Stránka 3 z 7

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 14:38
od Duhen
No dal jsem install pak restart a pak šlo uninnstall > restart a jedu dál....

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 14:40
od Duhen
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 14:39 on 17/11/2010 (User)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...
SPTD -> Already disabled


-=E.O.F=-

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 14:50
od Duhen
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2010-11-17 14:49:43
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\pxtdapob.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset )

---- EOF - GMER 1.0.15 ----

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 16:16
od Duhen
toto by měla být Gamer 2, ale jelo to přes hodinu a je tam toho nějak málo....nevim
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-17 16:10:57
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\pxtdapob.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF68C4360, 0x24BB1D, 0xE8000020]
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xF6762900]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2036] USER32.dll!TrackPopupMenu 7E3B50EE 5 Bytes JMP 10405CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2320] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset )

Device \FileSystem\Fastfat \Fat B741EC8A

AttachedDevice \FileSystem\Fastfat \Fat amon.sys (Amon monitor/Eset )

---- EOF - GMER 1.0.15 ----

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 16:17
od Duhen
MBR log
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600

CreateFile("\\.\PHYSICALDRIVE0"): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
device: opened successfully
user: error reading MBR

Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x83F3DAB8]
3 CLASSPNP[0xF764405B] -> nt!IofCallDriver[0x804E37D5] -> \Device\Ide\IdeDeviceP0T0L0-3[0x83F8EB00]
kernel: MBR read successfully
user != kernel MBR !!!

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 16:21
od Duhen
TDSSKiller proběhl a napsal not found

2010/11/17 16:18:28.0828 TDSS rootkit removing tool 2.4.8.0 Nov 17 2010 07:23:12
2010/11/17 16:18:28.0828 ================================================================================
2010/11/17 16:18:28.0828 SystemInfo:
2010/11/17 16:18:28.0828
2010/11/17 16:18:28.0828 OS Version: 5.1.2600 ServicePack: 2.0
2010/11/17 16:18:28.0828 Product type: Workstation
2010/11/17 16:18:28.0828 ComputerName: USER
2010/11/17 16:18:28.0828 UserName: User
2010/11/17 16:18:28.0828 Windows directory: C:\WINDOWS
2010/11/17 16:18:28.0828 System windows directory: C:\WINDOWS
2010/11/17 16:18:28.0828 Processor architecture: Intel x86
2010/11/17 16:18:28.0828 Number of processors: 1
2010/11/17 16:18:28.0828 Page size: 0x1000
2010/11/17 16:18:28.0828 Boot type: Normal boot
2010/11/17 16:18:28.0828 ================================================================================
2010/11/17 16:18:29.0359 Initialize success
2010/11/17 16:18:40.0718 ================================================================================
2010/11/17 16:18:40.0718 Scan started
2010/11/17 16:18:40.0718 Mode: Manual;
2010/11/17 16:18:40.0718 ================================================================================
2010/11/17 16:18:41.0843 ACPI (fa2fbcda96d2385f773b059fe5a125a6) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/11/17 16:18:41.0968 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/11/17 16:18:42.0218 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
2010/11/17 16:18:42.0343 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
2010/11/17 16:18:42.0765 ALCXSENS (ba88534a3ceb6161e7432438b9ea4f54) C:\WINDOWS\system32\drivers\ALCXSENS.SYS
2010/11/17 16:18:42.0906 ALCXWDM (dbe9a9ed605710cc5672e574920ac043) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010/11/17 16:18:43.0171 AMON (d2c4b2bd75eb35e1e0da7ad3b65d24d2) C:\WINDOWS\system32\drivers\amon.sys
2010/11/17 16:18:43.0437 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2010/11/17 16:18:43.0687 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/11/17 16:18:43.0796 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/11/17 16:18:44.0015 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/11/17 16:18:44.0203 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/11/17 16:18:44.0312 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/11/17 16:18:44.0703 btaudio (acff0fd5ebb4711534766bfe9c4cc4cd) C:\WINDOWS\system32\drivers\btaudio.sys
2010/11/17 16:18:44.0906 BTDriver (fd7ec7c3aa4a9b1d066fd1e36bec54e4) C:\WINDOWS\system32\DRIVERS\btport.sys
2010/11/17 16:18:45.0187 BTKRNL (fe1229036157344bb2789af6d9d9f6e1) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
2010/11/17 16:18:45.0328 BTSERIAL (510161a915ac376f5d47516aa275c544) C:\WINDOWS\system32\drivers\btserial.sys
2010/11/17 16:18:45.0453 BTSLBCSP (ef4808855e1180edb9627b6a7320e0fd) C:\WINDOWS\system32\drivers\btslbcsp.sys
2010/11/17 16:18:45.0671 BTWDNDIS (56a80e456145a8b1176933604cebcdac) C:\WINDOWS\system32\DRIVERS\btwdndis.sys
2010/11/17 16:18:45.0750 BTWUSB (4aa507d8b72378732147986cf5ff9f76) C:\WINDOWS\system32\Drivers\btwusb.sys
2010/11/17 16:18:45.0890 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/11/17 16:18:45.0968 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/11/17 16:18:46.0250 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/11/17 16:18:46.0359 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/11/17 16:18:46.0578 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/11/17 16:18:47.0250 DgiVecp (770471de2550820feeb7e5d24bf2e273) C:\WINDOWS\system32\Drivers\DgiVecp.sys
2010/11/17 16:18:47.0453 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/11/17 16:18:47.0593 dmboot (e1968edec81c430108feb23ab07bdb14) C:\WINDOWS\system32\drivers\dmboot.sys
2010/11/17 16:18:47.0750 dmio (1b1520a82e396e46b9ae9fa6b03ff6c6) C:\WINDOWS\system32\drivers\dmio.sys
2010/11/17 16:18:47.0921 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/11/17 16:18:48.0156 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
2010/11/17 16:18:48.0343 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/11/17 16:18:48.0515 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/11/17 16:18:48.0687 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
2010/11/17 16:18:48.0812 Fips (266dab58619b17bdf37fabbd48d875ca) C:\WINDOWS\system32\drivers\Fips.sys
2010/11/17 16:18:49.0015 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2010/11/17 16:18:49.0187 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/11/17 16:18:49.0312 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/11/17 16:18:49.0437 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/11/17 16:18:49.0656 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/11/17 16:18:49.0828 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/11/17 16:18:50.0031 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/11/17 16:18:50.0296 i8042prt (0f42de9909b5dbf2c48dd1a79d491af5) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/11/17 16:18:50.0437 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/11/17 16:18:50.0828 intelppm (10a3ac0f0df720ad3c3fd13861d50eb9) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/11/17 16:18:50.0953 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/11/17 16:18:51.0031 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/11/17 16:18:51.0203 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/11/17 16:18:51.0375 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/11/17 16:18:51.0515 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/11/17 16:18:51.0671 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/11/17 16:18:51.0765 isapnp (1091528512e4dd7ed5fddcc4df1c53d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/11/17 16:18:51.0859 Kbdclass (6f877bf8dc01a550cd666f3bedb2213c) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/11/17 16:18:52.0046 kbdhid (065b5a83aa78c0c7047bf22e0ab5c821) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2010/11/17 16:18:52.0171 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
2010/11/17 16:18:52.0390 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/11/17 16:18:52.0750 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys
2010/11/17 16:18:52.0937 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
2010/11/17 16:18:53.0156 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2010/11/17 16:18:53.0281 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/11/17 16:18:53.0375 Modem (60210deb037846afe521ebf349964f6b) C:\WINDOWS\system32\drivers\Modem.sys
2010/11/17 16:18:53.0562 Mouclass (b160ec94114715675509115986400fd9) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/11/17 16:18:53.0656 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/11/17 16:18:53.0781 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/11/17 16:18:54.0078 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/11/17 16:18:54.0750 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/11/17 16:18:54.0875 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
2010/11/17 16:18:54.0968 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/11/17 16:18:55.0062 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/11/17 16:18:55.0156 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/11/17 16:18:55.0281 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/11/17 16:18:55.0406 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/11/17 16:18:55.0578 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
2010/11/17 16:18:55.0687 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/11/17 16:18:55.0953 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
2010/11/17 16:18:56.0062 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/11/17 16:18:56.0281 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/11/17 16:18:56.0390 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/11/17 16:18:56.0515 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/11/17 16:18:56.0593 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/11/17 16:18:56.0781 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/11/17 16:18:56.0937 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/11/17 16:18:57.0234 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2010/11/17 16:18:57.0375 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
2010/11/17 16:18:57.0500 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/11/17 16:18:57.0687 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/11/17 16:18:57.0906 nv (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2010/11/17 16:18:58.0203 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/11/17 16:18:58.0328 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/11/17 16:18:58.0500 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2010/11/17 16:18:58.0734 Parport (76a18caa2fefb28a4ced38d76837e86e) C:\WINDOWS\system32\DRIVERS\parport.sys
2010/11/17 16:18:58.0859 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/11/17 16:18:59.0046 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/11/17 16:18:59.0218 PCI (b7979f37bb7b9df2230046134955e6e7) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/11/17 16:18:59.0375 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
2010/11/17 16:18:59.0515 Pcmcia (90505755634407d4ef4c6dea60fc1df9) C:\WINDOWS\system32\drivers\Pcmcia.sys
2010/11/17 16:18:59.0593 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
2010/11/17 16:19:00.0234 pfc (957b82ec80ad7ead64e5e47df6b0dc40) C:\WINDOWS\system32\drivers\pfc.sys
2010/11/17 16:19:00.0390 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/11/17 16:19:00.0515 Processor (9a10e4fd13824823da50d4758bd0a645) C:\WINDOWS\system32\DRIVERS\processr.sys
2010/11/17 16:19:00.0750 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/11/17 16:19:00.0828 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/11/17 16:19:01.0062 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2010/11/17 16:19:01.0593 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/11/17 16:19:01.0750 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/11/17 16:19:01.0875 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/11/17 16:19:01.0984 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/11/17 16:19:02.0171 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/11/17 16:19:02.0343 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/11/17 16:19:02.0453 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2010/11/17 16:19:02.0578 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/11/17 16:19:02.0812 redbook (aba13d33e1f888c9a68599a48a8840d6) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/11/17 16:19:02.0937 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2010/11/17 16:19:03.0093 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
2010/11/17 16:19:03.0250 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/11/17 16:19:03.0390 sensorsview (845af1ba23c8d5e64def61bcc441604c) C:\Program Files\SensorsViewPro41\drv\sensorsview32.sys
2010/11/17 16:19:03.0500 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/11/17 16:19:03.0625 Serial (c1ddbc85251551a840212999da3d95f3) C:\WINDOWS\system32\DRIVERS\serial.sys
2010/11/17 16:19:03.0828 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/11/17 16:19:04.0156 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/11/17 16:19:04.0328 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
2010/11/17 16:19:04.0562 sp_rsdrv2 (8831252bcf05fcfb5abd116a22e552d8) C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2010/11/17 16:19:04.0671 sr (a74035ea526db97d9d50d2143a55f5cf) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/11/17 16:19:04.0875 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/11/17 16:19:05.0109 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/11/17 16:19:05.0218 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/11/17 16:19:05.0406 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
2010/11/17 16:19:05.0843 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/11/17 16:19:06.0078 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/11/17 16:19:06.0203 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/11/17 16:19:06.0328 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/11/17 16:19:06.0437 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/11/17 16:19:06.0906 uagp35 (49c805d42d75eddc9b6a7130999c9054) C:\WINDOWS\system32\DRIVERS\uagp35.sys
2010/11/17 16:19:07.0109 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
2010/11/17 16:19:07.0281 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
2010/11/17 16:19:07.0406 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys
2010/11/17 16:19:07.0531 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/11/17 16:19:07.0718 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/11/17 16:19:07.0812 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/11/17 16:19:07.0906 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/11/17 16:19:08.0015 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/11/17 16:19:08.0140 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/11/17 16:19:08.0234 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/11/17 16:19:08.0468 VD_FileDisk (e3389e42561670d112d77a431010377b) C:\WINDOWS\system32\drivers\VD_FileDisk.sys
2010/11/17 16:19:08.0625 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
2010/11/17 16:19:08.0734 viaagp1 (4b039bbd037b01f5db5a144c837f283a) C:\WINDOWS\system32\DRIVERS\viaagp1.sys
2010/11/17 16:19:08.0843 viagfx (51760dd7be8b60938334fae7b83cf1de) C:\WINDOWS\system32\DRIVERS\vtmini.sys
2010/11/17 16:19:08.0968 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
2010/11/17 16:19:09.0078 VolSnap (cd8cce067f7e9cbd762c00bdddecaa34) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/11/17 16:19:09.0406 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/11/17 16:19:09.0484 wceusbsh (4a954a20a4c73d6db13c0fe25f3f1b0c) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
2010/11/17 16:19:09.0640 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/11/17 16:19:09.0890 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2010/11/17 16:19:10.0015 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/11/17 16:19:10.0140 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/11/17 16:19:10.0218 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/11/17 16:19:10.0453 ZSMC0305 (ebb174fe796b27b4c8fc673b9f0ae91c) C:\WINDOWS\system32\Drivers\usbVM305.sys
2010/11/17 16:19:10.0812 ================================================================================
2010/11/17 16:19:10.0812 Scan finished
2010/11/17 16:19:10.0812 ================================================================================

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 16:30
od motji
Máte inst. cd?
Kolik máte na tomto pc disků/oddílů? nějaký linux, šifrování dat a podobně?

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 17:23
od Duhen
Ins. CD mám a je tam jen jedna parttion C: a pouze XP Pro

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 22:17
od motji
Fajn, nabootujete z inst. cd a uděláte příkaz Fixmbr

http://viry.cz/forum/viewtopic.php?f=11&t=7294

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 23:05
od Duhen
jj, znám ráno to udělám.

Re: Nod hlasí červy...prosím o pomoc

Napsal: 17 lis 2010 23:06
od motji
Fajn, a proběhněte to i Avptoolem :) .
Co ten notas, avptool ok?

Re: Nod hlasí červy...prosím o pomoc

Napsal: 18 lis 2010 09:01
od Duhen
Jsem teď došel a na LCD hláška Win32/injektor.DPG Trojský kůň a nod ho kopl do karantény
Tato skutečnost byla zjištěna na nově vytvořeném souboru aplikací: C:\WINDOWS\System32\svchost.exe. Soubor byl přesunut do karantény. Můžete zavřít toto okno.


No jdu na ten fix a avp ....notebook opk a jdu ho projet avp

Re: Nod hlasí červy...prosím o pomoc

Napsal: 18 lis 2010 10:12
od motji
A v jakém souboru?

Re: Nod hlasí červy...prosím o pomoc

Napsal: 18 lis 2010 10:47
od Duhen
To nevím, najdu to někde?

Re: Nod hlasí červy...prosím o pomoc

Napsal: 18 lis 2010 11:29
od motji
V té karanténě :D