Stránka 4 z 5

Re: vypinanie pc z vírusu

Napsal: 04 zář 2011 22:07
od Dominika Polakova
no tak ja sa do toho zajtra pustím a dám vedieť :) zatiaľ veľmi pekne ˇˇdakujem :)

Re: vypinanie pc z vírusu

Napsal: 04 zář 2011 22:38
od vyosek
Neni zac, peknou dobrou noc :)

Re: vypinanie pc z vírusu

Napsal: 05 zář 2011 20:21
od Dominika Polakova
no ja som si spravila ten kaspersky virus a vypisalo mi no threats detected takze nemam co ukladat podla tych pokynov..neponuka mi moznost ulozit, takze je pc v poriadku tym padom?

Re: vypinanie pc z vírusu

Napsal: 06 zář 2011 08:02
od vyosek
Tim padem by melo byt :thumbsup:

Re: vypinanie pc z vírusu

Napsal: 06 zář 2011 18:05
od Dominika Polakova
tak potom dakujem pekne znova :) a pekný den! teda zvyšok :D

Re: vypinanie pc z vírusu

Napsal: 06 zář 2011 18:06
od vyosek
Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek


A na rozloucenou vam zahraje nase kapela :guitar: :150: :151: :152: :153: :154: :196:

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 11:44
od Dominika Polakova
no znova ja...ja som vám asi súdená...vcera mi znova vypinalo pc tak som si spravila ten kaspersky..posielam vysledok..uz ked tam vidim toho trojana je mi zle...ak viete co dalej budem rada :) prijemny den


Status: Deleted (events: 4)
6. 10. 2011 10:51:02 Deleted Trojan program Backdoor.Win32.Gbot.mnr C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{5B03A955-89C9-4336-5BCE-27E828CB24E1}-flash32.exe High
6. 10. 2011 10:51:02 Deleted Trojan program Backdoor.Win32.Gbot.mnr C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{5B03A955-89C9-4336-5BCE-27E828CB24E1}-flash32.exe//PE-Crypt.XorPE High
6. 10. 2011 10:51:10 Deleted Trojan program Backdoor.Win32.Gbot.mnr C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{7E675DA3-7B25-B013-A798-F862F07424F2}-conhost.exe High
6. 10. 2011 10:51:10 Deleted Trojan program Backdoor.Win32.Gbot.mnr C:\Documents and Settings\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{7E675DA3-7B25-B013-A798-F862F07424F2}-conhost.exe//PE-Crypt.XorPE High

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 15:12
od vyosek
Zdravim :)

bud se to odnekud obnovuje nebo si Vas nekdo vybral jako cil :boxed:

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Utilitu spustte a prikazte ji, at skenuje - klik na Start Scan
  • Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
  • Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
  • Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
  • Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
  • Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 16:43
od Dominika Polakova
no môže to byť aj tým, že som použila usb, ktoré som používala vtedy, keď som mala ten vírus a chcela som si nejaké veci uchovať pred stratou...potom som sa bála to usb použiť ale ku koncu septembra som bola nutena ho použiť tak možno je ten vírus odtial. Tu posielam ten report


17:41:03.0343 7316 TDSS rootkit removing tool 2.6.5.0 Oct 5 2011 20:52:46
17:41:03.0732 7316 ============================================================
17:41:03.0732 7316 Current date / time: 2011/10/06 17:41:03.0732
17:41:03.0732 7316 SystemInfo:
17:41:03.0732 7316
17:41:03.0732 7316 OS Version: 6.0.6002 ServicePack: 2.0
17:41:03.0732 7316 Product type: Workstation
17:41:03.0732 7316 ComputerName: DOMINIKA-PC
17:41:03.0732 7316 UserName: Dominika
17:41:03.0732 7316 Windows directory: C:\Windows
17:41:03.0732 7316 System windows directory: C:\Windows
17:41:03.0732 7316 Processor architecture: Intel x86
17:41:03.0732 7316 Number of processors: 2
17:41:03.0732 7316 Page size: 0x1000
17:41:03.0732 7316 Boot type: Normal boot
17:41:03.0732 7316 ============================================================
17:41:04.0158 7316 Initialize success
17:41:06.0849 7192 ============================================================
17:41:06.0849 7192 Scan started
17:41:06.0849 7192 Mode: Manual;
17:41:06.0849 7192 ============================================================
17:41:07.0473 7192 61366597 (186b54479d98e48aee0e9ada4b3c4d31) C:\Windows\system32\DRIVERS\61366597.sys
17:41:07.0475 7192 61366597 - ok
17:41:07.0555 7192 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
17:41:07.0557 7192 ACPI - ok
17:41:07.0724 7192 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
17:41:07.0728 7192 adp94xx - ok
17:41:07.0773 7192 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
17:41:07.0776 7192 adpahci - ok
17:41:07.0946 7192 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
17:41:07.0948 7192 adpu160m - ok
17:41:07.0995 7192 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
17:41:07.0997 7192 adpu320 - ok
17:41:08.0276 7192 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
17:41:08.0279 7192 AFD - ok
17:41:08.0482 7192 AgereSoftModem (5d97943c128ed756d1b0a08302c1b1f8) C:\Windows\system32\DRIVERS\AGRSM.sys
17:41:08.0490 7192 AgereSoftModem - ok
17:41:08.0607 7192 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
17:41:08.0609 7192 agp440 - ok
17:41:08.0719 7192 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
17:41:08.0721 7192 aic78xx - ok
17:41:08.0822 7192 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
17:41:08.0824 7192 aliide - ok
17:41:08.0885 7192 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
17:41:08.0886 7192 amdagp - ok
17:41:08.0982 7192 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
17:41:08.0984 7192 amdide - ok
17:41:09.0042 7192 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
17:41:09.0044 7192 AmdK7 - ok
17:41:09.0150 7192 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
17:41:09.0152 7192 AmdK8 - ok
17:41:09.0305 7192 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
17:41:09.0307 7192 arc - ok
17:41:09.0457 7192 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
17:41:09.0459 7192 arcsas - ok
17:41:09.0617 7192 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\Windows\system32\drivers\aswFsBlk.sys
17:41:09.0619 7192 aswFsBlk - ok
17:41:09.0723 7192 aswMonFlt (4804753a4ec7d67cc22d226bffd1c1e3) C:\Windows\system32\drivers\aswMonFlt.sys
17:41:09.0724 7192 aswMonFlt - ok
17:41:09.0824 7192 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\Windows\system32\drivers\aswRdr.sys
17:41:09.0825 7192 aswRdr - ok
17:41:09.0923 7192 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\Windows\system32\drivers\aswSnx.sys
17:41:09.0927 7192 aswSnx - ok
17:41:10.0069 7192 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\Windows\system32\drivers\aswSP.sys
17:41:10.0072 7192 aswSP - ok
17:41:10.0147 7192 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\Windows\system32\drivers\aswTdi.sys
17:41:10.0148 7192 aswTdi - ok
17:41:10.0286 7192 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
17:41:10.0287 7192 AsyncMac - ok
17:41:10.0403 7192 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
17:41:10.0405 7192 atapi - ok
17:41:10.0763 7192 atikmdag (be4d8fdc6b2598c46b2b5e6e4fbaafc5) C:\Windows\system32\DRIVERS\atikmdag.sys
17:41:10.0790 7192 atikmdag - ok
17:41:10.0948 7192 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
17:41:10.0950 7192 Beep - ok
17:41:11.0015 7192 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
17:41:11.0017 7192 blbdrive - ok
17:41:11.0118 7192 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
17:41:11.0120 7192 bowser - ok
17:41:11.0197 7192 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
17:41:11.0199 7192 BrFiltLo - ok
17:41:11.0284 7192 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
17:41:11.0286 7192 BrFiltUp - ok
17:41:11.0426 7192 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
17:41:11.0427 7192 Brserid - ok
17:41:11.0496 7192 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
17:41:11.0498 7192 BrSerWdm - ok
17:41:11.0589 7192 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
17:41:11.0590 7192 BrUsbMdm - ok
17:41:11.0784 7192 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
17:41:11.0786 7192 BrUsbSer - ok
17:41:11.0920 7192 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
17:41:11.0921 7192 BTHMODEM - ok
17:41:12.0098 7192 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
17:41:12.0100 7192 cdfs - ok
17:41:12.0236 7192 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
17:41:12.0237 7192 cdrom - ok
17:41:12.0305 7192 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
17:41:12.0306 7192 circlass - ok
17:41:12.0407 7192 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
17:41:12.0411 7192 CLFS - ok
17:41:12.0514 7192 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
17:41:12.0515 7192 CmBatt - ok
17:41:12.0653 7192 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
17:41:12.0654 7192 cmdide - ok
17:41:12.0759 7192 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
17:41:12.0760 7192 Compbatt - ok
17:41:12.0891 7192 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
17:41:12.0893 7192 crcdisk - ok
17:41:13.0045 7192 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
17:41:13.0046 7192 Crusoe - ok
17:41:13.0240 7192 dfmirage (699ef0fd9ae72b7f5ad756e382c73e0e) C:\Windows\system32\DRIVERS\dfmirage.sys
17:41:13.0243 7192 dfmirage - ok
17:41:13.0309 7192 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
17:41:13.0312 7192 DfsC - ok
17:41:13.0490 7192 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
17:41:13.0493 7192 disk - ok
17:41:13.0639 7192 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
17:41:13.0640 7192 drmkaud - ok
17:41:13.0785 7192 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
17:41:13.0792 7192 DXGKrnl - ok
17:41:13.0945 7192 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
17:41:13.0947 7192 E1G60 - ok
17:41:14.0063 7192 eamon (59d9e5dbcfef1e0e3dbac1b55c718f2d) C:\Windows\system32\DRIVERS\eamon.sys
17:41:14.0066 7192 eamon - ok
17:41:14.0137 7192 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
17:41:14.0140 7192 Ecache - ok
17:41:14.0256 7192 ehdrv (3bd67a869964bf57266cbbd1dca38c6a) C:\Windows\system32\DRIVERS\ehdrv.sys
17:41:14.0258 7192 ehdrv - ok
17:41:14.0360 7192 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
17:41:14.0364 7192 elxstor - ok
17:41:14.0461 7192 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
17:41:14.0462 7192 ErrDev - ok
17:41:14.0607 7192 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
17:41:14.0609 7192 exfat - ok
17:41:14.0677 7192 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
17:41:14.0679 7192 fastfat - ok
17:41:14.0772 7192 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
17:41:14.0773 7192 fdc - ok
17:41:14.0841 7192 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
17:41:14.0842 7192 FileInfo - ok
17:41:14.0989 7192 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
17:41:14.0990 7192 Filetrace - ok
17:41:15.0154 7192 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
17:41:15.0156 7192 flpydisk - ok
17:41:15.0239 7192 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
17:41:15.0242 7192 FltMgr - ok
17:41:15.0371 7192 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
17:41:15.0376 7192 Fs_Rec - ok
17:41:15.0449 7192 FwLnk (cbc22823628544735625b280665e434e) C:\Windows\system32\DRIVERS\FwLnk.sys
17:41:15.0451 7192 FwLnk - ok
17:41:15.0546 7192 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
17:41:15.0548 7192 gagp30kx - ok
17:41:15.0752 7192 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
17:41:15.0755 7192 HdAudAddService - ok
17:41:15.0841 7192 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
17:41:15.0847 7192 HDAudBus - ok
17:41:15.0915 7192 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
17:41:15.0916 7192 HidBth - ok
17:41:15.0999 7192 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
17:41:16.0000 7192 HidIr - ok
17:41:16.0107 7192 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
17:41:16.0109 7192 HidUsb - ok
17:41:16.0234 7192 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
17:41:16.0236 7192 HpCISSs - ok
17:41:16.0290 7192 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
17:41:16.0295 7192 HTTP - ok
17:41:16.0423 7192 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
17:41:16.0424 7192 i2omp - ok
17:41:16.0662 7192 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
17:41:16.0665 7192 i8042prt - ok
17:41:16.0804 7192 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\Windows\system32\DRIVERS\iaStor.sys
17:41:16.0807 7192 iaStor - ok
17:41:16.0873 7192 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
17:41:16.0875 7192 iaStorV - ok
17:41:16.0950 7192 igfx - ok
17:41:17.0025 7192 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
17:41:17.0027 7192 iirsp - ok
17:41:17.0106 7192 IntcAzAudAddService - ok
17:41:17.0191 7192 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
17:41:17.0192 7192 intelide - ok
17:41:17.0285 7192 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
17:41:17.0287 7192 intelppm - ok
17:41:17.0437 7192 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:41:17.0438 7192 IpFilterDriver - ok
17:41:17.0470 7192 IpInIp - ok
17:41:17.0515 7192 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
17:41:17.0516 7192 IPMIDRV - ok
17:41:17.0605 7192 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
17:41:17.0606 7192 IPNAT - ok
17:41:17.0668 7192 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
17:41:17.0669 7192 IRENUM - ok
17:41:17.0698 7192 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
17:41:17.0699 7192 isapnp - ok
17:41:17.0789 7192 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
17:41:17.0792 7192 iScsiPrt - ok
17:41:17.0831 7192 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
17:41:17.0833 7192 iteatapi - ok
17:41:17.0964 7192 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
17:41:17.0966 7192 iteraid - ok
17:41:18.0093 7192 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
17:41:18.0095 7192 kbdclass - ok
17:41:18.0152 7192 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys
17:41:18.0153 7192 kbdhid - ok
17:41:18.0316 7192 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
17:41:18.0322 7192 KSecDD - ok
17:41:18.0404 7192 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
17:41:18.0406 7192 lltdio - ok
17:41:18.0618 7192 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
17:41:18.0620 7192 LSI_FC - ok
17:41:18.0803 7192 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
17:41:18.0805 7192 LSI_SAS - ok
17:41:18.0924 7192 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
17:41:18.0926 7192 LSI_SCSI - ok
17:41:18.0988 7192 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
17:41:18.0991 7192 luafv - ok
17:41:19.0084 7192 MarvinBus (a3e700d78eec390f1208098cdca5c6b6) C:\Windows\system32\DRIVERS\MarvinBus.sys
17:41:19.0087 7192 MarvinBus - ok
17:41:19.0222 7192 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
17:41:19.0225 7192 megasas - ok
17:41:19.0273 7192 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
17:41:19.0277 7192 MegaSR - ok
17:41:19.0436 7192 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
17:41:19.0438 7192 Modem - ok
17:41:19.0501 7192 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
17:41:19.0503 7192 monitor - ok
17:41:19.0578 7192 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
17:41:19.0580 7192 mouclass - ok
17:41:19.0660 7192 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
17:41:19.0661 7192 mouhid - ok
17:41:19.0757 7192 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
17:41:19.0759 7192 MountMgr - ok
17:41:19.0801 7192 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\Windows\system32\DRIVERS\MpFilter.sys
17:41:19.0804 7192 MpFilter - ok
17:41:19.0921 7192 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
17:41:19.0923 7192 mpio - ok
17:41:20.0027 7192 MpKsl216232ec - ok
17:41:20.0059 7192 MpKsl432559b9 - ok
17:41:20.0074 7192 MpKsl75d8edd4 - ok
17:41:20.0259 7192 MpKsl851e0eea (5f53edfead46fa7adb78eee9ecce8fdf) C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{437D4EE8-748A-4232-9F48-EF8DB4521709}\MpKsl851e0eea.sys
17:41:20.0260 7192 Suspicious file (Forged): C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{437D4EE8-748A-4232-9F48-EF8DB4521709}\MpKsl851e0eea.sys. Real md5: 5f53edfead46fa7adb78eee9ecce8fdf, Fake md5: 7702b27661f74715060586b65246b849
17:41:20.0260 7192 MpKsl851e0eea ( ForgedFile.Multi.Generic ) - warning
17:41:20.0261 7192 MpKsl851e0eea - detected ForgedFile.Multi.Generic (1)
17:41:20.0401 7192 MpKslb797bcb0 - ok
17:41:20.0431 7192 MpKslc01debac - ok
17:41:20.0490 7192 MpKslc7a6bf16 - ok
17:41:20.0512 7192 MpKsld4321497 - ok
17:41:20.0726 7192 MpNWMon (f32e2d6a1640a469a9ed4f1929a4a861) C:\Windows\system32\DRIVERS\MpNWMon.sys
17:41:20.0728 7192 MpNWMon - ok
17:41:20.0824 7192 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
17:41:20.0826 7192 mpsdrv - ok
17:41:20.0918 7192 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
17:41:20.0919 7192 Mraid35x - ok
17:41:21.0002 7192 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
17:41:21.0004 7192 MRxDAV - ok
17:41:21.0064 7192 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
17:41:21.0066 7192 mrxsmb - ok
17:41:21.0152 7192 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:41:21.0155 7192 mrxsmb10 - ok
17:41:21.0265 7192 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:41:21.0267 7192 mrxsmb20 - ok
17:41:21.0382 7192 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
17:41:21.0384 7192 msahci - ok
17:41:21.0449 7192 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
17:41:21.0451 7192 msdsm - ok
17:41:21.0549 7192 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
17:41:21.0552 7192 Msfs - ok
17:41:21.0658 7192 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
17:41:21.0660 7192 msisadrv - ok
17:41:21.0791 7192 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
17:41:21.0792 7192 MSKSSRV - ok
17:41:21.0884 7192 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
17:41:21.0885 7192 MSPCLOCK - ok
17:41:21.0973 7192 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
17:41:21.0975 7192 MSPQM - ok
17:41:22.0043 7192 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
17:41:22.0045 7192 MsRPC - ok
17:41:22.0205 7192 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
17:41:22.0207 7192 mssmbios - ok
17:41:22.0281 7192 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
17:41:22.0283 7192 MSTEE - ok
17:41:22.0366 7192 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
17:41:22.0368 7192 Mup - ok
17:41:22.0445 7192 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
17:41:22.0449 7192 NativeWifiP - ok
17:41:22.0642 7192 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
17:41:22.0647 7192 NDIS - ok
17:41:22.0754 7192 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
17:41:22.0756 7192 NdisTapi - ok
17:41:22.0789 7192 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
17:41:22.0790 7192 Ndisuio - ok
17:41:22.0847 7192 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
17:41:22.0849 7192 NdisWan - ok
17:41:23.0022 7192 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
17:41:23.0024 7192 NDProxy - ok
17:41:23.0189 7192 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
17:41:23.0191 7192 NetBIOS - ok
17:41:23.0280 7192 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
17:41:23.0283 7192 netbt - ok
17:41:23.0492 7192 NETw5v32 (8de67bd902095a13329fd82c85a1fa09) C:\Windows\system32\DRIVERS\NETw5v32.sys
17:41:23.0516 7192 NETw5v32 - ok
17:41:23.0633 7192 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
17:41:23.0635 7192 nfrd960 - ok
17:41:23.0698 7192 NisDrv (17e2c08c5ecfbe94a7c67b1c275ee9d9) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
17:41:23.0700 7192 NisDrv - ok
17:41:23.0826 7192 npf (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys
17:41:23.0828 7192 npf - ok
17:41:23.0879 7192 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
17:41:23.0881 7192 Npfs - ok
17:41:23.0969 7192 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
17:41:23.0971 7192 nsiproxy - ok
17:41:24.0045 7192 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
17:41:24.0054 7192 Ntfs - ok
17:41:24.0153 7192 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
17:41:24.0155 7192 ntrigdigi - ok
17:41:24.0194 7192 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
17:41:24.0195 7192 Null - ok
17:41:24.0280 7192 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
17:41:24.0282 7192 nvraid - ok
17:41:24.0327 7192 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
17:41:24.0329 7192 nvstor - ok
17:41:24.0420 7192 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
17:41:24.0422 7192 nv_agp - ok
17:41:24.0448 7192 NwlnkFlt - ok
17:41:24.0460 7192 NwlnkFwd - ok
17:41:24.0525 7192 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
17:41:24.0527 7192 ohci1394 - ok
17:41:24.0663 7192 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
17:41:24.0666 7192 Parport - ok
17:41:24.0794 7192 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
17:41:24.0798 7192 partmgr - ok
17:41:24.0877 7192 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
17:41:24.0880 7192 Parvdm - ok
17:41:25.0004 7192 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
17:41:25.0007 7192 pci - ok
17:41:25.0055 7192 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
17:41:25.0057 7192 pciide - ok
17:41:25.0160 7192 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
17:41:25.0162 7192 pcmcia - ok
17:41:25.0385 7192 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
17:41:25.0394 7192 PEAUTH - ok
17:41:25.0562 7192 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
17:41:25.0564 7192 PptpMiniport - ok
17:41:25.0673 7192 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
17:41:25.0675 7192 Processor - ok
17:41:25.0809 7192 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
17:41:25.0811 7192 PSched - ok
17:41:25.0875 7192 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys
17:41:25.0877 7192 PxHelp20 - ok
17:41:26.0033 7192 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
17:41:26.0041 7192 ql2300 - ok
17:41:26.0150 7192 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
17:41:26.0153 7192 ql40xx - ok
17:41:26.0224 7192 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
17:41:26.0225 7192 QWAVEdrv - ok
17:41:26.0321 7192 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
17:41:26.0322 7192 RasAcd - ok
17:41:26.0370 7192 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
17:41:26.0372 7192 Rasl2tp - ok
17:41:26.0478 7192 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
17:41:26.0480 7192 RasPppoe - ok
17:41:26.0554 7192 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
17:41:26.0556 7192 RasSstp - ok
17:41:26.0622 7192 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
17:41:26.0625 7192 rdbss - ok
17:41:26.0761 7192 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
17:41:26.0763 7192 RDPCDD - ok
17:41:26.0866 7192 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
17:41:26.0869 7192 rdpdr - ok
17:41:27.0017 7192 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
17:41:27.0019 7192 RDPENCDD - ok
17:41:27.0133 7192 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
17:41:27.0136 7192 RDPWD - ok
17:41:27.0277 7192 rimmptsk (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys
17:41:27.0279 7192 rimmptsk - ok
17:41:27.0331 7192 rimsptsk (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
17:41:27.0332 7192 rimsptsk - ok
17:41:27.0462 7192 rismxdp (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys
17:41:27.0464 7192 rismxdp - ok
17:41:27.0576 7192 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
17:41:27.0580 7192 rspndr - ok
17:41:27.0756 7192 RTL8169 (2d19a7469ea19993d0c12e627f4530bc) C:\Windows\system32\DRIVERS\Rtlh86.sys
17:41:27.0760 7192 RTL8169 - ok
17:41:27.0935 7192 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
17:41:27.0937 7192 sbp2port - ok
17:41:28.0053 7192 SCREAMINGBDRIVER - ok
17:41:28.0163 7192 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
17:41:28.0165 7192 sdbus - ok
17:41:28.0305 7192 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
17:41:28.0307 7192 secdrv - ok
17:41:28.0490 7192 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
17:41:28.0492 7192 Serenum - ok
17:41:28.0616 7192 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
17:41:28.0618 7192 Serial - ok
17:41:28.0709 7192 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
17:41:28.0711 7192 sermouse - ok
17:41:28.0851 7192 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
17:41:28.0852 7192 sffdisk - ok
17:41:28.0908 7192 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
17:41:28.0910 7192 sffp_mmc - ok
17:41:29.0036 7192 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
17:41:29.0038 7192 sffp_sd - ok
17:41:29.0104 7192 sfloppy (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys
17:41:29.0106 7192 sfloppy - ok
17:41:29.0292 7192 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
17:41:29.0294 7192 sisagp - ok
17:41:29.0425 7192 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
17:41:29.0427 7192 SiSRaid2 - ok
17:41:29.0547 7192 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
17:41:29.0549 7192 SiSRaid4 - ok
17:41:29.0669 7192 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
17:41:29.0670 7192 Smb - ok
17:41:29.0742 7192 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
17:41:29.0743 7192 spldr - ok
17:41:29.0860 7192 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
17:41:29.0864 7192 srv - ok
17:41:29.0925 7192 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
17:41:29.0927 7192 srv2 - ok
17:41:30.0040 7192 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
17:41:30.0042 7192 srvnet - ok
17:41:30.0079 7192 StarOpen - ok
17:41:30.0174 7192 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
17:41:30.0175 7192 swenum - ok
17:41:30.0226 7192 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
17:41:30.0228 7192 Symc8xx - ok
17:41:30.0333 7192 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
17:41:30.0335 7192 Sym_hi - ok
17:41:30.0387 7192 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
17:41:30.0389 7192 Sym_u3 - ok
17:41:30.0532 7192 SynTP (2185cc5be9922562108cf87f42e4bbaf) C:\Windows\system32\DRIVERS\SynTP.sys
17:41:30.0541 7192 SynTP - ok
17:41:30.0663 7192 Tcpip (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\drivers\tcpip.sys
17:41:30.0670 7192 Tcpip - ok
17:41:30.0774 7192 Tcpip6 (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\DRIVERS\tcpip.sys
17:41:30.0781 7192 Tcpip6 - ok
17:41:30.0881 7192 tcpipreg (36606b165d04a397bdf613096986d85d) C:\Windows\system32\drivers\tcpipreg.sys
17:41:30.0883 7192 tcpipreg - ok
17:41:30.0940 7192 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys
17:41:30.0942 7192 tdcmdpst - ok
17:41:31.0037 7192 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
17:41:31.0039 7192 TDPIPE - ok
17:41:31.0101 7192 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
17:41:31.0103 7192 TDTCP - ok
17:41:31.0150 7192 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
17:41:31.0152 7192 tdx - ok
17:41:31.0252 7192 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
17:41:31.0254 7192 TermDD - ok
17:41:31.0406 7192 Tosrfcom - ok
17:41:31.0461 7192 tosrfec (5c4103544612e5011ef46301b93d1aa6) C:\Windows\system32\DRIVERS\tosrfec.sys
17:41:31.0463 7192 tosrfec - ok
17:41:31.0614 7192 tos_sps32 (4399a9bf7d8f49991a07fd86590a1619) C:\Windows\system32\DRIVERS\tos_sps32.sys
17:41:31.0618 7192 tos_sps32 - ok
17:41:31.0769 7192 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
17:41:31.0771 7192 tssecsrv - ok
17:41:31.0882 7192 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
17:41:31.0884 7192 tunmp - ok
17:41:32.0030 7192 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
17:41:32.0031 7192 tunnel - ok
17:41:32.0182 7192 TVALZ (792a8b80f8188aba4b2be271583f3e46) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
17:41:32.0184 7192 TVALZ - ok
17:41:32.0370 7192 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
17:41:32.0373 7192 uagp35 - ok
17:41:32.0503 7192 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
17:41:32.0509 7192 udfs - ok
17:41:32.0686 7192 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
17:41:32.0688 7192 uliagpkx - ok
17:41:32.0717 7192 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
17:41:32.0721 7192 uliahci - ok
17:41:32.0897 7192 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
17:41:32.0899 7192 UlSata - ok
17:41:33.0041 7192 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
17:41:33.0043 7192 ulsata2 - ok
17:41:33.0182 7192 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
17:41:33.0185 7192 umbus - ok
17:41:33.0284 7192 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
17:41:33.0286 7192 usbccgp - ok
17:41:33.0337 7192 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
17:41:33.0339 7192 usbcir - ok
17:41:33.0481 7192 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
17:41:33.0483 7192 usbehci - ok
17:41:33.0612 7192 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
17:41:33.0615 7192 usbhub - ok
17:41:33.0755 7192 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
17:41:33.0758 7192 usbohci - ok
17:41:33.0870 7192 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
17:41:33.0872 7192 usbprint - ok
17:41:33.0925 7192 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:41:33.0929 7192 USBSTOR - ok
17:41:34.0004 7192 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
17:41:34.0006 7192 usbuhci - ok
17:41:34.0075 7192 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
17:41:34.0079 7192 usbvideo - ok
17:41:34.0161 7192 UVCFTR (237c444fbd1c697a2e3fa60f02c61f22) C:\Windows\system32\Drivers\UVCFTR_S.SYS
17:41:34.0163 7192 UVCFTR - ok
17:41:34.0221 7192 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
17:41:34.0223 7192 vga - ok
17:41:34.0264 7192 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
17:41:34.0266 7192 VgaSave - ok
17:41:34.0364 7192 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
17:41:34.0366 7192 viaagp - ok
17:41:34.0437 7192 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
17:41:34.0439 7192 ViaC7 - ok
17:41:34.0552 7192 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
17:41:34.0554 7192 viaide - ok
17:41:34.0626 7192 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
17:41:34.0628 7192 volmgr - ok
17:41:34.0722 7192 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
17:41:34.0727 7192 volmgrx - ok
17:41:34.0848 7192 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
17:41:34.0852 7192 volsnap - ok
17:41:35.0004 7192 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
17:41:35.0007 7192 vsmraid - ok
17:41:35.0147 7192 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
17:41:35.0149 7192 WacomPen - ok
17:41:35.0175 7192 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
17:41:35.0180 7192 Wanarp - ok
17:41:35.0192 7192 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
17:41:35.0197 7192 Wanarpv6 - ok
17:41:35.0313 7192 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
17:41:35.0316 7192 Wd - ok
17:41:35.0399 7192 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
17:41:35.0404 7192 Wdf01000 - ok
17:41:35.0588 7192 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
17:41:35.0590 7192 WmiAcpi - ok
17:41:35.0733 7192 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
17:41:35.0735 7192 WpdUsb - ok
17:41:35.0807 7192 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
17:41:35.0811 7192 ws2ifsl - ok
17:41:35.0913 7192 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
17:41:35.0916 7192 WUDFRd - ok
17:41:35.0958 7192 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
17:41:35.0967 7192 \Device\Harddisk0\DR0 - ok
17:41:35.0974 7192 Boot (0x1200) (0424fa7296af759339f523a9c5305b2e) \Device\Harddisk0\DR0\Partition0
17:41:35.0975 7192 \Device\Harddisk0\DR0\Partition0 - ok
17:41:36.0002 7192 Boot (0x1200) (eea40d2ea7104213cfe86bd5b2b45034) \Device\Harddisk0\DR0\Partition1
17:41:36.0003 7192 \Device\Harddisk0\DR0\Partition1 - ok
17:41:36.0003 7192 ============================================================
17:41:36.0004 7192 Scan finished
17:41:36.0004 7192 ============================================================
17:41:36.0053 7180 Detected object count: 1
17:41:36.0053 7180 Actual detected object count: 1
17:41:42.0684 7180 MpKsl851e0eea ( ForgedFile.Multi.Generic ) - skipped by user
17:41:42.0685 7180 MpKsl851e0eea ( ForgedFile.Multi.Generic ) - User select action: Skip

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 18:15
od vyosek
:arrow: Zapojte do PC vsechny USB klice (flashky, ext. disky apod.)

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 18:45
od Dominika Polakova
############################## | UsbFix 7.059 | [Research]

User: Dominika (Administrator) # DOMINIKA-PC [TOSHIBA Satellite A300]
Updated 16/09/2011 by El Desaparecido
Started at 19:35:29 | 06/10/2011
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com

CPU: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
CPU 2: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Microsoft® Windows Vista™ Home Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 9.0.8112.16421

Windows Firewall: Enabled
RAM -> 3069 Mb
C:\ (%systemdrive%) -> Fixed drive # 149 Gb (57 Mb free - 38%) [Vista] # NTFS
D:\ -> Removable drive # 4 Gb (1 Mb free - 38%) [USB DISK] # FAT32
E:\ -> Fixed drive # 148 Gb (93 Mb free - 63%) [Data] # NTFS
F:\ -> CD-ROM

################## | Files # Infected Folders |

Found ! C:\Users\Public\NTUSER.DAT{4b59b073-f538-11de-828c-001e33b64b3b}.TM.blf
Found ! C:\Users\Public\NTUSER.DAT{4b59b073-f538-11de-828c-001e33b64b3b}.TMContainer00000000000000000001.regtrans-ms
Found ! C:\Users\Public\NTUSER.DAT{4b59b073-f538-11de-828c-001e33b64b3b}.TMContainer00000000000000000002.regtrans-ms
Found ! C:\Users\Public\NTUSER.DAT{e3d00b17-c239-11de-abe0-001e33b64b3b}.TM.blf
Found ! C:\Users\Public\NTUSER.DAT{e3d00b17-c239-11de-abe0-001e33b64b3b}.TMContainer00000000000000000001.regtrans-ms
Found ! C:\Users\Public\NTUSER.DAT{e3d00b17-c239-11de-abe0-001e33b64b3b}.TMContainer00000000000000000002.regtrans-ms

################## | Registry |

Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

################## | Mountpoints2 |


################## | Vaccin |

(!) This computer is not vaccinated!

################## | E.O.F |

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 18:59
od vyosek
USBFix spustte s volbou "Deletion"

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 19:20
od Dominika Polakova
############################## | UsbFix 7.059 | [Deletion]

User: Dominika (Administrator) # DOMINIKA-PC [TOSHIBA Satellite A300]
Updated 16/09/2011 by El Desaparecido
Started at 20:13:26 | 06/10/2011
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com

CPU: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
CPU 2: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Microsoft® Windows Vista™ Home Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 9.0.8112.16421

Windows Firewall: Enabled
RAM -> 3069 Mb
C:\ (%systemdrive%) -> Fixed drive # 149 Gb (57 Mb free - 39%) [Vista] # NTFS
D:\ -> Removable drive # 4 Gb (1 Mb free - 38%) [USB DISK] # FAT32
E:\ -> Fixed drive # 148 Gb (93 Mb free - 63%) [Data] # NTFS
F:\ -> CD-ROM

################## | Files # Infected Folders |

Deleted ! C:\Users\Public\NTUSER.DAT{4b59b073-f538-11de-828c-001e33b64b3b}.TM.blf
Deleted ! C:\Users\Public\NTUSER.DAT{4b59b073-f538-11de-828c-001e33b64b3b}.TMContainer00000000000000000001.regtrans-ms
Deleted ! C:\Users\Public\NTUSER.DAT{4b59b073-f538-11de-828c-001e33b64b3b}.TMContainer00000000000000000002.regtrans-ms
Deleted ! C:\Users\Public\NTUSER.DAT{e3d00b17-c239-11de-abe0-001e33b64b3b}.TM.blf
Deleted ! C:\Users\Public\NTUSER.DAT{e3d00b17-c239-11de-abe0-001e33b64b3b}.TMContainer00000000000000000001.regtrans-ms
Deleted ! C:\Users\Public\NTUSER.DAT{e3d00b17-c239-11de-abe0-001e33b64b3b}.TMContainer00000000000000000002.regtrans-ms
Deleted ! C:\$RECYCLE.BIN\S-1-5-20
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-1862361349-3501387422-1277301654-1000
Deleted ! E:\$RECYCLE.BIN\S-1-5-20
Deleted ! E:\$RECYCLE.BIN\S-1-5-21-1862361349-3501387422-1277301654-1000
Deleted ! E:\$RECYCLE.BIN\S-1-5-21-1862361349-3501387422-1277301654-501

(!) Temporary files deleted.


################## | Registry |

Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

################## | Mountpoints2 |


################## | Listing |

[06/10/2011 - 20:14:52 | D ] C:\$RECYCLE.BIN
[13/10/2010 - 14:26:55 | D ] C:\.config
[13/10/2010 - 14:26:55 | D ] C:\.local
[31/10/2009 - 20:42:37 | D ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[17/07/2008 - 10:41:30 | N | 8192] C:\BOOTSECT.BAK
[18/09/2006 - 23:43:37 | N | 10] C:\config.sys
[02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings
[06/10/2011 - 10:18:11 | ASH | 3219120128] C:\hiberfil.sys
[17/07/2008 - 11:23:04 | D ] C:\Intel
[17/07/2008 - 12:12:04 | RD ] C:\MSOCache
[07/02/2011 - 18:51:46 | D ] C:\My Video
[16/12/2010 - 15:59:40 | D ] C:\MyHeritage
[02/07/2011 - 20:03:41 | N | 268151] C:\P1005.log
[06/10/2011 - 10:18:09 | ASH | 3532713984] C:\pagefile.sys
[26/08/2011 - 21:29:43 | D ] C:\Program Files
[06/10/2011 - 10:41:12 | D ] C:\ProgramData
[17/07/2008 - 11:37:45 | N | 651] C:\RHDSetup.log
[21/07/2011 - 22:00:08 | N | 1147] C:\rkill.log
[22/07/2011 - 22:53:53 | D ] C:\rsit
[17/07/2008 - 11:45:01 | N | 86] C:\setup.log
[03/02/2009 - 12:41:10 | N | 335] C:\SWSTAMP.TXT
[06/10/2011 - 10:35:16 | SHD ] C:\System Volume Information
[06/10/2011 - 17:39:53 | N | 76450] C:\TDSSKiller.2.6.5.0_06.10.2011_17.38.52_log.txt
[06/10/2011 - 19:34:33 | N | 76450] C:\TDSSKiller.2.6.5.0_06.10.2011_17.41.03_log.txt
[22/09/2009 - 20:16:20 | D ] C:\Toshiba
[28/10/2009 - 11:39:54 | D ] C:\TRANSLAT
[22/07/2011 - 21:41:52 | D ] C:\Uninstall
[06/10/2011 - 20:14:52 | D ] C:\UsbFix
[06/10/2011 - 20:13:28 | A | 3516] C:\UsbFix.txt
[25/09/2009 - 20:57:56 | D ] C:\Users
[06/10/2011 - 10:51:02 | D ] C:\Windows
[17/07/2008 - 12:18:20 | D ] C:\Works
[03/02/2009 - 11:21:24 | T | 25592] C:\_wdsuef.dmp
[10/07/2011 - 22:38:16 | D ] D:\lomo
[25/09/2011 - 09:58:30 | N | 117737] D:\RyanairBoardingPass(1).pdf
[24/06/2011 - 18:13:42 | D ] D:\Londýn
[03/07/2011 - 06:07:12 | D ] D:\Pictures
[03/03/2011 - 11:01:18 | D ] D:\English is easy
[08/06/2010 - 22:32:36 | D ] D:\UCM-Bc1
[15/06/2011 - 16:14:54 | D ] D:\UCM-Bc2
[03/07/2011 - 06:07:00 | D ] D:\net
[03/07/2011 - 05:41:08 | D ] D:\Happiness in words
[22/06/2011 - 16:40:20 | D ] D:\happiness
[21/07/2011 - 22:40:04 | N | 27141] D:\combo.txt
[06/10/2011 - 20:14:52 | D ] E:\$RECYCLE.BIN
[05/08/2011 - 07:44:17 | D ] E:\271cd0d711514f6bee2c247a77bc3708
[02/10/2011 - 23:10:58 | D ] E:\Filmy
[05/09/2001 - 21:00:58 | N | 1700352] E:\gdiplus.dll
[23/09/2009 - 04:12:27 | D ] E:\HDDRecovery
[24/06/2011 - 17:59:14 | D ] E:\Hudba
[22/02/2011 - 13:06:04 | D ] E:\kamera.strih
[24/06/2011 - 18:22:43 | D ] E:\OA-SŠ
[24/06/2011 - 18:05:52 | D ] E:\Picasa3 filmy
[24/06/2011 - 17:59:25 | D ] E:\Programy
[22/09/2009 - 19:15:12 | SHD ] E:\System Volume Information
[22/07/2011 - 19:28:02 | D ] E:\UCM
[27/08/2011 - 10:48:38 | D ] E:\uk
[24/06/2011 - 18:14:49 | D ] E:\Video
[24/06/2011 - 18:02:44 | D ] E:\Z (C)

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
D:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
E:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_DOMINIKA-PC.zip
http://eldesaparecido.com/support.php
Thank you for your contribution.

################## | E.O.F |

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 19:39
od vyosek
:arrow: Znovu spusťte Usbfix a zvolte možnost Uninstall.

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: A melo by byt cisto, co PC :???:

Re: vypinanie pc z vírusu

Napsal: 06 říj 2011 21:24
od Dominika Polakova
pc? no dala som znovu ten kaspersky a už mi nevyhladalo žiadne vírusy..ale neviem načo mi je potom ten avast! ked moj pc aj tak napadaju virusy..cloveka to už nebavi..to asi ja mam také "stastie" len na napadanie pc...