Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Hacktool.Rootkit? - log

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Hacktool.Rootkit? - log

#1 Příspěvek od JanX »

Dobrý den, prosím o kontrolu logu, případně další pomoc.

Problémy se objevily kolem detekce Hacktool.Rootkit - jeho přetrvávající detekce, neustálé výstrahy od Nortnu, kdy je aktérem C:\Windows\System32\svchost.exe, celkově rychlost počítače, další dílčí problémy s Windows Centrem zabezpečení, adobe, atd...

Nevím jestli to je důležité, ale podezřelé konfigurace systému okolo okamžiku první blokace rootkitu (viz. Norton historie zabezpečení):
1.1 ms.exe konfiguroval C:\Users\Jenda\appdata\local\temp\gryxstif.exe
2.1 gryxstif.exe konfiguroval
C:\Users\Jenda\appdata\local\temp\vxckqoyl.sys
2.2 \registry\machine\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\donotallowexceptions
2.3 \registry\machine\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile\disablenotofications
2.4 \registry\machine\software\microsoft\windows\currentversion\run\windows defender
2.5 \registry\machine\software\microsoft\windows NT\currentversion\winlofon\userinit
3.1 omedqrgy.exe konfiguroval opět C:\Users\Jenda\appdata\local\temp\gryxstif.exe
později ještě
4.1 asghost.exe konfiguroval C:\Windows\System32\SndVol.exe
4.2 asghost.exe konfiguroval \registry\machine\software\microsoft\internet Explorer\extensions\{1009C944-97D5-44A9-DFF54F498968}ClsidExtension
5.1 adobe gamma loader.exe konfiguroval C:\program foles\common files\adobe\calibration\988s5inlt
pak ještě nějaké konfigurace, když začlo v historii zabezpečení naskakovat "zajímavým" tempem..jesli by to mohlo "pomoct" tak, kdyžak napiště a já to prohledám a vypíšu tady zbytek

:roll: ...snad správně vložím ten log...

PS: můžu vložit i logy z Gmeru, jestli to "pomůže"..
_____________________________________________________________________________________

Logfile of random's system information tool 1.09 (written by random/random)
Run by Jenda at 2012-11-03 07:09:46
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 52 GB (34%) free of 153 GB
Total RAM: 3070 MB (42% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "{8545daff-ad1e-493f-a37e-eed1ac79682b}:1.0, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {7BA52691-1876-45ce-9EE6-54BCB3B04BBC}:3.7.2, {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@bittorrent.com/BitTorrentDNA]
"Description"=Delivery Network Acceleration by BitTorrent™
"Path"=C:\Program Files\DNA\plugins\npbtdna.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448]
"Description"=6.0.12.448
"Path"=C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsIQTScriptablePlugin.xpt
nsJSRealPlayerPlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpjplug.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default\extensions\
{7b13ec3e-999a-4b70-b9cb-2617b8323822}
{800b5000-a755-47e1-992b-48a1c1357f07}

C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default\searchplugins\
icqplugin-1.xml
icqplugin-2.xml
icqplugin.xml
wikipedia-eng.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton 360\Engine\3.8.3.6\coIEPlg.dll [2011-09-22 378736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton 360\Engine\3.8.3.6\IPSBHO.DLL [2009-08-22 107896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2011-02-09 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
ASUS Security Protect Manager - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll [2006-11-21 70928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-07-17 691656]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton 360\Engine\3.8.3.6\coIEPlg.dll [2011-09-22 378736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
"P2Go_Menu"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-14 210216]
"HControlUser"=C:\Program Files\ATK Hotkey\HcontrolUser.exe [2008-01-12 98304]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2008-01-23 7766016]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-16 178712]
"IaNvSrv"=C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe [2008-05-03 33304]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 163840]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-04-01 6025216]
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2008-01-25 1208320]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-07 1029416]
"CognizanceTS"=C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll [2003-12-22 120832]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2008-02-01 61440]
"PowerForPhone"=C:\Program Files\P4P\P4P.exe [2007-08-03 778240]
"ASUS Screen Saver Protector"=C:\Windows\AsScrPro.exe [2008-08-31 3054136]
"ASUS Camera ScreenSaver"=C:\Windows\AsScrProlog.exe [2008-08-31 47672]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-12 39792]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe [2001-07-09 155648]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"WD Quick View"=C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [2012-09-19 5236664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Google Update"=C:\Users\Jenda\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-06 136176]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"OmeDqrgy"=C:\Users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
AVer HID Receiver.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Jenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="APSHook.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codecp"=l3codecp.acm
"VIDC.FPS1"=frapsvid.dll
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"wave2"=serwvdrv.dll
"wave4"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"VIDC.FMVC"=fmcodec.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-11-03 07:04:10 ----D---- C:\Program Files\trend micro
2012-11-03 07:04:08 ----D---- C:\rsit
2012-11-02 21:27:33 ----A---- C:\kwtoypob.sys
2012-10-29 14:09:56 ----SHD---- C:\found.006
2012-10-10 14:02:33 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-10 14:02:33 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-10 14:02:33 ----A---- C:\Windows\system32\crypt32.dll
2012-10-10 14:00:50 ----A---- C:\Windows\system32\wintrust.dll
2012-10-10 13:59:42 ----A---- C:\Windows\system32\tzres.dll
2012-10-10 13:58:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-10 13:58:53 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-10-08 20:06:28 ----D---- C:\Users\Jenda\AppData\Roaming\BSplayer Pro
2012-10-08 20:06:27 ----D---- C:\Program Files\Webteh

======List of files/folders modified in the last 1 month======

2012-11-03 07:09:45 ----SHD---- C:\System Volume Information
2012-11-03 07:06:41 ----D---- C:\Windows\Temp
2012-11-03 07:04:10 ----RD---- C:\Program Files
2012-11-02 20:40:58 ----D---- C:\Program Files\gretl
2012-11-02 19:13:47 ----D---- C:\Windows\System32
2012-11-02 19:13:47 ----D---- C:\Windows\inf
2012-11-02 19:13:47 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-11-02 17:02:08 ----D---- C:\Users\Jenda\AppData\Roaming\Media Player Classic
2012-11-02 17:02:08 ----D---- C:\Users\Jenda\AppData\Roaming\BitTorrent
2012-11-01 16:38:14 ----A---- C:\Windows\system32\acovcnt.exe
2012-10-31 18:02:34 ----D---- C:\Users\Jenda\AppData\Roaming\ICQ
2012-10-30 21:08:32 ----D---- C:\Program Files\Common Files\ESRI
2012-10-29 19:44:19 ----D---- C:\Program Files\Diablo III
2012-10-29 19:39:39 ----D---- C:\Program Files\ATK Hotkey
2012-10-29 17:11:09 ----D---- C:\Windows\system32\catroot2
2012-10-29 16:51:05 ----D---- C:\Program Files\Diablo II
2012-10-29 16:32:42 ----D---- C:\Program Files\Common Files\LightScribe
2012-10-29 15:42:55 ----D---- C:\Windows\system32\wbem
2012-10-29 15:42:55 ----D---- C:\Windows
2012-10-29 15:41:48 ----D---- C:\Program Files\Common Files\AVerMedia
2012-10-29 15:41:47 ----D---- C:\Program Files\ATKGFNEX
2012-10-29 15:41:40 ----D---- C:\Windows\Tasks
2012-10-29 15:41:40 ----D---- C:\Windows\system32\Tasks
2012-10-29 15:41:39 ----D---- C:\Windows\system32\spool
2012-10-29 15:41:38 ----SHD---- C:\Windows\Installer
2012-10-29 15:41:31 ----D---- C:\ProgramData\P4G
2012-10-29 15:41:18 ----D---- C:\Windows\registration
2012-10-29 13:59:17 ----HD---- C:\ProgramData
2012-10-25 18:23:16 ----D---- C:\ProgramData\Microsoft Help
2012-10-21 12:55:33 ----D---- C:\Windows\Prefetch
2012-10-14 21:39:20 ----D---- C:\Windows\system32\catroot
2012-10-14 21:38:50 ----D---- C:\Program Files\Western Digital
2012-10-14 21:38:17 ----D---- C:\ProgramData\Western Digital
2012-10-11 15:03:56 ----D---- C:\Windows\rescache
2012-10-11 09:31:44 ----D---- C:\Windows\winsxs
2012-10-11 08:39:51 ----D---- C:\Windows\system32\cs-CZ
2012-10-11 00:04:19 ----A---- C:\Windows\system32\mrt.exe
2012-10-08 20:08:04 ----D---- C:\Users\Jenda\AppData\Roaming\BSplayer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaNvStor;Intel(R) Turbo Memory Controller; C:\Windows\system32\DRIVERS\iaNvStor.sys [2008-04-24 226328]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2008-05-07 317976]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2008-10-03 717296]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360\0308030.006\SYMEFA.SYS [2009-08-22 310320]
R1 BHDrvx86;Symantec Heuristics Driver; C:\Windows\System32\Drivers\N360\0308030.006\BHDrvx86.sys [2009-08-22 259632]
R1 ccHP;Symantec Hash Provider; C:\Windows\System32\Drivers\N360\0308030.006\ccHPx86.sys [2011-09-22 467592]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2012-08-01 376480]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20121102.001\IDSvix86.sys [2012-09-01 386720]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\N360\0308030.006\SRTSPX.SYS [2009-08-22 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2009-08-22 25648]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\Windows\System32\Drivers\N360\0308030.006\SYMTDI.SYS [2011-09-22 217464]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2008-10-30 279712]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2008-10-30 25888]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-09 45568]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-03-29 3544064]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2007-06-17 146824]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-01 106656]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-04-01 2113624]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-25 5632]
R3 kwtoypob;kwtoypob; \??\C:\kwtoypob.sys [2012-11-02 100864]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-21 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20121102.008\NAVENG.SYS [2012-09-05 92704]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20121102.008\NAVEX15.SYS [2012-09-05 1601184]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2009-05-28 4233728]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-05-02 122368]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2008-01-25 1090304]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\N360\0308030.006\SRTSP.SYS [2009-08-22 308272]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2009-11-08 124976]
R3 SYMFW;Symantec Network Filter Driver; C:\Windows\System32\Drivers\N360\0308030.006\SYMFW.SYS [2011-09-22 89976]
R3 SYMNDISV;Symantec Network Filter Driver; C:\Windows\System32\Drivers\N360\0308030.006\SYMNDISV.SYS [2011-09-22 48760]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-07 196400]
S3 AVerFx2hbtv;AVerMedia USB SW Hybrid Tuner; C:\Windows\system32\drivers\AVerFx2hbtv.sys [2009-07-01 436480]
S3 awl0fhm0;awl0fhm0; C:\Windows\system32\drivers\awl0fhm0.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-03-17 81960]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2008-03-17 100392]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2008-03-17 17320]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-04-10 25280]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam.sys [2012-04-11 11520]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 ASBroker;Logon Session Broker; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 ASChannel;Local Communication Channel; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-03-29 667648]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 AVerRemote;AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [2009-04-08 344064]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [2008-12-09 405504]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-04-10 518696]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-16 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 N360;Norton 360; C:\Program Files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe [2011-09-22 117648]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
R2 WDBackup;WD Backup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [2012-09-19 1157056]
R2 WDDriveService;WD Drive Manager; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [2012-09-19 248248]
R2 WDRulesService;WD Rules; C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [2012-09-19 1177536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-12 129976]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------
Naposledy upravil(a) JanX dne 03 lis 2012 10:39, celkem upraveno 1 x.

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#2 Příspěvek od JanX »

LOG1
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-11-02 21:38:47
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST932032 rev.0303
Running: jhsyxns4.exe; Driver: C:\Users\Jenda\AppData\Local\Temp\kwtoypob.sys


---- Devices - GMER 1.0.15 ----

Device \Driver\iaStor \Device\Ide\iaStor0 [8A9435A0] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [8A9435A0] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 [8A9435A0] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\awl0fhm0 \Device\Scsi\awl0fhm01Port2Path0Target0Lun0 88D931F8
Device \Driver\awl0fhm0 \Device\Scsi\awl0fhm01 88D931F8
Device \FileSystem\Ntfs \Ntfs 85B351F8
Device \FileSystem\fastfat \Fat 9DF931F8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Společnost Microsoft)
AttachedDevice \Driver\tdx \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----



log2 je trochu delší :D :cry: ..budu muset rozdělit

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#3 Příspěvek od JanX »

tak se mi zdá že se rozhodilo při tom rozdělování formátování a ještě bych to pak musel dělit jednou, tak posílám, snad úspěšně, odkaz na ten 2.log...je to celý 2. log..

http://www.ulozto.cz/x99gZSh/2-log

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#4 Příspěvek od JanX »

Nj ja chtěl stihnout jeste pred odpovedi dopsat nejakou tu konfiguraci a myslel jsem, ze to este stihnu...Log-RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Jenda at 2012-11-03 12:52:28
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 57 GB (37%) free of 153 GB
Total RAM: 3070 MB (47% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "{8545daff-ad1e-493f-a37e-eed1ac79682b}:1.0, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0021-

ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {20a82645-

c095-46ed-80e3-08825760534b}:1.1, {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {7BA52691-1876-45ce-9EE6-54BCB3B04BBC}:3.7.2,

{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@bittorrent.com/BitTorrentDNA]
"Description"=Delivery Network Acceleration by BitTorrent™
"Path"=C:\Program Files\DNA\plugins\npbtdna.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448]
"Description"=6.0.12.448
"Path"=C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsIQTScriptablePlugin.xpt
nsJSRealPlayerPlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpjplug.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default\extensions\
{7b13ec3e-999a-4b70-b9cb-2617b8323822}
{800b5000-a755-47e1-992b-48a1c1357f07}

C:\Users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default\searchplugins\
icqplugin-1.xml
icqplugin-2.xml
icqplugin.xml
wikipedia-eng.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton 360\Engine\3.8.3.6\coIEPlg.dll [2011-09-22 378736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton 360\Engine\3.8.3.6\IPSBHO.DLL [2009-08-22 107896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2011-02-09 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
ASUS Security Protect Manager - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll [2006-11-21 70928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-07-17 691656]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton 360\Engine\3.8.3.6\coIEPlg.dll [2011-09-22 378736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
"P2Go_Menu"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-14 210216]
"HControlUser"=C:\Program Files\ATK Hotkey\HcontrolUser.exe [2008-01-12 98304]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2008-01-23 7766016]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-16 178712]
"IaNvSrv"=C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe [2008-05-03 33304]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 163840]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-04-01 6025216]
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2008-01-25 1208320]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-07 1029416]
"CognizanceTS"=C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll [2003-12-22 120832]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2008-02-01 61440]
"PowerForPhone"=C:\Program Files\P4P\P4P.exe [2007-08-03 778240]
"ASUS Screen Saver Protector"=C:\Windows\AsScrPro.exe [2008-08-31 3054136]
"ASUS Camera ScreenSaver"=C:\Windows\AsScrProlog.exe [2008-08-31 47672]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-12 39792]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe [2001-07-09 155648]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"WD Quick View"=C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [2012-09-19 5236664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Google Update"=C:\Users\Jenda\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-06 136176]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"OmeDqrgy"=C:\Users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
AVer HID Receiver.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Jenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="APSHook.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codecp"=l3codecp.acm
"VIDC.FPS1"=frapsvid.dll
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"wave2"=serwvdrv.dll
"wave4"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"VIDC.FMVC"=fmcodec.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-11-03 12:35:16 ----ASH---- C:\hiberfil.sys
2012-11-03 12:34:23 ----D---- C:\_OTL
2012-11-03 11:30:44 ----A---- C:\Windows\ntbtlog.txt
2012-11-03 07:04:10 ----D---- C:\Program Files\trend micro
2012-11-03 07:04:08 ----D---- C:\rsit
2012-11-02 21:27:33 ----A---- C:\kwtoypob.sys
2012-10-29 14:09:56 ----SHD---- C:\found.006
2012-10-10 14:02:33 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-10 14:02:33 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-10 14:02:33 ----A---- C:\Windows\system32\crypt32.dll
2012-10-10 14:00:50 ----A---- C:\Windows\system32\wintrust.dll
2012-10-10 13:59:42 ----A---- C:\Windows\system32\tzres.dll
2012-10-10 13:58:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-10 13:58:53 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-10-08 20:06:28 ----D---- C:\Users\Jenda\AppData\Roaming\BSplayer Pro
2012-10-08 20:06:27 ----D---- C:\Program Files\Webteh

======List of files/folders modified in the last 1 month======

2012-11-03 12:52:14 ----SHD---- C:\System Volume Information
2012-11-03 12:50:29 ----D---- C:\Windows\Temp
2012-11-03 12:41:12 ----A---- C:\Windows\system32\acovcnt.exe
2012-11-03 11:30:44 ----D---- C:\Windows
2012-11-03 07:04:10 ----RD---- C:\Program Files
2012-11-02 20:40:58 ----D---- C:\Program Files\gretl
2012-11-02 19:13:47 ----D---- C:\Windows\System32
2012-11-02 19:13:47 ----D---- C:\Windows\inf
2012-11-02 19:13:47 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-11-02 17:02:08 ----D---- C:\Users\Jenda\AppData\Roaming\Media Player Classic
2012-11-02 17:02:08 ----D---- C:\Users\Jenda\AppData\Roaming\BitTorrent
2012-10-31 18:02:34 ----D---- C:\Users\Jenda\AppData\Roaming\ICQ
2012-10-30 21:08:32 ----D---- C:\Program Files\Common Files\ESRI
2012-10-29 19:44:19 ----D---- C:\Program Files\Diablo III
2012-10-29 19:39:39 ----D---- C:\Program Files\ATK Hotkey
2012-10-29 17:11:09 ----D---- C:\Windows\system32\catroot2
2012-10-29 16:51:05 ----D---- C:\Program Files\Diablo II
2012-10-29 16:32:42 ----D---- C:\Program Files\Common Files\LightScribe
2012-10-29 15:42:55 ----D---- C:\Windows\system32\wbem
2012-10-29 15:41:48 ----D---- C:\Program Files\Common Files\AVerMedia
2012-10-29 15:41:47 ----D---- C:\Program Files\ATKGFNEX
2012-10-29 15:41:40 ----D---- C:\Windows\Tasks
2012-10-29 15:41:40 ----D---- C:\Windows\system32\Tasks
2012-10-29 15:41:39 ----D---- C:\Windows\system32\spool
2012-10-29 15:41:38 ----SHD---- C:\Windows\Installer
2012-10-29 15:41:31 ----D---- C:\ProgramData\P4G
2012-10-29 15:41:18 ----D---- C:\Windows\registration
2012-10-29 13:59:17 ----HD---- C:\ProgramData
2012-10-25 18:23:16 ----D---- C:\ProgramData\Microsoft Help
2012-10-21 12:55:33 ----D---- C:\Windows\Prefetch
2012-10-14 21:39:20 ----D---- C:\Windows\system32\catroot
2012-10-14 21:38:50 ----D---- C:\Program Files\Western Digital
2012-10-14 21:38:17 ----D---- C:\ProgramData\Western Digital
2012-10-11 15:03:56 ----D---- C:\Windows\rescache
2012-10-11 09:31:44 ----D---- C:\Windows\winsxs
2012-10-11 08:39:51 ----D---- C:\Windows\system32\cs-CZ
2012-10-11 00:04:19 ----A---- C:\Windows\system32\mrt.exe
2012-10-08 20:08:04 ----D---- C:\Users\Jenda\AppData\Roaming\BSplayer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaNvStor;Intel(R) Turbo Memory Controller; C:\Windows\system32\DRIVERS\iaNvStor.sys [2008-04-24 226328]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2008-05-07 317976]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2008-10-03 717296]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360\0308030.006\SYMEFA.SYS [2009-08-22 310320]
R1 BHDrvx86;Symantec Heuristics Driver; C:\Windows\System32\Drivers\N360\0308030.006\BHDrvx86.sys [2009-08-22 259632]
R1 ccHP;Symantec Hash Provider; C:\Windows\System32\Drivers\N360\0308030.006\ccHPx86.sys [2011-09-22 467592]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2012-08-01 376480]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20121102.001\IDSvix86.sys [2012-09-01 386720]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\N360\0308030.006\SRTSPX.SYS [2009-08-22 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2009-08-22 25648]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\Windows\System32\Drivers\N360\0308030.006\SYMTDI.SYS [2011-09-22 217464]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2008-10-30 279712]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2008-10-30 25888]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-09 45568]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-03-29 3544064]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2007-06-17 146824]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-01 106656]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-04-01 2113624]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-25 5632]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-21 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20121102.021\NAVENG.SYS [2012-09-05 92704]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20121102.021\NAVEX15.SYS [2012-09-05 1601184]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2009-05-28 4233728]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-05-02 122368]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2008-01-25 1090304]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\N360\0308030.006\SRTSP.SYS [2009-08-22 308272]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2009-11-08 124976]
R3 SYMFW;Symantec Network Filter Driver; C:\Windows\System32\Drivers\N360\0308030.006\SYMFW.SYS [2011-09-22 89976]
R3 SYMNDISV;Symantec Network Filter Driver; C:\Windows\System32\Drivers\N360\0308030.006\SYMNDISV.SYS [2011-09-22 48760]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-07 196400]
S3 angwa7sc;angwa7sc; C:\Windows\system32\drivers\angwa7sc.sys []
S3 AVerFx2hbtv;AVerMedia USB SW Hybrid Tuner; C:\Windows\system32\drivers\AVerFx2hbtv.sys [2009-07-01 436480]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-03-17 81960]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2008-03-17 100392]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2008-03-17 17320]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-04-10 25280]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam.sys [2012-04-11 11520]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 ASBroker;Logon Session Broker; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 ASChannel;Local Communication Channel; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-03-29 667648]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 AVerRemote;AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [2009-04-08 344064]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [2008-12-09 405504]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-04-10 518696]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-16 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 N360;Norton 360; C:\Program Files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe [2011-09-22 117648]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
R2 WDBackup;WD Backup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [2012-09-19 1157056]
R2 WDDriveService;WD Drive Manager; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [2012-09-19 248248]
R2 WDRulesService;WD Rules; C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [2012-09-19 1177536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-12 129976]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

[2010-03-18 753504]

-----------------EOF-----------------

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#5 Příspěvek od JanX »

Log-hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:51:43, on 3.11.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ATK Hotkey\MsgTranAgt.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Windows\System32\ACEngSvr.exe
C:\Windows\system32\conime.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\ATK Hotkey\HControlUser.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\P4P\P4P.exe
C:\Windows\AsScrPro.exe
C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe
C:\Users\Jenda\Desktop\HiJackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,,C:\Users\Jenda\AppData\Local\Temp\gryxstif.exe,C:\Users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.8.3.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.8.3.6\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.8.3.6\coIEPlg.dll
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [HControlUser] "C:\Program Files\ATK Hotkey\HcontrolUser.exe"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WD Quick View] C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jenda\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [OmeDqrgy] C:\Users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ASUS Security Protect Manager e-Wallet - {1009C944-97D5-44A9-9E32-DFF54F498968} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWallet.dll
O9 - Extra 'Tools' menuitem: ASUS Security Protect Manager e-&Wallet - {1009C944-97D5-44A9-9E32-DFF54F498968} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWallet.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.8.3.6\coIEPlg.dll
O20 - AppInit_DLLs: APSHook.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: WD Backup (WDBackup) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: WD Rules (WDRulesService) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe

--
End of file - 13195 bytes

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#6 Příspěvek od JanX »

Tak zatím jedu to OTL..nevím jak dlouho to potrvá..ve 14:00 budu muset bohuzel odejít, tak radši píšu, at se můžeš věnovat něčemu jinému mezitím, během odpoledne tedy asi nebudu schopen dalšího reportingu...

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#7 Příspěvek od JanX »

Takže pár poznámek pro jistotu:
Otl - OK
Mbrscan - po kliknutí na Report přestane pracovat - zkusím stáhnout na druhém počítači a pak to tu rozeběhnout znovu
Tdsskiller - nejde stáhnout, taky zkusím stáhnout ještě jinde

Powertool:
exportoval jsem přes RMB a výběr možnosti Export vždy ve vybrané záložce, tlačítko nebo volbu Export jsem jinde nenašel
*Hooks - u záložek SSDT mi nejde export (neexistuje v nabídce přes RMB click)
- u záložky IDT kliknu na volbu Export, ale exportovaný soubor se mi nezobrazí, nezobrazí se ani výběr cesty pro uložení
*Offline - jen dvě podzáložky - analyzoval jsem "jen" disk C a v druhé záložce disk C jako administrátorský účet
*Application - radši jsem analyzoval všechny podzáložky, protože jich tam bylo víc než 2
*System - nevidím "Image Hijack"
"Image Hijack" - nalezeno ve složce *Application - provedl jsem export
-Screen záložky Master Boot Record - Check - Disk 0 - blablabla - jiný v nabídce není, report se nevejde na jeden screenshot, screenshotuju jen to co se vejde po provedení reportu
Přílohy
Logy - OTL.rar
(130.33 KiB) Staženo 29 x

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#8 Příspěvek od JanX »

Powertool - reporty v .rar
Přílohy
Reporty - powertool.rar
(30.15 KiB) Staženo 36 x

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#9 Příspěvek od JanX »

Screeny - powertool v .rar
Přílohy
Screeny - powertool.rar
(235.84 KiB) Staženo 30 x

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#10 Příspěvek od JanX »

Další report:
Mbrscan - při stahování na druhém počítači mi Norton po dokončení stahování hlásil infikovanost souboru a Mbrscan odebíral, stáhnul jsem ho znovu, myslím že možná z jiného odkazu z tohoto fora, ale po spuštění, zvolení oblastí a kliku na tlačítko opět přestal pracovat a windows ho ukončil...

Tdsskiller - log přikládám níže...

Flashka - no mám dojem, že jediná flashka co jsem snad použil od napadení se mi normálně myslím hlásí jako disk G...nevím jestli je to důležité...


Combofix - Mám už ho stáhnout a postupovat podle návodu nebo počkat až se ti podaří zpracovat log z Tdsskilleru?

____________________________________________

11:54:52.0808 3864 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
11:54:53.0830 3864 ============================================================
11:54:53.0831 3864 Current date / time: 2012/11/04 11:54:53.0830
11:54:53.0831 3864 SystemInfo:
11:54:53.0831 3864
11:54:53.0831 3864 OS Version: 6.0.6002 ServicePack: 2.0
11:54:53.0831 3864 Product type: Workstation
11:54:53.0831 3864 ComputerName: JENDA-PC
11:54:53.0831 3864 UserName: Jenda
11:54:53.0831 3864 Windows directory: C:\Windows
11:54:53.0831 3864 System windows directory: C:\Windows
11:54:53.0831 3864 Processor architecture: Intel x86
11:54:53.0831 3864 Number of processors: 2
11:54:53.0831 3864 Page size: 0x1000
11:54:53.0831 3864 Boot type: Normal boot
11:54:53.0831 3864 ============================================================
11:54:58.0221 3864 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:54:58.0224 3864 Drive \Device\Harddisk2\DR2 - Size: 0x7AFFFE00 (1.92 Gb), SectorSize: 0x200, Cylinders: 0xFA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
11:54:58.0225 3864 ============================================================
11:54:58.0225 3864 \Device\Harddisk0\DR0:
11:54:58.0225 3864 MBR partitions:
11:54:58.0225 3864 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1388800, BlocksNum 0x12A17000
11:54:58.0226 3864 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x13DA0000, BlocksNum 0x1168E800
11:54:58.0226 3864 \Device\Harddisk2\DR2:
11:54:58.0226 3864 MBR partitions:
11:54:58.0226 3864 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x6, StartLBA 0x3F, BlocksNum 0x3D7FC0
11:54:58.0226 3864 ============================================================
11:54:58.0228 3864 C: <-> \Device\Harddisk0\DR0\Partition1
11:54:58.0460 3864 D: <-> \Device\Harddisk0\DR0\Partition2
11:54:58.0460 3864 ============================================================
11:54:58.0461 3864 Initialize success
11:54:58.0461 3864 ============================================================
11:55:19.0610 4492 ============================================================
11:55:19.0610 4492 Scan started
11:55:19.0610 4492 Mode: Manual; SigCheck; TDLFS;
11:55:19.0610 4492 ============================================================
11:55:21.0772 4492 ================ Scan system memory ========================
11:55:21.0772 4492 System memory - ok
11:55:21.0773 4492 ================ Scan services =============================
11:55:22.0039 4492 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
11:55:22.0253 4492 ACPI - ok
11:55:22.0419 4492 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
11:55:22.0511 4492 adp94xx - ok
11:55:22.0578 4492 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
11:55:22.0667 4492 adpahci - ok
11:55:22.0687 4492 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
11:55:22.0731 4492 adpu160m - ok
11:55:22.0762 4492 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
11:55:23.0053 4492 adpu320 - ok
11:55:23.0062 4492 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:55:23.0194 4492 AeLookupSvc - ok
11:55:23.0226 4492 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
11:55:23.0424 4492 AFD - ok
11:55:23.0489 4492 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
11:55:23.0512 4492 agp440 - ok
11:55:23.0537 4492 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
11:55:23.0561 4492 aic78xx - ok
11:55:23.0599 4492 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
11:55:23.0683 4492 aliide - ok
11:55:23.0704 4492 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
11:55:23.0727 4492 amdagp - ok
11:55:23.0745 4492 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
11:55:23.0774 4492 amdide - ok
11:55:23.0826 4492 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
11:55:24.0858 4492 AmdK7 - ok
11:55:24.0928 4492 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
11:55:25.0127 4492 AmdK8 - ok
11:55:25.0150 4492 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
11:55:25.0231 4492 Appinfo - ok
11:55:25.0339 4492 [ 4B5AE15E5C73EB4DC8DBEC2788230D41 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
11:55:25.0394 4492 Apple Mobile Device - ok
11:55:25.0435 4492 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
11:55:25.0482 4492 arc - ok
11:55:25.0555 4492 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
11:55:25.0656 4492 arcsas - ok
11:55:25.0752 4492 [ 2EEDA27C19259C2340324EF7180D086B ] ASBroker C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
11:55:25.0802 4492 ASBroker ( UnsignedFile.Multi.Generic ) - warning
11:55:25.0802 4492 ASBroker - detected UnsignedFile.Multi.Generic (1)
11:55:25.0826 4492 [ BB3C0521ECCA4BB17AC55EB640DF0FA5 ] ASChannel C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
11:55:25.0918 4492 ASChannel ( UnsignedFile.Multi.Generic ) - warning
11:55:25.0918 4492 ASChannel - detected UnsignedFile.Multi.Generic (1)
11:55:25.0927 4492 [ 5A055A4777CBBC8845DD598CB2EEBF69 ] ASLDRService C:\Program Files\ATK Hotkey\ASLDRSrv.exe
11:55:26.0043 4492 ASLDRService ( UnsignedFile.Multi.Generic ) - warning
11:55:26.0043 4492 ASLDRService - detected UnsignedFile.Multi.Generic (1)
11:55:26.0127 4492 [ 7B4D08D2017AC06689D422E06C43F0AA ] ASMMAP C:\Program Files\ATKGFNEX\ASMMAP.sys
11:55:26.0181 4492 ASMMAP - ok
11:55:26.0221 4492 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:55:26.0311 4492 AsyncMac - ok
11:55:26.0339 4492 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
11:55:26.0481 4492 atapi - ok
11:55:26.0635 4492 [ A8F308D79950DE33B478A3E5E026ADD9 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
11:55:27.0342 4492 Ati External Event Utility - ok
11:55:27.0463 4492 [ 5000E60040E45B3E72791B19E1CED1E9 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:55:27.0905 4492 atikmdag - ok
11:55:27.0917 4492 [ 7C157574A181B19B9DCF5F339E25337E ] ATKGFNEXSrv C:\Program Files\ATKGFNEX\GFNEXSrv.exe
11:55:28.0077 4492 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - warning
11:55:28.0077 4492 ATKGFNEXSrv - detected UnsignedFile.Multi.Generic (1)
11:55:28.0203 4492 [ F9C24D25D9FF29F894995A64812B4D85 ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys
11:55:28.0258 4492 atksgt - ok
11:55:28.0268 4492 [ F70D2392158CB68E775F8C4CD3D12FBB ] ATSWPDRV C:\Windows\system32\DRIVERS\ATSwpDrv.sys
11:55:28.0294 4492 ATSWPDRV - ok
11:55:28.0352 4492 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:55:28.0631 4492 AudioEndpointBuilder - ok
11:55:28.0776 4492 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
11:55:28.0901 4492 Audiosrv - ok
11:55:29.0058 4492 [ C9E6052BDF2BD7F0F6EDA14459CF6DE5 ] AVerFx2hbtv C:\Windows\system32\drivers\AVerFx2hbtv.sys
11:55:29.0462 4492 AVerFx2hbtv - ok
11:55:29.0536 4492 [ A33C07F7527FC4CBC664C3137EB7D744 ] AVerRemote C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
11:55:29.0687 4492 AVerRemote ( UnsignedFile.Multi.Generic ) - warning
11:55:29.0687 4492 AVerRemote - detected UnsignedFile.Multi.Generic (1)
11:55:29.0704 4492 [ B873ADD766CC4A3CC58EFF159861E649 ] AVerScheduleService C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
11:55:29.0899 4492 AVerScheduleService ( UnsignedFile.Multi.Generic ) - warning
11:55:29.0899 4492 AVerScheduleService - detected UnsignedFile.Multi.Generic (1)
11:55:30.0035 4492 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
11:55:30.0111 4492 Beep - ok
11:55:30.0172 4492 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
11:55:30.0267 4492 BFE - ok
11:55:30.0321 4492 [ 76154FA6A742C613B44BB636B1A7C057 ] BHDrvx86 C:\Windows\System32\Drivers\N360\0308030.006\BHDrvx86.sys
11:55:30.0350 4492 BHDrvx86 - ok
11:55:30.0407 4492 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
11:55:30.0618 4492 BITS - ok
11:55:30.0675 4492 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
11:55:30.0765 4492 blbdrive - ok
11:55:30.0851 4492 [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
11:55:30.0890 4492 Bonjour Service - ok
11:55:30.0897 4492 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:55:30.0952 4492 bowser - ok
11:55:31.0004 4492 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
11:55:31.0030 4492 BrFiltLo - ok
11:55:31.0048 4492 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
11:55:31.0112 4492 BrFiltUp - ok
11:55:31.0119 4492 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
11:55:31.0215 4492 Browser - ok
11:55:31.0263 4492 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
11:55:31.0467 4492 Brserid - ok
11:55:31.0487 4492 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
11:55:31.0581 4492 BrSerWdm - ok
11:55:31.0609 4492 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
11:55:31.0680 4492 BrUsbMdm - ok
11:55:31.0701 4492 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
11:55:31.0796 4492 BrUsbSer - ok
11:55:31.0830 4492 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
11:55:31.0891 4492 BthEnum - ok
11:55:31.0950 4492 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
11:55:32.0038 4492 BTHMODEM - ok
11:55:32.0069 4492 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
11:55:32.0211 4492 BthPan - ok
11:55:32.0295 4492 [ 611FF3F2F095C8D4A6D4CFD9DCC09793 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
11:55:32.0474 4492 BTHPORT - ok
11:55:32.0482 4492 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll
11:55:32.0556 4492 BthServ - ok
11:55:32.0589 4492 [ D330803EAB2A15CAEC7F011F1D4CB30E ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
11:55:32.0660 4492 BTHUSB - ok
11:55:32.0704 4492 [ F2F7342742180D5060285499DEE50F99 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
11:55:32.0755 4492 btwaudio - ok
11:55:32.0809 4492 [ 32F59F26A30CFC508DA11DB3EA0F8B77 ] btwavdt C:\Windows\system32\drivers\btwavdt.sys
11:55:32.0856 4492 btwavdt - ok
11:55:32.0942 4492 [ 09CB316DB9D61ED9FC9A7B07A1A301F6 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
11:55:33.0127 4492 btwdins - ok
11:55:33.0189 4492 [ ECB98391C756A7B9CFBAE89D9D1235E1 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
11:55:33.0305 4492 btwl2cap - ok
11:55:33.0345 4492 [ 03658734EF7D0F3B3F4636D3E8A38964 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
11:55:33.0399 4492 btwrchid - ok
11:55:33.0450 4492 [ 3182B846490DC4D71FABD4A8CB6B73EA ] ccHP C:\Windows\System32\Drivers\N360\0308030.006\ccHPx86.sys
11:55:33.0589 4492 ccHP - ok
11:55:33.0614 4492 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:55:33.0691 4492 cdfs - ok
11:55:33.0744 4492 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
11:55:33.0806 4492 cdrom - ok
11:55:33.0829 4492 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
11:55:33.0904 4492 CertPropSvc - ok
11:55:33.0944 4492 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
11:55:34.0073 4492 circlass - ok
11:55:34.0120 4492 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
11:55:34.0201 4492 CLFS - ok
11:55:34.0264 4492 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:55:34.0360 4492 clr_optimization_v2.0.50727_32 - ok
11:55:34.0445 4492 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:55:34.0568 4492 clr_optimization_v4.0.30319_32 - ok
11:55:34.0603 4492 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:55:34.0741 4492 CmBatt - ok
11:55:34.0778 4492 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:55:34.0821 4492 cmdide - ok
11:55:34.0868 4492 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:55:34.0911 4492 Compbatt - ok
11:55:34.0915 4492 COMSysApp - ok
11:55:34.0922 4492 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
11:55:34.0945 4492 crcdisk - ok
11:55:35.0002 4492 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
11:55:35.0081 4492 Crusoe - ok
11:55:35.0104 4492 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:55:35.0201 4492 CryptSvc - ok
11:55:35.0248 4492 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
11:55:35.0415 4492 DcomLaunch - ok
11:55:35.0422 4492 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:55:35.0526 4492 DfsC - ok
11:55:35.0683 4492 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
11:55:36.0011 4492 DFSR - ok
11:55:36.0040 4492 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
11:55:36.0076 4492 Dhcp - ok
11:55:36.0095 4492 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
11:55:36.0145 4492 disk - ok
11:55:36.0154 4492 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:55:36.0274 4492 Dnscache - ok
11:55:36.0301 4492 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
11:55:36.0408 4492 dot3svc - ok
11:55:36.0439 4492 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
11:55:36.0501 4492 DPS - ok
11:55:36.0540 4492 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:55:36.0590 4492 drmkaud - ok
11:55:36.0614 4492 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:55:36.0744 4492 DXGKrnl - ok
11:55:36.0860 4492 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
11:55:37.0204 4492 E1G60 - ok
11:55:37.0211 4492 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
11:55:37.0294 4492 EapHost - ok
11:55:37.0369 4492 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
11:55:37.0398 4492 Ecache - ok
11:55:37.0448 4492 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
11:55:37.0488 4492 eeCtrl - ok
11:55:37.0668 4492 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:55:37.0754 4492 ehRecvr - ok
11:55:37.0846 4492 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
11:55:37.0948 4492 ehSched - ok
11:55:37.0953 4492 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
11:55:37.0974 4492 ehstart - ok
11:55:38.0085 4492 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
11:55:38.0125 4492 elxstor - ok
11:55:38.0278 4492 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
11:55:38.0497 4492 EMDMgmt - ok
11:55:38.0541 4492 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
11:55:38.0672 4492 EraserUtilRebootDrv - ok
11:55:38.0690 4492 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:55:38.0755 4492 ErrDev - ok
11:55:38.0806 4492 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
11:55:38.0866 4492 EventSystem - ok
11:55:38.0904 4492 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
11:55:39.0017 4492 exfat - ok
11:55:39.0027 4492 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:55:39.0113 4492 fastfat - ok
11:55:39.0136 4492 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:55:39.0193 4492 fdc - ok
11:55:39.0200 4492 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
11:55:39.0246 4492 fdPHost - ok
11:55:39.0252 4492 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
11:55:39.0365 4492 FDResPub - ok
11:55:39.0407 4492 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:55:39.0455 4492 FileInfo - ok
11:55:39.0513 4492 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:55:39.0581 4492 Filetrace - ok
11:55:39.0604 4492 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:55:39.0662 4492 flpydisk - ok
11:55:39.0688 4492 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:55:39.0740 4492 FltMgr - ok
11:55:39.0814 4492 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
11:55:39.0955 4492 FontCache - ok
11:55:40.0018 4492 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:55:40.0048 4492 FontCache3.0.0.0 - ok
11:55:40.0057 4492 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:55:40.0139 4492 Fs_Rec - ok
11:55:40.0186 4492 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
11:55:40.0214 4492 gagp30kx - ok
11:55:40.0223 4492 [ DF6E37B27A9A1A498C6D9F29995B7A03 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
11:55:40.0243 4492 GEARAspiWDM - ok
11:55:40.0268 4492 [ 31B40F40E09513ADDC460F6A297AD474 ] ghaio C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
11:55:40.0310 4492 ghaio - ok
11:55:40.0350 4492 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
11:55:40.0618 4492 gpsvc - ok
11:55:40.0695 4492 [ 7929A161F9951D173CA9900FE7067391 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
11:55:40.0728 4492 hamachi - ok
11:55:40.0786 4492 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:55:40.0838 4492 HdAudAddService - ok
11:55:40.0860 4492 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
11:55:40.0962 4492 HDAudBus - ok
11:55:41.0020 4492 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
11:55:41.0111 4492 HidBth - ok
11:55:41.0127 4492 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
11:55:41.0212 4492 HidIr - ok
11:55:41.0219 4492 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
11:55:41.0259 4492 hidserv - ok
11:55:41.0264 4492 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
11:55:41.0304 4492 HidUsb - ok
11:55:41.0319 4492 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:55:41.0379 4492 hkmsvc - ok
11:55:41.0419 4492 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
11:55:41.0480 4492 HpCISSs - ok
11:55:41.0497 4492 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:55:41.0656 4492 HTTP - ok
11:55:41.0682 4492 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
11:55:41.0729 4492 i2omp - ok
11:55:41.0780 4492 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
11:55:41.0885 4492 i8042prt - ok
11:55:41.0946 4492 [ CB686F44BF955EA02520710A56874FA4 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
11:55:42.0087 4492 IAANTMON - ok
11:55:42.0120 4492 [ AEC6DBA23C2BE5C4457DBD14FA920146 ] iaNvStor C:\Windows\system32\DRIVERS\iaNvStor.sys
11:55:42.0177 4492 iaNvStor - ok
11:55:42.0191 4492 [ 80C633722DA72E97F3F5B3B11325696D ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
11:55:42.0214 4492 iaStor - ok
11:55:42.0277 4492 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
11:55:42.0313 4492 iaStorV - ok
11:55:42.0501 4492 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:55:42.0718 4492 idsvc - ok
11:55:42.0924 4492 [ 404FB2AAF532BC7BBACC8880BE401C74 ] IDSVix86 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20121102.001\IDSvix86.sys
11:55:43.0034 4492 IDSVix86 - ok
11:55:43.0070 4492 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
11:55:43.0120 4492 iirsp - ok
11:55:43.0161 4492 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
11:55:43.0278 4492 IKEEXT - ok
11:55:43.0390 4492 [ 2B1B7E0CC16A361FC3E10D5C2E868C72 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
11:55:43.0634 4492 IntcAzAudAddService - ok
11:55:43.0712 4492 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
11:55:43.0733 4492 intelide - ok
11:55:43.0746 4492 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:55:43.0827 4492 intelppm - ok
11:55:43.0857 4492 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:55:43.0983 4492 IPBusEnum - ok
11:55:44.0007 4492 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:55:44.0040 4492 IpFilterDriver - ok
11:55:44.0086 4492 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:55:44.0200 4492 iphlpsvc - ok
11:55:44.0206 4492 IpInIp - ok
11:55:44.0258 4492 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
11:55:44.0355 4492 IPMIDRV - ok
11:55:44.0371 4492 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
11:55:44.0418 4492 IPNAT - ok
11:55:44.0483 4492 [ 6E0FAEA90E71C5F1B9F3BC71B4CCA2FA ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
11:55:44.0616 4492 iPod Service - ok
11:55:44.0656 4492 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:55:44.0755 4492 IRENUM - ok
11:55:44.0787 4492 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:55:44.0833 4492 isapnp - ok
11:55:44.0847 4492 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
11:55:44.0888 4492 iScsiPrt - ok
11:55:44.0917 4492 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
11:55:44.0972 4492 iteatapi - ok
11:55:44.0999 4492 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
11:55:45.0054 4492 iteraid - ok
11:55:45.0133 4492 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
11:55:45.0232 4492 kbdclass - ok
11:55:45.0238 4492 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
11:55:45.0317 4492 kbdhid - ok
11:55:45.0340 4492 [ CC2A86D7BBF14977340DCA61BBCBA771 ] kbfiltr C:\Windows\system32\DRIVERS\kbfiltr.sys
11:55:45.0402 4492 kbfiltr - ok
11:55:45.0408 4492 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
11:55:45.0499 4492 KeyIso - ok
11:55:45.0524 4492 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:55:45.0735 4492 KSecDD - ok
11:55:45.0879 4492 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
11:55:46.0015 4492 KtmRm - ok
11:55:46.0038 4492 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
11:55:46.0194 4492 LanmanServer - ok
11:55:46.0267 4492 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:55:46.0421 4492 LanmanWorkstation - ok
11:55:46.0469 4492 [ ABF90FC5A127F481219B873C1B8DFC1C ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
11:55:46.0559 4492 LightScribeService ( UnsignedFile.Multi.Generic ) - warning
11:55:46.0559 4492 LightScribeService - detected UnsignedFile.Multi.Generic (1)
11:55:46.0607 4492 [ 8CCF9ED46D52AF1375875F74A91FFACF ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
11:55:46.0651 4492 lirsgt - ok
11:55:46.0658 4492 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:55:46.0692 4492 lltdio - ok
11:55:46.0726 4492 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:55:46.0794 4492 lltdsvc - ok
11:55:46.0799 4492 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
11:55:46.0874 4492 lmhosts - ok
11:55:46.0903 4492 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
11:55:46.0959 4492 LSI_FC - ok
11:55:47.0112 4492 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
11:55:47.0189 4492 LSI_SAS - ok
11:55:47.0332 4492 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
11:55:47.0411 4492 LSI_SCSI - ok
11:55:47.0426 4492 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
11:55:47.0530 4492 luafv - ok
11:55:47.0573 4492 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:55:47.0618 4492 Mcx2Svc - ok
11:55:47.0658 4492 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
11:55:49.0044 4492 megasas - ok
11:55:49.0182 4492 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
11:55:49.0499 4492 MegaSR - ok
11:55:49.0509 4492 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
11:55:49.0545 4492 MMCSS - ok
11:55:49.0586 4492 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
11:55:49.0650 4492 Modem - ok
11:55:49.0695 4492 [ CBB59C41F19EFEA1A000793E08070A62 ] MODEMCSA C:\Windows\system32\drivers\MODEMCSA.sys
11:55:49.0768 4492 MODEMCSA - ok
11:55:49.0786 4492 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:55:49.0842 4492 monitor - ok
11:55:49.0869 4492 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
11:55:49.0910 4492 mouclass - ok
11:55:49.0933 4492 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:55:50.0018 4492 mouhid - ok
11:55:50.0061 4492 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
11:55:50.0104 4492 MountMgr - ok
11:55:50.0190 4492 [ 96AA8BA23142CC8E2B30F3CAE0C80254 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
11:55:50.0249 4492 MozillaMaintenance - ok
11:55:50.0377 4492 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
11:55:50.0779 4492 mpio - ok
11:55:50.0834 4492 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:55:50.0905 4492 mpsdrv - ok
11:55:50.0968 4492 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
11:55:51.0006 4492 Mraid35x - ok
11:55:51.0015 4492 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:55:51.0082 4492 MRxDAV - ok
11:55:51.0102 4492 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:55:51.0194 4492 mrxsmb - ok
11:55:51.0241 4492 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:55:51.0290 4492 mrxsmb10 - ok
11:55:51.0313 4492 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:55:51.0359 4492 mrxsmb20 - ok
11:55:51.0404 4492 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
11:55:51.0481 4492 msahci - ok
11:55:51.0511 4492 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:55:51.0557 4492 msdsm - ok
11:55:51.0604 4492 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
11:55:51.0670 4492 MSDTC - ok
11:55:51.0692 4492 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:55:52.0233 4492 Msfs - ok
11:55:52.0270 4492 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:55:52.0291 4492 msisadrv - ok
11:55:52.0413 4492 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:55:52.0544 4492 MSiSCSI - ok
11:55:52.0549 4492 msiserver - ok
11:55:52.0643 4492 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:55:52.0732 4492 MSKSSRV - ok
11:55:52.0876 4492 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:55:53.0009 4492 MSPCLOCK - ok
11:55:53.0062 4492 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:55:53.0136 4492 MSPQM - ok
11:55:53.0166 4492 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:55:53.0241 4492 MsRPC - ok
11:55:53.0253 4492 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
11:55:53.0296 4492 mssmbios - ok
11:55:53.0319 4492 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:55:53.0390 4492 MSTEE - ok
11:55:53.0397 4492 [ 97AFFA9D95FFE20EEE6229BC6BE166CF ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
11:55:53.0456 4492 MTsensor - ok
11:55:53.0475 4492 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
11:55:53.0530 4492 Mup - ok
11:55:53.0546 4492 [ 64C89DB40949FD0E7C8FF303676A91F1 ] N360 C:\Program Files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
11:55:53.0604 4492 N360 - ok
11:55:53.0656 4492 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
11:55:53.0768 4492 napagent - ok
11:55:53.0778 4492 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:55:53.0865 4492 NativeWifiP - ok
11:55:53.0962 4492 [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20121103.005\NAVENG.SYS
11:55:53.0984 4492 NAVENG - ok
11:55:54.0238 4492 [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20121103.005\NAVEX15.SYS
11:55:54.0456 4492 NAVEX15 - ok
11:55:54.0488 4492 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:55:54.0567 4492 NDIS - ok
11:55:54.0575 4492 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:55:54.0643 4492 NdisTapi - ok
11:55:54.0648 4492 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:55:54.0714 4492 Ndisuio - ok
11:55:54.0746 4492 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:55:54.0981 4492 NdisWan - ok
11:55:54.0987 4492 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:55:55.0039 4492 NDProxy - ok
11:55:55.0049 4492 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:55:55.0099 4492 NetBIOS - ok
11:55:55.0109 4492 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
11:55:55.0298 4492 netbt - ok
11:55:55.0303 4492 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
11:55:55.0356 4492 Netlogon - ok
11:55:55.0384 4492 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
11:55:55.0465 4492 Netman - ok
11:55:55.0477 4492 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
11:55:55.0535 4492 netprofm - ok
11:55:55.0601 4492 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:55:55.0645 4492 NetTcpPortSharing - ok
11:55:55.0783 4492 [ F0C42E0CDCE558D658FA53A222B4CCB1 ] NETw5v32 C:\Windows\system32\DRIVERS\NETw5v32.sys
11:55:56.0172 4492 NETw5v32 - ok
11:55:56.0195 4492 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
11:55:56.0272 4492 nfrd960 - ok
11:55:56.0282 4492 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
11:55:56.0394 4492 NlaSvc - ok
11:55:56.0400 4492 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:55:56.0428 4492 Npfs - ok
11:55:56.0434 4492 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
11:55:56.0515 4492 nsi - ok
11:55:56.0520 4492 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:55:56.0565 4492 nsiproxy - ok
11:55:56.0602 4492 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:55:56.0769 4492 Ntfs - ok
11:55:56.0796 4492 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
11:55:56.0874 4492 ntrigdigi - ok
11:55:56.0879 4492 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
11:55:56.0924 4492 Null - ok
11:55:56.0996 4492 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:55:57.0156 4492 nvraid - ok
11:55:57.0263 4492 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:55:57.0748 4492 nvstor - ok
11:55:57.0787 4492 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:55:57.0885 4492 nv_agp - ok
11:55:57.0890 4492 NwlnkFlt - ok
11:55:57.0896 4492 NwlnkFwd - ok
11:55:58.0010 4492 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:55:58.0152 4492 odserv - ok
11:55:58.0162 4492 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
11:55:58.0214 4492 ohci1394 - ok
11:55:58.0270 4492 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:55:58.0361 4492 ose - ok
11:55:58.0539 4492 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
11:55:58.0683 4492 p2pimsvc - ok
11:55:58.0718 4492 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
11:55:58.0774 4492 p2psvc - ok
11:55:58.0873 4492 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
11:55:58.0939 4492 Parport - ok
11:55:58.0966 4492 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:55:59.0076 4492 partmgr - ok
11:55:59.0115 4492 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
11:55:59.0174 4492 Parvdm - ok
11:55:59.0180 4492 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
11:55:59.0236 4492 PcaSvc - ok
11:55:59.0257 4492 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
11:55:59.0300 4492 pci - ok
11:55:59.0322 4492 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
11:55:59.0343 4492 pciide - ok
11:55:59.0387 4492 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
11:55:59.0437 4492 pcmcia - ok
11:55:59.0469 4492 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:55:59.0654 4492 PEAUTH - ok
11:55:59.0811 4492 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
11:56:00.0056 4492 pla - ok
11:56:00.0073 4492 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:56:00.0226 4492 PlugPlay - ok
11:56:00.0417 4492 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
11:56:00.0530 4492 PNRPAutoReg - ok
11:56:00.0606 4492 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
11:56:00.0683 4492 PNRPsvc - ok
11:56:00.0734 4492 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:56:01.0110 4492 PolicyAgent - ok
11:56:01.0127 4492 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:56:01.0229 4492 PptpMiniport - ok
11:56:01.0304 4492 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
11:56:01.0392 4492 Processor - ok
11:56:01.0401 4492 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
11:56:01.0456 4492 ProfSvc - ok
11:56:01.0462 4492 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
11:56:01.0505 4492 ProtectedStorage - ok
11:56:01.0512 4492 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
11:56:01.0565 4492 PSched - ok
11:56:01.0629 4492 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
11:56:01.0727 4492 ql2300 - ok
11:56:01.0768 4492 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
11:56:01.0844 4492 ql40xx - ok
11:56:01.0866 4492 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
11:56:01.0904 4492 QWAVE - ok
11:56:01.0924 4492 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:56:01.0969 4492 QWAVEdrv - ok
11:56:01.0974 4492 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:56:02.0027 4492 RasAcd - ok
11:56:02.0084 4492 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
11:56:02.0197 4492 RasAuto - ok
11:56:02.0205 4492 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:56:02.0254 4492 Rasl2tp - ok
11:56:02.0282 4492 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
11:56:02.0390 4492 RasMan - ok
11:56:02.0397 4492 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:56:02.0469 4492 RasPppoe - ok
11:56:02.0477 4492 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:56:02.0510 4492 RasSstp - ok
11:56:02.0524 4492 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:56:02.0636 4492 rdbss - ok
11:56:02.0642 4492 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:56:02.0702 4492 RDPCDD - ok
11:56:02.0743 4492 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
11:56:02.0801 4492 rdpdr - ok
11:56:02.0808 4492 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:56:02.0918 4492 RDPENCDD - ok
11:56:02.0983 4492 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:56:03.0114 4492 RDPWD - ok
11:56:03.0158 4492 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
11:56:03.0208 4492 RemoteAccess - ok
11:56:03.0226 4492 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:56:03.0313 4492 RemoteRegistry - ok
11:56:03.0380 4492 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
11:56:03.0467 4492 RFCOMM - ok
11:56:03.0506 4492 [ C35CA13D3627EBD9DD12A23CE781BC3D ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys
11:56:03.0571 4492 rimmptsk ( UnsignedFile.Multi.Generic ) - warning
11:56:03.0571 4492 rimmptsk - detected UnsignedFile.Multi.Generic (1)
11:56:03.0577 4492 [ C398BCA91216755B098679A8DA8A2300 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
11:56:03.0629 4492 rimsptsk - ok
11:56:03.0635 4492 [ 2A2554CB24506E0A0508FC395C4A1B42 ] rismxdp C:\Windows\system32\DRIVERS\rixdptsk.sys
11:56:03.0686 4492 rismxdp - ok
11:56:03.0691 4492 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
11:56:03.0772 4492 RpcLocator - ok
11:56:03.0809 4492 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
11:56:03.0861 4492 RpcSs - ok
11:56:03.0868 4492 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:56:03.0971 4492 rspndr - ok
11:56:03.0980 4492 [ 2FC33077F85D7DC0D03678C06D43898C ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
11:56:04.0226 4492 RTL8169 - ok
11:56:04.0231 4492 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
11:56:04.0265 4492 SamSs - ok
11:56:04.0283 4492 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:56:04.0308 4492 sbp2port - ok
11:56:04.0316 4492 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:56:04.0448 4492 SCardSvr - ok
11:56:04.0515 4492 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
11:56:04.0753 4492 Schedule - ok
11:56:04.0789 4492 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
11:56:04.0816 4492 SCPolicySvc - ok
11:56:04.0832 4492 [ 8F36B54688C31EED4580129040C6A3D3 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
11:56:04.0881 4492 sdbus - ok
11:56:04.0919 4492 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:56:05.0007 4492 SDRSVC - ok
11:56:05.0013 4492 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:56:05.0060 4492 secdrv - ok
11:56:05.0067 4492 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
11:56:05.0143 4492 seclogon - ok
11:56:05.0149 4492 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
11:56:05.0202 4492 SENS - ok
11:56:05.0344 4492 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
11:56:05.0429 4492 Serenum - ok
11:56:05.0489 4492 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
11:56:05.0597 4492 Serial - ok
11:56:05.0625 4492 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
11:56:05.0766 4492 sermouse - ok
11:56:05.0800 4492 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
11:56:05.0860 4492 SessionEnv - ok
11:56:05.0885 4492 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
11:56:05.0911 4492 sffdisk - ok
11:56:05.0936 4492 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:56:05.0976 4492 sffp_mmc - ok
11:56:06.0010 4492 [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
11:56:06.0055 4492 sffp_sd - ok
11:56:06.0085 4492 [ C33BFBD6E9E41FCD9FFEF9729E9FAED6 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:56:06.0144 4492 sfloppy - ok
11:56:06.0176 4492 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:56:06.0233 4492 ShellHWDetection - ok
11:56:06.0252 4492 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
11:56:06.0276 4492 sisagp - ok
11:56:06.0348 4492 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
11:56:06.0382 4492 SiSRaid2 - ok
11:56:06.0422 4492 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
11:56:06.0470 4492 SiSRaid4 - ok
11:56:06.0593 4492 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
11:56:07.0022 4492 slsvc - ok
11:56:07.0121 4492 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
11:56:07.0315 4492 SLUINotify - ok
11:56:07.0390 4492 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:56:07.0633 4492 Smb - ok
11:56:07.0704 4492 [ 09CBB7A04C5D6E9FE876BA5D97EB873D ] smserial C:\Windows\system32\DRIVERS\smserial.sys
11:56:07.0876 4492 smserial - ok
11:56:07.0886 4492 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:56:07.0916 4492 SNMPTRAP - ok
11:56:07.0976 4492 [ 0302BC619D4A723317E7F8EB0C362BD3 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
11:56:08.0142 4492 SNP2UVC - ok
11:56:08.0281 4492 [ 1A623F2B69E1F182F995F963C55DB935 ] Sony Ericsson PCCompanion C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
11:56:08.0336 4492 Sony Ericsson PCCompanion - ok
11:56:08.0364 4492 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
11:56:08.0404 4492 spldr - ok
11:56:08.0411 4492 [ 739DB668DBD812285ECC553E64A5E212 ] spmgr C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
11:56:08.0507 4492 spmgr - ok
11:56:08.0516 4492 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
11:56:08.0607 4492 Spooler - ok
11:56:08.0659 4492 [ 71E276F6D189413266EA22171806597B ] sptd C:\Windows\system32\Drivers\sptd.sys
11:56:08.0660 4492 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 71E276F6D189413266EA22171806597B
11:56:08.0661 4492 sptd ( LockedFile.Multi.Generic ) - warning
11:56:08.0661 4492 sptd - detected LockedFile.Multi.Generic (1)
11:56:08.0729 4492 [ E81F6CAEAB9AD5732E94C07C97866AA2 ] SRTSP C:\Windows\System32\Drivers\N360\0308030.006\SRTSP.SYS
11:56:08.0760 4492 SRTSP - ok
11:56:08.0766 4492 [ E28DE499D942B08058BFFAC69D4122B6 ] SRTSPX C:\Windows\system32\drivers\N360\0308030.006\SRTSPX.SYS
11:56:08.0786 4492 SRTSPX - ok
11:56:08.0801 4492 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:56:08.0883 4492 srv - ok
11:56:08.0893 4492 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:56:08.0960 4492 srv2 - ok
11:56:08.0968 4492 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:56:09.0017 4492 srvnet - ok
11:56:09.0026 4492 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:56:09.0278 4492 SSDPSRV - ok
11:56:09.0319 4492 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:56:09.0361 4492 SstpSvc - ok
11:56:09.0410 4492 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
11:56:09.0586 4492 stisvc - ok
11:56:09.0593 4492 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
11:56:09.0624 4492 swenum - ok
11:56:09.0729 4492 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
11:56:09.0844 4492 swprv - ok
11:56:09.0863 4492 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
11:56:09.0893 4492 Symc8xx - ok
11:56:09.0941 4492 [ D0885F6E24259A6C65E68D6AD749910A ] SymEFA C:\Windows\system32\drivers\N360\0308030.006\SYMEFA.SYS
11:56:09.0969 4492 SymEFA - ok
11:56:09.0979 4492 [ A54FF04BD6E75DC4D8CB6F3E352635E0 ] SymEvent C:\Windows\system32\Drivers\SYMEVENT.SYS
11:56:10.0003 4492 SymEvent - ok
11:56:10.0013 4492 [ A8C45C36309EE066F9191E511F88ED76 ] SYMFW C:\Windows\System32\Drivers\N360\0308030.006\SYMFW.SYS
11:56:10.0052 4492 SYMFW - ok
11:56:10.0060 4492 [ 34F1C9D5DCC19DF1E824D6B73767B8AF ] SymIM C:\Windows\system32\DRIVERS\SymIMv.sys
11:56:10.0168 4492 SymIM - ok
11:56:10.0174 4492 [ D8B16289F39B63456F48EA95243A788A ] SYMNDISV C:\Windows\System32\Drivers\N360\0308030.006\SYMNDISV.SYS
11:56:10.0195 4492 SYMNDISV - ok
11:56:10.0208 4492 [ 26BC80EC79D7BA478249C266CBDF17B4 ] SYMTDI C:\Windows\System32\Drivers\N360\0308030.006\SYMTDI.SYS
11:56:10.0237 4492 SYMTDI - ok
11:56:10.0254 4492 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
11:56:10.0320 4492 Sym_hi - ok
11:56:10.0342 4492 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
11:56:10.0364 4492 Sym_u3 - ok
11:56:10.0410 4492 [ 55F6E55CC2430CA8713387106FA79817 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
11:56:10.0438 4492 SynTP - ok
11:56:10.0480 4492 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
11:56:10.0690 4492 SysMain - ok
11:56:10.0703 4492 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:56:10.0788 4492 TabletInputService - ok
11:56:10.0817 4492 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
11:56:10.0966 4492 TapiSrv - ok
11:56:11.0010 4492 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
11:56:11.0047 4492 TBS - ok
11:56:11.0096 4492 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:56:11.0282 4492 Tcpip - ok
11:56:11.0329 4492 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
11:56:11.0476 4492 Tcpip6 - ok
11:56:11.0481 4492 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:56:11.0524 4492 tcpipreg - ok
11:56:11.0545 4492 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:56:11.0626 4492 TDPIPE - ok
11:56:11.0643 4492 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:56:11.0686 4492 TDTCP - ok
11:56:11.0693 4492 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:56:11.0728 4492 tdx - ok
11:56:11.0734 4492 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
11:56:11.0758 4492 TermDD - ok
11:56:11.0803 4492 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
11:56:11.0899 4492 TermService - ok
11:56:11.0928 4492 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
11:56:11.0983 4492 Themes - ok
11:56:11.0989 4492 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
11:56:12.0039 4492 THREADORDER - ok
11:56:12.0046 4492 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
11:56:12.0104 4492 TrkWks - ok
11:56:12.0110 4492 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:56:12.0244 4492 TrustedInstaller - ok
11:56:12.0304 4492 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:56:12.0382 4492 tssecsrv - ok
11:56:12.0388 4492 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
11:56:12.0437 4492 tunmp - ok
11:56:12.0442 4492 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:56:12.0471 4492 tunnel - ok
11:56:12.0511 4492 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
11:56:12.0535 4492 uagp35 - ok
11:56:12.0647 4492 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:56:12.0741 4492 udfs - ok
11:56:12.0778 4492 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:56:12.0900 4492 UI0Detect - ok
11:56:12.0943 4492 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:56:12.0968 4492 uliagpkx - ok
11:56:12.0997 4492 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
11:56:13.0057 4492 uliahci - ok
11:56:13.0073 4492 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
11:56:13.0167 4492 UlSata - ok
11:56:13.0194 4492 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
11:56:13.0217 4492 ulsata2 - ok
11:56:13.0224 4492 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
11:56:13.0264 4492 umbus - ok
11:56:13.0290 4492 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
11:56:13.0367 4492 upnphost - ok
11:56:13.0376 4492 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:56:13.0420 4492 usbccgp - ok
11:56:13.0446 4492 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:56:13.0509 4492 usbcir - ok
11:56:13.0516 4492 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
11:56:13.0651 4492 usbehci - ok
11:56:13.0667 4492 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:56:13.0742 4492 usbhub - ok
11:56:13.0775 4492 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
11:56:13.0867 4492 usbohci - ok
11:56:13.0894 4492 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:56:13.0940 4492 usbprint - ok
11:56:13.0966 4492 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:56:14.0039 4492 USBSTOR - ok
11:56:14.0044 4492 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
11:56:14.0192 4492 usbuhci - ok
11:56:14.0228 4492 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
11:56:14.0263 4492 usbvideo - ok
11:56:14.0275 4492 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
11:56:14.0347 4492 UxSms - ok
11:56:14.0376 4492 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
11:56:14.0548 4492 vds - ok
11:56:14.0581 4492 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:56:14.0637 4492 vga - ok
11:56:14.0642 4492 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
11:56:14.0714 4492 VgaSave - ok
11:56:14.0742 4492 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
11:56:14.0813 4492 viaagp - ok
11:56:14.0917 4492 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
11:56:14.0951 4492 ViaC7 - ok
11:56:14.0970 4492 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
11:56:14.0992 4492 viaide - ok
11:56:15.0021 4492 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:56:15.0090 4492 volmgr - ok
11:56:15.0153 4492 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:56:15.0243 4492 volmgrx - ok
11:56:15.0276 4492 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:56:15.0310 4492 volsnap - ok
11:56:15.0387 4492 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
11:56:15.0430 4492 vsmraid - ok
11:56:15.0477 4492 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
11:56:15.0891 4492 VSS - ok
11:56:15.0915 4492 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
11:56:16.0058 4492 W32Time - ok
11:56:16.0088 4492 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
11:56:16.0169 4492 WacomPen - ok
11:56:16.0178 4492 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
11:56:16.0261 4492 Wanarp - ok
11:56:16.0271 4492 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:56:16.0311 4492 Wanarpv6 - ok
11:56:16.0349 4492 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:56:16.0517 4492 wcncsvc - ok
11:56:16.0574 4492 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:56:16.0657 4492 WcsPlugInService - ok
11:56:16.0677 4492 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
11:56:16.0699 4492 Wd - ok
11:56:16.0764 4492 [ 96C4C98FE4866C16FC64E4578A0AA975 ] WDBackup C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
11:56:16.0912 4492 WDBackup - ok
11:56:16.0960 4492 [ D6EFAF429FD30C5DF613D220E344CCE7 ] WDC_SAM C:\Windows\system32\DRIVERS\wdcsam.sys
11:56:17.0020 4492 WDC_SAM - ok
11:56:17.0047 4492 [ 80F8944EA183004D6EDCBBDCEC166404 ] WDDriveService C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
11:56:17.0085 4492 WDDriveService - ok
11:56:17.0179 4492 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:56:17.0513 4492 Wdf01000 - ok
11:56:17.0523 4492 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:56:17.0748 4492 WdiServiceHost - ok
11:56:17.0755 4492 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:56:17.0832 4492 WdiSystemHost - ok
11:56:18.0023 4492 [ FD2D1C60CDBDFAB63EF182539D8FFC2D ] WDRulesService C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
11:56:18.0208 4492 WDRulesService - ok
11:56:18.0300 4492 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
11:56:18.0429 4492 WebClient - ok
11:56:18.0446 4492 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:56:18.0494 4492 Wecsvc - ok
11:56:18.0512 4492 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:56:18.0561 4492 wercplsupport - ok
11:56:18.0572 4492 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
11:56:18.0687 4492 WerSvc - ok
11:56:18.0734 4492 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:56:18.0771 4492 WinDefend - ok
11:56:18.0779 4492 WinHttpAutoProxySvc - ok
11:56:18.0809 4492 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:56:18.0844 4492 Winmgmt - ok
11:56:18.0880 4492 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
11:56:19.0103 4492 WinRM - ok
11:56:19.0129 4492 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:56:19.0225 4492 Wlansvc - ok
11:56:19.0303 4492 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
11:56:19.0366 4492 WmiAcpi - ok
11:56:19.0394 4492 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:56:19.0552 4492 wmiApSrv - ok
11:56:19.0611 4492 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:56:19.0859 4492 WMPNetworkSvc - ok
11:56:19.0887 4492 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:56:19.0965 4492 WPCSvc - ok
11:56:19.0977 4492 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:56:20.0091 4492 WPDBusEnum - ok
11:56:20.0149 4492 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
11:56:20.0267 4492 WpdUsb - ok
11:56:20.0327 4492 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
11:56:20.0387 4492 WPFFontCache_v0400 - ok
11:56:20.0426 4492 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:56:20.0508 4492 ws2ifsl - ok
11:56:20.0517 4492 WSearch - ok
11:56:20.0594 4492 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
11:56:20.0896 4492 wuauserv - ok
11:56:20.0962 4492 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:56:21.0021 4492 WUDFRd - ok
11:56:21.0027 4492 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:56:21.0092 4492 wudfsvc - ok
11:56:21.0133 4492 [ 7D1F3B131D503EF43EE594B5A2B9B427 ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
11:56:21.0226 4492 yukonwlh - ok
11:56:21.0238 4492 ================ Scan global ===============================
11:56:21.0244 4492 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
11:56:21.0306 4492 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
11:56:21.0494 4492 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
11:56:21.0530 4492 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
11:56:21.0588 4492 [Global] - ok
11:56:21.0588 4492 ================ Scan MBR ==================================
11:56:21.0606 4492 [ 64B1E91C5C6C2157642651010728F90F ] \Device\Harddisk0\DR0
11:56:21.0822 4492 \Device\Harddisk0\DR0 - ok
11:56:21.0828 4492 [ E5FA06ACA0D60BA9C870D0EF3D9898C9 ] \Device\Harddisk2\DR2
11:56:28.0769 4492 \Device\Harddisk2\DR2 - ok
11:56:28.0771 4492 ================ Scan VBR ==================================
11:56:28.0777 4492 [ 6FFC5C9A81849FDADD2D68E6CAC93B81 ] \Device\Harddisk0\DR0\Partition1
11:56:28.0781 4492 \Device\Harddisk0\DR0\Partition1 - ok
11:56:28.0791 4492 [ B78881A9E12F7EC0CE2827DE81EA5B32 ] \Device\Harddisk0\DR0\Partition2
11:56:28.0794 4492 \Device\Harddisk0\DR0\Partition2 - ok
11:56:28.0803 4492 [ 9A2A6AFD2C4A45BB841BBCA1836B4978 ] \Device\Harddisk2\DR2\Partition1
11:56:28.0805 4492 \Device\Harddisk2\DR2\Partition1 - ok
11:56:28.0809 4492 ============================================================
11:56:28.0809 4492 Scan finished
11:56:28.0809 4492 ============================================================
11:56:28.0831 5768 Detected object count: 9
11:56:28.0831 5768 Actual detected object count: 9
11:57:05.0428 5768 ASBroker ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0428 5768 ASBroker ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0431 5768 ASChannel ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0431 5768 ASChannel ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0433 5768 ASLDRService ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0433 5768 ASLDRService ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0435 5768 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0435 5768 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0437 5768 AVerRemote ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0438 5768 AVerRemote ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0440 5768 AVerScheduleService ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0440 5768 AVerScheduleService ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0442 5768 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0442 5768 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0444 5768 rimmptsk ( UnsignedFile.Multi.Generic ) - skipped by user
11:57:05.0444 5768 rimmptsk ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:57:05.0446 5768 sptd ( LockedFile.Multi.Generic ) - skipped by user
11:57:05.0446 5768 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#11 Příspěvek od JanX »

Ok, pouziju ten Combofix a reportnu, ale ted se musim presunout do Brna, ozvat se tak budu moct asi az tak v 18:00...

oprava: nejde mi otevřít odkaz, snad se pozdě večer ještě přesunu do studovny s nějakými dalšími počítači, kde to snad půjde..

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#12 Příspěvek od JanX »

Tak raději podrobně:
Combofix stáhnut na jiném PC, z flashky prenesen na plochu, vypnutí antiviru - Auto-protect funkce u Nortona, poprvé nenastartoval, přejmenoval jsem to na cf.exe, spuštění se daří (placebo efekt? :D ), Combofix mě upozorňuje, že si mám opsat cestu k c:\windows\system32\APSHook.dll, že to bude deaktivovat...scan běžel a níže by měl být výsledek...

Po restartování nejde řádně pracovat s notebookem, respektive...minimálně IE (a chrome) nefungují: hláška (...iexplorer.exe, ...chrome.exe) "Pokus použít neplatnou operaci na klíč registru, který je označen pro odstranění"
__________________________

ComboFix 12-11-04.01 - Jenda 04.11.2012 22:17:15.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.1525 [GMT 1:00]
Spuštěný z: c:\users\Jenda\Desktop\CF.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
Tyto soubory byly během aplikování deaktivovány:
c:\windows\system32\APSHook.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jenda\AppData\Local\bvvvymdp.log
c:\users\Jenda\AppData\Local\ciowdgjg.log
c:\users\Jenda\AppData\Local\ebitpfnj.log
c:\users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe
c:\users\Jenda\AppData\Local\gsyhynlv.log
c:\users\Jenda\AppData\Local\ipxjuonh.log
c:\users\Jenda\AppData\Local\nhaoxnvf.log
c:\users\Jenda\AppData\Local\qgujfnfp.log
c:\users\Jenda\AppData\Local\rgkyduij.log
c:\users\Jenda\AppData\Local\uylqljrk.log
c:\users\Jenda\ms.exe
c:\windows\IsUn0405.exe
c:\windows\system32\pthreadVC.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-04 do 2012-11-04 )))))))))))))))))))))))))))))))
.
.
2012-11-04 20:27 . 2009-07-28 22:26 6144 ----a-w- c:\windows\system32\kbdru668.dll
2012-11-04 20:27 . 2007-03-14 14:06 6144 ----a-w- c:\windows\system32\kbdur666.dll
2012-11-04 20:27 . 2007-03-14 14:06 6144 ----a-w- c:\windows\system32\kbdru667.dll
2012-11-04 20:27 . 2007-03-14 14:05 6144 ----a-w- c:\windows\system32\kbdru666.dll
2012-11-04 20:27 . 2012-11-04 20:26 695675 ----a-w- c:\windows\unins000.exe
2012-11-03 12:18 . 2012-11-03 12:18 512 ----a-w- C:\PhysicalMBR.bin
2012-11-03 11:34 . 2012-11-03 11:34 -------- d-----w- C:\_OTL
2012-11-03 06:04 . 2012-11-03 06:04 -------- d-----w- c:\program files\trend micro
2012-11-03 06:04 . 2012-11-03 06:04 -------- d-----w- C:\rsit
2012-11-02 20:27 . 2012-11-02 20:27 100864 ----a-w- C:\kwtoypob.sys
2012-11-01 15:38 . 2012-11-04 21:51 108672 ---ha-w- c:\windows\system32\iXUxlYo
2012-10-29 14:43 . 2012-11-04 21:52 384 ---ha-w- c:\windows\system32\NgELZcjt
2012-10-29 14:43 . 2012-11-04 21:51 182736 ---ha-w- c:\windows\system32\9A3voGafB
2012-10-29 14:20 . 2012-11-04 21:52 336 ---ha-w- c:\windows\system32\988S5InLt
2012-10-29 13:09 . 2012-10-29 13:09 -------- d-----w- C:\found.006
2012-10-29 12:59 . 2012-11-04 21:52 -------- d-----w- c:\users\Jenda\AppData\Local\ggmngrwi
2012-10-28 00:39 . 2012-10-28 00:39 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8654349E-D793-40E3-8175-5CEB828FFA57}\offreg.dll
2012-10-27 16:24 . 2012-10-17 00:32 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8654349E-D793-40E3-8175-5CEB828FFA57}\mpengine.dll
2012-10-14 20:34 . 2012-10-14 20:34 5164496 ----a-r- c:\users\Jenda\AppData\Roaming\Microsoft\Installer\{865961DF-C3B4-47DC-8CFD-4AB5131494AE}\icon.exe
2012-10-10 13:02 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-10 13:02 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-10 13:02 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 13:00 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-10 12:59 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-10 12:58 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-10 12:58 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-10-08 19:06 . 2012-10-08 19:06 -------- d-----w- c:\users\Jenda\AppData\Roaming\BSplayer Pro
2012-10-08 19:06 . 2012-10-08 19:06 -------- d-----w- c:\program files\Webteh
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-04 21:51 . 2008-10-03 13:19 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-09-12 17:53 . 2012-09-12 17:53 5163984 ----a-r- c:\users\Jenda\AppData\Roaming\Microsoft\Installer\{094D3055-1F1D-4221-B288-4DD0BE529794}\icon.exe
2012-08-24 06:59 . 2012-09-22 23:01 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51 . 2012-09-22 23:01 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51 . 2012-09-22 23:01 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 23:01 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 23:01 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43 . 2012-09-22 23:01 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-12 17:46 . 2012-05-12 17:46 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"OmeDqrgy"="c:\users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe" [2012-10-29 101004]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-12 98304]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"IaNvSrv"="c:\program files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2008-05-03 33304]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 163840]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-01 6025216]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2008-01-24 1208320]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-07 1029416]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-22 120832]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2008-02-01 61440]
"PowerForPhone"="c:\program files\P4P\P4P.exe" [2007-08-03 778240]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2008-08-31 3054136]
"ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2008-08-31 47672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"WD Quick View"="c:\program files\Western Digital\WD Quick View\WDDMStatus.exe" [2012-09-19 5236664]
.
c:\users\Jenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
omedqrgy.exe [2012-10-29 101004]
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-12 216576]
AVer HID Receiver.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2010-7-21 159744]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-10 752168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,,c:\users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MICORSOFT_WINDOWS_SERVICE
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
Cognizance REG_MULTI_SZ ASBroker ASChannel
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000Core.job
- c:\users\Jenda\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-06 12:10]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000UA.job
- c:\users\Jenda\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-06 12:10]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 147.251.4.33 147.251.6.10
FF - ProfilePath - c:\users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=
FF - ExtSQL: !HIDDEN! 2009-09-22 22:32; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Adobe Photoshop 7.0 CE - c:\windows\ISUN0405.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-04 22:52
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002
.
CreateFile("\\.\PHYSICALDRIVE0"): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.3.6\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4300)
c:\windows\system32\APSHook.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItClient.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe
c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\Western Digital\WD Drive Manager\WDDriveService.exe
c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Western Digital\WD SmartWare\WDBackupEngine.exe
c:\windows\system32\vssvc.exe
c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\program files\ATK Hotkey\MsgTranAgt.exe
c:\windows\system32\conime.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\windows\System32\ACEngSvr.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wermgr.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\system32\WerFault.exe
c:\windows\system32\WerFault.exe
c:\program files\Western Digital\WD SmartWare\WDLockedFiles.exe
.
**************************************************************************
.
Celkový čas: 2012-11-04 22:56:01 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-04 21:55
.
Před spuštěním: Volných bajtů: 58 867 548 160
Po spuštění: Volných bajtů: 57 886 797 824
.
- - End Of File - - 92BE15F2932AA154A709B32DEBC5BDC6

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#13 Příspěvek od JanX »

Aha tak oprava. Nejde mi spustit nic, u všeho je ta chybová hláška.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Hacktool.Rootkit? - log

#14 Příspěvek od vyosek »

Zdravim,

jen jednorazove zaskocim :)

:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

JanX
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 lis 2012 09:27

Re: Hacktool.Rootkit? - log

#15 Příspěvek od JanX »

Ok, taky děkuju za informaci, (počítač jsem ale ani nepotřeboval)...
pro jistotu zase postup: antivirus jsem nevypinal, vytvořil jsem ten CFScript, přetáhl ho, spustilo se to, zeptal se na aktualizaci jestli chci, tady jsem si nebyl jist, ale potvrdil jsem, pak to běželo, restart a to níže uvedené to vyplivlo...
nevím jestli to je důležité, ale po restartu Norton reportoval Bloodhound.MalPE a když jsem otevřel historii zabezpečení tak se tam po restartu (nebo během) objevily zase nějaké úpravy v nastavení windows (nevím jestli to je žádoucí...)
___________________________________
ComboFix 12-11-05.03 - Jenda 05.11.2012 23:53:51.2.2 - x86
Spuštěný z: c:\users\Jenda\Desktop\CF.exe
Použité ovládací přepínače :: c:\users\Jenda\Desktop\CFScript.txt
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\kbdru666.dll"
"c:\windows\system32\kbdru667.dll"
"c:\windows\system32\kbdru668.dll"
"c:\windows\system32\kbdur666.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jenda\AppData\Local\bvvvymdp.log
c:\users\Jenda\AppData\Local\ciowdgjg.log
c:\users\Jenda\AppData\Local\ebitpfnj.log
c:\users\Jenda\AppData\Local\ggmngrwi
c:\users\Jenda\AppData\Local\ggmngrwi\omedqrgy.exe
c:\users\Jenda\AppData\Local\gsyhynlv.log
c:\users\Jenda\AppData\Local\ipxjuonh.log
c:\users\Jenda\AppData\Local\qgujfnfp.log
c:\users\Jenda\AppData\Local\rgkyduij.log
c:\users\Jenda\AppData\Local\uylqljrk.log
c:\windows\msvcr71.dll
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\ijl11.dll
c:\windows\system32\vbpng1.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MICORSOFT_WINDOWS_SERVICE
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-05 do 2012-11-05 )))))))))))))))))))))))))))))))
.
.
2012-11-05 23:12 . 2012-11-05 23:19 -------- d-----w- c:\users\Jenda\AppData\Local\temp
2012-11-05 23:12 . 2012-11-05 23:12 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-11-05 23:12 . 2012-11-05 23:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-04 20:27 . 2009-07-28 22:26 6144 ----a-w- c:\windows\system32\kbdru668.dll
2012-11-04 20:27 . 2007-03-14 14:06 6144 ----a-w- c:\windows\system32\kbdur666.dll
2012-11-04 20:27 . 2007-03-14 14:06 6144 ----a-w- c:\windows\system32\kbdru667.dll
2012-11-04 20:27 . 2007-03-14 14:05 6144 ----a-w- c:\windows\system32\kbdru666.dll
2012-11-04 20:27 . 2012-11-04 20:26 695675 ----a-w- c:\windows\unins000.exe
2012-11-03 12:18 . 2012-11-03 12:18 512 ----a-w- C:\PhysicalMBR.bin
2012-11-03 11:34 . 2012-11-03 11:34 -------- d-----w- C:\_OTL
2012-11-03 06:04 . 2012-11-03 06:04 -------- d-----w- c:\program files\trend micro
2012-11-03 06:04 . 2012-11-03 06:04 -------- d-----w- C:\rsit
2012-11-02 20:27 . 2012-11-02 20:27 100864 ----a-w- C:\kwtoypob.sys
2012-11-01 15:38 . 2012-11-05 23:16 108672 ---ha-w- c:\windows\system32\iXUxlYo
2012-10-29 14:43 . 2012-11-05 23:17 182736 ---ha-w- c:\windows\system32\9A3voGafB
2012-10-29 14:20 . 2012-11-05 23:18 48 ---ha-w- c:\windows\system32\988S5InLt
2012-10-29 13:09 . 2012-10-29 13:09 -------- d-----w- C:\found.006
2012-10-14 20:34 . 2012-10-14 20:34 5164496 ----a-r- c:\users\Jenda\AppData\Roaming\Microsoft\Installer\{865961DF-C3B4-47DC-8CFD-4AB5131494AE}\icon.exe
2012-10-10 13:02 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-10 13:02 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-10 13:02 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-08 19:06 . 2012-10-08 19:06 -------- d-----w- c:\users\Jenda\AppData\Roaming\BSplayer Pro
2012-10-08 19:06 . 2012-10-08 19:06 -------- d-----w- c:\program files\Webteh
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-05 23:19 . 2012-10-29 14:43 108592 ---ha-w- c:\windows\system32\NgELZcjt
2012-11-05 23:16 . 2008-10-03 13:19 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-10-28 00:39 . 2012-10-28 00:39 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8654349E-D793-40E3-8175-5CEB828FFA57}\offreg.dll
2012-10-17 00:32 . 2012-10-27 16:24 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8654349E-D793-40E3-8175-5CEB828FFA57}\mpengine.dll
2012-09-13 13:28 . 2012-10-10 12:59 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-12 17:53 . 2012-09-12 17:53 5163984 ----a-r- c:\users\Jenda\AppData\Roaming\Microsoft\Installer\{094D3055-1F1D-4221-B288-4DD0BE529794}\icon.exe
2012-08-29 11:27 . 2012-10-10 12:58 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-29 11:27 . 2012-10-10 12:58 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-24 15:53 . 2012-10-10 13:00 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-08-24 06:59 . 2012-09-22 23:01 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51 . 2012-09-22 23:01 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51 . 2012-09-22 23:01 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 23:01 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 23:01 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43 . 2012-09-22 23:01 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-12 17:46 . 2012-05-12 17:46 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-12 98304]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"IaNvSrv"="c:\program files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2008-05-03 33304]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 163840]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-01 6025216]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2008-01-24 1208320]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-07 1029416]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-22 120832]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2008-02-01 61440]
"PowerForPhone"="c:\program files\P4P\P4P.exe" [2007-08-03 778240]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2008-08-31 3054136]
"ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2008-08-31 47672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"WD Quick View"="c:\program files\Western Digital\WD Quick View\WDDMStatus.exe" [2012-09-19 5236664]
.
c:\users\Jenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-12 216576]
AVer HID Receiver.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2010-7-21 159744]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-10 752168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
Cognizance REG_MULTI_SZ ASBroker ASChannel
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000Core.job
- c:\users\Jenda\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-06 12:10]
.
2012-11-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-902740715-3543083593-2925968300-1000UA.job
- c:\users\Jenda\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-06 12:10]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Jenda\AppData\Roaming\Mozilla\Firefox\Profiles\gaotgyes.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=
FF - ExtSQL: !HIDDEN! 2009-09-22 22:32; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-06 00:21
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.3.6\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(6100)
c:\windows\system32\APSHook.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItClient.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\ASUS\SmartLogon\smartlogon.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe
c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\Western Digital\WD Drive Manager\WDDriveService.exe
c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Western Digital\WD SmartWare\WDBackupEngine.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
c:\program files\ATK Hotkey\MsgTranAgt.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\windows\system32\DllHost.exe
c:\program files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\system32\WerFault.exe
c:\windows\system32\WerFault.exe
c:\program files\Western Digital\WD SmartWare\WDLockedFiles.exe
c:\windows\system32\vssvc.exe
.
**************************************************************************
.
Celkový čas: 2012-11-06 00:34:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-05 23:33
ComboFix2.txt 2012-11-04 21:56
.
Před spuštěním: Volných bajtů: 58 628 915 200
Po spuštění: Volných bajtů: 60 413 476 864
.
- - End Of File - - 7188A393ED904E543F28775D5FB2C07F

Zamčeno