Stránka 1 z 2

Fejsbuk vir

Napsal: 22 črc 2011 13:25
od mako
Logfile of random's system information tool 1.09 (written by random/random)
Run by mashinka at 2011-07-22 14:09:39
Microsoft Windows 7 Ultimate
System drive C: has 16 GB (32%) free of 50 GB
Total RAM: 1024 MB (22% free)


======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for mashinka.job
C:\Windows\tasks\xeudnp.job
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job

=========Mozilla firefox=========

ProfilePath - C:\Users\mashinka\AppData\Roaming\Mozilla\Firefox\Profiles\rfo9nd2b.default

prefs.js - "browser.startup.homepage" - "http://search.bearshare.com/"
prefs.js - "extensions.enabledItems" - "1vffxtbr@SmileyCentral_1v.com:1.2, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900, {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900, DTToolbar@toolbarnet.com:1.1.7.0190, {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.18"
prefs.js - "keyword.URL" - "http://dts.search-results.com/sr?src=ff ... temid=2&q="

"1vffxtbr@SmileyCentral_1v.com"=C:\Program Files\SmileyCentral_1v\bar\2.bin
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
"{6904342A-8307-11DF-A508-4AE2DFD72085}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0]
"Description"=DivX OVS Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SmileyCentral_1v.com/Plugin]
"Description"=SmileyCentral Plugin
"Path"=C:\Program Files\SmileyCentral_1v\bar\2.bin\NP1vStub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat

C:\Program Files\Mozilla Firefox\plugins\
npnul32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
SearchResults.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\mashinka\AppData\Roaming\Mozilla\Firefox\Profiles\rfo9nd2b.default\extensions\
DTToolbar@toolbarnet.com
plugin3@gameplaylabs.com
{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}

C:\Users\mashinka\AppData\Roaming\Mozilla\Firefox\Profiles\rfo9nd2b.default\searchplugins\
daemon-search.xml
SearchResults.xml
SmileyCentral_1v.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2011-05-30 798771]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-13 3913000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSoft.dll [2010-11-13 3913000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
UrlHelper Class - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll [2011-06-01 1236400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\mashinka\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-10-12 149968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-09 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-12-09 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTo1.dll [2010-12-25 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}]
MediaBar - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll [2011-05-30 87480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2011-04-21 1000768]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2011-05-30 798771]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-09 297648]
{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSoft.dll [2010-11-13 3913000]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-13 3913000]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTo1.dll [2010-12-25 3911776]
{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - MediaBar - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll [2011-05-30 87480]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\Windows\RTHDCPL.EXE [2007-01-30 16116224]
"SkyTel"=C:\Windows\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\Windows\ALCMTR.EXE [2005-05-03 69632]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"ATICustomerCare"=C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [2010-03-04 311296]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-01-11 1230704]
"DivX Download Manager"=C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe [2010-12-08 63360]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2011-05-25 1951112]
"DATAMNGR"=C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE [2011-06-01 1545144]
"wxpdrv"=C:\Windows\services32.exe [2011-07-21 1178112]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-9-0\svchost.exe [2011-07-21 1180672]
"tray_ico1"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-21 1180672]
"tray_ico2"=C:\Windows\update.tray-3-0\svchost.exe [2011-07-21 1180672]
"tray_ico3"=C:\Windows\update.tray-2-0\svchost.exe [2011-07-21 1180672]
"tray_ico4"= []
"2581088.exe"=C:\Windows\Temp\2581088.exe [2011-07-21 245760]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-22 249344]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-22 249344]
"2651026.exe"=C:\Users\mashinka\AppData\Local\Temp\2651026.exe [2011-07-21 245760]
"5716000.exe"=C:\Windows\Temp\5716000.exe [2011-07-21 483328]
"85746731-loader2.exe"=C:\Windows\Temp\85746731-loader2.exe [2011-07-21 245760]
"systemup"=C:\Windows\systemup.exe [2011-07-21 118784]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-21 115200]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui []
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice []
"29296929-loader2.exe"=C:\Windows\Temp\29296929-loader2.exe [2011-07-21 245760]
"24914502-loader2.exe"=C:\Users\mashinka\AppData\Local\Temp\24914502-loader2.exe [2011-07-21 245760]
"40749927-loader2.exe"=C:\Windows\Temp\40749927-loader2.exe [2011-07-22 249344]
"74015843-loader2.exe"=C:\Users\mashinka\AppData\Local\Temp\74015843-loader2.exe [2011-07-22 249344]
"1694350.exe"=C:\Windows\Temp\1694350.exe [2011-07-22 249344]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-05-24 336384]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-08-25 39408]
"JP595IR86O"=C:\Users\mashinka\AppData\Local\Temp\Yrs.exe []
"Z30KYPG3WS"=C:\Users\mashinka\AppData\Local\Temp\Yrr.exe []
"OEXPRESS"= []
"Nektra OEAPI"= []
"Device Detector"=DevDetect.exe -autorun []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe silent []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Users\mashinka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Xfire.lnk - C:\Program Files\Xfire\Xfire.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\datamngr.dll C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=L3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.ffds"=C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.div4"=DivXc32f.dll
"vidc.div3"=DivXc32.dll
"vidc.xvid"=xvid.dll
"vidc.mp43"=mpg4c32.dll
"msacm.l3radius"=l3codecp.acm
"msacm.divxa"=divxa32.acm
"msacm.vorbis"=Vorbis.acm
"msacm.a3d"=a3d.dll
"msacm.ogg"=ogg.dll
"msacm.vorbisenc"=vorbisenc.dll
"VIDC.ACDV"=ACDV.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-07-22 14:09:40 ----D---- C:\Program Files\trend micro
2011-07-22 14:09:39 ----D---- C:\rsit
2011-07-22 11:58:30 ----D---- C:\ProgramData\ATI
2011-07-22 11:58:27 ----D---- C:\Program Files\AMD APP
2011-07-22 11:57:59 ----D---- C:\ProgramData\AMD
2011-07-22 11:57:52 ----A---- C:\Windows\system32\drivers\amdiox86.sys
2011-07-22 11:56:31 ----D---- C:\Windows\LastGood
2011-07-21 23:56:46 ----A---- C:\Windows\ntbtlog.txt
2011-07-21 23:49:51 ----HD---- C:\Windows\update.tray-3-0-lnk
2011-07-21 23:49:51 ----HD---- C:\Windows\update.tray-3-0
2011-07-21 23:49:51 ----HD---- C:\Windows\update.tray-2-0-lnk
2011-07-21 23:49:51 ----HD---- C:\Windows\update.tray-2-0
2011-07-21 23:24:16 ----D---- C:\Program Files\CCleaner
2011-07-21 23:03:23 ----R---- C:\Windows\Alcmtr.exe
2011-07-21 23:00:52 ----D---- C:\Windows\ufa
2011-07-21 23:00:52 ----D---- C:\Windows\rpcminer
2011-07-21 23:00:52 ----D---- C:\Windows\phoenix
2011-07-21 22:24:42 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-21 22:04:33 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-21 22:04:33 ----HD---- C:\Windows\update.tray-7-0
2011-07-21 22:01:12 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-07-21 22:01:11 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-07-21 22:01:09 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-07-21 22:01:08 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-07-21 22:01:04 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-07-21 22:01:01 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-07-21 22:00:37 ----A---- C:\Windows\avastSS.scr
2011-07-21 22:00:36 ----A---- C:\Windows\system32\aswBoot.exe
2011-07-21 20:44:03 ----A---- C:\Windows\ddh_iplist.txt
2011-07-21 20:43:27 ----A---- C:\Windows\l1rezerv.exe
2011-07-21 20:43:21 ----A---- C:\Windows\systemup.exe
2011-07-21 20:41:41 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-21 20:41:20 ----HD---- C:\Windows\update.2
2011-07-21 20:38:52 ----HD---- C:\Windows\update.5.0
2011-07-21 20:38:46 ----A---- C:\Windows\unrar.exe
2011-07-21 20:38:06 ----A---- C:\Windows\iplist.txt
2011-07-21 20:37:59 ----A---- C:\Windows\sysdriver32_.exe
2011-07-21 20:37:45 ----A---- C:\Windows\sysdriver32.exe
2011-07-21 20:37:25 ----D---- C:\Windows\av_ico
2011-07-21 20:37:25 ----A---- C:\Windows\front_ip_list.txt
2011-07-21 20:35:52 ----HD---- C:\Windows\update.1
2011-07-21 20:35:51 ----HD---- C:\Windows\update.tray-9-0-lnk
2011-07-21 20:35:51 ----HD---- C:\Windows\update.tray-9-0
2011-07-21 20:25:17 ----A---- C:\Windows\winlog-ids.txt
2011-07-21 20:25:17 ----A---- C:\Windows\winlog-dirs.txt
2011-07-21 20:25:11 ----A---- C:\Windows\services32.exe
2011-07-15 08:32:04 ----D---- C:\ProgramData\430D
2011-07-14 23:29:32 ----D---- C:\ProgramData\boost_interprocess
2011-07-14 23:28:02 ----D---- C:\Program Files\BearShare Applications
2011-07-12 12:49:13 ----D---- C:\Users\mashinka\AppData\Roaming\Moto assistant
2011-07-12 12:49:11 ----D---- C:\Moto assistant
2011-07-12 12:46:03 ----D---- C:\sgcfinder5t
2011-07-12 12:46:03 ----A---- C:\Windows\iun3405.exe
2011-07-08 21:30:04 ----A---- C:\Users\mashinka\AppData\Roaming\room.dat
2011-07-08 21:29:22 ----D---- C:\Program Files\Garena
2011-07-04 19:06:26 ----D---- C:\Program Files\LogMeIn Hamachi
2011-07-04 18:18:53 ----A---- C:\Windows\War3Unin.pif
2011-07-04 18:18:53 ----A---- C:\Windows\War3Unin.exe
2011-07-04 18:18:53 ----A---- C:\Windows\War3Unin.dat

======List of files/folders modified in the last 1 month======

2011-07-22 14:09:52 ----D---- C:\Windows\Prefetch
2011-07-22 14:09:40 ----RD---- C:\Program Files
2011-07-22 13:37:19 ----D---- C:\Users\mashinka\AppData\Roaming\ICQ
2011-07-22 13:36:47 ----D---- C:\Windows\Temp
2011-07-22 13:32:10 ----SHD---- C:\$Recycle.Bin
2011-07-22 13:31:51 ----RD---- C:\Users
2011-07-22 12:23:56 ----D---- C:\Users\mashinka\AppData\Roaming\Winamp
2011-07-22 11:58:30 ----HD---- C:\ProgramData
2011-07-22 11:58:28 ----SHD---- C:\Windows\Installer
2011-07-22 11:58:28 ----SHD---- C:\Config.Msi
2011-07-22 11:58:27 ----D---- C:\Windows\System32
2011-07-22 11:58:07 ----D---- C:\Program Files\ATI Technologies
2011-07-22 11:57:55 ----D---- C:\Windows\system32\drivers
2011-07-22 11:57:54 ----D---- C:\Windows\system32\DriverStore
2011-07-22 11:57:54 ----D---- C:\Windows\system32\catroot
2011-07-22 11:57:54 ----D---- C:\Windows\inf
2011-07-22 11:57:04 ----D---- C:\Windows\system32\catroot2
2011-07-22 11:56:45 ----D---- C:\Windows
2011-07-22 11:50:59 ----D---- C:\Users\mashinka\AppData\Roaming\vlc
2011-07-22 11:19:35 ----D---- C:\ProgramData\AutoKMS
2011-07-22 00:03:34 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-07-21 23:47:10 ----SHD---- C:\System Volume Information
2011-07-21 23:28:02 ----D---- C:\Users\mashinka\AppData\Roaming\Media Player Classic
2011-07-21 23:28:02 ----D---- C:\Users\mashinka\AppData\Roaming\DAEMON Tools Lite
2011-07-21 23:27:54 ----D---- C:\Users\mashinka\AppData\Roaming\uTorrent
2011-07-21 23:27:25 ----D---- C:\Windows\Minidump
2011-07-21 23:27:25 ----D---- C:\Windows\Logs
2011-07-21 23:27:25 ----D---- C:\Windows\debug
2011-07-21 23:03:22 ----D---- C:\Windows\system32\RTCOM
2011-07-21 23:03:22 ----A---- C:\Windows\DIFxAPI.dll
2011-07-21 23:02:59 ----D---- C:\Program Files\Realtek
2011-07-21 22:52:50 ----D---- C:\Windows\system32\config
2011-07-21 21:18:48 ----SHD---- C:\Recovery
2011-07-21 21:18:47 ----D---- C:\Windows\system32\Recovery
2011-07-21 20:41:42 ----D---- C:\Windows\system32\drivers\etc
2011-07-20 19:37:26 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-20 18:51:35 ----RSD---- C:\Windows\assembly
2011-07-20 10:48:00 ----D---- C:\Users\mashinka\AppData\Roaming\dvdcss
2011-07-19 22:34:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-15 20:55:25 ----D---- C:\Program Files\Softonic-Eng7
2011-07-12 12:46:03 ----A---- C:\Windows\win.ini
2011-07-07 20:13:14 ----D---- C:\Windows\system32\wdi
2011-06-23 20:42:39 ----D---- C:\Program Files\Mozilla Firefox

Re: Fejsbuk vir

Napsal: 22 črc 2011 14:06
od vyosek
Zdravim, pekne odpoledne preji a vitam vas u nas na foru :welcome:

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com :arrow: Aplikujte exeHelper by Raktor :arrow: Aplikujte RogueKiller
stell píše: pouzijes RogueKiller>.spustis>>stlac 2> [enter] log vloz sem
http://www.viry.cz/forum/viewtopic.php? ... 05#p981205
:arrow: Jeste znovu RogueKiller ale nyni s moznosti 3 a pote jeste jednou s moznosti 4

:arrow: RKill, eXeHelper i RogueKiller by mely udelat logy, vlozte mi je sem

Re: Fejsbuk vir

Napsal: 22 črc 2011 14:53
od mako
spustil som rkill a poitom som sa snazil ten exehelper ale ked nan kliknem zacne robit a potom mi napise ze program prestal pracovat tu je log z rkill:
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on . 07. 2011 at 15:49:11.
Operating System: Windows 7 Ultimate


Processes terminated by Rkill or while it was running:

\\.\globalroot\Device\svchost.exe\svchost.exe


Rkill completed on . 07. 2011 at 15:49:31.

Re: Fejsbuk vir

Napsal: 22 črc 2011 14:54
od vyosek
Pokracujte tedy RogueKillerem

Re: Fejsbuk vir

Napsal: 22 črc 2011 15:00
od mako
RogueKiller V5.2.7 [06/30/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: mashinka [Admin rights]
Mode: Remove -- Date : 07/22/2011 15:59:07

Bad processes: 12
[SUSP PATH] AutoKMS.exe -- c:\windows\autokms.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.5.0\svchost.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.2\svchost.exe -> KILLED
[SUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.tray-9-0\svchost.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.tray-7-0\svchost.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.tray-3-0\svchost.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.tray-2-0\svchost.exe -> KILLED
[SUSP PATH] sysdriver32_.exe -- c:\windows\sysdriver32_.exe -> KILLED
[SUSP PATH] systemup.exe -- c:\windows\systemup.exe -> KILLED
[SUSP PATH] l1rezerv.exe -- c:\windows\l1rezerv.exe -> KILLED
[SUSP PATH] WebIE.dll -- C:\ProgramData\LangSoft\WebIE.dll -> UNLOADED

Registry Entries: 24
[SUSP PATH] HKCU\[...]\Run : JP595IR86O (C:\Users\mashinka\AppData\Local\Temp\Yrs.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Run : Z30KYPG3WS (C:\Users\mashinka\AppData\Local\Temp\Yrr.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : wxpdrv (C:\Windows\services32.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 2581088.exe ("C:\Windows\Temp\2581088.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\Windows\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\Windows\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 2651026.exe ("C:\Users\mashinka\AppData\Local\Temp\2651026.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 5716000.exe ("C:\Windows\Temp\5716000.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 85746731-loader2.exe ("C:\Windows\Temp\85746731-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : systemup ("C:\Windows\systemup.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("C:\Windows\l1rezerv.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 29296929-loader2.exe ("C:\Windows\Temp\29296929-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 24914502-loader2.exe ("C:\Users\mashinka\AppData\Local\Temp\24914502-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 40749927-loader2.exe ("C:\Windows\Temp\40749927-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 74015843-loader2.exe ("C:\Users\mashinka\AppData\Local\Temp\74015843-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1694350.exe ("C:\Windows\Temp\1694350.exe") -> DELETED
[SUSP PATH] {22116563-108C-42c0-A7CE-60161B75E508}.job : c:\users\mashinka\appdata\local\temp\yrs.exe -> DELETED
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]


Finished : << RKreport[1].txt >>
RKreport[1].txt

Re: Fejsbuk vir

Napsal: 22 črc 2011 15:01
od mako
RogueKiller V5.2.7 [06/30/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: mashinka [Admin rights]
Mode: HOSTSFix -- Date : 07/22/2011 16:01:24

Bad processes: 0

HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

Re: Fejsbuk vir

Napsal: 22 črc 2011 15:03
od mako
tu je posledny log :
RogueKiller V5.2.7 [06/30/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: mashinka [Admin rights]
Mode: ProxyFix -- Date : 07/22/2011 16:02:51

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

Re: Fejsbuk vir

Napsal: 22 črc 2011 15:04
od vyosek
Fajn, RogueKiller nam neco pomazal, ted tam pustime poradny nastroj

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Fejsbuk vir

Napsal: 22 črc 2011 15:32
od mako
nemôzem to spustiti pretoze mi pise ze mam stale aktivny antivirus avast internet security a antispyware avast... netusim ale rpeco pretoze som ho uz odinstaloval takze nemam vôbec sajnu ako ho vypnem ani v Task manageri ho nejak nevidim co s tym?

Re: Fejsbuk vir

Napsal: 22 črc 2011 15:45
od vyosek
Okliknete hlasku a nechte CF probehnout, CF je obcas na Avast paranoidni

Re: Fejsbuk vir

Napsal: 22 črc 2011 16:26
od mako
takze po prvom raze mi neslo nic spustit ziadny internetovy browser tak som zopaknul combofix a teraz mi ide aspon internet exp.. tu je log z combo fixu treba este nieco?
ComboFix 11-07-22.02 - mashinka . 07. 2011 17:10:03.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1033.18.1024.442 [GMT 2:00]
Running from: C:\Users\mashinka\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

/wow section - STAGE 1

/wow section - STAGE 3
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.

/wow section - STAGE 4
Access is denied.
Access is denied.
The system cannot find the file tempAA.
Could Not Find C:\ComboFix\tempAA
Access is denied.

/wow section - STAGE 5
Access is denied.

/wow section - STAGE 6
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.

/wow section - STAGE 6A
Access is denied.

/wow section - STAGE 7
Access is denied.

/wow section - STAGE 8
Access is denied.
Access is denied.

/wow section - STAGE 10
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.

/wow section - STAGE 17
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
SED: can't read temp1500: No such file or directory
Access is denied.
Access is denied.
SED: can't read temp1505: No such file or directory
Access is denied.
'.0.\\.' is not recognized as an internal or external command
Access is denied.

/wow section - STAGE 23
Access is denied.
Access is denied.
Access is denied.
Access is denied.
FINDSTR: Cannot open temp2000
Access is denied.
Access is denied.
Access is denied.
SED: can't read temp2201: No such file or directory
Access is denied.

/wow section - STAGE 27
Access is denied.
Access is denied.
SED: can't read temp2400: No such file or directory
Access is denied.
Access is denied.
grep: temp2401: No such file or directory
Access is denied.

/wow section - STAGE 32
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
SED: can't read WrgNameDLL00: No such file or directory
Access is denied.
Access is denied.
Access is denied.
Access is denied.
SED: can't read VList02: No such file or directory
SED: can't read VList02: No such file or directory
Access is denied.

/wow section - STAGE 32A
Access is denied.
Access is denied.

/wow section - STAGE 33
Access is denied.
Access is denied.

/wow section - STAGE 48
Access is denied.
Access is denied.
SED: can't read temp3300: No such file or directory
FINDSTR: Cannot open temp3300
SED: can't read temp3300: No such file or directory
Access is denied.
SED: can't read temp3300: No such file or directory
Access is denied.
SED: can't read temp3300: No such file or directory
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
The system cannot find the file temp4700.
The system cannot find the file temp4700.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
Access is denied.
The system cannot find the file temp4700.
Access is denied.
Access is denied.
Access is denied.

/wow section - STAGE 49
Access is denied.
Access is denied.

/wow section - STAGE 50

/wow section not completed

Re: Fejsbuk vir

Napsal: 22 črc 2011 16:29
od vyosek
No tak CFko bylo necim omezene :o

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Utilitu spustte a prikazte ji, at skenuje - klik na Start Scan
  • Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
  • Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
  • Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
  • Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
  • Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte
:arrow: Opakujte postup s CFkem v nouzovem rezimu

Re: Fejsbuk vir

Napsal: 22 črc 2011 16:36
od mako
nechcelo restart tu je log:
2011/07/22 17:33:41.0349 3320 TDSS rootkit removing tool 2.5.11.0 Jul 11 2011 16:56:56
2011/07/22 17:33:41.0786 3320 ================================================================================
2011/07/22 17:33:41.0786 3320 SystemInfo:
2011/07/22 17:33:41.0786 3320
2011/07/22 17:33:41.0786 3320 OS Version: 6.1.7600 ServicePack: 0.0
2011/07/22 17:33:41.0786 3320 Product type: Workstation
2011/07/22 17:33:41.0786 3320 ComputerName: MASHINKA-PC
2011/07/22 17:33:41.0786 3320 UserName: mashinka
2011/07/22 17:33:41.0786 3320 Windows directory: C:\Windows
2011/07/22 17:33:41.0786 3320 System windows directory: C:\Windows
2011/07/22 17:33:41.0786 3320 Processor architecture: Intel x86
2011/07/22 17:33:41.0786 3320 Number of processors: 2
2011/07/22 17:33:41.0786 3320 Page size: 0x1000
2011/07/22 17:33:41.0786 3320 Boot type: Normal boot
2011/07/22 17:33:41.0786 3320 ================================================================================
2011/07/22 17:33:43.0159 3320 Initialize success
2011/07/22 17:33:56.0247 6744 ================================================================================
2011/07/22 17:33:56.0247 6744 Scan started
2011/07/22 17:33:56.0247 6744 Mode: Manual;
2011/07/22 17:33:56.0247 6744 ================================================================================
2011/07/22 17:33:58.0603 6744 1394ohci (2cc2633557be62ffadc32705b4d888f7) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/07/22 17:33:58.0634 6744 1394ohci - detected Rootkit.Win32.ZAccess.c (0)
2011/07/22 17:33:58.0759 6744 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2011/07/22 17:33:58.0837 6744 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/07/22 17:33:58.0915 6744 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/07/22 17:33:59.0009 6744 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/07/22 17:33:59.0118 6744 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/07/22 17:33:59.0274 6744 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2011/07/22 17:33:59.0352 6744 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2011/07/22 17:33:59.0430 6744 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/07/22 17:33:59.0555 6744 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2011/07/22 17:33:59.0664 6744 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2011/07/22 17:33:59.0742 6744 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2011/07/22 17:33:59.0882 6744 amdiox86 (ff258424f0b2ef25eb98f04ee386e6e3) C:\Windows\system32\DRIVERS\amdiox86.sys
2011/07/22 17:33:59.0976 6744 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/07/22 17:34:00.0225 6744 amdkmdag (aeae5ecbeaa0107d36c0b94ef341abc7) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/07/22 17:34:00.0522 6744 amdkmdap (60643c3abe28015269a62eb3dd4a49f4) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/07/22 17:34:00.0631 6744 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/07/22 17:34:00.0678 6744 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2011/07/22 17:34:00.0740 6744 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/07/22 17:34:00.0787 6744 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2011/07/22 17:34:00.0865 6744 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2011/07/22 17:34:00.0943 6744 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/07/22 17:34:00.0990 6744 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/07/22 17:34:01.0177 6744 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/07/22 17:34:01.0255 6744 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2011/07/22 17:34:01.0349 6744 AtiHDAudioService (7b4342936a3885cfe18e5d1df6d55bc5) C:\Windows\system32\drivers\AtihdW73.sys
2011/07/22 17:34:01.0614 6744 atikmdag (aeae5ecbeaa0107d36c0b94ef341abc7) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/07/22 17:34:01.0785 6744 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\Windows\system32\DRIVERS\atksgt.sys
2011/07/22 17:34:01.0926 6744 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/07/22 17:34:02.0019 6744 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/07/22 17:34:02.0082 6744 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/07/22 17:34:02.0191 6744 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/07/22 17:34:02.0253 6744 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
2011/07/22 17:34:02.0347 6744 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/07/22 17:34:02.0409 6744 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/07/22 17:34:02.0503 6744 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/07/22 17:34:02.0581 6744 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/07/22 17:34:02.0643 6744 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/07/22 17:34:02.0690 6744 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/07/22 17:34:02.0737 6744 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/07/22 17:34:03.0002 6744 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/07/22 17:34:03.0111 6744 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2011/07/22 17:34:03.0189 6744 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/07/22 17:34:03.0267 6744 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/07/22 17:34:03.0361 6744 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/07/22 17:34:03.0408 6744 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2011/07/22 17:34:03.0470 6744 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/07/22 17:34:03.0533 6744 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/07/22 17:34:03.0626 6744 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/07/22 17:34:03.0845 6744 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/07/22 17:34:03.0938 6744 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
2011/07/22 17:34:04.0047 6744 DfsC (580486a0df446fabfb20f795078367d7) C:\Windows\system32\Drivers\dfsc.sys
2011/07/22 17:34:04.0110 6744 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/07/22 17:34:04.0188 6744 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/07/22 17:34:04.0328 6744 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/07/22 17:34:04.0422 6744 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
2011/07/22 17:34:04.0531 6744 eamonm (04cba07e73f152970fc34d66d3892e2a) C:\Windows\system32\DRIVERS\eamonm.sys
2011/07/22 17:34:04.0687 6744 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/07/22 17:34:04.0921 6744 ehdrv (fe7824239d132ad9ebd8645fe1199b30) C:\Windows\system32\DRIVERS\ehdrv.sys
2011/07/22 17:34:05.0124 6744 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/07/22 17:34:05.0202 6744 epfwwfpr (ddb45f6371714601a43e8be38145be18) C:\Windows\system32\DRIVERS\epfwwfpr.sys
2011/07/22 17:34:05.0264 6744 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2011/07/22 17:34:05.0373 6744 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/07/22 17:34:05.0436 6744 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/07/22 17:34:05.0514 6744 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/07/22 17:34:05.0607 6744 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/07/22 17:34:05.0670 6744 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/07/22 17:34:05.0748 6744 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/07/22 17:34:05.0857 6744 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/07/22 17:34:05.0951 6744 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/07/22 17:34:05.0997 6744 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/07/22 17:34:06.0060 6744 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys
2011/07/22 17:34:06.0122 6744 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/07/22 17:34:06.0169 6744 gdrv (ad6bd6bdc97bede8a5507ee01220c00f) C:\Windows\gdrv.sys
2011/07/22 17:34:06.0434 6744 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
2011/07/22 17:34:06.0528 6744 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/07/22 17:34:06.0621 6744 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2011/07/22 17:34:06.0746 6744 HDAudBus (c874b1f18a7dd0d5db9974bd0470618d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/07/22 17:34:06.0762 6744 HDAudBus - detected Rootkit.Win32.ZAccess.c (0)
2011/07/22 17:34:06.0824 6744 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/07/22 17:34:06.0887 6744 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/07/22 17:34:06.0965 6744 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/07/22 17:34:07.0074 6744 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2011/07/22 17:34:07.0230 6744 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/07/22 17:34:07.0308 6744 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2011/07/22 17:34:07.0370 6744 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2011/07/22 17:34:07.0433 6744 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/07/22 17:34:07.0511 6744 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2011/07/22 17:34:07.0604 6744 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/07/22 17:34:07.0947 6744 IntcAzAudAddService (b29781b9a90cd55fc5d859c0b1c243bc) C:\Windows\system32\drivers\RtkHDAud.sys
2011/07/22 17:34:08.0259 6744 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2011/07/22 17:34:08.0322 6744 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/07/22 17:34:08.0415 6744 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/07/22 17:34:08.0603 6744 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/07/22 17:34:08.0649 6744 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/07/22 17:34:08.0712 6744 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/07/22 17:34:08.0774 6744 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2011/07/22 17:34:08.0837 6744 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/07/22 17:34:08.0915 6744 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/07/22 17:34:08.0961 6744 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/07/22 17:34:09.0024 6744 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2011/07/22 17:34:09.0086 6744 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2011/07/22 17:34:09.0305 6744 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/07/22 17:34:09.0414 6744 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/07/22 17:34:09.0523 6744 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/07/22 17:34:09.0585 6744 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/07/22 17:34:09.0663 6744 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/07/22 17:34:09.0757 6744 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/07/22 17:34:09.0851 6744 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/07/22 17:34:09.0975 6744 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/07/22 17:34:10.0038 6744 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/07/22 17:34:10.0147 6744 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/07/22 17:34:10.0194 6744 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/07/22 17:34:10.0256 6744 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2011/07/22 17:34:10.0303 6744 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/07/22 17:34:10.0350 6744 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2011/07/22 17:34:10.0397 6744 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2011/07/22 17:34:10.0443 6744 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/07/22 17:34:10.0521 6744 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2011/07/22 17:34:10.0599 6744 mrxsmb (b4c76ef46322a9711c7b0f4e21ef6ea5) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/07/22 17:34:10.0677 6744 mrxsmb10 (e593d45024a3fdd11e93cc4a6ca91101) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/07/22 17:34:10.0724 6744 mrxsmb20 (a9f86c82c9cc3b679cc3957e1183a30f) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/07/22 17:34:10.0818 6744 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2011/07/22 17:34:10.0865 6744 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2011/07/22 17:34:10.0943 6744 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/07/22 17:34:11.0021 6744 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/07/22 17:34:11.0052 6744 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/07/22 17:34:11.0208 6744 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/07/22 17:34:11.0270 6744 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/07/22 17:34:11.0333 6744 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/07/22 17:34:11.0379 6744 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/07/22 17:34:11.0442 6744 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/07/22 17:34:11.0504 6744 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/07/22 17:34:11.0551 6744 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/07/22 17:34:11.0613 6744 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/07/22 17:34:11.0676 6744 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/07/22 17:34:11.0769 6744 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2011/07/22 17:34:11.0847 6744 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/07/22 17:34:11.0910 6744 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/07/22 17:34:11.0957 6744 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/07/22 17:34:12.0003 6744 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/07/22 17:34:12.0066 6744 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2011/07/22 17:34:12.0128 6744 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/07/22 17:34:12.0175 6744 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2011/07/22 17:34:12.0315 6744 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/07/22 17:34:12.0393 6744 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/07/22 17:34:12.0471 6744 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/07/22 17:34:12.0565 6744 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2011/07/22 17:34:12.0627 6744 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/07/22 17:34:12.0783 6744 NVENETFD (c7859d19648d45ee888666c044ecab23) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2011/07/22 17:34:12.0893 6744 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2011/07/22 17:34:12.0955 6744 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2011/07/22 17:34:13.0017 6744 nvstor32 (5fbf62a83b551f757112b4a0c27432ec) C:\Windows\system32\DRIVERS\nvstor32.sys
2011/07/22 17:34:13.0095 6744 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/07/22 17:34:13.0189 6744 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/07/22 17:34:13.0376 6744 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/07/22 17:34:13.0439 6744 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2011/07/22 17:34:13.0485 6744 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/07/22 17:34:13.0548 6744 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2011/07/22 17:34:13.0610 6744 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2011/07/22 17:34:13.0782 6744 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/07/22 17:34:13.0829 6744 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/07/22 17:34:13.0891 6744 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/07/22 17:34:14.0125 6744 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/07/22 17:34:14.0187 6744 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/07/22 17:34:14.0265 6744 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/07/22 17:34:14.0359 6744 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/07/22 17:34:14.0484 6744 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/07/22 17:34:14.0562 6744 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/07/22 17:34:14.0640 6744 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/07/22 17:34:14.0733 6744 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/07/22 17:34:14.0811 6744 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/07/22 17:34:15.0014 6744 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/07/22 17:34:15.0077 6744 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/07/22 17:34:15.0139 6744 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2011/07/22 17:34:15.0217 6744 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/07/22 17:34:15.0279 6744 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/07/22 17:34:15.0373 6744 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
2011/07/22 17:34:15.0482 6744 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/07/22 17:34:15.0529 6744 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/07/22 17:34:15.0607 6744 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2011/07/22 17:34:15.0669 6744 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2011/07/22 17:34:15.0794 6744 RMCAST (b4090006a82eeb608c358ab5d37de85a) C:\Windows\system32\DRIVERS\RMCAST.sys
2011/07/22 17:34:15.0903 6744 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/07/22 17:34:15.0950 6744 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/07/22 17:34:16.0075 6744 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/07/22 17:34:16.0215 6744 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2011/07/22 17:34:16.0387 6744 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/07/22 17:34:16.0574 6744 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/07/22 17:34:16.0637 6744 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/07/22 17:34:16.0777 6744 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/07/22 17:34:16.0902 6744 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/07/22 17:34:16.0995 6744 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/07/22 17:34:17.0105 6744 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/07/22 17:34:17.0151 6744 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/07/22 17:34:17.0245 6744 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2011/07/22 17:34:17.0354 6744 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/07/22 17:34:17.0401 6744 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/07/22 17:34:17.0495 6744 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/07/22 17:34:17.0573 6744 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/07/22 17:34:17.0697 6744 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/07/22 17:34:17.0697 6744 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/07/22 17:34:17.0713 6744 sptd - detected LockedFile.Multi.Generic (1)
2011/07/22 17:34:17.0775 6744 srv (4a9b0f215de2519e2363f91df25c1e97) C:\Windows\system32\DRIVERS\srv.sys
2011/07/22 17:34:17.0869 6744 srv2 (14c44875518ae1c982e54ea8c5f7fe28) C:\Windows\system32\DRIVERS\srv2.sys
2011/07/22 17:34:17.0963 6744 srvnet (07a14223b0a50e76ade003fdf95d4fec) C:\Windows\system32\DRIVERS\srvnet.sys
2011/07/22 17:34:18.0056 6744 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/07/22 17:34:18.0119 6744 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/07/22 17:34:18.0197 6744 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
2011/07/22 17:34:18.0228 6744 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2011/07/22 17:34:18.0415 6744 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2011/07/22 17:34:18.0540 6744 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2011/07/22 17:34:18.0649 6744 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2011/07/22 17:34:18.0743 6744 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2011/07/22 17:34:18.0805 6744 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2011/07/22 17:34:18.0852 6744 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2011/07/22 17:34:18.0914 6744 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2011/07/22 17:34:19.0086 6744 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/07/22 17:34:19.0179 6744 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2011/07/22 17:34:19.0242 6744 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/07/22 17:34:19.0304 6744 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2011/07/22 17:34:19.0429 6744 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/07/22 17:34:19.0491 6744 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2011/07/22 17:34:19.0538 6744 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/07/22 17:34:19.0663 6744 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/07/22 17:34:19.0772 6744 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2011/07/22 17:34:19.0835 6744 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2011/07/22 17:34:19.0928 6744 usbhub (90549f3f9fc3404ea89d85f6ae6addcd) C:\Windows\system32\DRIVERS\usbhub.sys
2011/07/22 17:34:19.0944 6744 usbhub - detected Rootkit.Win32.ZAccess.c (0)
2011/07/22 17:34:19.0991 6744 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2011/07/22 17:34:20.0053 6744 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/07/22 17:34:20.0115 6744 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/07/22 17:34:20.0193 6744 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/07/22 17:34:20.0240 6744 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/07/22 17:34:20.0381 6744 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/07/22 17:34:20.0459 6744 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/07/22 17:34:20.0505 6744 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/07/22 17:34:20.0568 6744 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/07/22 17:34:20.0630 6744 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2011/07/22 17:34:20.0693 6744 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/07/22 17:34:20.0739 6744 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2011/07/22 17:34:20.0786 6744 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
2011/07/22 17:34:20.0849 6744 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/07/22 17:34:20.0880 6744 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/07/22 17:34:20.0942 6744 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/07/22 17:34:20.0989 6744 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2011/07/22 17:34:21.0067 6744 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/07/22 17:34:21.0145 6744 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2011/07/22 17:34:21.0239 6744 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/07/22 17:34:21.0317 6744 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/22 17:34:21.0332 6744 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/22 17:34:21.0473 6744 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/07/22 17:34:21.0566 6744 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/07/22 17:34:21.0722 6744 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/07/22 17:34:21.0785 6744 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/07/22 17:34:21.0987 6744 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/07/22 17:34:22.0159 6744 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/07/22 17:34:22.0315 6744 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/07/22 17:34:22.0409 6744 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/07/22 17:34:22.0471 6744 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/07/22 17:34:22.0502 6744 Boot (0x1200) (52c1188b3ed9fdf1d9cd76be9d246079) \Device\Harddisk0\DR0\Partition0
2011/07/22 17:34:22.0533 6744 Boot (0x1200) (0479f8f00d14284df2064b7c4102a968) \Device\Harddisk0\DR0\Partition1
2011/07/22 17:34:22.0549 6744 ================================================================================
2011/07/22 17:34:22.0549 6744 Scan finished
2011/07/22 17:34:22.0549 6744 ================================================================================
2011/07/22 17:34:22.0565 6676 Detected object count: 4
2011/07/22 17:34:22.0580 6676 Actual detected object count: 4
2011/07/22 17:34:40.0349 6676 1394ohci (2cc2633557be62ffadc32705b4d888f7) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/07/22 17:34:43.0874 6676 Backup copy not found, trying to cure infected file..
2011/07/22 17:34:43.0890 6676 C:\Windows\system32\DRIVERS\1394ohci.sys - Cure failed (FFFFFFFF)
2011/07/22 17:34:43.0890 6676 C:\Windows\system32\DRIVERS\1394ohci.sys - processing error
2011/07/22 17:34:43.0890 6676 Rootkit.Win32.ZAccess.c(1394ohci) - User select action: Cure
2011/07/22 17:34:44.0139 6676 HDAudBus (c874b1f18a7dd0d5db9974bd0470618d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/07/22 17:34:44.0295 6676 Backup copy not found, trying to cure infected file..
2011/07/22 17:34:44.0295 6676 C:\Windows\system32\DRIVERS\HDAudBus.sys - Cure failed (FFFFFFFF)
2011/07/22 17:34:44.0295 6676 C:\Windows\system32\DRIVERS\HDAudBus.sys - processing error
2011/07/22 17:34:44.0295 6676 Rootkit.Win32.ZAccess.c(HDAudBus) - User select action: Cure
2011/07/22 17:34:44.0295 6676 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/07/22 17:34:44.0373 6676 usbhub (90549f3f9fc3404ea89d85f6ae6addcd) C:\Windows\system32\DRIVERS\usbhub.sys
2011/07/22 17:34:44.0576 6676 Backup copy not found, trying to cure infected file..
2011/07/22 17:34:44.0576 6676 C:\Windows\system32\DRIVERS\usbhub.sys - Cure failed (FFFFFFFF)
2011/07/22 17:34:44.0576 6676 C:\Windows\system32\DRIVERS\usbhub.sys - processing error
2011/07/22 17:34:44.0576 6676 Rootkit.Win32.ZAccess.c(usbhub) - User select action: Cure

Re: Fejsbuk vir

Napsal: 22 črc 2011 16:37
od mako
ist teraz do nudzoveho rezimu a spustiti CF?

Re: Fejsbuk vir

Napsal: 22 črc 2011 16:41
od vyosek
No zkuste, uvidime, je poskozeno mnoho systemovych souboru