Prosím o kontrolu logu
Napsal: 30 črc 2010 17:39
Chtěl bych poprosit o kontrolu logu, mám problém se spuštěním WIN XP. Děkuji
SmallARK
================================================================
[R]NtClose -> D:\windows\system32\drivers\aswSP.SYS
[R]NtCreateFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtCreateKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtCreateProcess -> D:\windows\system32\drivers\SbFw.sys
[R]NtCreateProcessEx -> D:\windows\system32\drivers\SbFw.sys
[R]NtCreateThread -> D:\windows\system32\drivers\SbFw.sys
[R]NtDeleteFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtDeleteKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtDeleteValueKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtDuplicateObject -> D:\windows\system32\drivers\aswSP.SYS
[R]NtLoadDriver -> D:\windows\system32\drivers\sbhips.sys
[R]NtMapViewOfSection -> D:\windows\system32\drivers\sbhips.sys
[R]NtOpenFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtOpenKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtOpenProcess -> D:\windows\system32\drivers\aswSP.SYS
[R]NtOpenThread -> D:\windows\system32\drivers\aswSP.SYS
[R]NtQueryValueKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtRenameKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtRestoreKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtResumeThread -> D:\windows\system32\drivers\SbFw.sys
[R]NtSetInformationFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtSetValueKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtWriteFile -> D:\windows\system32\drivers\SbFw.sys
MBR ROOTKIT DETECTED!
Běžící procesy
================================================================
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[R] AvastUI.exe
Spouští se po startu HKLM Run [avast5]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[R] schedhlp.exe
Spouští se po startu HKLM Run [Acronis Scheduler2 Service]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
Po spuštění
================================================================
HKCU Run
|_ [X][SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
HKLM Run
|_ [R][avast5] D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
|_ [X][ATIModeChange] Ati2mdxx.exe (Soubor nenalezen)
|_ [X][KernelFaultCheck] D:\windows\system32\dumprep 0 -k (Soubor nenalezen)
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] D:\WINDOWS\INF\mplayer2.inf ,PerUserStub.NT
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] D:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] D:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] D:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM Winlogon Notify
|_ [X][AtiExtEvent] Ati2evxx.dll (Soubor nenalezen)
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[X] Ati HotKey Poller
|_ Cesta: D:\windows\System32\Ati2evxx.exe
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: Ati HotKey Poller
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Zastaveno
|_ Typ:
|_ Dependency:
[X] Java Quick Starter
|_ Cesta: D:\Program Files\Java\jre6\bin\jqs.exe -service -config D:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] AMD Processor Driver
|_ Cesta: D:\windows\System32\DRIVERS\AmdK8.sys
| |_ Výrobce: Advanced Micro Devices
| |_ Popis: AMD Processor Driver
| |_ MD5: 59301936898AE62245A6F09C0ABA9475
|
|_ Jméno: AmdK8
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver
|_ Cesta: D:\windows\System32\DRIVERS\Rtenicxp.sys
| |_ Výrobce: Realtek Semiconductor Corporation
| |_ Popis: Realtek 10/100/1000 NDIS 5.1 Driver
| |_ MD5: BB0AE2171F08129F4F3FF9DF20FFBF89
|
|_ Jméno: RTLE8023xp
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] SVKP
|_ Cesta: D:\windows\System32\SVKP.sys
| |_ Výrobce: AntiCracking
| |_ Popis: SVKP driver for NT
| |_ MD5: F05028B163B92C302A74409D683AC9B0
|
|_ Jméno: SVKP
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (1176) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (1304) svchost.exe 0.0.0.0:1026 LISTENING
TCP (4) Systém 0.0.0.0:1028 LISTENING
TCP (456) SbPFCl.exe 0.0.0.0:1029 LISTENING
TCP (456) SbPFCl.exe 0.0.0.0:1031 LISTENING
TCP (1228) SbPFSvc.exe 0.0.0.0:1033 LISTENING
TCP (2908) firefox.exe 0.0.0.0:1049 LISTENING
TCP (2908) firefox.exe 0.0.0.0:1053 LISTENING
TCP (1760) AvastSvc.exe 0.0.0.0:1340 LISTENING
TCP (1760) AvastSvc.exe 0.0.0.0:2819 LISTENING
TCP (1552) svchost.exe 0.0.0.0:5000 LISTENING
TCP (1228) SbPFSvc.exe 0.0.0.0:44334 LISTENING
TCP (1228) SbPFSvc.exe 0.0.0.0:44501 LISTENING
TCP (456) SbPFCl.exe 127.0.0.1:1029 <-> 127.0.0.1:44334 ESTABLISHED
TCP (456) SbPFCl.exe 127.0.0.1:1031 <-> 127.0.0.1:1033 ESTABLISHED
TCP (1228) SbPFSvc.exe 127.0.0.1:1033 <-> 127.0.0.1:1031 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1048 LISTENING
TCP (2908) firefox.exe 127.0.0.1:1048 <-> 127.0.0.1:1049 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1049 <-> 127.0.0.1:1048 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1052 LISTENING
TCP (2908) firefox.exe 127.0.0.1:1052 <-> 127.0.0.1:1053 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1053 <-> 127.0.0.1:1052 ESTABLISHED
TCP (0) 127.0.0.1:2822 TIME_WAIT
TCP (0) 127.0.0.1:2824 TIME_WAIT
TCP (0) 127.0.0.1:2829 TIME_WAIT
TCP (0) 127.0.0.1:2831 TIME_WAIT
TCP (0) 127.0.0.1:2833 TIME_WAIT
TCP (0) 127.0.0.1:2836 TIME_WAIT
TCP (800) jqs.exe 127.0.0.1:5152 LISTENING
TCP (800) jqs.exe 127.0.0.1:5152 CLOSE_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (1228) SbPFSvc.exe 127.0.0.1:44334 <-> 127.0.0.1:1029 ESTABLISHED
TCP (0) 127.0.0.1:44501 TIME_WAIT
TCP (4) Systém 192.168.2.200:139 LISTENING
UDP (1176) svchost.exe 0.0.0.0:135 TIME_WAIT
UDP (4) Systém 0.0.0.0:445
UDP (988) lsass.exe 0.0.0.0:500
UDP (1516) svchost.exe 0.0.0.0:1025
UDP (1304) svchost.exe 0.0.0.0:1027
UDP (456) SbPFCl.exe 0.0.0.0:1030
UDP (456) SbPFCl.exe 0.0.0.0:1032
UDP (1516) svchost.exe 0.0.0.0:1057
UDP (1516) svchost.exe 0.0.0.0:1065
UDP (456) SbPFCl.exe 0.0.0.0:1975
UDP (1228) SbPFSvc.exe 0.0.0.0:44334
UDP (1304) svchost.exe 127.0.0.1:123
UDP (1552) svchost.exe 127.0.0.1:1900
UDP (1304) svchost.exe 192.168.2.200:123
UDP (4) Systém 192.168.2.200:137
UDP (4) Systém 192.168.2.200:138
UDP (1552) svchost.exe 192.168.2.200:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: 222AFED911CBF5F9A454ADEE53D31B30
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2908)
[?] nssdbm3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\nssdbm3.dll
|_ MD5: DCE543B6B3FF516BD65C1030E4B933FF
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2908)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: 10BED437023F93DD1AD8EFA80E71280F
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2908)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]
SmallARK
================================================================
[R]NtClose -> D:\windows\system32\drivers\aswSP.SYS
[R]NtCreateFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtCreateKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtCreateProcess -> D:\windows\system32\drivers\SbFw.sys
[R]NtCreateProcessEx -> D:\windows\system32\drivers\SbFw.sys
[R]NtCreateThread -> D:\windows\system32\drivers\SbFw.sys
[R]NtDeleteFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtDeleteKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtDeleteValueKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtDuplicateObject -> D:\windows\system32\drivers\aswSP.SYS
[R]NtLoadDriver -> D:\windows\system32\drivers\sbhips.sys
[R]NtMapViewOfSection -> D:\windows\system32\drivers\sbhips.sys
[R]NtOpenFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtOpenKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtOpenProcess -> D:\windows\system32\drivers\aswSP.SYS
[R]NtOpenThread -> D:\windows\system32\drivers\aswSP.SYS
[R]NtQueryValueKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtRenameKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtRestoreKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtResumeThread -> D:\windows\system32\drivers\SbFw.sys
[R]NtSetInformationFile -> D:\windows\system32\drivers\SbFw.sys
[R]NtSetValueKey -> D:\windows\system32\drivers\aswSP.SYS
[R]NtWriteFile -> D:\windows\system32\drivers\SbFw.sys
MBR ROOTKIT DETECTED!
Běžící procesy
================================================================
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[R] AvastUI.exe
Spouští se po startu HKLM Run [avast5]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[R] schedhlp.exe
Spouští se po startu HKLM Run [Acronis Scheduler2 Service]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
Po spuštění
================================================================
HKCU Run
|_ [X][SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
HKLM Run
|_ [R][avast5] D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
|_ [X][ATIModeChange] Ati2mdxx.exe (Soubor nenalezen)
|_ [X][KernelFaultCheck] D:\windows\system32\dumprep 0 -k (Soubor nenalezen)
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] D:\WINDOWS\INF\mplayer2.inf ,PerUserStub.NT
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] D:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] D:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] D:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM Winlogon Notify
|_ [X][AtiExtEvent] Ati2evxx.dll (Soubor nenalezen)
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[X] Ati HotKey Poller
|_ Cesta: D:\windows\System32\Ati2evxx.exe
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: Ati HotKey Poller
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Zastaveno
|_ Typ:
|_ Dependency:
[X] Java Quick Starter
|_ Cesta: D:\Program Files\Java\jre6\bin\jqs.exe -service -config D:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] AMD Processor Driver
|_ Cesta: D:\windows\System32\DRIVERS\AmdK8.sys
| |_ Výrobce: Advanced Micro Devices
| |_ Popis: AMD Processor Driver
| |_ MD5: 59301936898AE62245A6F09C0ABA9475
|
|_ Jméno: AmdK8
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver
|_ Cesta: D:\windows\System32\DRIVERS\Rtenicxp.sys
| |_ Výrobce: Realtek Semiconductor Corporation
| |_ Popis: Realtek 10/100/1000 NDIS 5.1 Driver
| |_ MD5: BB0AE2171F08129F4F3FF9DF20FFBF89
|
|_ Jméno: RTLE8023xp
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] SVKP
|_ Cesta: D:\windows\System32\SVKP.sys
| |_ Výrobce: AntiCracking
| |_ Popis: SVKP driver for NT
| |_ MD5: F05028B163B92C302A74409D683AC9B0
|
|_ Jméno: SVKP
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (1176) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (1304) svchost.exe 0.0.0.0:1026 LISTENING
TCP (4) Systém 0.0.0.0:1028 LISTENING
TCP (456) SbPFCl.exe 0.0.0.0:1029 LISTENING
TCP (456) SbPFCl.exe 0.0.0.0:1031 LISTENING
TCP (1228) SbPFSvc.exe 0.0.0.0:1033 LISTENING
TCP (2908) firefox.exe 0.0.0.0:1049 LISTENING
TCP (2908) firefox.exe 0.0.0.0:1053 LISTENING
TCP (1760) AvastSvc.exe 0.0.0.0:1340 LISTENING
TCP (1760) AvastSvc.exe 0.0.0.0:2819 LISTENING
TCP (1552) svchost.exe 0.0.0.0:5000 LISTENING
TCP (1228) SbPFSvc.exe 0.0.0.0:44334 LISTENING
TCP (1228) SbPFSvc.exe 0.0.0.0:44501 LISTENING
TCP (456) SbPFCl.exe 127.0.0.1:1029 <-> 127.0.0.1:44334 ESTABLISHED
TCP (456) SbPFCl.exe 127.0.0.1:1031 <-> 127.0.0.1:1033 ESTABLISHED
TCP (1228) SbPFSvc.exe 127.0.0.1:1033 <-> 127.0.0.1:1031 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1048 LISTENING
TCP (2908) firefox.exe 127.0.0.1:1048 <-> 127.0.0.1:1049 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1049 <-> 127.0.0.1:1048 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1052 LISTENING
TCP (2908) firefox.exe 127.0.0.1:1052 <-> 127.0.0.1:1053 ESTABLISHED
TCP (2908) firefox.exe 127.0.0.1:1053 <-> 127.0.0.1:1052 ESTABLISHED
TCP (0) 127.0.0.1:2822 TIME_WAIT
TCP (0) 127.0.0.1:2824 TIME_WAIT
TCP (0) 127.0.0.1:2829 TIME_WAIT
TCP (0) 127.0.0.1:2831 TIME_WAIT
TCP (0) 127.0.0.1:2833 TIME_WAIT
TCP (0) 127.0.0.1:2836 TIME_WAIT
TCP (800) jqs.exe 127.0.0.1:5152 LISTENING
TCP (800) jqs.exe 127.0.0.1:5152 CLOSE_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (0) 127.0.0.1:12080 TIME_WAIT
TCP (1228) SbPFSvc.exe 127.0.0.1:44334 <-> 127.0.0.1:1029 ESTABLISHED
TCP (0) 127.0.0.1:44501 TIME_WAIT
TCP (4) Systém 192.168.2.200:139 LISTENING
UDP (1176) svchost.exe 0.0.0.0:135 TIME_WAIT
UDP (4) Systém 0.0.0.0:445
UDP (988) lsass.exe 0.0.0.0:500
UDP (1516) svchost.exe 0.0.0.0:1025
UDP (1304) svchost.exe 0.0.0.0:1027
UDP (456) SbPFCl.exe 0.0.0.0:1030
UDP (456) SbPFCl.exe 0.0.0.0:1032
UDP (1516) svchost.exe 0.0.0.0:1057
UDP (1516) svchost.exe 0.0.0.0:1065
UDP (456) SbPFCl.exe 0.0.0.0:1975
UDP (1228) SbPFSvc.exe 0.0.0.0:44334
UDP (1304) svchost.exe 127.0.0.1:123
UDP (1552) svchost.exe 127.0.0.1:1900
UDP (1304) svchost.exe 192.168.2.200:123
UDP (4) Systém 192.168.2.200:137
UDP (4) Systém 192.168.2.200:138
UDP (1552) svchost.exe 192.168.2.200:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: 222AFED911CBF5F9A454ADEE53D31B30
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2908)
[?] nssdbm3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\nssdbm3.dll
|_ MD5: DCE543B6B3FF516BD65C1030E4B933FF
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2908)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: 10BED437023F93DD1AD8EFA80E71280F
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2908)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]