflib_Perfdata_4e0.dat
+ 2011-06-10 23:58 . 2011-06-10 23:58 51024 c:\windows\system32\vcomp100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 51024 c:\windows\system32\vcomp100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100u.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 81744 c:\windows\system32\mfcm100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 60752 c:\windows\system32\mfc100rus.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 60752 c:\windows\system32\mfc100rus.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 43344 c:\windows\system32\mfc100kor.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 43344 c:\windows\system32\mfc100kor.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 43856 c:\windows\system32\mfc100jpn.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100chs.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 36176 c:\windows\system32\mfc100chs.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100fra.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 64336 c:\windows\system32\mfc100fra.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 63824 c:\windows\system32\mfc100esn.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 63824 c:\windows\system32\mfc100esn.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 55120 c:\windows\system32\mfc100enu.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 55120 c:\windows\system32\mfc100enu.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 64336 c:\windows\system32\mfc100deu.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100deu.dll
+ 2011-12-14 03:18 . 2012-06-02 13:19 35864 c:\windows\system32\dllcache\wups.dll
+ 2011-12-14 03:20 . 2012-07-01 10:57 76487 c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2011-12-14 03:20 . 2011-12-14 03:20 76487 c:\windows\pchealth\helpctr\OfflineCache\index.dat
+ 2011-12-14 03:20 . 2012-07-01 10:57 2378 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2011-12-14 03:20 . 2012-07-01 10:57 8972 c:\windows\pchealth\helpctr\Config\Cntstore.bin
+ 2011-06-10 23:58 . 2011-06-10 23:58 773968 c:\windows\system32\msvcr100.dll
- 2011-02-18 22:40 . 2011-02-18 22:40 773968 c:\windows\system32\msvcr100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 421200 c:\windows\system32\msvcp100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 421200 c:\windows\system32\msvcp100.dll
+ 2011-12-14 03:18 . 2012-06-02 13:19 577048 c:\windows\system32\dllcache\wuapi.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 138056 c:\windows\system32\atl100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 138056 c:\windows\system32\atl100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 4422992 c:\windows\system32\mfc100u.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 4422992 c:\windows\system32\mfc100u.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 4397384 c:\windows\system32\mfc100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 4397384 c:\windows\system32\mfc100.dll
+ 2011-06-28 19:27 . 2011-06-28 19:27 4028928 c:\windows\Installer\427a0.msp
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JulaPan"="JulaPan.Exe" [2008-06-24 421888]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-05 98304]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\AutorunsDisabled
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-10-14 291896]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\36X Raid Configurer]
2007-11-19 03:28 1966080 ------r- c:\windows\system32\xRaidSetup.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeARM.exe]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALCMTR.EXE]
2008-06-19 08:20 57344 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ------r- c:\windows\alcwzrd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneVI]
2007-07-26 14:05 20480 ----a-w- c:\program files\GIGABYTE\ET6\ETcall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2012-05-22 06:13 980920 ----a-w- c:\progra~1\Eraser\Eraser.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-01-16 23:24 136176 ----atw- c:\documents and settings\Inna\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
2007-03-20 06:36 36864 ------r- c:\windows\RaidTool\xInsIDE.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-04-04 13:56 462408 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetLimiter]
2004-03-31 13:23 823296 ----a-w- c:\program files\NetLimiter\NetLimiter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-07-23 08:51 16804864 ------r- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ------r- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 09:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ThreatFire]
2010-01-14 14:08 378128 ----a-w- c:\program files\ThreatFire\TFTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2012-06-20 16:13 74752 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [25.3.2012 17:49 28552]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [30.3.2012 11:37 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [30.3.2012 11:37 59664]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [7.10.2011 19:48 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.10.2011 19:48 31704]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [13.2.2012 13:28 100368]
R3 JULA_01;Service for Juli@ 1;c:\windows\system32\drivers\JulaWdm.sys [24.6.2008 11:21 22912]
R3 JULA_AA;Service for Juli@ Audio Driver (EWDM);c:\windows\system32\drivers\Jula.sys [24.6.2008 11:20 29600]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [14.12.2011 6:17 60255]
R3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [14.12.2011 6:17 549421]
S3 etdrv;etdrv;c:\windows\etdrv.sys [14.1.2012 16:47 17488]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [29.6.2012 9:00 22344]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [23.6.2012 22:44 113120]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2.8.2005 23:10 32512]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [1.9.2010 10:30 15544]
S3 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\psia.exe [14.10.2011 8:01 994360]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [30.3.2012 11:37 33552]
S4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
S4 ADExchange;ArcSoft Exchange Service;c:\program files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [16.9.2011 20:13 39528]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [29.6.2012 9:00 654408]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.12.2011 0:09 477240]
S4 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?]
.
.
------- Doplňkový sken -------
.
mSearch Bar = hxxp://www.google.com/ie
LSP: c:\program files\NetLimiter\nl_lsp.dll
FF - ProfilePath - c:\documents and settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-mwavscan_autoscan - c:\documents and settings\Inna\Local Settings\Temp\mwavscan.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-09 21:29
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(696)
c:\windows\system32\guard32.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'lsass.exe'(752)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
- - - - - - - > 'csrss.exe'(652)
c:\windows\system32\cmdcsr.dll
.
Celkový čas: 2012-07-09 21:30:05
ComboFix-quarantined-files.txt 2012-07-09 19:30
ComboFix2.txt 2012-06-30 23:35
.
Před spuštěním: Volných bajtů: 42 713 063 424
Po spuštění: Volných bajtů: 43 055 935 488
.
- - End Of File - - B190B12C7F64ECACA9B251A3BE7F27B6

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu(IRCBot)

#15 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    C:\Documents and Settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default\searchplugins\askcom.xml
    
    Restore::
    c:\windows\system32\drivers\tcpip.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeARM.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět