Stránka 1 z 1

Prosím o prevenci

Napsal: 19 črc 2011 17:15
od Anna.ja
Zdravím a prosím o preventivní kontrolu, díky.

Log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Petr at 2011-07-19 18:06:15
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 459 GB (64%) free of 715 GB
Total RAM: 2047 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:06:42, on 19.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Petr\Desktop\RSIT.exe
C:\Program Files\trend micro\Petr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpyEmergency] C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 6582 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-11-24 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [2009-08-28 1486848]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-07-24 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-07-24 174104]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-07-24 151064]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-10-29 1352272]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2009-10-14 2793304]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-08-02 281768]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-11-22 2424560]
"SpyEmergency"=C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-26 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
C:\Program Files\Samsung\Kies\KiesHelper.exe [2011-04-28 934800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2011-04-28 19856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2011-04-28 3373968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk]
C:\PROGRA~1\T-Mobile\DATASY~1\Voxsync.exe [2010-10-27 696320]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MIF5BA~1\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-07-21 216576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2010-10-28 64592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-04-17 203776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.I420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-07-19 18:06:15 ----D---- C:\rsit
2011-07-19 07:34:05 ----D---- C:\Program Files\Lavalys
2011-07-13 20:54:17 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-13 20:54:17 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 20:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 20:54:15 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 20:54:14 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 20:54:11 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 20:54:11 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 20:54:11 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 20:53:42 ----A---- C:\Windows\system32\win32k.sys
2011-07-12 01:12:00 ----D---- C:\Users\Petr\AppData\Roaming\Zoner
2011-07-12 01:11:34 ----D---- C:\Program Files\Zoner
2011-07-12 00:19:36 ----D---- C:\Users\Petr\AppData\Roaming\TeamViewer
2011-06-29 00:53:33 ----A---- C:\Windows\system32\tquery.dll
2011-06-29 00:53:33 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-29 00:53:33 ----A---- C:\Windows\system32\mssrch.dll
2011-06-29 00:53:32 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-29 00:53:32 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-29 00:53:32 ----A---- C:\Windows\system32\mssvp.dll
2011-06-29 00:53:32 ----A---- C:\Windows\system32\mssph.dll
2011-06-29 00:53:31 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-29 00:53:31 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-29 00:53:29 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-28 21:34:29 ----D---- C:\Program Files\Zrychleni Pocitace

======List of files/folders modified in the last 1 month======

2011-07-19 18:06:27 ----D---- C:\Windows\Prefetch
2011-07-19 18:06:18 ----D---- C:\Program Files\trend micro
2011-07-19 18:02:43 ----D---- C:\Windows\temp
2011-07-19 18:02:37 ----D---- C:\Windows\system32\config
2011-07-19 15:49:02 ----D---- C:\Users\Petr\AppData\Roaming\Skype
2011-07-19 14:00:36 ----D---- C:\Users\Petr\AppData\Roaming\Vso
2011-07-19 07:34:05 ----RD---- C:\Program Files
2011-07-18 10:52:07 ----SHD---- C:\System Volume Information
2011-07-18 09:30:28 ----D---- C:\Windows\system32\NDF
2011-07-16 20:26:30 ----D---- C:\Windows\System32
2011-07-16 20:26:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-16 20:26:29 ----D---- C:\Windows\inf
2011-07-16 16:31:31 ----D---- C:\Users\Petr\AppData\Roaming\ICQ
2011-07-14 07:44:33 ----D---- C:\Windows\winsxs
2011-07-14 01:45:18 ----D---- C:\Windows\system32\DriverStore
2011-07-14 01:45:18 ----D---- C:\Windows\system32\drivers
2011-07-14 01:42:10 ----D---- C:\Windows\debug
2011-07-14 01:42:09 ----A---- C:\Windows\system32\MRT.exe
2011-07-14 01:42:06 ----SHD---- C:\Windows\Installer
2011-07-14 01:42:00 ----D---- C:\ProgramData\Microsoft Help
2011-07-13 20:52:36 ----D---- C:\Windows\system32\catroot2
2011-07-13 20:52:36 ----D---- C:\Windows\system32\catroot
2011-07-11 13:33:43 ----D---- C:\ProgramData\TrackMania
2011-07-02 20:26:03 ----D---- C:\Windows\system32\Tasks
2011-07-02 20:25:59 ----RD---- C:\Program Files\Skype
2011-07-02 20:25:47 ----D---- C:\Program Files\Common Files
2011-07-02 20:25:31 ----D---- C:\ProgramData\Skype
2011-07-01 18:32:36 ----D---- C:\Program Files\ICQ7.5
2011-07-01 14:42:18 ----D---- C:\Users\Petr\AppData\Roaming\DivX
2011-07-01 01:25:29 ----D---- C:\ProgramData\Easybits GO
2011-07-01 00:05:22 ----D---- C:\Users\Petr\AppData\Roaming\go
2011-07-01 00:05:22 ----D---- C:\ProgramData\Skype Extras
2011-06-29 21:35:47 ----D---- C:\Program Files\Opera
2011-06-29 09:59:29 ----D---- C:\Windows
2011-06-29 03:10:30 ----RSD---- C:\Windows\Fonts
2011-06-29 03:09:40 ----D---- C:\ProgramData
2011-06-29 02:35:32 ----D---- C:\Windows\pss
2011-06-29 02:34:15 ----D---- C:\Program Files\GameTop.com
2011-06-29 00:54:29 ----D---- C:\Program Files\Microsoft Office
2011-06-28 21:41:49 ----SD---- C:\Users\Petr\AppData\Roaming\Microsoft
2011-06-28 21:31:00 ----D---- C:\Users\Petr\AppData\Roaming\DAEMON Tools Lite
2011-06-28 21:30:52 ----D---- C:\Windows\Logs
2011-06-28 21:27:47 ----D---- C:\Program Files\CCleaner
2011-06-23 10:43:28 ----D---- C:\Windows\Microsoft.NET
2011-06-23 10:43:26 ----RSD---- C:\Windows\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-06 691696]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-06-29 138192]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKslf7718b1f;MpKslf7718b1f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{656B21B6-7C06-44E8-AD6A-DF4B1C2815C3}\MpKslf7718b1f.sys [2011-07-19 28752]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-06-29 66616]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\System32\Drivers\LEqdUsb.Sys [2010-08-24 40912]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\System32\Drivers\LHidEqd.Sys [2010-08-24 10448]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2010-08-24 38864]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2010-08-24 37328]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2009-10-07 25752]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 13216]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 PID_0928;Logitech QuickCam Express(PID_0928); C:\Windows\system32\DRIVERS\LV561AV.SYS [2009-05-01 495768]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
S1 aawewgme;aawewgme; \??\C:\Windows\system32\drivers\aawewgme.sys []
S1 abqkehqt;abqkehqt; \??\C:\Windows\system32\drivers\abqkehqt.sys []
S1 aczmhypl;aczmhypl; \??\C:\Windows\system32\drivers\aczmhypl.sys []
S1 addkmbvj;addkmbvj; \??\C:\Windows\system32\drivers\addkmbvj.sys []
S1 adfkglfq;adfkglfq; \??\C:\Windows\system32\drivers\adfkglfq.sys []
S1 adhhvdmy;adhhvdmy; \??\C:\Windows\system32\drivers\adhhvdmy.sys []
S1 afnitpjk;afnitpjk; \??\C:\Windows\system32\drivers\afnitpjk.sys []
S1 amxalhys;amxalhys; \??\C:\Windows\system32\drivers\amxalhys.sys []
S1 bimhdgty;bimhdgty; \??\C:\Windows\system32\drivers\bimhdgty.sys []
S1 bojtifav;bojtifav; \??\C:\Windows\system32\drivers\bojtifav.sys []
S1 cfcwvlje;cfcwvlje; \??\C:\Windows\system32\drivers\cfcwvlje.sys []
S1 ciwkbgmc;ciwkbgmc; \??\C:\Windows\system32\drivers\ciwkbgmc.sys []
S1 cuopvdmv;cuopvdmv; \??\C:\Windows\system32\drivers\cuopvdmv.sys []
S1 dbmmjtnm;dbmmjtnm; \??\C:\Windows\system32\drivers\dbmmjtnm.sys []
S1 eabszwjv;eabszwjv; \??\C:\Windows\system32\drivers\eabszwjv.sys []
S1 ebnanrya;ebnanrya; \??\C:\Windows\system32\drivers\ebnanrya.sys []
S1 eektuhga;eektuhga; \??\C:\Windows\system32\drivers\eektuhga.sys []
S1 ejiejfcu;ejiejfcu; \??\C:\Windows\system32\drivers\ejiejfcu.sys []
S1 elzwtbfc;elzwtbfc; \??\C:\Windows\system32\drivers\elzwtbfc.sys []
S1 emazupze;emazupze; \??\C:\Windows\system32\drivers\emazupze.sys []
S1 emmjfeni;emmjfeni; \??\C:\Windows\system32\drivers\emmjfeni.sys []
S1 eufvpivq;eufvpivq; \??\C:\Windows\system32\drivers\eufvpivq.sys []
S1 ewadmjyi;ewadmjyi; \??\C:\Windows\system32\drivers\ewadmjyi.sys []
S1 fetyhnit;fetyhnit; \??\C:\Windows\system32\drivers\fetyhnit.sys []
S1 fhzpaugn;fhzpaugn; \??\C:\Windows\system32\drivers\fhzpaugn.sys []
S1 fovltltr;fovltltr; \??\C:\Windows\system32\drivers\fovltltr.sys []
S1 gcuwmlgu;gcuwmlgu; \??\C:\Windows\system32\drivers\gcuwmlgu.sys []
S1 ggsqzafh;ggsqzafh; \??\C:\Windows\system32\drivers\ggsqzafh.sys []
S1 gpylgoxn;gpylgoxn; \??\C:\Windows\system32\drivers\gpylgoxn.sys []
S1 hujguwgh;hujguwgh; \??\C:\Windows\system32\drivers\hujguwgh.sys []
S1 hzxbkpxt;hzxbkpxt; \??\C:\Windows\system32\drivers\hzxbkpxt.sys []
S1 iceyzanj;iceyzanj; \??\C:\Windows\system32\drivers\iceyzanj.sys []
S1 idklhixm;idklhixm; \??\C:\Windows\system32\drivers\idklhixm.sys []
S1 ifrmilpk;ifrmilpk; \??\C:\Windows\system32\drivers\ifrmilpk.sys []
S1 ihzuhraw;ihzuhraw; \??\C:\Windows\system32\drivers\ihzuhraw.sys []
S1 iufibibt;iufibibt; \??\C:\Windows\system32\drivers\iufibibt.sys []
S1 izsjmshi;izsjmshi; \??\C:\Windows\system32\drivers\izsjmshi.sys []
S1 jczdvtob;jczdvtob; \??\C:\Windows\system32\drivers\jczdvtob.sys []
S1 jlbhbjta;jlbhbjta; \??\C:\Windows\system32\drivers\jlbhbjta.sys []
S1 josmnand;josmnand; \??\C:\Windows\system32\drivers\josmnand.sys []
S1 jtxvkhdz;jtxvkhdz; \??\C:\Windows\system32\drivers\jtxvkhdz.sys []
S1 jwgtnbrz;jwgtnbrz; \??\C:\Windows\system32\drivers\jwgtnbrz.sys []
S1 jwmypcuu;jwmypcuu; \??\C:\Windows\system32\drivers\jwmypcuu.sys []
S1 kmffmyws;kmffmyws; \??\C:\Windows\system32\drivers\kmffmyws.sys []
S1 kzdqoorf;kzdqoorf; \??\C:\Windows\system32\drivers\kzdqoorf.sys []
S1 lgbsqoks;lgbsqoks; \??\C:\Windows\system32\drivers\lgbsqoks.sys []
S1 lilofhxo;lilofhxo; \??\C:\Windows\system32\drivers\lilofhxo.sys []
S1 llxhmred;llxhmred; \??\C:\Windows\system32\drivers\llxhmred.sys []
S1 lqoreyjj;lqoreyjj; \??\C:\Windows\system32\drivers\lqoreyjj.sys []
S1 lvaofivh;lvaofivh; \??\C:\Windows\system32\drivers\lvaofivh.sys []
S1 mivmpyqj;mivmpyqj; \??\C:\Windows\system32\drivers\mivmpyqj.sys []
S1 MpKsl032a711f;MpKsl032a711f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3B1C517E-BFE0-47E0-AAD1-60F4B7FBFC0B}\MpKsl032a711f.sys []
S1 MpKsl27444b43;MpKsl27444b43; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{35AD0FC2-91FC-43E0-A019-4615D0FB6366}\MpKsl27444b43.sys []
S1 MpKsl2dd3f829;MpKsl2dd3f829; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C6080A4F-A161-442F-B3E1-533F10B63377}\MpKsl2dd3f829.sys []
S1 MpKsl3f0c654f;MpKsl3f0c654f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{20840DA4-05B5-4515-B34E-153E1E5AAE49}\MpKsl3f0c654f.sys []
S1 MpKsl48bb5ebc;MpKsl48bb5ebc; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C073EB2C-E2A0-4042-BF3C-2AE5A8354267}\MpKsl48bb5ebc.sys []
S1 MpKsl4b5eb67a;MpKsl4b5eb67a; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2567CAAE-BDB7-4E08-9D09-CB773B3C8A18}\MpKsl4b5eb67a.sys []
S1 MpKsl6e1d0fe3;MpKsl6e1d0fe3; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C8219011-C70A-4F8B-AD74-8AC3C3FDA9AC}\MpKsl6e1d0fe3.sys []
S1 MpKsl7b52bf5c;MpKsl7b52bf5c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F8A0FFBC-D557-431A-A041-B2CF535CC426}\MpKsl7b52bf5c.sys []
S1 MpKsl87f8aba0;MpKsl87f8aba0; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{69C29859-67F3-4D94-84E3-D8B52F08B501}\MpKsl87f8aba0.sys []
S1 MpKsl8f2fc6d7;MpKsl8f2fc6d7; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F99D5C8D-7B6B-45BD-8FDE-BC6CE6360DDE}\MpKsl8f2fc6d7.sys []
S1 MpKsl9e6156dc;MpKsl9e6156dc; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{94C583BB-A866-4821-A030-49252F79AE6F}\MpKsl9e6156dc.sys []
S1 MpKslb1a2c2aa;MpKslb1a2c2aa; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4148D607-4D06-441E-87A8-F5C3D48D48E7}\MpKslb1a2c2aa.sys []
S1 MpKslbf11449c;MpKslbf11449c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{80386A5F-58FF-459C-ACB2-53439196099C}\MpKslbf11449c.sys []
S1 MpKslc72fae6f;MpKslc72fae6f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A8D661AA-7307-4244-AD29-3B8AC4DC4DAA}\MpKslc72fae6f.sys []
S1 MpKslc86f06c3;MpKslc86f06c3; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A4A047A4-45A5-4646-A530-A058C1BF93CD}\MpKslc86f06c3.sys []
S1 MpKsld6f9af00;MpKsld6f9af00; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AE36E33C-FC92-46DE-B4F1-3C3FAC54A8AA}\MpKsld6f9af00.sys []
S1 mqmrzfgt;mqmrzfgt; \??\C:\Windows\system32\drivers\mqmrzfgt.sys []
S1 mrmztfxn;mrmztfxn; \??\C:\Windows\system32\drivers\mrmztfxn.sys []
S1 ndakyxka;ndakyxka; \??\C:\Windows\system32\drivers\ndakyxka.sys []
S1 nqzcavfj;nqzcavfj; \??\C:\Windows\system32\drivers\nqzcavfj.sys []
S1 ocbnwuxb;ocbnwuxb; \??\C:\Windows\system32\drivers\ocbnwuxb.sys []
S1 ofhbudog;ofhbudog; \??\C:\Windows\system32\drivers\ofhbudog.sys []
S1 ohvocfcy;ohvocfcy; \??\C:\Windows\system32\drivers\ohvocfcy.sys []
S1 olxyhvcu;olxyhvcu; \??\C:\Windows\system32\drivers\olxyhvcu.sys []
S1 ovyfhmpp;ovyfhmpp; \??\C:\Windows\system32\drivers\ovyfhmpp.sys []
S1 pcdlykjv;pcdlykjv; \??\C:\Windows\system32\drivers\pcdlykjv.sys []
S1 pnjvbnch;pnjvbnch; \??\C:\Windows\system32\drivers\pnjvbnch.sys []
S1 pyywcehx;pyywcehx; \??\C:\Windows\system32\drivers\pyywcehx.sys []
S1 qxbkjvcz;qxbkjvcz; \??\C:\Windows\system32\drivers\qxbkjvcz.sys []
S1 qyxykowi;qyxykowi; \??\C:\Windows\system32\drivers\qyxykowi.sys []
S1 sbygosut;sbygosut; \??\C:\Windows\system32\drivers\sbygosut.sys []
S1 sgnlkpcq;sgnlkpcq; \??\C:\Windows\system32\drivers\sgnlkpcq.sys []
S1 sgwiczhr;sgwiczhr; \??\C:\Windows\system32\drivers\sgwiczhr.sys []
S1 sojjopkm;sojjopkm; \??\C:\Windows\system32\drivers\sojjopkm.sys []
S1 sphxqmcl;sphxqmcl; \??\C:\Windows\system32\drivers\sphxqmcl.sys []
S1 stgwsoco;stgwsoco; \??\C:\Windows\system32\drivers\stgwsoco.sys []
S1 tfdgxacf;tfdgxacf; \??\C:\Windows\system32\drivers\tfdgxacf.sys []
S1 tiatxvas;tiatxvas; \??\C:\Windows\system32\drivers\tiatxvas.sys []
S1 tmbitahs;tmbitahs; \??\C:\Windows\system32\drivers\tmbitahs.sys []
S1 uixtlaec;uixtlaec; \??\C:\Windows\system32\drivers\uixtlaec.sys []
S1 umfwxiho;umfwxiho; \??\C:\Windows\system32\drivers\umfwxiho.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 catchme;catchme; \??\C:\Users\Petr\AppData\Local\Temp\catchme.sys []
S3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys []
S3 DrvSnSht;DrvSnSht; \??\C:\Program Files\R-Drive Image\DrvSnSht.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-07-21 5924864]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 R-ImageDisk;R-ImageDisk; \??\C:\Program Files\R-Drive Image\R-ImageDisk.sys []
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\Windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\Windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\Windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM); C:\Windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-06-29 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-28 136360]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2010-07-04 238952]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 154136]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 NAUpdate;@C:\Program Files\Nero\Update\NASvc.exe,-200; C:\Program Files\Nero\Update\NASvc.exe [2010-03-25 490280]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-10-28 293456]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-05-03 403240]

-----------------EOF-----------------

Re: Prosím o prevenci

Napsal: 19 črc 2011 19:31
od vyosek
Zdravim a pekny vecer preji :)

:arrow: Vyberte si jen jeden antivir - MSE nebo Aviru - druhy odinstalujte - vice AV v systemu zpusobuje jeho zpomaleni a nestabilitu

:arrow: Vy jste se dala na chov rootkitu - pekne stadecko tam mate :boxed:

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Utilitu spustte a prikazte ji, at skenuje - klik na Start Scan
  • Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
  • Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
  • Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
  • Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
  • Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Prosím o prevenci

Napsal: 19 črc 2011 20:08
od Anna.ja
log TDSS killer:

2011/07/19 20:35:30.0223 1760 TDSS rootkit removing tool 2.5.11.0 Jul 11 2011 16:56:56
2011/07/19 20:35:30.0455 1760 ================================================================================
2011/07/19 20:35:30.0455 1760 SystemInfo:
2011/07/19 20:35:30.0455 1760
2011/07/19 20:35:30.0455 1760 OS Version: 6.1.7601 ServicePack: 1.0
2011/07/19 20:35:30.0455 1760 Product type: Workstation
2011/07/19 20:35:30.0455 1760 ComputerName: PETR-PC
2011/07/19 20:35:30.0455 1760 UserName: Petr
2011/07/19 20:35:30.0455 1760 Windows directory: C:\Windows
2011/07/19 20:35:30.0455 1760 System windows directory: C:\Windows
2011/07/19 20:35:30.0456 1760 Processor architecture: Intel x86
2011/07/19 20:35:30.0456 1760 Number of processors: 2
2011/07/19 20:35:30.0456 1760 Page size: 0x1000
2011/07/19 20:35:30.0456 1760 Boot type: Normal boot
2011/07/19 20:35:30.0456 1760 ================================================================================
2011/07/19 20:35:31.0925 1760 Initialize success
2011/07/19 20:35:39.0014 5600 ================================================================================
2011/07/19 20:35:39.0014 5600 Scan started
2011/07/19 20:35:39.0014 5600 Mode: Manual;
2011/07/19 20:35:39.0014 5600 ================================================================================
2011/07/19 20:35:39.0741 5600 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
2011/07/19 20:35:39.0851 5600 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
2011/07/19 20:35:39.0916 5600 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
2011/07/19 20:35:40.0094 5600 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/07/19 20:35:40.0123 5600 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/07/19 20:35:40.0162 5600 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/07/19 20:35:40.0229 5600 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
2011/07/19 20:35:40.0294 5600 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
2011/07/19 20:35:40.0314 5600 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/07/19 20:35:40.0347 5600 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
2011/07/19 20:35:40.0389 5600 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
2011/07/19 20:35:40.0413 5600 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
2011/07/19 20:35:40.0435 5600 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/07/19 20:35:40.0453 5600 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/07/19 20:35:40.0489 5600 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
2011/07/19 20:35:40.0532 5600 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/07/19 20:35:40.0570 5600 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
2011/07/19 20:35:40.0677 5600 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
2011/07/19 20:35:40.0724 5600 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/07/19 20:35:40.0752 5600 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/07/19 20:35:40.0782 5600 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/07/19 20:35:40.0812 5600 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
2011/07/19 20:35:40.0856 5600 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/07/19 20:35:40.0877 5600 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
2011/07/19 20:35:40.0915 5600 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/07/19 20:35:40.0947 5600 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/07/19 20:35:40.0981 5600 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/07/19 20:35:41.0077 5600 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/07/19 20:35:41.0138 5600 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
2011/07/19 20:35:41.0164 5600 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/07/19 20:35:41.0180 5600 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/07/19 20:35:41.0215 5600 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/07/19 20:35:41.0246 5600 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/07/19 20:35:41.0265 5600 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/07/19 20:35:41.0285 5600 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/07/19 20:35:41.0328 5600 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\drivers\BthEnum.sys
2011/07/19 20:35:41.0349 5600 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/07/19 20:35:41.0398 5600 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
2011/07/19 20:35:41.0439 5600 BTHPORT (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\System32\Drivers\BTHport.sys
2011/07/19 20:35:41.0480 5600 BTHUSB (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\System32\Drivers\BTHUSB.sys
2011/07/19 20:35:41.0598 5600 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/07/19 20:35:41.0649 5600 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
2011/07/19 20:35:41.0700 5600 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/07/19 20:35:41.0759 5600 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/07/19 20:35:41.0804 5600 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/07/19 20:35:41.0846 5600 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
2011/07/19 20:35:41.0884 5600 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/07/19 20:35:41.0910 5600 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/07/19 20:35:41.0967 5600 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
2011/07/19 20:35:41.0988 5600 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/07/19 20:35:42.0149 5600 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
2011/07/19 20:35:42.0224 5600 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/07/19 20:35:42.0261 5600 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/07/19 20:35:42.0330 5600 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/07/19 20:35:42.0386 5600 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
2011/07/19 20:35:42.0500 5600 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/07/19 20:35:42.0647 5600 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/07/19 20:35:42.0733 5600 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
2011/07/19 20:35:42.0818 5600 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/07/19 20:35:42.0858 5600 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/07/19 20:35:42.0903 5600 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/07/19 20:35:42.0973 5600 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/07/19 20:35:42.0996 5600 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/07/19 20:35:43.0017 5600 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/07/19 20:35:43.0047 5600 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/07/19 20:35:43.0110 5600 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/07/19 20:35:43.0149 5600 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys
2011/07/19 20:35:43.0206 5600 FsUsbExDisk (cbe5f69a5e5b918225f420ba748f3742) C:\Windows\system32\FsUsbExDisk.SYS
2011/07/19 20:35:43.0241 5600 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/07/19 20:35:43.0299 5600 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
2011/07/19 20:35:43.0322 5600 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/07/19 20:35:43.0405 5600 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/07/19 20:35:43.0454 5600 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
2011/07/19 20:35:43.0482 5600 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
2011/07/19 20:35:43.0498 5600 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/07/19 20:35:43.0527 5600 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/07/19 20:35:43.0560 5600 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/07/19 20:35:43.0625 5600 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
2011/07/19 20:35:43.0687 5600 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
2011/07/19 20:35:43.0749 5600 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
2011/07/19 20:35:43.0797 5600 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
2011/07/19 20:35:43.0855 5600 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
2011/07/19 20:35:43.0910 5600 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
2011/07/19 20:35:44.0116 5600 igfx (8828710129b835fd59e8be6615eb3786) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/07/19 20:35:44.0238 5600 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/07/19 20:35:44.0278 5600 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
2011/07/19 20:35:44.0301 5600 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/07/19 20:35:44.0347 5600 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/07/19 20:35:44.0398 5600 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
2011/07/19 20:35:44.0423 5600 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/07/19 20:35:44.0444 5600 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/07/19 20:35:44.0487 5600 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
2011/07/19 20:35:44.0514 5600 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
2011/07/19 20:35:44.0714 5600 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
2011/07/19 20:35:44.0734 5600 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
2011/07/19 20:35:44.0804 5600 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
2011/07/19 20:35:44.0828 5600 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
2011/07/19 20:35:44.0919 5600 LEqdUsb (eee5a87ec378c9ad7ce91073fbd63465) C:\Windows\system32\Drivers\LEqdUsb.Sys
2011/07/19 20:35:44.0989 5600 LHidEqd (62663b385087f5977d8ebd1fdc67b639) C:\Windows\system32\Drivers\LHidEqd.Sys
2011/07/19 20:35:45.0030 5600 LHidFilt (318b3d608fbec44b7e0c23bf759dced5) C:\Windows\system32\DRIVERS\LHidFilt.Sys
2011/07/19 20:35:45.0094 5600 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/07/19 20:35:45.0149 5600 LMouFilt (84af069d219df3c43dc6792b2bbd7bed) C:\Windows\system32\DRIVERS\LMouFilt.Sys
2011/07/19 20:35:45.0207 5600 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/07/19 20:35:45.0224 5600 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/07/19 20:35:45.0254 5600 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/07/19 20:35:45.0283 5600 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/07/19 20:35:45.0312 5600 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/07/19 20:35:45.0374 5600 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\Windows\system32\DRIVERS\LVPr2Mon.sys
2011/07/19 20:35:45.0411 5600 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/07/19 20:35:45.0437 5600 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/07/19 20:35:45.0493 5600 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/07/19 20:35:45.0528 5600 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/07/19 20:35:45.0554 5600 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
2011/07/19 20:35:45.0579 5600 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/07/19 20:35:45.0623 5600 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
2011/07/19 20:35:45.0670 5600 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\Windows\system32\DRIVERS\MpFilter.sys
2011/07/19 20:35:45.0722 5600 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
2011/07/19 20:35:46.0178 5600 MpKslf7718b1f (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{656B21B6-7C06-44E8-AD6A-DF4B1C2815C3}\MpKslf7718b1f.sys
2011/07/19 20:35:46.0202 5600 MpNWMon (f32e2d6a1640a469a9ed4f1929a4a861) C:\Windows\system32\DRIVERS\MpNWMon.sys
2011/07/19 20:35:46.0228 5600 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/07/19 20:35:46.0324 5600 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
2011/07/19 20:35:46.0367 5600 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/07/19 20:35:46.0392 5600 mrxsmb10 (a70c828a93cce4c11617f6249f4d87fc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/07/19 20:35:46.0421 5600 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/07/19 20:35:46.0466 5600 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
2011/07/19 20:35:46.0492 5600 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
2011/07/19 20:35:46.0546 5600 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/07/19 20:35:46.0593 5600 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/07/19 20:35:46.0622 5600 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
2011/07/19 20:35:46.0663 5600 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/07/19 20:35:46.0704 5600 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/07/19 20:35:46.0720 5600 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/07/19 20:35:46.0755 5600 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/07/19 20:35:46.0810 5600 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
2011/07/19 20:35:46.0828 5600 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/07/19 20:35:46.0860 5600 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/07/19 20:35:46.0902 5600 MTsensor (cbe71c122434805cb73ffb6619f60598) C:\Windows\system32\DRIVERS\ASACPI.sys
2011/07/19 20:35:46.0924 5600 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/07/19 20:35:46.0963 5600 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/07/19 20:35:47.0046 5600 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
2011/07/19 20:35:47.0075 5600 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/07/19 20:35:47.0099 5600 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/07/19 20:35:47.0139 5600 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/07/19 20:35:47.0167 5600 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/07/19 20:35:47.0197 5600 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
2011/07/19 20:35:47.0246 5600 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/07/19 20:35:47.0287 5600 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
2011/07/19 20:35:47.0353 5600 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/07/19 20:35:47.0383 5600 NisDrv (17e2c08c5ecfbe94a7c67b1c275ee9d9) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
2011/07/19 20:35:47.0437 5600 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/07/19 20:35:47.0503 5600 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/07/19 20:35:47.0559 5600 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
2011/07/19 20:35:47.0619 5600 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/07/19 20:35:47.0835 5600 nvlddmkm (377140a534d013bd661c69f1741de43c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/07/19 20:35:47.0976 5600 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
2011/07/19 20:35:48.0006 5600 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
2011/07/19 20:35:48.0063 5600 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
2011/07/19 20:35:48.0169 5600 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
2011/07/19 20:35:48.0294 5600 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/07/19 20:35:48.0343 5600 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
2011/07/19 20:35:48.0363 5600 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/07/19 20:35:48.0415 5600 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\Windows\system32\DRIVERS\pccsmcfd.sys
2011/07/19 20:35:48.0464 5600 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
2011/07/19 20:35:48.0485 5600 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
2011/07/19 20:35:48.0516 5600 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/07/19 20:35:48.0545 5600 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/07/19 20:35:48.0579 5600 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/07/19 20:35:48.0648 5600 PID_0928 (d2d2fa02b722336960eeae0ae7107891) C:\Windows\system32\DRIVERS\LV561AV.SYS
2011/07/19 20:35:48.0747 5600 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/07/19 20:35:48.0772 5600 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/07/19 20:35:48.0826 5600 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/07/19 20:35:48.0899 5600 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/07/19 20:35:48.0945 5600 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/07/19 20:35:48.0974 5600 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/07/19 20:35:49.0091 5600 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/07/19 20:35:49.0123 5600 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/07/19 20:35:49.0160 5600 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/07/19 20:35:49.0186 5600 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/07/19 20:35:49.0204 5600 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/07/19 20:35:49.0260 5600 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
2011/07/19 20:35:49.0288 5600 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/07/19 20:35:49.0336 5600 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/07/19 20:35:49.0367 5600 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/07/19 20:35:49.0388 5600 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/07/19 20:35:49.0439 5600 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
2011/07/19 20:35:49.0497 5600 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
2011/07/19 20:35:49.0553 5600 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
2011/07/19 20:35:49.0595 5600 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/07/19 20:35:49.0656 5600 RTL8167 (d5ede44ca85899e0478208c8413c1c31) C:\Windows\system32\DRIVERS\Rt86win7.sys
2011/07/19 20:35:49.0727 5600 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/07/19 20:35:49.0762 5600 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/07/19 20:35:49.0811 5600 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
2011/07/19 20:35:49.0888 5600 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
2011/07/19 20:35:49.0928 5600 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/07/19 20:35:49.0975 5600 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/07/19 20:35:49.0997 5600 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/07/19 20:35:50.0039 5600 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/07/19 20:35:50.0119 5600 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
2011/07/19 20:35:50.0145 5600 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
2011/07/19 20:35:50.0167 5600 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
2011/07/19 20:35:50.0200 5600 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/07/19 20:35:50.0273 5600 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
2011/07/19 20:35:50.0299 5600 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/07/19 20:35:50.0326 5600 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/07/19 20:35:50.0360 5600 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/07/19 20:35:50.0459 5600 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/07/19 20:35:50.0565 5600 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/07/19 20:35:50.0565 5600 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/07/19 20:35:50.0575 5600 sptd - detected LockedFile.Multi.Generic (1)
2011/07/19 20:35:50.0627 5600 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
2011/07/19 20:35:50.0656 5600 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
2011/07/19 20:35:50.0685 5600 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
2011/07/19 20:35:50.0722 5600 sscebus (b2063ce662af3ab20045121a5b716df6) C:\Windows\system32\DRIVERS\sscebus.sys
2011/07/19 20:35:50.0758 5600 sscemdfl (66799dc0afe3dcaf8368cae17394a762) C:\Windows\system32\DRIVERS\sscemdfl.sys
2011/07/19 20:35:50.0788 5600 sscemdm (cbf03ffc08f8db547bab2f79aa663d16) C:\Windows\system32\DRIVERS\sscemdm.sys
2011/07/19 20:35:50.0836 5600 ssceserd (60cd4ad33aa52e58faac3abad18cf8ef) C:\Windows\system32\DRIVERS\ssceserd.sys
2011/07/19 20:35:50.0885 5600 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
2011/07/19 20:35:50.0931 5600 ss_bbus (3f0164fbc0bd1adbd02df9759181451a) C:\Windows\system32\DRIVERS\ss_bbus.sys
2011/07/19 20:35:50.0984 5600 ss_bmdfl (b89d62206034e5fe573c80a24dd55675) C:\Windows\system32\DRIVERS\ss_bmdfl.sys
2011/07/19 20:35:51.0027 5600 ss_bmdm (1ed0fcea586fe2a416ee15196e5631dd) C:\Windows\system32\DRIVERS\ss_bmdm.sys
2011/07/19 20:35:51.0067 5600 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/07/19 20:35:51.0144 5600 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
2011/07/19 20:35:51.0226 5600 Tcpip (24326784df8f3d5f5bbb9f878ce33c14) C:\Windows\system32\drivers\tcpip.sys
2011/07/19 20:35:51.0281 5600 TCPIP6 (24326784df8f3d5f5bbb9f878ce33c14) C:\Windows\system32\DRIVERS\tcpip.sys
2011/07/19 20:35:51.0336 5600 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
2011/07/19 20:35:51.0381 5600 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
2011/07/19 20:35:51.0409 5600 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
2011/07/19 20:35:51.0456 5600 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
2011/07/19 20:35:51.0480 5600 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
2011/07/19 20:35:51.0630 5600 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/07/19 20:35:51.0679 5600 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
2011/07/19 20:35:51.0729 5600 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
2011/07/19 20:35:51.0771 5600 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/07/19 20:35:51.0798 5600 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
2011/07/19 20:35:51.0887 5600 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
2011/07/19 20:35:51.0937 5600 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
2011/07/19 20:35:51.0982 5600 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/07/19 20:35:52.0017 5600 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/07/19 20:35:52.0070 5600 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
2011/07/19 20:35:52.0108 5600 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\drivers\usbehci.sys
2011/07/19 20:35:52.0131 5600 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
2011/07/19 20:35:52.0174 5600 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys
2011/07/19 20:35:52.0203 5600 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/07/19 20:35:52.0248 5600 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\drivers\USBSTOR.SYS
2011/07/19 20:35:52.0289 5600 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
2011/07/19 20:35:52.0369 5600 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
2011/07/19 20:35:52.0399 5600 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/07/19 20:35:52.0426 5600 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/07/19 20:35:52.0466 5600 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
2011/07/19 20:35:52.0496 5600 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
2011/07/19 20:35:52.0525 5600 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/07/19 20:35:52.0587 5600 VIAHdAudAddService (4906e025dd6b322c4bbd6b9e35c9993a) C:\Windows\system32\drivers\viahduaa.sys
2011/07/19 20:35:52.0626 5600 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
2011/07/19 20:35:52.0682 5600 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
2011/07/19 20:35:52.0708 5600 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/07/19 20:35:52.0765 5600 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
2011/07/19 20:35:52.0794 5600 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/07/19 20:35:52.0827 5600 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2011/07/19 20:35:52.0891 5600 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/07/19 20:35:52.0944 5600 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/19 20:35:52.0957 5600 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/19 20:35:53.0023 5600 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/07/19 20:35:53.0053 5600 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/07/19 20:35:53.0132 5600 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/07/19 20:35:53.0165 5600 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/07/19 20:35:53.0263 5600 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/07/19 20:35:53.0350 5600 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
2011/07/19 20:35:53.0406 5600 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/07/19 20:35:53.0470 5600 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
2011/07/19 20:35:53.0499 5600 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/07/19 20:35:53.0865 5600 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/07/19 20:35:53.0877 5600 Boot (0x1200) (fb118bdb01105456a7f5e667dbf39823) \Device\Harddisk0\DR0\Partition0
2011/07/19 20:35:53.0900 5600 Boot (0x1200) (aa27fd86a21309d07553c25603433e0b) \Device\Harddisk0\DR0\Partition1
2011/07/19 20:35:53.0905 5600 ================================================================================
2011/07/19 20:35:53.0906 5600 Scan finished
2011/07/19 20:35:53.0906 5600 ================================================================================
2011/07/19 20:35:53.0920 0588 Detected object count: 1
2011/07/19 20:35:53.0920 0588 Actual detected object count: 1
2011/07/19 20:35:59.0153 0588 LockedFile.Multi.Generic(sptd) - User select action: Skip


log Combofix:

ComboFix 11-07-19.03 - Petr 19.07.2011 20:43:46.5.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2047.920 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\system32
c:\windows\system32\system32\3DAudio.ax
c:\windows\system32\system32\cis-2.4.dll
c:\windows\system32\system32\issacapi_bs-2.3.dll
c:\windows\system32\system32\issacapi_pe-2.3.dll
c:\windows\system32\system32\issacapi_se-2.3.dll
c:\windows\system32\system32\MACXMLProto.dll
c:\windows\system32\system32\MaDRM.dll
c:\windows\system32\system32\MaJGUILib.dll
c:\windows\system32\system32\MAMACExtract.dll
c:\windows\system32\system32\MASetupCleaner.exe
c:\windows\system32\system32\MaXMLProto.dll
c:\windows\system32\system32\MK_Lyric.dll
c:\windows\system32\system32\MSCLib.dll
c:\windows\system32\system32\MSFLib.dll
c:\windows\system32\system32\MSLUR71.dll
c:\windows\system32\system32\msvcp60.dll
c:\windows\system32\system32\MTTELECHIP.dll
c:\windows\system32\system32\MTXSYNCICON.dll
c:\windows\system32\system32\muzaf1.dll
c:\windows\system32\system32\muzapp.dll
c:\windows\system32\system32\muzapp.exe
c:\windows\system32\system32\muzdecode.ax
c:\windows\system32\system32\muzeffect.ax
c:\windows\system32\system32\muzmp4sp.ax
c:\windows\system32\system32\muzmpgsp.ax
c:\windows\system32\system32\muzoggsp.ax
c:\windows\system32\system32\muzwmts.dll
c:\windows\system32\system32\psapi.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-19 do 2011-07-19 )))))))))))))))))))))))))))))))
.
.
2011-07-19 18:59 . 2011-07-19 19:01 -------- d-----w- c:\users\Petr\AppData\Local\temp
2011-07-19 18:59 . 2011-07-19 18:59 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-07-19 18:59 . 2011-07-19 18:59 -------- d-----w- c:\users\Kristýnka\AppData\Local\temp
2011-07-19 18:59 . 2011-07-19 18:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-19 16:06 . 2011-07-19 16:06 -------- d-----w- C:\rsit
2011-07-19 15:49 . 2011-07-19 15:49 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{656B21B6-7C06-44E8-AD6A-DF4B1C2815C3}\MpKslf7718b1f.sys
2011-07-19 05:34 . 2011-07-19 05:34 -------- d-----w- c:\program files\Lavalys
2011-07-18 16:21 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{656B21B6-7C06-44E8-AD6A-DF4B1C2815C3}\mpengine.dll
2011-07-13 18:53 . 2011-06-11 02:29 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-07-11 23:12 . 2011-07-11 23:14 -------- d-----w- c:\users\Petr\AppData\Roaming\Zoner
2011-07-11 23:11 . 2011-07-11 23:11 -------- d-----w- c:\program files\Zoner
2011-07-11 22:19 . 2011-07-11 22:19 -------- d-----w- c:\users\Petr\AppData\Roaming\TeamViewer
2011-06-28 22:53 . 2011-05-04 04:34 1549312 ----a-w- c:\windows\system32\tquery.dll
2011-06-28 22:53 . 2011-05-04 04:32 1401344 ----a-w- c:\windows\system32\mssrch.dll
2011-06-28 22:53 . 2011-05-04 04:28 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-28 22:53 . 2011-05-04 04:32 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-28 22:53 . 2011-05-04 04:32 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-28 22:53 . 2011-05-04 04:28 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-28 22:53 . 2011-05-04 04:28 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-28 22:53 . 2011-05-04 04:32 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-28 22:53 . 2011-05-04 04:32 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-28 22:53 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-28 19:34 . 2011-06-29 00:32 -------- d-----w- c:\program files\Zrychleni Pocitace
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-29 07:39 . 2011-02-11 23:28 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-29 07:39 . 2011-02-11 23:28 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-21 04:23 . 2011-05-17 04:23 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-07 15:55 . 2010-10-02 17:39 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-03 04:30 . 2011-06-17 09:51 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46 . 2011-06-17 09:51 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46 . 2011-06-17 09:51 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46 . 2011-06-17 09:51 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17 . 2011-06-17 09:50 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17 . 2011-06-17 09:50 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17 . 2011-06-17 09:50 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31 . 2011-06-17 09:51 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18 . 2011-06-17 09:51 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 23:35 . 2011-06-18 01:01 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-04-22 23:25 . 2011-06-18 01:01 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-22 19:14 . 2011-05-25 02:23 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-11-22 2424560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-08-28 1486848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-24 174104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-24 151064]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:13 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Data Sync.lnk
backup=c:\windows\pss\Data Sync.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-04-26 17:32 136176 ----atw- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-04-28 16:24 934800 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-04-28 16:24 19856 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-04-28 16:24 3373968 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
R1 aawewgme;aawewgme;c:\windows\system32\drivers\aawewgme.sys [x]
R1 abqkehqt;abqkehqt;c:\windows\system32\drivers\abqkehqt.sys [x]
R1 aczmhypl;aczmhypl;c:\windows\system32\drivers\aczmhypl.sys [x]
R1 addkmbvj;addkmbvj;c:\windows\system32\drivers\addkmbvj.sys [x]
R1 adfkglfq;adfkglfq;c:\windows\system32\drivers\adfkglfq.sys [x]
R1 adhhvdmy;adhhvdmy;c:\windows\system32\drivers\adhhvdmy.sys [x]
R1 afnitpjk;afnitpjk;c:\windows\system32\drivers\afnitpjk.sys [x]
R1 amxalhys;amxalhys;c:\windows\system32\drivers\amxalhys.sys [x]
R1 bimhdgty;bimhdgty;c:\windows\system32\drivers\bimhdgty.sys [x]
R1 bojtifav;bojtifav;c:\windows\system32\drivers\bojtifav.sys [x]
R1 cfcwvlje;cfcwvlje;c:\windows\system32\drivers\cfcwvlje.sys [x]
R1 ciwkbgmc;ciwkbgmc;c:\windows\system32\drivers\ciwkbgmc.sys [x]
R1 cuopvdmv;cuopvdmv;c:\windows\system32\drivers\cuopvdmv.sys [x]
R1 dbmmjtnm;dbmmjtnm;c:\windows\system32\drivers\dbmmjtnm.sys [x]
R1 eabszwjv;eabszwjv;c:\windows\system32\drivers\eabszwjv.sys [x]
R1 ebnanrya;ebnanrya;c:\windows\system32\drivers\ebnanrya.sys [x]
R1 eektuhga;eektuhga;c:\windows\system32\drivers\eektuhga.sys [x]
R1 ejiejfcu;ejiejfcu;c:\windows\system32\drivers\ejiejfcu.sys [x]
R1 elzwtbfc;elzwtbfc;c:\windows\system32\drivers\elzwtbfc.sys [x]
R1 emazupze;emazupze;c:\windows\system32\drivers\emazupze.sys [x]
R1 emmjfeni;emmjfeni;c:\windows\system32\drivers\emmjfeni.sys [x]
R1 eufvpivq;eufvpivq;c:\windows\system32\drivers\eufvpivq.sys [x]
R1 ewadmjyi;ewadmjyi;c:\windows\system32\drivers\ewadmjyi.sys [x]
R1 fetyhnit;fetyhnit;c:\windows\system32\drivers\fetyhnit.sys [x]
R1 fhzpaugn;fhzpaugn;c:\windows\system32\drivers\fhzpaugn.sys [x]
R1 fovltltr;fovltltr;c:\windows\system32\drivers\fovltltr.sys [x]
R1 gcuwmlgu;gcuwmlgu;c:\windows\system32\drivers\gcuwmlgu.sys [x]
R1 ggsqzafh;ggsqzafh;c:\windows\system32\drivers\ggsqzafh.sys [x]
R1 gpylgoxn;gpylgoxn;c:\windows\system32\drivers\gpylgoxn.sys [x]
R1 hujguwgh;hujguwgh;c:\windows\system32\drivers\hujguwgh.sys [x]
R1 hzxbkpxt;hzxbkpxt;c:\windows\system32\drivers\hzxbkpxt.sys [x]
R1 iceyzanj;iceyzanj;c:\windows\system32\drivers\iceyzanj.sys [x]
R1 idklhixm;idklhixm;c:\windows\system32\drivers\idklhixm.sys [x]
R1 ifrmilpk;ifrmilpk;c:\windows\system32\drivers\ifrmilpk.sys [x]
R1 ihzuhraw;ihzuhraw;c:\windows\system32\drivers\ihzuhraw.sys [x]
R1 iufibibt;iufibibt;c:\windows\system32\drivers\iufibibt.sys [x]
R1 izsjmshi;izsjmshi;c:\windows\system32\drivers\izsjmshi.sys [x]
R1 jczdvtob;jczdvtob;c:\windows\system32\drivers\jczdvtob.sys [x]
R1 jlbhbjta;jlbhbjta;c:\windows\system32\drivers\jlbhbjta.sys [x]
R1 josmnand;josmnand;c:\windows\system32\drivers\josmnand.sys [x]
R1 jtxvkhdz;jtxvkhdz;c:\windows\system32\drivers\jtxvkhdz.sys [x]
R1 jwgtnbrz;jwgtnbrz;c:\windows\system32\drivers\jwgtnbrz.sys [x]
R1 jwmypcuu;jwmypcuu;c:\windows\system32\drivers\jwmypcuu.sys [x]
R1 kmffmyws;kmffmyws;c:\windows\system32\drivers\kmffmyws.sys [x]
R1 kzdqoorf;kzdqoorf;c:\windows\system32\drivers\kzdqoorf.sys [x]
R1 lgbsqoks;lgbsqoks;c:\windows\system32\drivers\lgbsqoks.sys [x]
R1 lilofhxo;lilofhxo;c:\windows\system32\drivers\lilofhxo.sys [x]
R1 llxhmred;llxhmred;c:\windows\system32\drivers\llxhmred.sys [x]
R1 lqoreyjj;lqoreyjj;c:\windows\system32\drivers\lqoreyjj.sys [x]
R1 lvaofivh;lvaofivh;c:\windows\system32\drivers\lvaofivh.sys [x]
R1 mivmpyqj;mivmpyqj;c:\windows\system32\drivers\mivmpyqj.sys [x]
R1 MpKsl032a711f;MpKsl032a711f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3B1C517E-BFE0-47E0-AAD1-60F4B7FBFC0B}\MpKsl032a711f.sys [x]
R1 MpKsl27444b43;MpKsl27444b43;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{35AD0FC2-91FC-43E0-A019-4615D0FB6366}\MpKsl27444b43.sys [x]
R1 MpKsl2dd3f829;MpKsl2dd3f829;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6080A4F-A161-442F-B3E1-533F10B63377}\MpKsl2dd3f829.sys [x]
R1 MpKsl3f0c654f;MpKsl3f0c654f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{20840DA4-05B5-4515-B34E-153E1E5AAE49}\MpKsl3f0c654f.sys [x]
R1 MpKsl48bb5ebc;MpKsl48bb5ebc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C073EB2C-E2A0-4042-BF3C-2AE5A8354267}\MpKsl48bb5ebc.sys [x]
R1 MpKsl4b5eb67a;MpKsl4b5eb67a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2567CAAE-BDB7-4E08-9D09-CB773B3C8A18}\MpKsl4b5eb67a.sys [x]
R1 MpKsl6e1d0fe3;MpKsl6e1d0fe3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C8219011-C70A-4F8B-AD74-8AC3C3FDA9AC}\MpKsl6e1d0fe3.sys [x]
R1 MpKsl7b52bf5c;MpKsl7b52bf5c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F8A0FFBC-D557-431A-A041-B2CF535CC426}\MpKsl7b52bf5c.sys [x]
R1 MpKsl87f8aba0;MpKsl87f8aba0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{69C29859-67F3-4D94-84E3-D8B52F08B501}\MpKsl87f8aba0.sys [x]
R1 MpKsl8f2fc6d7;MpKsl8f2fc6d7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F99D5C8D-7B6B-45BD-8FDE-BC6CE6360DDE}\MpKsl8f2fc6d7.sys [x]
R1 MpKsl9e6156dc;MpKsl9e6156dc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{94C583BB-A866-4821-A030-49252F79AE6F}\MpKsl9e6156dc.sys [x]
R1 MpKslb1a2c2aa;MpKslb1a2c2aa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4148D607-4D06-441E-87A8-F5C3D48D48E7}\MpKslb1a2c2aa.sys [x]
R1 MpKslbf11449c;MpKslbf11449c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{80386A5F-58FF-459C-ACB2-53439196099C}\MpKslbf11449c.sys [x]
R1 MpKslc72fae6f;MpKslc72fae6f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A8D661AA-7307-4244-AD29-3B8AC4DC4DAA}\MpKslc72fae6f.sys [x]
R1 MpKslc86f06c3;MpKslc86f06c3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A4A047A4-45A5-4646-A530-A058C1BF93CD}\MpKslc86f06c3.sys [x]
R1 MpKsld6f9af00;MpKsld6f9af00;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AE36E33C-FC92-46DE-B4F1-3C3FAC54A8AA}\MpKsld6f9af00.sys [x]
R1 mqmrzfgt;mqmrzfgt;c:\windows\system32\drivers\mqmrzfgt.sys [x]
R1 mrmztfxn;mrmztfxn;c:\windows\system32\drivers\mrmztfxn.sys [x]
R1 ndakyxka;ndakyxka;c:\windows\system32\drivers\ndakyxka.sys [x]
R1 nqzcavfj;nqzcavfj;c:\windows\system32\drivers\nqzcavfj.sys [x]
R1 ocbnwuxb;ocbnwuxb;c:\windows\system32\drivers\ocbnwuxb.sys [x]
R1 ofhbudog;ofhbudog;c:\windows\system32\drivers\ofhbudog.sys [x]
R1 ohvocfcy;ohvocfcy;c:\windows\system32\drivers\ohvocfcy.sys [x]
R1 olxyhvcu;olxyhvcu;c:\windows\system32\drivers\olxyhvcu.sys [x]
R1 ovyfhmpp;ovyfhmpp;c:\windows\system32\drivers\ovyfhmpp.sys [x]
R1 pcdlykjv;pcdlykjv;c:\windows\system32\drivers\pcdlykjv.sys [x]
R1 pnjvbnch;pnjvbnch;c:\windows\system32\drivers\pnjvbnch.sys [x]
R1 pyywcehx;pyywcehx;c:\windows\system32\drivers\pyywcehx.sys [x]
R1 qxbkjvcz;qxbkjvcz;c:\windows\system32\drivers\qxbkjvcz.sys [x]
R1 qyxykowi;qyxykowi;c:\windows\system32\drivers\qyxykowi.sys [x]
R1 sbygosut;sbygosut;c:\windows\system32\drivers\sbygosut.sys [x]
R1 sgnlkpcq;sgnlkpcq;c:\windows\system32\drivers\sgnlkpcq.sys [x]
R1 sgwiczhr;sgwiczhr;c:\windows\system32\drivers\sgwiczhr.sys [x]
R1 sojjopkm;sojjopkm;c:\windows\system32\drivers\sojjopkm.sys [x]
R1 sphxqmcl;sphxqmcl;c:\windows\system32\drivers\sphxqmcl.sys [x]
R1 stgwsoco;stgwsoco;c:\windows\system32\drivers\stgwsoco.sys [x]
R1 tfdgxacf;tfdgxacf;c:\windows\system32\drivers\tfdgxacf.sys [x]
R1 tiatxvas;tiatxvas;c:\windows\system32\drivers\tiatxvas.sys [x]
R1 tmbitahs;tmbitahs;c:\windows\system32\drivers\tmbitahs.sys [x]
R1 uixtlaec;uixtlaec;c:\windows\system32\drivers\uixtlaec.sys [x]
R1 umfwxiho;umfwxiho;c:\windows\system32\drivers\umfwxiho.sys [x]
R1 uvmaupmv;uvmaupmv;c:\windows\system32\drivers\uvmaupmv.sys [x]
R1 vatgread;vatgread;c:\windows\system32\drivers\vatgread.sys [x]
R1 vogtnpyj;vogtnpyj;c:\windows\system32\drivers\vogtnpyj.sys [x]
R1 vysatiwr;vysatiwr;c:\windows\system32\drivers\vysatiwr.sys [x]
R1 wfhygevs;wfhygevs;c:\windows\system32\drivers\wfhygevs.sys [x]
R1 wkfxgxhc;wkfxgxhc;c:\windows\system32\drivers\wkfxgxhc.sys [x]
R1 wzzmsqft;wzzmsqft;c:\windows\system32\drivers\wzzmsqft.sys [x]
R1 xbhjhjnd;xbhjhjnd;c:\windows\system32\drivers\xbhjhjnd.sys [x]
R1 xohlphxj;xohlphxj;c:\windows\system32\drivers\xohlphxj.sys [x]
R1 xrfcdyev;xrfcdyev;c:\windows\system32\drivers\xrfcdyev.sys [x]
R1 xsmfwqoy;xsmfwqoy;c:\windows\system32\drivers\xsmfwqoy.sys [x]
R1 yeoibqdt;yeoibqdt;c:\windows\system32\drivers\yeoibqdt.sys [x]
R1 ygignqem;ygignqem;c:\windows\system32\drivers\ygignqem.sys [x]
R1 yhlqstvj;yhlqstvj;c:\windows\system32\drivers\yhlqstvj.sys [x]
R1 ykavftqj;ykavftqj;c:\windows\system32\drivers\ykavftqj.sys [x]
R1 ykfhlopn;ykfhlopn;c:\windows\system32\drivers\ykfhlopn.sys [x]
R1 ywthbitm;ywthbitm;c:\windows\system32\drivers\ywthbitm.sys [x]
R1 yxsrdtog;yxsrdtog;c:\windows\system32\drivers\yxsrdtog.sys [x]
R1 yzzehqit;yzzehqit;c:\windows\system32\drivers\yzzehqit.sys [x]
R1 zcjbviuk;zcjbviuk;c:\windows\system32\drivers\zcjbviuk.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 DrvSnSht;DrvSnSht;c:\program files\R-Drive Image\DrvSnSht.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 R-ImageDisk;R-ImageDisk;c:\program files\R-Drive Image\R-ImageDisk.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-01 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-06 691696]
S1 MpKslf7718b1f;MpKslf7718b1f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{656B21B6-7C06-44E8-AD6A-DF4B1C2815C3}\MpKslf7718b1f.sys [2011-07-19 28752]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-28 136360]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [2010-08-24 40912]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [2010-08-24 10448]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-08-17 1077760]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 88131794
*NewlyCreated* - MPKSLF7718B1F
*Deregistered* - 88131794
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 11:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001Core.job
- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-26 17:32]
.
2011-07-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001UA.job
- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-26 17:32]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
mWindow Title = Microsoft Internet Explorer
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-SpyEmergency - c:\program files\NETGATE\Spy Emergency\SpyEmergency.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\Kies\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3553766604-1357380040-1039371910-1001\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2011-07-19 21:03:47
ComboFix-quarantined-files.txt 2011-07-19 19:03
.
Před spuštěním: Volných bajtů: 480 844 218 368
Po spuštění: Volných bajtů: 480 570 335 232
.
- - End Of File - - 59E7BE15B6245594208173454453187C

Re: Prosím o prevenci

Napsal: 19 črc 2011 20:11
od vyosek
Co bude s temi antiviry, ktery nechame :???: Aviru nebo ten MSE od microsoftu :???:

Re: Prosím o prevenci

Napsal: 19 črc 2011 20:13
od Anna.ja
No to nevím, který z nich byste nechal vy?

Re: Prosím o prevenci

Napsal: 19 črc 2011 20:20
od vyosek
:arrow: Ja bych nechal MSE, pro bezneho uzivatele je vice pratelsky, navic je cesky

:arrow: Takze Aviru odinstalujte a pro jistotu jeste pouzijte remover http://dlpro.antivir.com/package/remova ... n32-en.exe

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe ARM"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    
    Driver::
    aawewgme
    abqkehqt
    aczmhypl
    addkmbvj
    adfkglfq
    adhhvdmy
    afnitpjk
    amxalhys
    bimhdgty
    bojtifav
    cfcwvlje
    ciwkbgmc
    cuopvdmv
    dbmmjtnm
    eabszwjv
    ebnanrya
    eektuhga
    ejiejfcu
    elzwtbfc
    emazupze
    emmjfeni
    eufvpivq
    ewadmjyi
    fetyhnit
    fhzpaugn
    fovltltr
    gcuwmlgu
    ggsqzafh
    gpylgoxn
    hujguwgh
    hzxbkpxt
    iceyzanj
    idklhixm
    ifrmilpk
    ihzuhraw
    iufibibt
    izsjmshi
    jczdvtob
    jlbhbjta
    josmnand
    jtxvkhdz
    jwgtnbrz
    jwmypcuu
    kmffmyws
    kzdqoorf
    lgbsqoks
    lilofhxo
    llxhmred
    lqoreyjj
    lvaofivh
    mivmpyqj
    MpKsl032a711f
    MpKsl27444b43
    MpKsl2dd3f829
    MpKsl3f0c654f
    MpKsl48bb5ebc
    MpKsl4b5eb67a
    MpKsl6e1d0fe3
    MpKsl7b52bf5c
    MpKsl87f8aba0
    MpKsl8f2fc6d7
    MpKsl9e6156dc
    MpKslb1a2c2aa
    MpKslbf11449c
    MpKslc72fae6f
    MpKslc86f06c3
    MpKsld6f9af00
    mqmrzfgt
    mrmztfxn
    ndakyxka
    nqzcavfj
    ocbnwuxb
    ofhbudog
    ohvocfcy
    olxyhvcu
    ovyfhmpp
    pcdlykjv
    pnjvbnch
    pyywcehx
    qxbkjvcz
    qyxykowi
    sbygosut
    sgnlkpcq
    sgwiczhr
    sojjopkm
    sphxqmcl
    stgwsoco
    tfdgxacf
    tiatxvas
    tmbitahs
    uixtlaec
    umfwxiho
    uvmaupmv
    vatgread
    vogtnpyj
    vysatiwr
    wfhygevs
    wkfxgxhc
    wzzmsqft
    xbhjhjnd
    xohlphxj
    xrfcdyev
    xsmfwqoy
    yeoibqdt
    ygignqem
    yhlqstvj
    ykavftqj
    ykfhlopn
    ywthbitm
    yxsrdtog
    yzzehqit
    zcjbviuk
    88131794
    MPKSLF7718B1F
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001Core.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001UA.job
    
    Collect::
    c:\windows\system32\drivers\aawewgme.sys
    c:\windows\system32\drivers\abqkehqt.sys
    c:\windows\system32\drivers\aczmhypl.sys
    c:\windows\system32\drivers\addkmbvj.sys
    c:\windows\system32\drivers\adfkglfq.sys
    c:\windows\system32\drivers\adhhvdmy.sys
    c:\windows\system32\drivers\afnitpjk.sys
    c:\windows\system32\drivers\amxalhys.sys
    c:\windows\system32\drivers\bimhdgty.sys
    c:\windows\system32\drivers\bojtifav.sys
    c:\windows\system32\drivers\cfcwvlje.sys
    c:\windows\system32\drivers\ciwkbgmc.sys
    c:\windows\system32\drivers\cuopvdmv.sys
    c:\windows\system32\drivers\dbmmjtnm.sys
    c:\windows\system32\drivers\eabszwjv.sys
    c:\windows\system32\drivers\ebnanrya.sys
    c:\windows\system32\drivers\eektuhga.sys
    c:\windows\system32\drivers\ejiejfcu.sys
    c:\windows\system32\drivers\elzwtbfc.sys
    c:\windows\system32\drivers\emazupze.sys
    c:\windows\system32\drivers\emmjfeni.sys
    c:\windows\system32\drivers\eufvpivq.sys
    c:\windows\system32\drivers\ewadmjyi.sys
    c:\windows\system32\drivers\fetyhnit.sys
    c:\windows\system32\drivers\fhzpaugn.sys
    c:\windows\system32\drivers\fovltltr.sys
    c:\windows\system32\drivers\gcuwmlgu.sys
    c:\windows\system32\drivers\ggsqzafh.sys
    c:\windows\system32\drivers\gpylgoxn.sys
    c:\windows\system32\drivers\hujguwgh.sys
    c:\windows\system32\drivers\hzxbkpxt.sys
    c:\windows\system32\drivers\iceyzanj.sys
    c:\windows\system32\drivers\idklhixm.sys
    c:\windows\system32\drivers\ifrmilpk.sys
    c:\windows\system32\drivers\ihzuhraw.sys
    c:\windows\system32\drivers\iufibibt.sys
    c:\windows\system32\drivers\izsjmshi.sys
    c:\windows\system32\drivers\jczdvtob.sys
    c:\windows\system32\drivers\jlbhbjta.sys
    c:\windows\system32\drivers\josmnand.sys
    c:\windows\system32\drivers\jtxvkhdz.sys
    c:\windows\system32\drivers\jwgtnbrz.sys
    c:\windows\system32\drivers\jwmypcuu.sys
    c:\windows\system32\drivers\kmffmyws.sys
    c:\windows\system32\drivers\kzdqoorf.sys
    c:\windows\system32\drivers\lgbsqoks.sys
    c:\windows\system32\drivers\lilofhxo.sys
    c:\windows\system32\drivers\llxhmred.sys
    c:\windows\system32\drivers\lqoreyjj.sys
    c:\windows\system32\drivers\lvaofivh.sys
    c:\windows\system32\drivers\mivmpyqj.sys
    c:\windows\system32\drivers\mqmrzfgt.sys
    c:\windows\system32\drivers\mrmztfxn.sys
    c:\windows\system32\drivers\ndakyxka.sys
    c:\windows\system32\drivers\nqzcavfj.sys
    c:\windows\system32\drivers\ocbnwuxb.sys
    c:\windows\system32\drivers\ofhbudog.sys
    c:\windows\system32\drivers\ohvocfcy.sys
    c:\windows\system32\drivers\olxyhvcu.sys
    c:\windows\system32\drivers\ovyfhmpp.sys
    c:\windows\system32\drivers\pcdlykjv.sys
    c:\windows\system32\drivers\pnjvbnch.sys
    c:\windows\system32\drivers\pyywcehx.sys
    c:\windows\system32\drivers\qxbkjvcz.sys
    c:\windows\system32\drivers\qyxykowi.sys
    c:\windows\system32\drivers\sbygosut.sys
    c:\windows\system32\drivers\sgnlkpcq.sys
    c:\windows\system32\drivers\sgwiczhr.sys
    c:\windows\system32\drivers\sojjopkm.sys
    c:\windows\system32\drivers\sphxqmcl.sys
    c:\windows\system32\drivers\stgwsoco.sys
    c:\windows\system32\drivers\tfdgxacf.sys
    c:\windows\system32\drivers\tiatxvas.sys
    c:\windows\system32\drivers\tmbitahs.sys
    c:\windows\system32\drivers\uixtlaec.sys
    c:\windows\system32\drivers\umfwxiho.sys
    c:\windows\system32\drivers\uvmaupmv.sys
    c:\windows\system32\drivers\vatgread.sys
    c:\windows\system32\drivers\vogtnpyj.sys
    c:\windows\system32\drivers\vysatiwr.sys
    c:\windows\system32\drivers\wfhygevs.sys
    c:\windows\system32\drivers\wkfxgxhc.sys
    c:\windows\system32\drivers\wzzmsqft.sys
    c:\windows\system32\drivers\xbhjhjnd.sys
    c:\windows\system32\drivers\xohlphxj.sys
    c:\windows\system32\drivers\xrfcdyev.sys
    c:\windows\system32\drivers\xsmfwqoy.sys
    c:\windows\system32\drivers\yeoibqdt.sys
    c:\windows\system32\drivers\ygignqem.sys
    c:\windows\system32\drivers\yhlqstvj.sys
    c:\windows\system32\drivers\ykavftqj.sys
    c:\windows\system32\drivers\ykfhlopn.sys
    c:\windows\system32\drivers\ywthbitm.sys
    c:\windows\system32\drivers\yxsrdtog.sys
    c:\windows\system32\drivers\yzzehqit.sys
    c:\windows\system32\drivers\zcjbviuk.sys
    
    DDS::
    uStart Page = hxxp://start.icq.com/
    
    RegLock::
    [HKEY_USERS\S-1-5-21-3553766604-1357380040-1039371910-1001\Software\SecuROM\License information*]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
    
    Reboot::
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Prosím o prevenci

Napsal: 19 črc 2011 21:19
od Anna.ja
nový CF log:

ComboFix 11-07-19.03 - Petr 19.07.2011 21:46:51.6.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2047.951 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3553766604-1357380040-1039371910-1001UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_88131794
-------\Legacy_MPKSL032A711F
-------\Legacy_MPKSL27444B43
-------\Legacy_MPKSL2DD3F829
-------\Legacy_MPKSL3F0C654F
-------\Legacy_MPKSL48BB5EBC
-------\Legacy_MPKSL4B5EB67A
-------\Legacy_MPKSL6E1D0FE3
-------\Legacy_MPKSL7B52BF5C
-------\Legacy_MPKSL87F8ABA0
-------\Legacy_MPKSL8F2FC6D7
-------\Legacy_MPKSL9E6156DC
-------\Legacy_MPKSLB1A2C2AA
-------\Legacy_MPKSLBF11449C
-------\Legacy_MPKSLC72FAE6F
-------\Legacy_MPKSLC86F06C3
-------\Legacy_MPKSLD6F9AF00
-------\Legacy_MPKSLF7718B1F
-------\Service_aawewgme
-------\Service_abqkehqt
-------\Service_aczmhypl
-------\Service_addkmbvj
-------\Service_adfkglfq
-------\Service_adhhvdmy
-------\Service_afnitpjk
-------\Service_amxalhys
-------\Service_bimhdgty
-------\Service_bojtifav
-------\Service_cfcwvlje
-------\Service_ciwkbgmc
-------\Service_cuopvdmv
-------\Service_dbmmjtnm
-------\Service_eabszwjv
-------\Service_ebnanrya
-------\Service_eektuhga
-------\Service_ejiejfcu
-------\Service_elzwtbfc
-------\Service_emazupze
-------\Service_emmjfeni
-------\Service_eufvpivq
-------\Service_ewadmjyi
-------\Service_fetyhnit
-------\Service_fhzpaugn
-------\Service_fovltltr
-------\Service_gcuwmlgu
-------\Service_ggsqzafh
-------\Service_gpylgoxn
-------\Service_hujguwgh
-------\Service_hzxbkpxt
-------\Service_iceyzanj
-------\Service_idklhixm
-------\Service_ifrmilpk
-------\Service_ihzuhraw
-------\Service_iufibibt
-------\Service_izsjmshi
-------\Service_jczdvtob
-------\Service_jlbhbjta
-------\Service_josmnand
-------\Service_jtxvkhdz
-------\Service_jwgtnbrz
-------\Service_jwmypcuu
-------\Service_kmffmyws
-------\Service_kzdqoorf
-------\Service_lgbsqoks
-------\Service_lilofhxo
-------\Service_llxhmred
-------\Service_lqoreyjj
-------\Service_lvaofivh
-------\Service_mivmpyqj
-------\Service_MpKsl032a711f
-------\Service_MpKsl27444b43
-------\Service_MpKsl2dd3f829
-------\Service_MpKsl3f0c654f
-------\Service_MpKsl48bb5ebc
-------\Service_MpKsl4b5eb67a
-------\Service_MpKsl6e1d0fe3
-------\Service_MpKsl7b52bf5c
-------\Service_MpKsl87f8aba0
-------\Service_MpKsl8f2fc6d7
-------\Service_MpKsl9e6156dc
-------\Service_MpKslb1a2c2aa
-------\Service_MpKslbf11449c
-------\Service_MpKslc72fae6f
-------\Service_MpKslc86f06c3
-------\Service_MpKsld6f9af00
-------\Service_MpKslf7718b1f
-------\Service_mqmrzfgt
-------\Service_mrmztfxn
-------\Service_ndakyxka
-------\Service_nqzcavfj
-------\Service_ocbnwuxb
-------\Service_ofhbudog
-------\Service_ohvocfcy
-------\Service_olxyhvcu
-------\Service_ovyfhmpp
-------\Service_pcdlykjv
-------\Service_pnjvbnch
-------\Service_pyywcehx
-------\Service_qxbkjvcz
-------\Service_qyxykowi
-------\Service_sbygosut
-------\Service_sgnlkpcq
-------\Service_sgwiczhr
-------\Service_sojjopkm
-------\Service_sphxqmcl
-------\Service_stgwsoco
-------\Service_tfdgxacf
-------\Service_tiatxvas
-------\Service_tmbitahs
-------\Service_uixtlaec
-------\Service_umfwxiho
-------\Service_uvmaupmv
-------\Service_vatgread
-------\Service_vogtnpyj
-------\Service_vysatiwr
-------\Service_wfhygevs
-------\Service_wkfxgxhc
-------\Service_wzzmsqft
-------\Service_xbhjhjnd
-------\Service_xohlphxj
-------\Service_xrfcdyev
-------\Service_xsmfwqoy
-------\Service_yeoibqdt
-------\Service_ygignqem
-------\Service_yhlqstvj
-------\Service_ykavftqj
-------\Service_ykfhlopn
-------\Service_ywthbitm
-------\Service_yxsrdtog
-------\Service_yzzehqit
-------\Service_zcjbviuk
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-19 do 2011-07-19 )))))))))))))))))))))))))))))))
.
.
2011-07-19 20:04 . 2011-07-19 20:15 -------- d-----w- c:\users\Petr\AppData\Local\temp
2011-07-19 20:04 . 2011-07-19 20:04 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-07-19 20:04 . 2011-07-19 20:04 -------- d-----w- c:\users\Kristýnka\AppData\Local\temp
2011-07-19 20:04 . 2011-07-19 20:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-19 16:06 . 2011-07-19 16:06 -------- d-----w- C:\rsit
2011-07-19 15:49 . 2011-07-19 15:49 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{656B21B6-7C06-44E8-AD6A-DF4B1C2815C3}\MpKslf7718b1f.sys
2011-07-19 05:34 . 2011-07-19 05:34 -------- d-----w- c:\program files\Lavalys
2011-07-18 16:21 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{656B21B6-7C06-44E8-AD6A-DF4B1C2815C3}\mpengine.dll
2011-07-13 18:53 . 2011-06-11 02:29 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-07-11 23:12 . 2011-07-11 23:14 -------- d-----w- c:\users\Petr\AppData\Roaming\Zoner
2011-07-11 23:11 . 2011-07-11 23:11 -------- d-----w- c:\program files\Zoner
2011-07-11 22:19 . 2011-07-11 22:19 -------- d-----w- c:\users\Petr\AppData\Roaming\TeamViewer
2011-06-28 22:53 . 2011-05-04 04:34 1549312 ----a-w- c:\windows\system32\tquery.dll
2011-06-28 22:53 . 2011-05-04 04:32 1401344 ----a-w- c:\windows\system32\mssrch.dll
2011-06-28 22:53 . 2011-05-04 04:28 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-28 22:53 . 2011-05-04 04:32 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-28 22:53 . 2011-05-04 04:32 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-28 22:53 . 2011-05-04 04:28 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-28 22:53 . 2011-05-04 04:28 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-28 22:53 . 2011-05-04 04:32 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-28 22:53 . 2011-05-04 04:32 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-28 22:53 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-28 19:34 . 2011-06-29 00:32 -------- d-----w- c:\program files\Zrychleni Pocitace
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-21 04:23 . 2011-05-17 04:23 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-07 15:55 . 2010-10-02 17:39 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-03 04:30 . 2011-06-17 09:51 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46 . 2011-06-17 09:51 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46 . 2011-06-17 09:51 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46 . 2011-06-17 09:51 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17 . 2011-06-17 09:50 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17 . 2011-06-17 09:50 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17 . 2011-06-17 09:50 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31 . 2011-06-17 09:51 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18 . 2011-06-17 09:51 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 23:35 . 2011-06-18 01:01 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-04-22 23:25 . 2011-06-18 01:01 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-22 19:14 . 2011-05-25 02:23 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-11-22 2424560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-08-28 1486848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-24 174104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-24 151064]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:13 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Data Sync.lnk
backup=c:\windows\pss\Data Sync.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-04-28 16:24 934800 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-04-28 16:24 19856 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-04-28 16:24 3373968 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 DrvSnSht;DrvSnSht;c:\program files\R-Drive Image\DrvSnSht.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 R-ImageDisk;R-ImageDisk;c:\program files\R-Drive Image\R-ImageDisk.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-01 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-06 691696]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [2010-08-24 40912]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [2010-08-24 10448]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-08-17 1077760]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - FSUSBEXDISK
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 11:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
mWindow Title = Microsoft Internet Explorer
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3553766604-1357380040-1039371910-1001\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4408)
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\DllHost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\AUDIODG.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2011-07-19 22:18:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-19 20:18
ComboFix2.txt 2011-07-19 19:03
.
Před spuštěním: Volných bajtů: 481 717 514 240
Po spuštění: Volných bajtů: 481 558 593 536
.
- - End Of File - - C4DA453993ABF8F8A65E50A228B2721E

Re: Prosím o prevenci

Napsal: 19 črc 2011 21:26
od vyosek
:arrow: Jeste nam tam neco zustalo, takze si dame znovu ComboFix a jeho skript - postup je stejny

Kód: Vybrat vše

KillAll::

Driver::
dgderdrv

Collect::
c:\windows\system32\drivers\dgderdrv.sys

Reboot::

Re: Prosím o prevenci

Napsal: 19 črc 2011 21:52
od Anna.ja
další CF log:

ComboFix 11-07-19.03 - Petr 19.07.2011 22:30:50.7.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2047.1118 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_dgderdrv
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-19 do 2011-07-19 )))))))))))))))))))))))))))))))
.
.
2011-07-19 20:46 . 2011-07-19 20:46 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-07-19 20:46 . 2011-07-19 20:46 -------- d-----w- c:\users\Kristýnka\AppData\Local\temp
2011-07-19 20:46 . 2011-07-19 20:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-19 20:17 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B7ECB9E6-4D02-4DFF-A8C4-ECCF1677B2A5}\mpengine.dll
2011-07-19 20:04 . 2011-07-19 20:48 -------- d-----w- c:\users\Petr\AppData\Local\temp
2011-07-19 16:06 . 2011-07-19 16:06 -------- d-----w- C:\rsit
2011-07-19 05:34 . 2011-07-19 05:34 -------- d-----w- c:\program files\Lavalys
2011-07-13 18:53 . 2011-06-11 02:29 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-07-11 23:12 . 2011-07-11 23:14 -------- d-----w- c:\users\Petr\AppData\Roaming\Zoner
2011-07-11 23:11 . 2011-07-11 23:11 -------- d-----w- c:\program files\Zoner
2011-07-11 22:19 . 2011-07-11 22:19 -------- d-----w- c:\users\Petr\AppData\Roaming\TeamViewer
2011-06-28 22:53 . 2011-05-04 04:34 1549312 ----a-w- c:\windows\system32\tquery.dll
2011-06-28 22:53 . 2011-05-04 04:32 1401344 ----a-w- c:\windows\system32\mssrch.dll
2011-06-28 22:53 . 2011-05-04 04:28 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-28 22:53 . 2011-05-04 04:32 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-28 22:53 . 2011-05-04 04:32 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-28 22:53 . 2011-05-04 04:28 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-28 22:53 . 2011-05-04 04:28 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-28 22:53 . 2011-05-04 04:32 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-28 22:53 . 2011-05-04 04:32 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-28 22:53 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-28 19:34 . 2011-06-29 00:32 -------- d-----w- c:\program files\Zrychleni Pocitace
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-21 04:23 . 2011-05-17 04:23 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-07 15:55 . 2010-10-02 17:39 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-03 04:30 . 2011-06-17 09:51 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46 . 2011-06-17 09:51 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46 . 2011-06-17 09:51 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46 . 2011-06-17 09:51 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17 . 2011-06-17 09:50 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17 . 2011-06-17 09:50 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17 . 2011-06-17 09:50 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31 . 2011-06-17 09:51 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18 . 2011-06-17 09:51 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 23:35 . 2011-06-18 01:01 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-04-22 23:25 . 2011-06-18 01:01 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-22 19:14 . 2011-05-25 02:23 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-11-22 2424560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-08-28 1486848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-24 174104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-24 151064]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:13 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Data Sync.lnk
backup=c:\windows\pss\Data Sync.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-04-28 16:24 934800 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-04-28 16:24 19856 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-04-28 16:24 3373968 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 DrvSnSht;DrvSnSht;c:\program files\R-Drive Image\DrvSnSht.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 R-ImageDisk;R-ImageDisk;c:\program files\R-Drive Image\R-ImageDisk.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-01 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-06 691696]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [2010-08-24 40912]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [2010-08-24 10448]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-08-17 1077760]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 11:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
mWindow Title = Microsoft Internet Explorer
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3553766604-1357380040-1039371910-1001\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(5432)
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\system32\AUDIODG.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2011-07-19 22:51:45 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-19 20:51
ComboFix2.txt 2011-07-19 20:18
ComboFix3.txt 2011-07-19 19:03
.
Před spuštěním: Volných bajtů: 481 639 292 928
Po spuštění: Volných bajtů: 481 585 254 400
.
- - End Of File - - 40CDA420F7C03A97F36EA3E7F35DB6D1

Re: Prosím o prevenci

Napsal: 20 črc 2011 11:11
od vyosek
Jak se chova PC :???:

Re: Prosím o prevenci

Napsal: 20 črc 2011 12:34
od Anna.ja
Zatím celkem v pohodě, ještě nebyla možnost zkontrolovat programy, který zlobily, hlavně mi padalo ICQ, to poznám až později. Ale zdá se být o něco rychlejší, Opera už mi netvrdí, že mám pomalé připojení (Máme UPC fiber 10 Mb). Takže zatím dobrý.

Jinak klobouk dolů, vaše znalosti jsou perfektní, už jste mě párkrát zachránili před formátováním. Díky, že tohle fórum existuje.

Přeju hezký den.

Re: Prosím o prevenci

Napsal: 20 črc 2011 15:30
od vyosek
Tak jeste uklidime :James008:

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /UninstallA
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: PC sledujte a napiste jak se chova

:arrow: Dekuji za chvalu :oops: Pomahame radi :)

Re: Prosím o prevenci

Napsal: 21 črc 2011 09:11
od Anna.ja
Zdravím opět. PCse zdá být už v pohodě, až na jednu maličkost a tou je neustálé padání ICQ. Zatím to řeším qipem a ICQ jsem odinstalovala. Přes Revo uninstaler hledám zbytky po ICQ a pak ho zkusím znovu naisntalovat.

ICQ se nechá zapnout, pokud nepíšu tak běží, ale jak začnu s někým psát, po chvilce ohlásí chybu a vypne se. U hodin zůstává viset ikona, ale jak přes ní jen přejedu myší, tak zmizí.
Máte nějaký tip, čím by to mohlo být, jak to spravit?

Re: Prosím o prevenci

Napsal: 21 črc 2011 09:49
od vyosek
ICQ bohuzel netusim a doporucuji pouzivam zmineny QIP - daleko mene zatezuje system, nema priblblble reklamy, je stabilnejsi...