Podezření na rootkity
Napsal: 19 dub 2010 19:08
Dobrý den,
FW Zone Alarm zachytil cizí aplikace pokoušející se o přístup na internet. Použil jsem eset online scanner a potom AVG9 našli různou havěť trojany a viry. Vše co našli jsem odstranil. Programem a-sguared HiJackFree jsem odstrelil podezřele procesy a zakázal spuštění službám viz..
C:\DOCUME~1\root\LOCALS~1\Temp\VKVCIVFAT.exe
C:\DOCUME~1\root\LOCALS~1\Temp\BWIMPS.exe []
C:\DOCUME~1\root\LOCALS~1\Temp\CJTDEO.exe []
C:\DOCUME~1\root\LOCALS~1\Temp\IOXKV.exe []
V strtup files je konfigurační wininit.ini, který obsahuje další odkaz na havět exe soubor C:\DOCUME~1\root\LOCALS~1\Temp\utildel.exe
Pravděpodobně bude v pc nějaký rootkit.
Aktulální problémy:
------------------
Při restartu PC zatuhne.
Nelze přepnout do režimu hybernace.
log z Ristu
----------------------------------------------------------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by root at 2010-04-19 19:23:25
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (22%) free of 30 GB
Total RAM: 1535 MB (61% free)
======Scheduled tasks folder======
C:\WINDOWS\tasks\PandaUSBVaccine.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-04-19 1615200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2005-05-06 716800]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-11-10 761945]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2006-02-22 40960]
"Scheduler"=C:\WINDOWS\SMINST\Scheduler.exe [2006-02-15 892928]
"Logitech Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2004-12-10 49152]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-02-16 981384]
"MsmqIntCert"=regsvr32 /s mqrt.dll []
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-04-19 2064736]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-04-17 196608]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2006-01-30 88203]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
C:\Program Files\D-Tools\daemon.exe [2004-08-22 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDDHealth]
C:\Program Files\HDD Health\hddhealth.exe -wl []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2006-03-02 131072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\Sminst\Recguard.exe [2005-12-20 1187840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
C:\WINDOWS\Creator\Remind_XP.exe [2006-01-23 802816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Cisco Systems VPN Client.lnk]
C:\PROGRA~1\CISCOS~1\VPNCLI~1\vpngui.exe [2006-04-20 1528880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^forteManager.lnk]
C:\PROGRA~1\LGSOFT~1\FORTEM~1\bin\Monitor.exe [2008-03-27 1126400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^root^Nabídka Start^Programy^Po spuštění^Picture Motion Browser Media Check Tool.lnk]
H:\MY_WORD\SONY\SONY_P~1\PMBCore\SPUVOL~1.EXE [2007-11-27 385024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"OracleServiceZMVS"=3
"OracleOraHome81TNSListener"=3
"OracleOraHome81PagingServer"=3
"OracleOraHome81HTTPServer"=3
"OracleOraHome81DataGatherer"=3
"OracleOraHome81CMan"=3
"OracleOraHome81CMAdmin"=3
"OracleOraHome81ClientCache"=3
"OracleOraHome81Agent"=3
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-01-22 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-04-15 12464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##192.168.100.4#psion]
shell\Auto\command - RECYCLER\usbdriver.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\usbdriver.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c579675-6f5a-11dd-82e7-0018de161019}]
shell\AutoRun\command - H:\wd_windows_tools\WDSetup.exe
======List of files/folders created in the last 1 months======
2010-04-18 23:40:12 ----D---- C:\rsit
2010-04-18 23:40:12 ----D---- C:\Program Files\trend micro
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer.ini
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer.exe
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer.dll
2010-04-15 23:57:13 ----A---- C:\WINDOWS\system32\RootkitReveal.txt
2010-04-15 18:12:06 ----D---- C:\Program Files\VS Revo Group
2010-04-15 17:46:39 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 17:45:56 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 17:44:35 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-04-15 17:40:38 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 17:40:29 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 18:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 18:00:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-14 00:13:00 ----D---- C:\WINDOWS\CSC
2010-04-14 00:12:49 ----A---- C:\WINDOWS\ntbtlog.txt
2010-04-13 22:24:31 ----HD---- C:\$AVG
2010-04-13 22:23:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\avg9
2010-04-06 22:40:31 ----D---- C:\Documents and Settings\root\Data aplikací\Foxit
======List of files/folders modified in the last 1 months======
2010-04-19 19:22:42 ----D---- C:\WINDOWS\SMINST
2010-04-19 19:22:41 ----D---- C:\WINDOWS\Temp
2010-04-19 19:22:25 ----D---- C:\WINDOWS
2010-04-19 19:22:20 ----D---- C:\WINDOWS\system32
2010-04-19 19:20:38 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-19 19:19:43 ----D---- C:\WINDOWS\Prefetch
2010-04-19 19:19:07 ----D---- C:\WINDOWS\Internet Logs
2010-04-19 18:55:55 ----RD---- C:\Program Files
2010-04-19 18:50:41 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-19 18:46:52 ----HD---- C:\WINDOWS\inf
2010-04-19 18:46:52 ----D---- C:\WINDOWS\system32\drivers
2010-04-19 18:46:52 ----D---- C:\WINDOWS\system32\CatRoot
2010-04-19 18:46:40 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-19 00:01:54 ----D---- C:\WINDOWS\system32\NtmsData
2010-04-15 22:34:57 ----SHD---- C:\System Volume Information
2010-04-15 20:05:17 ----D---- C:\WINDOWS\SoftwareDistribution
2010-04-15 19:44:53 ----D---- C:\temp
2010-04-15 19:15:14 ----SHD---- C:\WINDOWS\Installer
2010-04-15 19:15:12 ----SD---- C:\Documents and Settings\root\Data aplikací\Microsoft
2010-04-15 18:41:42 ----D---- C:\Program Files\Runtime Software
2010-04-15 18:38:18 ----D---- C:\Program Files\Common Files
2010-04-15 18:38:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\BioWare
2010-04-15 18:20:47 ----D---- C:\Program Files\Common Files\Real
2010-04-15 18:08:24 ----D---- C:\Program Files\AdVantage
2010-04-15 18:06:56 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-04-15 17:47:14 ----A---- C:\WINDOWS\imsins.BAK
2010-04-15 17:47:06 ----RSHD---- C:\WINDOWS\system32\dllcache
2010-04-15 17:46:06 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-15 17:40:16 ----D---- C:\WINDOWS\ie8updates
2010-04-06 22:40:16 ----D---- C:\Program Files\Foxit Software
2010-04-06 22:39:27 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-06 22:38:22 ----D---- C:\SwSetup
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-06 17:57:20 ----D---- C:\Program Files\Mozilla Firefox
2010-04-01 06:47:32 ----D---- C:\Program Files\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-04-15 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-04-15 29512]
R1 AvgTdiX;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-04-19 242896]
R1 eabfiltr;eabfiltr; C:\WINDOWS\system32\DRIVERS\eabfiltr.sys [2005-09-19 7808]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\WINDOWS\System32\Drivers\Uim_IM.sys [2008-01-17 131456]
R1 UimBus;Universal Image Mounter Controller; C:\WINDOWS\system32\DRIVERS\UimBus.sys [2008-01-17 32352]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-02-16 353672]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 CVPNDRVA;Cisco Systems IPsec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R3 Accelerometer;Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2006-01-10 22016]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-02-28 176128]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-01-30 1120352]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-01-22 2845696]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (AES2500); C:\WINDOWS\system32\DRIVERS\ATSwpDrv.sys [2006-03-10 130048]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2006-02-09 142720]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2006-02-15 401664]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2006-02-15 30363]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-02-15 1342570]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2006-02-16 57096]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2005-06-29 110080]
R3 GTIPCI21;GTIPCI21; C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 87936]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2005-09-19 9344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IFXTPM;IFXTPM; C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-06-10 35968]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2004-12-10 13056]
R3 LHidKe;Logitech SetPoint HID Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidKE.Sys [2004-12-10 24704]
R3 LHidUsbK;Logitech SetPoint USB Receiver device driver; C:\WINDOWS\System32\Drivers\LHidUsbK.Sys [2004-12-10 36480]
R3 LMouKE;Logitech SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2004-12-10 68992]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MQAC;Message Queuing access control; \??\C:\WINDOWS\system32\drivers\mqac.sys []
R3 RMCAST;Reliable Multicast Protocol driver; \??\C:\WINDOWS\system32\drivers\RMCast.sys []
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-11-10 191936]
R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-09-20 162432]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys [2006-01-19 1428096]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\adusbser.sys [2006-10-23 93440]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 Axtmvflt;Axesstel USB Filter Service; C:\WINDOWS\system32\DRIVERS\Axtmvflt.sys [2007-03-22 3456]
S3 Axtmvmdm;Axesstel USB Modem; C:\WINDOWS\system32\DRIVERS\Axtmvmdm.sys [2007-03-26 40064]
S3 Axtmvprt;Axesstel Diagnostic Port; C:\WINDOWS\System32\Drivers\Axtmvprt.sys [2007-03-26 38784]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2006-02-15 148168]
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2005-05-17 5315]
S3 eabusb;eabusb; C:\WINDOWS\system32\DRIVERS\eabusb.sys [2005-09-19 5760]
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2010-04-18 68961]
S3 LGDDCDevice;LGDDCDevice; \??\C:\Program Files\LG Soft India\forteManager\bin\I2CDriver.sys []
S3 LGII2CDevice;LGII2CDevice; \??\C:\Program Files\LG Soft India\forteManager\bin\PII2CDriver.sys []
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
S3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2001-10-24 35913]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-14 12800]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-01-22 512000]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-04-15 308064]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-02-15 258103]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2006-04-20 1520688]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-01-10 98304]
R2 MSMQ;Message Queuing; C:\WINDOWS\system32\mqsvc.exe [2008-04-14 4608]
R2 MSMQTriggers;Message Queuing Triggers; C:\WINDOWS\system32\mqtgsvc.exe [2008-04-14 117248]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-02-16 2402184]
S2 PCA;PC Angel; C:\WINDOWS\SMINST\PCAngel.exe [2006-01-12 294912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 BWIMPS;BWIMPS; C:\DOCUME~1\root\LOCALS~1\Temp\BWIMPS.exe []
S4 CJTDEO;CJTDEO; C:\DOCUME~1\root\LOCALS~1\Temp\CJTDEO.exe []
S4 IOXKV;IOXKV; C:\DOCUME~1\root\LOCALS~1\Temp\IOXKV.exe []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 OBVCAJPHRR;OBVCAJPHRR; C:\DOCUME~1\root\LOCALS~1\Temp\OBVCAJPHRR.exe []
S4 OracleOraHome81Agent;OracleOraHome81Agent; C:\oracle\ora81\bin\dbsnmp.exe [2000-11-11 246332]
S4 OracleOraHome81ClientCache;OracleOraHome81ClientCache; C:\oracle\ora81\BIN\ONRSD.EXE [2000-10-19 411244]
S4 OracleOraHome81CMAdmin;OracleOraHome81CMAdmin; C:\oracle\ora81\BIN\CMADMIN.EXE [2000-10-19 172680]
S4 OracleOraHome81CMan;OracleOraHome81CMan; C:\oracle\ora81\BIN\CMGW.EXE [2000-10-19 179836]
S4 OracleOraHome81DataGatherer;OracleOraHome81DataGatherer; C:\oracle\ora81\bin\vppdc.exe [2000-11-11 170724]
S4 OracleOraHome81HTTPServer;OracleOraHome81HTTPServer; C:\oracle\ora81\Apache\Apache\Apache.exe [2000-11-09 3584]
S4 OracleOraHome81PagingServer;OracleOraHome81PagingServer; C:\oracle\ora81/bin/pagntsrv.exe [2009-04-10 52224]
S4 OracleOraHome81TNSListener;OracleOraHome81TNSListener; C:\oracle\ora81\BIN\TNSLSNR []
S4 OracleServiceZMVS;OracleServiceZMVS; c:\oracle\ora81\bin\ORACLE.EXE [2000-11-05 14531344]
S4 VKVCIVFAT;VKVCIVFAT; C:\DOCUME~1\root\LOCALS~1\Temp\VKVCIVFAT.exe []
-----------------EOF-----------------
Prosím o pomoc.
FW Zone Alarm zachytil cizí aplikace pokoušející se o přístup na internet. Použil jsem eset online scanner a potom AVG9 našli různou havěť trojany a viry. Vše co našli jsem odstranil. Programem a-sguared HiJackFree jsem odstrelil podezřele procesy a zakázal spuštění službám viz..
C:\DOCUME~1\root\LOCALS~1\Temp\VKVCIVFAT.exe
C:\DOCUME~1\root\LOCALS~1\Temp\BWIMPS.exe []
C:\DOCUME~1\root\LOCALS~1\Temp\CJTDEO.exe []
C:\DOCUME~1\root\LOCALS~1\Temp\IOXKV.exe []
V strtup files je konfigurační wininit.ini, který obsahuje další odkaz na havět exe soubor C:\DOCUME~1\root\LOCALS~1\Temp\utildel.exe
Pravděpodobně bude v pc nějaký rootkit.
Aktulální problémy:
------------------
Při restartu PC zatuhne.
Nelze přepnout do režimu hybernace.
log z Ristu
----------------------------------------------------------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by root at 2010-04-19 19:23:25
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (22%) free of 30 GB
Total RAM: 1535 MB (61% free)
======Scheduled tasks folder======
C:\WINDOWS\tasks\PandaUSBVaccine.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-04-19 1615200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2005-05-06 716800]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-11-10 761945]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2006-02-22 40960]
"Scheduler"=C:\WINDOWS\SMINST\Scheduler.exe [2006-02-15 892928]
"Logitech Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2004-12-10 49152]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-02-16 981384]
"MsmqIntCert"=regsvr32 /s mqrt.dll []
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-04-19 2064736]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-04-17 196608]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2006-01-30 88203]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
C:\Program Files\D-Tools\daemon.exe [2004-08-22 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDDHealth]
C:\Program Files\HDD Health\hddhealth.exe -wl []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2006-03-02 131072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\Sminst\Recguard.exe [2005-12-20 1187840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
C:\WINDOWS\Creator\Remind_XP.exe [2006-01-23 802816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Cisco Systems VPN Client.lnk]
C:\PROGRA~1\CISCOS~1\VPNCLI~1\vpngui.exe [2006-04-20 1528880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^forteManager.lnk]
C:\PROGRA~1\LGSOFT~1\FORTEM~1\bin\Monitor.exe [2008-03-27 1126400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^root^Nabídka Start^Programy^Po spuštění^Picture Motion Browser Media Check Tool.lnk]
H:\MY_WORD\SONY\SONY_P~1\PMBCore\SPUVOL~1.EXE [2007-11-27 385024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"OracleServiceZMVS"=3
"OracleOraHome81TNSListener"=3
"OracleOraHome81PagingServer"=3
"OracleOraHome81HTTPServer"=3
"OracleOraHome81DataGatherer"=3
"OracleOraHome81CMan"=3
"OracleOraHome81CMAdmin"=3
"OracleOraHome81ClientCache"=3
"OracleOraHome81Agent"=3
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-01-22 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-04-15 12464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##192.168.100.4#psion]
shell\Auto\command - RECYCLER\usbdriver.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\usbdriver.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c579675-6f5a-11dd-82e7-0018de161019}]
shell\AutoRun\command - H:\wd_windows_tools\WDSetup.exe
======List of files/folders created in the last 1 months======
2010-04-18 23:40:12 ----D---- C:\rsit
2010-04-18 23:40:12 ----D---- C:\Program Files\trend micro
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer.ini
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer.exe
2010-04-18 22:26:15 ----A---- C:\WINDOWS\gmer.dll
2010-04-15 23:57:13 ----A---- C:\WINDOWS\system32\RootkitReveal.txt
2010-04-15 18:12:06 ----D---- C:\Program Files\VS Revo Group
2010-04-15 17:46:39 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 17:45:56 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 17:44:35 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-04-15 17:40:38 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 17:40:29 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 18:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 18:00:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-14 00:13:00 ----D---- C:\WINDOWS\CSC
2010-04-14 00:12:49 ----A---- C:\WINDOWS\ntbtlog.txt
2010-04-13 22:24:31 ----HD---- C:\$AVG
2010-04-13 22:23:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\avg9
2010-04-06 22:40:31 ----D---- C:\Documents and Settings\root\Data aplikací\Foxit
======List of files/folders modified in the last 1 months======
2010-04-19 19:22:42 ----D---- C:\WINDOWS\SMINST
2010-04-19 19:22:41 ----D---- C:\WINDOWS\Temp
2010-04-19 19:22:25 ----D---- C:\WINDOWS
2010-04-19 19:22:20 ----D---- C:\WINDOWS\system32
2010-04-19 19:20:38 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-19 19:19:43 ----D---- C:\WINDOWS\Prefetch
2010-04-19 19:19:07 ----D---- C:\WINDOWS\Internet Logs
2010-04-19 18:55:55 ----RD---- C:\Program Files
2010-04-19 18:50:41 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-19 18:46:52 ----HD---- C:\WINDOWS\inf
2010-04-19 18:46:52 ----D---- C:\WINDOWS\system32\drivers
2010-04-19 18:46:52 ----D---- C:\WINDOWS\system32\CatRoot
2010-04-19 18:46:40 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-19 00:01:54 ----D---- C:\WINDOWS\system32\NtmsData
2010-04-15 22:34:57 ----SHD---- C:\System Volume Information
2010-04-15 20:05:17 ----D---- C:\WINDOWS\SoftwareDistribution
2010-04-15 19:44:53 ----D---- C:\temp
2010-04-15 19:15:14 ----SHD---- C:\WINDOWS\Installer
2010-04-15 19:15:12 ----SD---- C:\Documents and Settings\root\Data aplikací\Microsoft
2010-04-15 18:41:42 ----D---- C:\Program Files\Runtime Software
2010-04-15 18:38:18 ----D---- C:\Program Files\Common Files
2010-04-15 18:38:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\BioWare
2010-04-15 18:20:47 ----D---- C:\Program Files\Common Files\Real
2010-04-15 18:08:24 ----D---- C:\Program Files\AdVantage
2010-04-15 18:06:56 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-04-15 17:47:14 ----A---- C:\WINDOWS\imsins.BAK
2010-04-15 17:47:06 ----RSHD---- C:\WINDOWS\system32\dllcache
2010-04-15 17:46:06 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-15 17:40:16 ----D---- C:\WINDOWS\ie8updates
2010-04-06 22:40:16 ----D---- C:\Program Files\Foxit Software
2010-04-06 22:39:27 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-06 22:38:22 ----D---- C:\SwSetup
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-06 17:57:20 ----D---- C:\Program Files\Mozilla Firefox
2010-04-01 06:47:32 ----D---- C:\Program Files\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-04-15 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-04-15 29512]
R1 AvgTdiX;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-04-19 242896]
R1 eabfiltr;eabfiltr; C:\WINDOWS\system32\DRIVERS\eabfiltr.sys [2005-09-19 7808]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\WINDOWS\System32\Drivers\Uim_IM.sys [2008-01-17 131456]
R1 UimBus;Universal Image Mounter Controller; C:\WINDOWS\system32\DRIVERS\UimBus.sys [2008-01-17 32352]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-02-16 353672]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 CVPNDRVA;Cisco Systems IPsec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R3 Accelerometer;Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2006-01-10 22016]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-02-28 176128]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-01-30 1120352]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-01-22 2845696]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (AES2500); C:\WINDOWS\system32\DRIVERS\ATSwpDrv.sys [2006-03-10 130048]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2006-02-09 142720]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2006-02-15 401664]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2006-02-15 30363]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-02-15 1342570]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2006-02-16 57096]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2005-06-29 110080]
R3 GTIPCI21;GTIPCI21; C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 87936]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2005-09-19 9344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IFXTPM;IFXTPM; C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-06-10 35968]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2004-12-10 13056]
R3 LHidKe;Logitech SetPoint HID Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidKE.Sys [2004-12-10 24704]
R3 LHidUsbK;Logitech SetPoint USB Receiver device driver; C:\WINDOWS\System32\Drivers\LHidUsbK.Sys [2004-12-10 36480]
R3 LMouKE;Logitech SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2004-12-10 68992]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MQAC;Message Queuing access control; \??\C:\WINDOWS\system32\drivers\mqac.sys []
R3 RMCAST;Reliable Multicast Protocol driver; \??\C:\WINDOWS\system32\drivers\RMCast.sys []
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-11-10 191936]
R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-09-20 162432]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys [2006-01-19 1428096]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\adusbser.sys [2006-10-23 93440]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 Axtmvflt;Axesstel USB Filter Service; C:\WINDOWS\system32\DRIVERS\Axtmvflt.sys [2007-03-22 3456]
S3 Axtmvmdm;Axesstel USB Modem; C:\WINDOWS\system32\DRIVERS\Axtmvmdm.sys [2007-03-26 40064]
S3 Axtmvprt;Axesstel Diagnostic Port; C:\WINDOWS\System32\Drivers\Axtmvprt.sys [2007-03-26 38784]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2006-02-15 148168]
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2005-05-17 5315]
S3 eabusb;eabusb; C:\WINDOWS\system32\DRIVERS\eabusb.sys [2005-09-19 5760]
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2010-04-18 68961]
S3 LGDDCDevice;LGDDCDevice; \??\C:\Program Files\LG Soft India\forteManager\bin\I2CDriver.sys []
S3 LGII2CDevice;LGII2CDevice; \??\C:\Program Files\LG Soft India\forteManager\bin\PII2CDriver.sys []
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
S3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2001-10-24 35913]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-14 12800]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-01-22 512000]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-04-15 308064]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-02-15 258103]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2006-04-20 1520688]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-01-10 98304]
R2 MSMQ;Message Queuing; C:\WINDOWS\system32\mqsvc.exe [2008-04-14 4608]
R2 MSMQTriggers;Message Queuing Triggers; C:\WINDOWS\system32\mqtgsvc.exe [2008-04-14 117248]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-02-16 2402184]
S2 PCA;PC Angel; C:\WINDOWS\SMINST\PCAngel.exe [2006-01-12 294912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 BWIMPS;BWIMPS; C:\DOCUME~1\root\LOCALS~1\Temp\BWIMPS.exe []
S4 CJTDEO;CJTDEO; C:\DOCUME~1\root\LOCALS~1\Temp\CJTDEO.exe []
S4 IOXKV;IOXKV; C:\DOCUME~1\root\LOCALS~1\Temp\IOXKV.exe []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 OBVCAJPHRR;OBVCAJPHRR; C:\DOCUME~1\root\LOCALS~1\Temp\OBVCAJPHRR.exe []
S4 OracleOraHome81Agent;OracleOraHome81Agent; C:\oracle\ora81\bin\dbsnmp.exe [2000-11-11 246332]
S4 OracleOraHome81ClientCache;OracleOraHome81ClientCache; C:\oracle\ora81\BIN\ONRSD.EXE [2000-10-19 411244]
S4 OracleOraHome81CMAdmin;OracleOraHome81CMAdmin; C:\oracle\ora81\BIN\CMADMIN.EXE [2000-10-19 172680]
S4 OracleOraHome81CMan;OracleOraHome81CMan; C:\oracle\ora81\BIN\CMGW.EXE [2000-10-19 179836]
S4 OracleOraHome81DataGatherer;OracleOraHome81DataGatherer; C:\oracle\ora81\bin\vppdc.exe [2000-11-11 170724]
S4 OracleOraHome81HTTPServer;OracleOraHome81HTTPServer; C:\oracle\ora81\Apache\Apache\Apache.exe [2000-11-09 3584]
S4 OracleOraHome81PagingServer;OracleOraHome81PagingServer; C:\oracle\ora81/bin/pagntsrv.exe [2009-04-10 52224]
S4 OracleOraHome81TNSListener;OracleOraHome81TNSListener; C:\oracle\ora81\BIN\TNSLSNR []
S4 OracleServiceZMVS;OracleServiceZMVS; c:\oracle\ora81\bin\ORACLE.EXE [2000-11-05 14531344]
S4 VKVCIVFAT;VKVCIVFAT; C:\DOCUME~1\root\LOCALS~1\Temp\VKVCIVFAT.exe []
-----------------EOF-----------------
Prosím o pomoc.