Stránka 1 z 2

kontrola logu, děkuji

Napsal: 16 kvě 2011 20:04
od lluckyn
Windows Vista SP 0 (build 7600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.7600.16385 (win7_rtm.090713-1255)
Log vygenerován: 16.5.2011 20:56:50
================================================================

Běžící procesy
================================================================

C:\PROGRAM FILES\PINNACLE\SHARED FILES\PROGRAMS\USBTIP\USBTIP.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQBAM08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQGPC01.EXE
C:\PROGRAM FILES\REGCLEANER\REGCLEANR.EXE
C:\USERS\LUCKA\SOUEH.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE
(rootkit?) audiodg.exe

Scanner
================================================================
[S] smss.exe
Podvržená cesta modulu: (00110000) [DLL] ?

[S] csrss.exe
Podvržená cesta modulu: (00100000) [DLL] ?

[S] csrss.exe
Podvržená cesta modulu: (00100000) [DLL] ?

[S] svchost.exe
Podvržená cesta modulu: (00010000) [DLL] ?

[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
Podvržená cesta modulu: (00010000) [DLL] ?

[R] egui.exe
Spouští se po startu HKLM Run [egui]

[S] rundll32.exe
Spouští se po startu HKLM Run [NvSvc]

[R] hpwuSchd2.exe
Spouští se po startu HKLM Run [HP Software Update]

[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]

[?] USBTip.exe
Spouští se po startu HKLM Run [USBToolTip]
Soubor 14%

[R] DTLite.exe
Spouští se po startu HKCU Run [DAEMON Tools Lite]

[R] NMBgMonitor.exe
Spouští se po startu HKCU Run [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

[R] hpqtra08.exe
Spouští se po startu Po spuštění []

[?] hpqste08.exe
Soubor 7%

[?] hpqbam08.exe
Soubor 14%

[?] hpqgpc01.exe
Soubor 7%

[?] RegCleanr.exe
EntryPoint v sekci: CODE
|_ Celkový počet sekcí: 8
Soubor 63%

[R] firefox.exe
Podvržená cesta modulu: (00010000) [DLL] ?

[?] soueh.exe
Bez výrobce
Spouští se po startu HKCU Run [soueh]
Soubor 14%

[?] sp_rsser.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Nemá okno
Soubor 70%

[R] SpywareTerminator.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9

[R] audiodg.exe
Proces se nepodařilo otevřít
ROOTKIT? Skrytá cesta
Spouští se po startu HKCU Run [DAEMON Tools Lite]
Nelze otevřít


Po spuštění
================================================================

HKCU Run
|_ [R][DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun
|_ [?][soueh] C:\Users\Lucka\soueh.exe /H

HKLM Run
|_ [?][NvSvc] C:\Windows\system32\nvsvc.dll ,nvsvcStart
|_ [?][NvCplDaemon] C:\Windows\system32\NvCpl.dll ,NvStartup
|_ [?][NvMediaCenter] C:\Windows\system32\NvMcTray.dll ,NvTaskbarInit
|_ [R][egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice
|_ [?][USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe

HKLM RunOnce
|_ [R][Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

HKLM ShellServiceObjectDelayLoad
|_ [X][WebCheck] (Soubor nenalezen)

HKLM IC
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll


HKLM BHO
|_ [X][{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] (Soubor nenalezen)

Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] hpqcxs08
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP CUE Context Manager Objects
| |_ MD5: 0A3C6AA4A9FC38C20BA4EAC2C3351C05
|
|_ Jméno: hpqcxs08
|_ StartName: LocalSystem
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS

[?] Služba HP CUE DeviceDiscovery
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP CUE DeviceDiscovery Service
| |_ MD5: F3F72A2A86C22610BCA5439FA789DD52
|
|_ Jméno: hpqddsvc
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS

[?] Net Driver HPZ12
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\HPZinw12.dll
| |_ Výrobce: Hewlett-Packard
| |_ Popis: Dot4Net Module
| |_ MD5: 510C138564486FF926A3F773205C63D1
|
|_ Jméno: Net Driver HPZ12
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:

[?] Pml Driver HPZ12
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\HPZipm12.dll
| |_ Výrobce: Hewlett-Packard
| |_ Popis: PmlDrv Module
| |_ MD5: 37E5E8FFBAD35605DAEEC3224EA0E465
|
|_ Jméno: Pml Driver HPZ12
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:

[!] Spyware Terminator Realtime Shield Service
|_ Cesta: C:\Program Files\Spyware Terminator\sp_rsser.exe
| |_ Výrobce: Crawler.com
| |_ Popis: Spyware Terminator Realtime Shield Service
| |_ MD5: C5C51BF81B6F5B787F6A69F70518C37C
|
|_ Jméno: sp_rssrv
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:


Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] NDIS Miniport Driver for Atheros L2 Fast Ethernet - adaptér
|_ Cesta: C:\Windows\system32\DRIVERS\l260x86.sys
| |_ Výrobce: Atheros Communications, Inc.
| |_ Popis: Atheros L2 Fast Ethernet Controller ndis miniport driver
| |_ MD5: EE67F3634096D49DF6ED2D43DDABF290
|
|_ Jméno: Atc002
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:

[?] EIO
|_ Cesta: C:\Windows\system32\drivers\EIO.sys
| |_ Výrobce: ASUSTeK Computer Inc.
| |_ Popis: ASUS Kernel Mode Driver for NT
| |_ MD5: 6F41DA43AA4806A7BDBB2F9A8B05023E
|
|_ Jméno: EIO
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:

[?] Pinnacle Marvin Bus
|_ Cesta: C:\Windows\system32\DRIVERS\MarvinBus.sys
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: Pinnacle Marvin Discrete Bus Enumerator
| |_ MD5: A3E700D78EEC390F1208098CDCA5C6B6
|
|_ Jméno: MarvinBus
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:

[?] ATK0110 ACPI UTILITY
|_ Cesta: C:\Windows\system32\DRIVERS\ASACPI.sys
| |_ Výrobce:
| |_ Popis: ATK0110 ACPI Utility
| |_ MD5: DCDAAB8697A47894A554050CE18D0B56
|
|_ Jméno: MTsensor
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:

[?] nvlddmkm
|_ Cesta: C:\Windows\system32\DRIVERS\nvlddmkm.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Compatible Windows 2000 Miniport Driver, Version 100.65
| |_ MD5: D5EDB88C13863473B2314AA14364B140
|
|_ Jméno: nvlddmkm
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:

[?] sptd
|_ Cesta: C:\Windows\System32\Drivers\sptd.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: sptd
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:

[?] TAP-Win32 Adapter V9
|_ Cesta: C:\Windows\system32\DRIVERS\tap0901.sys
| |_ Výrobce: The OpenVPN Project
| |_ Popis: TAP-Win32 Virtual Network Driver
| |_ MD5: 11D34FC869F5BDA29949FE3858380894
|
|_ Jméno: tap0901
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:


Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] hpqddsvc.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
|_ MD5: F3F72A2A86C22610BCA5439FA789DD52
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1744)

[?] hpocxi08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll
|_ MD5: 331EEC127602FF5627C471C3D1E2CFF7
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1744)

[?] hpqcob08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
|_ MD5: 145788078F51416A7CA96038BD4C35DC
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1744)
|_ hpqtra08.exe (2536)
|_ hpqste08.exe (3252)

[?] hpqcxs08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
|_ MD5: 0A3C6AA4A9FC38C20BA4EAC2C3351C05
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1744)

[?] hpqddcmn.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll
|_ MD5: 7E53957E73BFB209D49932A9DDEBEDE4
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1744)
|_ hpqtra08.exe (2536)

[?] hpzinw12.dll
|_ Cesta: C:\Windows\System32\HPZinw12.dll
|_ MD5: 510C138564486FF926A3F773205C63D1
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ svchost.exe (1844)

[?] mfc80u.dll
|_ Cesta: C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\MFC80U.DLL
|_ MD5: 686B224B4987C22B153FBB545FEE9657
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ egui.exe (2304)

[?] hpqrif08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll
|_ MD5: 3C69CE161C7007E9AD53A325492D446A
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpqmif08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll
|_ MD5: B0A41262968DD6FCE3933527892D4A24
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpodio08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
|_ MD5: 2C0F29D95E964398FA02E9A7CE6309DB
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)
|_ hpqste08.exe (3252)

[?] hpqddusr.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddusr.dll
|_ MD5: 03211597018F96769F7F731039F692E1
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpqusg.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqusg.dll
|_ MD5: B4FEBBAC47297242F04EF7F14FE6DF99
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpotradd.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll
|_ MD5: D78036B2F1990527822CC274E8F8E611
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpquio08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll
|_ MD5: C0E1D09C01019F27F2B06BBA152CDB07
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpqtra08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
|_ MD5: 87814D70ADAB6837817BC6FB4DBEDDDD
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpqtao08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll
|_ MD5: DD1173E82083162858D1D4EAF43EC69B
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpotra08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll
|_ MD5: 8A03428D237E5A96DD6732F06CCEA660
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpotra08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc
|_ MD5: 1B131553022698F115E963157672F18F
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2536)

[?] hpqgpb01.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqgpb01.dll
|_ MD5: 347A39B69AC03B8F56D8807B989F5CA8
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqstp08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqstp08.rsc
|_ MD5: A516D2C3AD3837E0B3168C85F239E23D
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqssm08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqssm08.dll
|_ MD5: 9E438543222120696C04A39BFAC56FB6
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqsplh08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\HpqSplh08.dll
|_ MD5: 55CF0A197DC8972AC829B30ACAE00E5E
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqsem08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc
|_ MD5: CA7AC8091046956DF8510F5EABA6F9BE
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqwso08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqwso08.dll
|_ MD5: F0842CF3C0B33C07B2CA1692900F21B4
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqsti08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll
|_ MD5: 9F6258F4166AB24B4B681EB1ED44534C
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqstp08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqstp08.dll
|_ MD5: 0EE03D901B5DCD3941686B95FCC98C89
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3252)

[?] hpqgpreh.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqgpreh.dll
|_ MD5: CC190B07E357BCD40C2AFB57B9A67B7F
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqgpc01.exe (3520)

[?] hprbevst.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbevst.dll
|_ MD5: CBBAF06C2AC8882D239C8DC5BFA197FD
|_ Výrobce: Hewlett Packard
|_ Procesy
|_ hpqgpc01.exe (3520)

[?] hpneologging.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\hpNeoLogging.dll
|_ MD5: 32D8BE1860EFA6C2F5570D217CA75BEF
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (1800)

[?] atl80.dll
|_ Cesta: C:\Windows\winsxs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.dll
|_ MD5: 3E9A33113D663D8BD5ED38858E669652
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ firefox.exe (1800)

[?] hpswpoperation.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpSWPOperation.dll
|_ MD5: DDE8E0F31B5806F24D728B11778E4D6F
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (1800)

[?] hpxpmtl.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXPMTL.dll
|_ MD5: 151092A6AC1D654EF5733C657FE84DC5
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (1800)

[?] hpxpmtc.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXPMTC.dll
|_ MD5: B154750A0BB6F7605596D1552E204032
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (1800)

[?] hpxre.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\hpXRE.dll
|_ MD5: 4F0600DD0D8E9FA742654931B3D00925
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (1800)

[?] hpxrestub.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXREStub.dll
|_ MD5: 27F87473C96FE9EC6A71CD1F1BD2DCD3
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (1800)



================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]

Re: kontrola logu, děkuji

Napsal: 16 kvě 2011 20:34
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: kontrola logu, děkuji

Napsal: 16 kvě 2011 21:10
od lluckyn
bohužel po spuštění ComboFixu to chvíli nabíhá a pak se objeví modrá obrazovka a počítač se restartuje (nedostanu se k obrazovce s licenčními podmínkami) , tak nevim (rezidentní štít antispywaru jsem předtím vypnul)

Re: kontrola logu, děkuji

Napsal: 16 kvě 2011 21:13
od lluckyn
ještě mám v počítači ESET NOD a u toho jsem nic nevypínal..

Re: kontrola logu, děkuji

Napsal: 16 kvě 2011 21:20
od Rudy
lluckyn píše:ještě mám v počítači ESET NOD a u toho jsem nic nevypínal..
Vše, co má rezident, musí být vypnuto. Tzn. antivir, antspy a firewall (pokud máte).

Re: kontrola logu, děkuji

Napsal: 16 kvě 2011 21:26
od lluckyn
všechno jsem povypínal, ale zase to skočí na tu modrou obrazovku:( a restart

Re: kontrola logu, děkuji

Napsal: 16 kvě 2011 21:54
od Rudy
OK. Tak jinak Zkuste spustit TDSSKiller: http://support.kaspersky.com/downloads/ ... killer.exe .
- uložte na plochu.
- 2x klikněte na ikonu programu a spusťte
- dejte volbu Spustit kontrolu - pak potvrdte start sken
- pokud program najde infikovaný soubor, ukáže se Vám předvolená akce Cure, v tom případě potvrdte tlačítko Continue
- pokud bude chtít program restartovat počítač, klikněte na tlačítko Reboot Now
- pokud si restart nevyžádá, klikněte na tlačítko Report. Měl vy na Vás vyskočit log, obsah logu zkopírujte do svého topicu.
- pokud se log nezobrazí, je uložený ve Vašem kořenovém adresáři.

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 09:57
od lluckyn
TDSSKiller jsem spustil, poté to našlo infikovaný soubor, potvrdil jsem Continue a poté to chtělo restart.
Při restartu pořád to samé, modrá obrazovka...
V podstatě nemůžu udělat regulérní restart nebo vypnutí počítače.
Navíc na C:/ mně zmizel uživatelský účet je tam pouze Default a Veřejné.

Přikládám log z TDSSKilleru:

2011/05/17 10:46:34.0003 3608 TDSS rootkit removing tool 2.5.1.0 May 13 2011 13:20:29
2011/05/17 10:46:34.0825 3608 ================================================================================
2011/05/17 10:46:34.0825 3608 SystemInfo:
2011/05/17 10:46:34.0825 3608
2011/05/17 10:46:34.0825 3608 OS Version: 6.1.7600 ServicePack: 0.0
2011/05/17 10:46:34.0825 3608 Product type: Workstation
2011/05/17 10:46:34.0825 3608 ComputerName: LUCKA-PC
2011/05/17 10:46:34.0825 3608 UserName: Lucka
2011/05/17 10:46:34.0825 3608 Windows directory: C:\Windows
2011/05/17 10:46:34.0826 3608 System windows directory: C:\Windows
2011/05/17 10:46:34.0826 3608 Processor architecture: Intel x86
2011/05/17 10:46:34.0826 3608 Number of processors: 2
2011/05/17 10:46:34.0826 3608 Page size: 0x1000
2011/05/17 10:46:34.0826 3608 Boot type: Normal boot
2011/05/17 10:46:34.0826 3608 ================================================================================
2011/05/17 10:46:35.0221 3608 Initialize success
2011/05/17 10:46:48.0921 0108 ================================================================================
2011/05/17 10:46:48.0921 0108 Scan started
2011/05/17 10:46:48.0921 0108 Mode: Manual;
2011/05/17 10:46:48.0921 0108 ================================================================================
2011/05/17 10:46:56.0986 0108 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/05/17 10:46:57.0087 0108 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2011/05/17 10:46:57.0245 0108 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/05/17 10:46:57.0397 0108 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/05/17 10:46:57.0470 0108 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/05/17 10:46:57.0550 0108 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/05/17 10:46:57.0650 0108 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2011/05/17 10:46:57.0697 0108 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2011/05/17 10:46:57.0874 0108 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/05/17 10:46:57.0992 0108 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2011/05/17 10:46:58.0072 0108 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2011/05/17 10:46:58.0124 0108 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2011/05/17 10:46:58.0169 0108 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/05/17 10:46:58.0220 0108 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/05/17 10:46:58.0270 0108 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2011/05/17 10:46:58.0399 0108 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/05/17 10:46:58.0431 0108 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2011/05/17 10:46:59.0547 0108 appdrv01 (f951c27fe54e1b2b5ada9719289b4756) C:\Windows\system32\Drivers\appdrv01.sys
2011/05/17 10:46:59.0753 0108 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2011/05/17 10:46:59.0876 0108 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/05/17 10:46:59.0922 0108 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/05/17 10:47:00.0050 0108 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/17 10:47:00.0113 0108 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2011/05/17 10:47:00.0209 0108 Atc002 (ee67f3634096d49df6ed2d43ddabf290) C:\Windows\system32\DRIVERS\l260x86.sys
2011/05/17 10:47:00.0473 0108 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/05/17 10:47:00.0585 0108 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/05/17 10:47:00.0712 0108 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/05/17 10:47:00.0862 0108 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/05/17 10:47:00.0946 0108 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/17 10:47:00.0991 0108 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/05/17 10:47:01.0067 0108 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/05/17 10:47:01.0200 0108 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/05/17 10:47:01.0270 0108 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/05/17 10:47:01.0318 0108 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/05/17 10:47:01.0366 0108 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/05/17 10:47:01.0414 0108 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/05/17 10:47:01.0524 0108 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/17 10:47:01.0742 0108 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/17 10:47:01.0873 0108 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/05/17 10:47:01.0967 0108 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/05/17 10:47:02.0079 0108 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/05/17 10:47:02.0166 0108 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2011/05/17 10:47:02.0227 0108 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/05/17 10:47:02.0272 0108 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/05/17 10:47:02.0371 0108 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/05/17 10:47:02.0505 0108 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/05/17 10:47:02.0613 0108 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
2011/05/17 10:47:02.0734 0108 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/05/17 10:47:02.0778 0108 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/05/17 10:47:02.0930 0108 Dot4 (b5e479eb83707dd698f66953e922042c) C:\Windows\system32\DRIVERS\Dot4.sys
2011/05/17 10:47:03.0048 0108 Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2011/05/17 10:47:03.0106 0108 dot4usb (cf491ff38d62143203c065260567e2f7) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/05/17 10:47:03.0250 0108 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/05/17 10:47:03.0332 0108 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
2011/05/17 10:47:03.0474 0108 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/17 10:47:03.0631 0108 eamon (30372bcc67d63bee538cdfeca755d81c) C:\Windows\system32\DRIVERS\eamon.sys
2011/05/17 10:47:04.0097 0108 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/05/17 10:47:04.0208 0108 ehdrv (6504d6afb75fef830dd99e8c4235d54d) C:\Windows\system32\DRIVERS\ehdrv.sys
2011/05/17 10:47:04.0379 0108 EIO (6f41da43aa4806a7bdbb2f9a8b05023e) C:\Windows\system32\drivers\EIO.sys
2011/05/17 10:47:04.0561 0108 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/05/17 10:47:04.0659 0108 epfwwfpr (edce64430652f6a0bbccc348e2713fc3) C:\Windows\system32\DRIVERS\epfwwfpr.sys
2011/05/17 10:47:04.0720 0108 epmntdrv (539ca34fbc74ec366a0d751028c32a08) C:\Windows\system32\epmntdrv.sys
2011/05/17 10:47:04.0766 0108 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2011/05/17 10:47:04.0895 0108 EuGdiDrv (1f2f4ab15ce03ecc257feb2f6dc5a013) C:\Windows\system32\EuGdiDrv.sys
2011/05/17 10:47:04.0943 0108 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/05/17 10:47:04.0994 0108 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/05/17 10:47:05.0082 0108 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/17 10:47:05.0173 0108 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/05/17 10:47:05.0232 0108 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/05/17 10:47:05.0260 0108 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/17 10:47:05.0334 0108 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/05/17 10:47:05.0381 0108 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/05/17 10:47:05.0427 0108 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/17 10:47:05.0516 0108 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys
2011/05/17 10:47:05.0635 0108 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/05/17 10:47:05.0685 0108 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/05/17 10:47:05.0853 0108 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2011/05/17 10:47:05.0936 0108 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/17 10:47:05.0986 0108 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/05/17 10:47:06.0028 0108 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/05/17 10:47:06.0075 0108 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/05/17 10:47:06.0261 0108 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2011/05/17 10:47:06.0410 0108 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/05/17 10:47:06.0542 0108 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2011/05/17 10:47:06.0622 0108 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2011/05/17 10:47:06.0676 0108 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/17 10:47:06.0978 0108 iaStor (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\DRIVERS\iaStor.sys
2011/05/17 10:47:07.0071 0108 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2011/05/17 10:47:07.0129 0108 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/05/17 10:47:07.0195 0108 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2011/05/17 10:47:07.0234 0108 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/17 10:47:07.0274 0108 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/17 10:47:07.0307 0108 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/05/17 10:47:07.0360 0108 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/05/17 10:47:07.0435 0108 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/05/17 10:47:07.0512 0108 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2011/05/17 10:47:07.0592 0108 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/17 10:47:07.0659 0108 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/17 10:47:07.0750 0108 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/05/17 10:47:07.0806 0108 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/17 10:47:07.0913 0108 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2011/05/17 10:47:08.0058 0108 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/17 10:47:08.0146 0108 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/05/17 10:47:08.0229 0108 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/05/17 10:47:08.0316 0108 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/05/17 10:47:08.0377 0108 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/05/17 10:47:08.0546 0108 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/05/17 10:47:08.0692 0108 MarvinBus (a3e700d78eec390f1208098cdca5c6b6) C:\Windows\system32\DRIVERS\MarvinBus.sys
2011/05/17 10:47:08.0781 0108 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/05/17 10:47:08.0843 0108 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/05/17 10:47:08.0903 0108 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/05/17 10:47:08.0974 0108 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/17 10:47:09.0053 0108 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/17 10:47:09.0103 0108 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/17 10:47:09.0169 0108 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2011/05/17 10:47:09.0209 0108 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2011/05/17 10:47:09.0261 0108 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/17 10:47:09.0314 0108 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2011/05/17 10:47:09.0388 0108 mrxsmb (b4c76ef46322a9711c7b0f4e21ef6ea5) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/17 10:47:09.0449 0108 mrxsmb10 (e593d45024a3fdd11e93cc4a6ca91101) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/17 10:47:09.0496 0108 mrxsmb20 (a9f86c82c9cc3b679cc3957e1183a30f) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/17 10:47:09.0544 0108 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2011/05/17 10:47:09.0593 0108 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2011/05/17 10:47:09.0670 0108 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/05/17 10:47:09.0722 0108 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/05/17 10:47:09.0784 0108 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/05/17 10:47:09.0914 0108 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/17 10:47:09.0955 0108 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/17 10:47:09.0998 0108 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/05/17 10:47:10.0079 0108 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/05/17 10:47:10.0145 0108 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/17 10:47:10.0190 0108 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/05/17 10:47:10.0266 0108 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/05/17 10:47:10.0418 0108 MTsensor (dcdaab8697a47894a554050ce18d0b56) C:\Windows\system32\DRIVERS\ASACPI.sys
2011/05/17 10:47:10.0469 0108 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/05/17 10:47:10.0625 0108 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/17 10:47:10.0897 0108 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2011/05/17 10:47:10.0977 0108 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/05/17 10:47:11.0062 0108 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/17 10:47:11.0157 0108 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/17 10:47:11.0243 0108 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/17 10:47:11.0332 0108 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2011/05/17 10:47:11.0450 0108 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/17 10:47:11.0514 0108 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/17 10:47:11.0691 0108 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/05/17 10:47:11.0779 0108 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/05/17 10:47:11.0873 0108 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/17 10:47:12.0195 0108 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2011/05/17 10:47:12.0292 0108 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/05/17 10:47:13.0949 0108 nvlddmkm (d5edb88c13863473b2314aa14364b140) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/05/17 10:47:14.0152 0108 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2011/05/17 10:47:14.0189 0108 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2011/05/17 10:47:14.0219 0108 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/05/17 10:47:14.0275 0108 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/05/17 10:47:14.0345 0108 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/05/17 10:47:14.0393 0108 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2011/05/17 10:47:14.0473 0108 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/05/17 10:47:14.0547 0108 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2011/05/17 10:47:14.0612 0108 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2011/05/17 10:47:14.0657 0108 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/05/17 10:47:14.0689 0108 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/05/17 10:47:14.0862 0108 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/05/17 10:47:15.0048 0108 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/17 10:47:15.0077 0108 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/05/17 10:47:15.0185 0108 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/17 10:47:15.0346 0108 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/05/17 10:47:15.0438 0108 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/05/17 10:47:15.0514 0108 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/17 10:47:15.0556 0108 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/17 10:47:15.0643 0108 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/05/17 10:47:15.0686 0108 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/17 10:47:15.0776 0108 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/17 10:47:15.0877 0108 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/05/17 10:47:15.0920 0108 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/17 10:47:15.0980 0108 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/05/17 10:47:16.0029 0108 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/17 10:47:16.0113 0108 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/17 10:47:16.0159 0108 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/05/17 10:47:16.0209 0108 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2011/05/17 10:47:16.0345 0108 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2011/05/17 10:47:16.0416 0108 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/17 10:47:16.0521 0108 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/05/17 10:47:16.0582 0108 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2011/05/17 10:47:16.0633 0108 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/05/17 10:47:16.0699 0108 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/05/17 10:47:16.0800 0108 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/05/17 10:47:16.0875 0108 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/05/17 10:47:16.0934 0108 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/05/17 10:47:16.0986 0108 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/05/17 10:47:17.0033 0108 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/05/17 10:47:17.0086 0108 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/05/17 10:47:17.0136 0108 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2011/05/17 10:47:17.0329 0108 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/05/17 10:47:17.0474 0108 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/05/17 10:47:17.0570 0108 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/05/17 10:47:17.0660 0108 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/05/17 10:47:17.0968 0108 sptd (a80cd850d69d996c832bea37e3a6aa1e) C:\Windows\system32\Drivers\sptd.sys
2011/05/17 10:47:17.0968 0108 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: a80cd850d69d996c832bea37e3a6aa1e
2011/05/17 10:47:17.0981 0108 sptd - detected LockedFile.Multi.Generic (1)
2011/05/17 10:47:18.0122 0108 sp_rsdrv2 (ae59a60e67d3b3f864d2ee4e1fd4eb0c) C:\Windows\system32\drivers\sp_rsdrv2.sys
2011/05/17 10:47:18.0277 0108 srv (4a9b0f215de2519e2363f91df25c1e97) C:\Windows\system32\DRIVERS\srv.sys
2011/05/17 10:47:18.0335 0108 srv2 (14c44875518ae1c982e54ea8c5f7fe28) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/17 10:47:18.0398 0108 srvnet (07a14223b0a50e76ade003fdf95d4fec) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/17 10:47:18.0528 0108 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/05/17 10:47:18.0579 0108 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/17 10:47:18.0643 0108 tap0901 (11d34fc869f5bda29949fe3858380894) C:\Windows\system32\DRIVERS\tap0901.sys
2011/05/17 10:47:19.0076 0108 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2011/05/17 10:47:19.0518 0108 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/17 10:47:19.0585 0108 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/17 10:47:19.0639 0108 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2011/05/17 10:47:19.0686 0108 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2011/05/17 10:47:19.0738 0108 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/17 10:47:19.0787 0108 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/17 10:47:19.0895 0108 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/17 10:47:20.0017 0108 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/17 10:47:20.0163 0108 txjmwxv (e6d35f3aa51a65eb35c1f2340154a25e) C:\Windows\system32\drivers\tuysm.sys
2011/05/17 10:47:20.0221 0108 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/05/17 10:47:20.0299 0108 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/17 10:47:20.0362 0108 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/05/17 10:47:20.0446 0108 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/17 10:47:20.0495 0108 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/05/17 10:47:20.0554 0108 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/17 10:47:20.0606 0108 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2011/05/17 10:47:20.0635 0108 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2011/05/17 10:47:20.0753 0108 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/17 10:47:20.0928 0108 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2011/05/17 10:47:21.0107 0108 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/05/17 10:47:21.0214 0108 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/05/17 10:47:21.0280 0108 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/05/17 10:47:21.0322 0108 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/17 10:47:21.0372 0108 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/05/17 10:47:21.0452 0108 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/17 10:47:21.0471 0108 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/05/17 10:47:21.0542 0108 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/05/17 10:47:21.0629 0108 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2011/05/17 10:47:21.0694 0108 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/05/17 10:47:21.0749 0108 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2011/05/17 10:47:21.0797 0108 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/05/17 10:47:21.0876 0108 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/05/17 10:47:21.0963 0108 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2011/05/17 10:47:22.0081 0108 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/05/17 10:47:22.0151 0108 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2011/05/17 10:47:22.0223 0108 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/05/17 10:47:22.0296 0108 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/17 10:47:22.0317 0108 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/17 10:47:22.0403 0108 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/05/17 10:47:22.0557 0108 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/17 10:47:22.0663 0108 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/05/17 10:47:22.0682 0108 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/05/17 10:47:22.0796 0108 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/05/17 10:47:22.0891 0108 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/05/17 10:47:22.0977 0108 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/17 10:47:23.0071 0108 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/05/17 10:47:23.0173 0108 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/17 10:47:23.0252 0108 \HardDisk2 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/05/17 10:47:23.0298 0108 ================================================================================
2011/05/17 10:47:23.0298 0108 Scan finished
2011/05/17 10:47:23.0298 0108 ================================================================================
2011/05/17 10:47:23.0314 1972 Detected object count: 2
2011/05/17 10:47:42.0906 1972 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/05/17 10:47:42.0953 1972 \HardDisk2 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
2011/05/17 10:47:42.0954 1972 \HardDisk2 - ok
2011/05/17 10:47:42.0955 1972 Rootkit.Win32.TDSS.tdl4(\HardDisk2) - User select action: Cure
2011/05/17 10:48:11.0788 3352 Deinitialize success

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 16:10
od lluckyn
Prosím co mám dělat,
v jiném tématu jsem četl,že se dá použít nejdříve RKill a pak teprve vámi zamýšlený Combofix (díky čemuž se pak dá normálně restartovat), moc děkuji

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 18:11
od lluckyn
použil jsem RKill a poté Combofix, tady je log z ComboFixu:

ComboFix 11-05-16.04 - Lucka 17.05.2011 19:02:54.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.2559.1613 [GMT 2:00]
Spuštěný z: c:\users\Lucka\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\users\Lucka\AUTORUN.INF
c:\users\Lucka\haudud.exe
c:\users\Lucka\kaalo.exe
c:\users\Lucka\svc32.exe
c:\users\Lucka\weisibx.exe
c:\users\Lucka\zuoit.exe
c:\windows\system32\Chip.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-17 do 2011-05-17 )))))))))))))))))))))))))))))))
.
.
2011-05-17 17:09 . 2011-05-17 17:09 -------- d-----w- c:\users\Lucka\AppData\Local\temp
2011-05-17 17:09 . 2011-05-17 17:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-17 15:24 . 2011-04-11 07:04 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2371378A-B725-425B-8803-07E3C8EA3900}\mpengine.dll
2011-05-16 20:38 . 2011-05-16 20:38 -------- d-----w- c:\program files\trend micro
2011-05-16 18:48 . 2011-05-16 18:49 -------- d-----w- c:\program files\Ultimate Process Manager
2011-05-16 18:40 . 2011-05-16 18:58 -------- d-----w- c:\program files\WinClamAVShield
2011-05-16 18:39 . 2011-05-16 18:39 138752 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-05-16 18:39 . 2011-05-17 09:00 -------- d-----w- c:\users\Lucka\AppData\Roaming\Spyware Terminator
2011-05-16 18:39 . 2011-05-17 08:51 -------- d-----w- c:\programdata\Spyware Terminator
2011-05-16 18:39 . 2011-05-16 20:03 -------- d-----w- c:\program files\Spyware Terminator
2011-05-16 18:24 . 2011-05-16 18:24 -------- d-----w- c:\users\Lucka\AppData\Roaming\Malwarebytes
2011-05-16 18:24 . 2011-05-16 18:24 -------- d-----w- c:\programdata\Malwarebytes
2011-05-16 18:24 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-16 18:24 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-16 18:24 . 2011-05-16 18:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-16 18:08 . 2011-05-16 18:08 -------- d-----w- c:\program files\Recuva
2011-05-16 18:07 . 2011-05-16 18:07 -------- d-----w- c:\program files\RegCleaner
2011-05-16 15:22 . 2011-05-16 15:22 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-13 16:49 . 2011-04-09 06:13 3957632 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-13 16:49 . 2011-04-09 06:13 3901824 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-03 19:34 . 2011-05-03 19:34 -------- d-----w- c:\programdata\AVS4YOU
2011-05-03 19:33 . 2011-05-03 19:33 -------- d-----w- c:\users\Lucka\AppData\Roaming\AVS4YOU
2011-05-03 19:32 . 2010-09-08 13:36 10833920 ----a-w- c:\windows\system32\libmfxsw32.dll
2011-05-03 19:32 . 2010-09-08 13:36 10915840 ----a-w- c:\windows\system32\libmfxhw32.dll
2011-05-03 19:32 . 2011-05-03 19:33 -------- d-----w- c:\program files\Common Files\AVSMedia
2011-05-03 19:32 . 2011-05-03 19:33 -------- d-----w- c:\program files\AVS4YOU
2011-05-03 19:32 . 2010-08-17 13:02 24576 ----a-w- c:\windows\system32\msxml3a.dll
2011-04-26 18:53 . 2011-04-26 18:53 -------- d-----w- c:\users\Lucka\AppData\Local\Apps
2011-04-26 18:53 . 2011-05-06 15:11 -------- d-----w- c:\users\Lucka\AppData\Local\Deployment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-12 19:22 . 2011-04-12 19:22 3333808 ----a-w- c:\windows\system32\drivers\appdrv01.sys
2011-04-12 19:22 . 2011-04-12 19:22 316888 ----a-w- c:\windows\system32\appdrvrem01.exe
2011-03-11 05:40 . 2011-04-13 14:34 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-03-11 05:40 . 2011-04-13 14:34 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-08 05:38 . 2011-04-13 14:35 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 05:29 . 2011-04-13 14:34 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:27 . 2011-04-13 14:34 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-03-03 03:31 . 2011-04-13 14:34 2331136 ----a-w- c:\windows\system32\win32k.sys
2011-03-01 17:15 . 2011-01-24 17:39 737280 ----a-w- c:\windows\iun6002.exe
2011-02-24 05:32 . 2011-04-13 14:35 981504 ----a-w- c:\windows\system32\wininet.dll
2011-02-24 05:30 . 2011-04-13 14:35 44544 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-24 04:23 . 2011-04-13 14:35 386048 ----a-w- c:\windows\system32\html.iec
2011-02-24 03:50 . 2011-04-13 14:35 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-02-23 05:06 . 2011-04-13 14:34 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-23 05:05 . 2011-04-13 14:34 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-02-23 05:05 . 2011-04-13 14:34 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-02-23 05:05 . 2011-04-13 14:35 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-02-23 05:05 . 2011-04-13 14:35 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-02-23 05:05 . 2011-04-13 14:35 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-23 05:05 . 2011-04-13 14:35 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-02-19 05:32 . 2011-04-13 14:35 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-19 03:37 . 2011-04-13 14:35 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-02-18 05:36 . 2011-04-13 14:35 428032 ----a-w- c:\windows\system32\vbscript.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-10 90192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-10 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-10 81920]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-11 2054360]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2011-05-16 2957824]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 12:06 40048 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-03-28 22:37 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-25 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-01-24 722416]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2011-04-12 3333808]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-25 218688]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-05-16 138752]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-09-11 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2009-09-11 95896]
S3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet - adaptér;c:\windows\system32\DRIVERS\l260x86.sys [2009-07-13 29184]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Lucka\AppData\Roaming\Mozilla\Firefox\Profiles\scrq9f7q.default\
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: HP Smart Web Printing: smartwebprinting@hp.com - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - Ext: HP Smart Web Printing: smartwebprinting@hp.com - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-zuoit - c:\users\Lucka\zuoit.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-05-17 19:10:09
ComboFix-quarantined-files.txt 2011-05-17 17:10
.
Před spuštěním: Volných bajtů: 39 608 078 336
Po spuštění: Volných bajtů: 39 916 474 368
.
- - End Of File - - AF7F4F47F52B8FED8A5286D31DF53563

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 19:00
od Rudy
Několik položek CF smazal, zbytek logu vypadá čistý. Nastala nějaká změna?

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 19:15
od lluckyn
Vypadá to už docela dobře počítač už je zase rychlý, ještě se mi po restartu spustil checkdisk.
Ještě mám problém, že jsem měl v počítači flashdisk a teď když ho strčím do počítače tak u adresářů mám v příponě místo DIR napsáno lnk a navíc se mi zdá, že tam jsou položky navíc. Mám flashku něčím projet?
Díky

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 20:14
od Rudy

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 20:24
od lluckyn
Bohužel FlashDisinfector mi nejde spustit:(
Mám to zkusit v jiném počítači? Jak poznám, že tam z tý flashky nepřenesu nějakej vir? Mám flashku předtím projet například antimalwarem?

Re: kontrola logu, děkuji

Napsal: 17 kvě 2011 20:33
od Rudy
lluckyn píše:Bohužel FlashDisinfector mi nejde spustit:(
Mám to zkusit v jiném počítači? Jak poznám, že tam z tý flashky nepřenesu nějakej vir? Mám flashku předtím projet například antimalwarem?
Můžete to zkusit. Pokud máte soubory, které máte na flashdisku někde jinde uloženy, je nejlepší ho zformatovat a soubory znovu nakopírovat. To je jistota.