Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Torpig?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Torpig?

#1 Příspěvek od TomPerys »

Ahoj,
zřejmě mám zavirovaný PC Torpigem. Respektive používám Spybot a AVG Internet Security 2011 ale ani jeden z nich mi nenašel nějaký vir nebo cokoliv.... i přesto je prokazatelně nakažený, protože mi zablokovali z toho důvoru IP adresu. Torpiga prý vytváří jiný vir, který je přímo v MBR.

Chci se zeptat, jestli o tom někdo nevíte víc a jestli mi vůbec pomůže ho nějak lokalizovat v tom MBR nebo jestli budu muset formátovat :(((

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Torpig?

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Formatem se haveti z mbr sektoru disku nezbavite :o

:arrow: Trvate na antiviru AVG :???: U nas nepatri mezi oblibene - vysoka zatez systemu, slabsi detekce. Zvolil bych spise Avast, Aviru ci MSE

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Utilitu spustte a prikazte ji, at skenuje - klik na Start Scan
  • Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
  • Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
  • Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
  • Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
  • Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte
:arrow: Dejte log z RSIT - viz muj podpis
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Re: Torpig?

#3 Příspěvek od TomPerys »

Avg mám kvůli licenci, získal jsem ji za slušnou cenu od známé, která tam dělá. Předtím jsem měl NOD od Esetu a ten mi taky celek h---o našel. Avasta jsem měl ještě před NODem ale ten byl právě na prostředky daleko víc náročnější a brzdil mi neuvěřitelně počítač.

Jinak jsem zkoušel MBR, ten mi nenašel nic. Ani utilita přímo od Esetu "Mebroot removal tool" (ten prá toho torpiga nejčastěji vytváří). Až tenTDSSKiller opravdu něco našel. Log po restartu je tady:


2011/07/29 15:11:49.0621 1320 TDSS rootkit removing tool 2.5.12.0 Jul 29 2011 12:58:14
2011/07/29 15:11:51.0622 1320 ================================================================================
2011/07/29 15:11:51.0622 1320 SystemInfo:
2011/07/29 15:11:51.0622 1320
2011/07/29 15:11:51.0622 1320 OS Version: 5.1.2600 ServicePack: 3.0
2011/07/29 15:11:51.0622 1320 Product type: Workstation
2011/07/29 15:11:51.0622 1320 ComputerName: D3BCXG3J
2011/07/29 15:11:51.0716 1320 UserName: Tomi
2011/07/29 15:11:51.0716 1320 Windows directory: C:\WINDOWS
2011/07/29 15:11:51.0716 1320 System windows directory: C:\WINDOWS
2011/07/29 15:11:51.0716 1320 Processor architecture: Intel x86
2011/07/29 15:11:51.0716 1320 Number of processors: 2
2011/07/29 15:11:51.0716 1320 Page size: 0x1000
2011/07/29 15:11:51.0716 1320 Boot type: Normal boot
2011/07/29 15:11:51.0716 1320 ================================================================================
2011/07/29 15:11:58.0909 1320 Initialize success
2011/07/29 15:12:04.0460 0504 ================================================================================
2011/07/29 15:12:04.0460 0504 Scan started
2011/07/29 15:12:04.0460 0504 Mode: Manual;
2011/07/29 15:12:04.0460 0504 ================================================================================
2011/07/29 15:12:11.0309 0504 83587731 (7dd41b7ac1fbb1dbf20bb1f4e4fbe58c) C:\WINDOWS\system32\DRIVERS\83587731.sys
2011/07/29 15:12:12.0028 0504 83587732 (a305fad3719c5db0c13d1c2bfd08a04d) C:\WINDOWS\system32\DRIVERS\83587732.sys
2011/07/29 15:12:13.0451 0504 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
2011/07/29 15:12:14.0154 0504 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/07/29 15:12:15.0061 0504 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/07/29 15:12:17.0125 0504 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
2011/07/29 15:12:17.0579 0504 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/07/29 15:12:17.0923 0504 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/07/29 15:12:18.0908 0504 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/07/29 15:12:20.0034 0504 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
2011/07/29 15:12:21.0238 0504 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
2011/07/29 15:12:22.0035 0504 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
2011/07/29 15:12:22.0958 0504 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
2011/07/29 15:12:23.0615 0504 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/07/29 15:12:24.0412 0504 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
2011/07/29 15:12:25.0288 0504 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
2011/07/29 15:12:26.0367 0504 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
2011/07/29 15:12:27.0305 0504 ApfiltrService (350f19eb5fe4ec37a2414df56cde1aa8) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2011/07/29 15:12:28.0180 0504 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
2011/07/29 15:12:30.0995 0504 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/07/29 15:12:31.0933 0504 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
2011/07/29 15:12:32.0434 0504 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
2011/07/29 15:12:33.0122 0504 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
2011/07/29 15:12:33.0622 0504 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/07/29 15:12:33.0825 0504 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/07/29 15:12:35.0076 0504 atksgt (e46d344412d1abc60c58e95c73bcdc70) C:\WINDOWS\system32\DRIVERS\atksgt.sys
2011/07/29 15:12:35.0733 0504 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/07/29 15:12:36.0390 0504 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/07/29 15:12:37.0093 0504 Avgfwdx (0c5941af0b6bf2fdf378937392865217) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys
2011/07/29 15:12:37.0171 0504 Avgfwfd (0c5941af0b6bf2fdf378937392865217) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys
2011/07/29 15:12:37.0844 0504 AVGIDSDriver (c403e7f715bb0a851a9dfae16ec4ae42) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
2011/07/29 15:12:38.0501 0504 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
2011/07/29 15:12:39.0267 0504 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
2011/07/29 15:12:39.0877 0504 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
2011/07/29 15:12:40.0424 0504 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
2011/07/29 15:12:41.0237 0504 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
2011/07/29 15:12:41.0878 0504 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
2011/07/29 15:12:42.0519 0504 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
2011/07/29 15:12:43.0332 0504 b57w2k (f96038aa1ec4013a93d2420fc689d1e9) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
2011/07/29 15:12:43.0582 0504 BASFND (5c68ac6f3e5b3e6d6a78e97d05e42c3a) C:\Program Files\Broadcom\ASFIPMon\BASFND.sys
2011/07/29 15:12:44.0818 0504 BCM43XX (e9ea635b8432d68f0005b3f6cebab837) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
2011/07/29 15:12:45.0662 0504 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/07/29 15:12:46.0491 0504 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
2011/07/29 15:12:47.0054 0504 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/07/29 15:12:47.0601 0504 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
2011/07/29 15:12:48.0633 0504 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/07/29 15:12:50.0025 0504 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/07/29 15:12:50.0541 0504 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/07/29 15:12:51.0526 0504 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys
2011/07/29 15:12:53.0762 0504 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/07/29 15:12:54.0622 0504 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
2011/07/29 15:12:55.0435 0504 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/07/29 15:12:55.0857 0504 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
2011/07/29 15:12:56.0420 0504 cpuz132 (097a0a4899b759a4f032bd464963b4be) C:\WINDOWS\system32\drivers\cpuz132_x32.sys
2011/07/29 15:12:57.0343 0504 cvintdrv (dbd89bc0dbe00dcd245be8f61dbee291) C:\WINDOWS\system32\drivers\cvintdrv.sys
2011/07/29 15:13:01.0893 0504 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
2011/07/29 15:13:02.0644 0504 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
2011/07/29 15:13:03.0597 0504 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/07/29 15:13:04.0426 0504 DLABMFSM (0659e6e0a95564f958d9df7313f7701e) C:\WINDOWS\system32\DLA\DLABMFSM.SYS
2011/07/29 15:13:04.0973 0504 DLABOIOM (8691c78908f0bd66170669db268369f2) C:\WINDOWS\system32\DLA\DLABOIOM.SYS
2011/07/29 15:13:05.0661 0504 DLACDBHM (76167b5eb2dffc729edc36386876b40b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
2011/07/29 15:13:06.0365 0504 DLADResM (5615744a1056933b90e6ac54feb86f35) C:\WINDOWS\system32\DLA\DLADResM.SYS
2011/07/29 15:13:07.0006 0504 DLAIFS_M (1aeca2afa5005ce4a550cf8eb55a8c88) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
2011/07/29 15:13:07.0725 0504 DLAOPIOM (840e7f6abb885c72b9ffddb022ef5b6d) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
2011/07/29 15:13:08.0413 0504 DLAPoolM (0294d18731ac05da80132ce88f8a876b) C:\WINDOWS\system32\DLA\DLAPoolM.SYS
2011/07/29 15:13:08.0929 0504 DLARTL_M (91886fed52a3f9966207bce46cfd794f) C:\WINDOWS\system32\Drivers\DLARTL_M.SYS
2011/07/29 15:13:09.0633 0504 DLAUDFAM (cca4e121d599d7d1706a30f603731e59) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
2011/07/29 15:13:10.0352 0504 DLAUDF_M (7dab85c33135df24419951da4e7d38e5) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
2011/07/29 15:13:11.0431 0504 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/07/29 15:13:12.0260 0504 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/07/29 15:13:13.0589 0504 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/07/29 15:13:14.0856 0504 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/07/29 15:13:15.0419 0504 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
2011/07/29 15:13:16.0060 0504 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/07/29 15:13:16.0763 0504 DRVMCDB (c00440385cf9f3d142917c63f989e244) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS
2011/07/29 15:13:17.0420 0504 DRVNDDM (6e6ab29d3c06e64ce81feacda85394b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
2011/07/29 15:13:17.0811 0504 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
2011/07/29 15:13:18.0249 0504 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
2011/07/29 15:13:18.0906 0504 DXEC01 (549734664886d91222969845e4311d1b) C:\WINDOWS\system32\drivers\dxec01.sys
2011/07/29 15:13:20.0063 0504 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/07/29 15:13:20.0704 0504 ElbyCDIO (06708b1423b3f5306249b0e0097f876e) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
2011/07/29 15:13:21.0877 0504 fanio (8b5c73dfb031d5d5112cd7be5b0f85ad) C:\WINDOWS\system32\drivers\fanio.sys
2011/07/29 15:13:23.0331 0504 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/07/29 15:13:23.0956 0504 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/07/29 15:13:24.0582 0504 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/07/29 15:13:25.0598 0504 FlashUSB (e044b5c7cd5cea728d13d30d431b13e0) C:\WINDOWS\system32\DRIVERS\FlashUSB.sys
2011/07/29 15:13:26.0317 0504 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/07/29 15:13:26.0865 0504 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/07/29 15:13:27.0240 0504 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/07/29 15:13:30.0023 0504 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/07/29 15:13:31.0024 0504 genmcmnUSB (86f732d2995ada73fd307539ec266d3a) C:\WINDOWS\system32\DRIVERS\gflmouhid.sys
2011/07/29 15:13:31.0868 0504 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
2011/07/29 15:13:34.0542 0504 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/07/29 15:13:35.0027 0504 guardian2 (7031a936832967a93b0e5d5f1c76745a) C:\WINDOWS\system32\Drivers\oz776.sys
2011/07/29 15:13:35.0387 0504 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/07/29 15:13:35.0652 0504 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/07/29 15:13:36.0387 0504 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
2011/07/29 15:13:37.0153 0504 HSFHWAZL (290cdbb05903742ea06b7203c5a662f5) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/07/29 15:13:38.0154 0504 HSF_DPV (7ab812355f98858b9ecdd46e6fcc221f) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/07/29 15:13:39.0436 0504 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/07/29 15:13:40.0500 0504 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
2011/07/29 15:13:41.0610 0504 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
2011/07/29 15:13:42.0314 0504 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/07/29 15:13:42.0939 0504 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/07/29 15:13:43.0643 0504 InCDFs (7c45a5d6dc0dee7eaa4cda2b489f4700) C:\WINDOWS\system32\drivers\InCDFs.sys
2011/07/29 15:13:45.0316 0504 InCDRm (f0c13333acd75ad4942a99c1aeb5429c) C:\WINDOWS\system32\drivers\InCDRm.sys
2011/07/29 15:13:47.0302 0504 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
2011/07/29 15:13:48.0365 0504 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/07/29 15:13:49.0100 0504 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/07/29 15:13:49.0694 0504 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/07/29 15:13:50.0366 0504 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/07/29 15:13:50.0992 0504 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/07/29 15:13:51.0586 0504 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/07/29 15:13:52.0055 0504 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/07/29 15:13:53.0056 0504 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/07/29 15:13:54.0119 0504 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/07/29 15:13:54.0948 0504 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/07/29 15:13:55.0839 0504 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/07/29 15:13:56.0684 0504 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/07/29 15:13:57.0497 0504 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/07/29 15:13:58.0779 0504 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
2011/07/29 15:13:59.0983 0504 LgBttPort (4dd47b5af0b24871ebb9efc012a7474e) C:\WINDOWS\system32\DRIVERS\lgbtport.sys
2011/07/29 15:14:00.0843 0504 lgbusenum (1d038ca6c529203087a990e5e97887b4) C:\WINDOWS\system32\DRIVERS\lgbtbus.sys
2011/07/29 15:14:01.0578 0504 LGVMODEM (26f1976a330195d62a6224c76968cf0d) C:\WINDOWS\system32\DRIVERS\lgvmodem.sys
2011/07/29 15:14:02.0031 0504 lirsgt (8ccf9ed46d52af1375875f74a91ffacf) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
2011/07/29 15:14:03.0048 0504 MBAMProtector (eca00eed9ab95489007b0ef84c7149de) C:\WINDOWS\system32\drivers\mbam.sys
2011/07/29 15:14:03.0986 0504 MBAMSwissArmy (b18225739ed9caa83ba2df966e9f43e8) C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011/07/29 15:14:04.0955 0504 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/07/29 15:14:05.0503 0504 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/07/29 15:14:06.0566 0504 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/07/29 15:14:07.0958 0504 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/07/29 15:14:08.0739 0504 moufiltr (9b5d39ed7659ba9b38b64df2a83f1768) C:\WINDOWS\system32\DRIVERS\moufiltr.sys
2011/07/29 15:14:09.0115 0504 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/07/29 15:14:10.0194 0504 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/07/29 15:14:10.0788 0504 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
2011/07/29 15:14:11.0648 0504 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/07/29 15:14:12.0273 0504 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/07/29 15:14:12.0836 0504 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/07/29 15:14:13.0446 0504 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/07/29 15:14:13.0962 0504 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/07/29 15:14:14.0963 0504 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/07/29 15:14:15.0479 0504 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/07/29 15:14:16.0057 0504 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/07/29 15:14:17.0011 0504 NCHSSVAD (0df9cc7b5cc173f545723f23e68fac93) C:\WINDOWS\system32\drivers\nchssvad.sys
2011/07/29 15:14:18.0309 0504 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/07/29 15:14:19.0122 0504 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/07/29 15:14:19.0622 0504 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/07/29 15:14:20.0279 0504 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/07/29 15:14:21.0061 0504 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/07/29 15:14:21.0640 0504 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/07/29 15:14:22.0328 0504 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/07/29 15:14:23.0125 0504 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/07/29 15:14:23.0891 0504 nmwcd (4a8a2aa0706b659175169decf198e9d7) C:\WINDOWS\system32\drivers\ccdcmb.sys
2011/07/29 15:14:24.0892 0504 nmwcdc (fd3e61831095ac62e6840d986b5a2016) C:\WINDOWS\system32\drivers\ccdcmbo.sys
2011/07/29 15:14:25.0517 0504 nmwcdnsu (02e96113511171ba7559386d10d3daea) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
2011/07/29 15:14:26.0284 0504 nmwcdnsuc (fb09150cfc7a499a53c308d04841a3bd) C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
2011/07/29 15:14:27.0316 0504 npf (b48dc6abcd3aeff8618350ccbdc6b09a) C:\WINDOWS\system32\drivers\npf.sys
2011/07/29 15:14:27.0863 0504 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/07/29 15:14:28.0864 0504 NSNDIS5 (53f7546e8daefb3a0813f5e19c4613c9) C:\WINDOWS\system32\NSNDIS5.SYS
2011/07/29 15:14:30.0646 0504 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/07/29 15:14:32.0398 0504 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/07/29 15:14:34.0039 0504 nv (8129d762cc3e3c5ab9cf2eabc377fb73) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/07/29 15:14:39.0481 0504 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/07/29 15:14:40.0028 0504 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/07/29 15:14:41.0217 0504 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/07/29 15:14:41.0795 0504 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/07/29 15:14:42.0937 0504 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/07/29 15:14:43.0828 0504 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/07/29 15:14:45.0892 0504 PBADRV (9ec004140e1b675acdeb07f66ee797a4) C:\WINDOWS\system32\DRIVERS\PBADRV.sys
2011/07/29 15:14:46.0580 0504 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/07/29 15:14:48.0800 0504 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/07/29 15:14:49.0379 0504 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/07/29 15:14:50.0317 0504 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
2011/07/29 15:14:51.0240 0504 PCTCore (ad629e621cb1242ba8707cd9c2c5b6ec) C:\WINDOWS\system32\drivers\PCTCore.sys
2011/07/29 15:14:53.0648 0504 PDRJNDL (ce9f92ddd0a5f362929f86fdfafaae03) C:\Program Files\Dekart\Private Disk Light\PDRJNDL.SYS
2011/07/29 15:14:54.0211 0504 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
2011/07/29 15:14:54.0883 0504 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
2011/07/29 15:14:55.0493 0504 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/07/29 15:14:55.0931 0504 PQNTDrv (4228630829c0e521c43d882a00533374) C:\WINDOWS\system32\drivers\PQNTDrv.sys
2011/07/29 15:14:58.0636 0504 PRVDISK (4da378d3626af74db40acc7641343a8d) C:\Program Files\Dekart\Private Disk Light\PRVDISK.SYS
2011/07/29 15:14:59.0496 0504 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/07/29 15:15:00.0575 0504 PSSDK42 (c8eb36910d3bd582891977e80925e21e) C:\WINDOWS\system32\Drivers\pssdk42.sys
2011/07/29 15:15:00.0997 0504 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/07/29 15:15:01.0622 0504 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/07/29 15:15:02.0967 0504 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
2011/07/29 15:15:03.0890 0504 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
2011/07/29 15:15:05.0047 0504 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
2011/07/29 15:15:05.0719 0504 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
2011/07/29 15:15:06.0376 0504 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
2011/07/29 15:15:07.0048 0504 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/07/29 15:15:07.0908 0504 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/07/29 15:15:08.0815 0504 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/07/29 15:15:09.0800 0504 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/07/29 15:15:10.0629 0504 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/07/29 15:15:11.0192 0504 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/07/29 15:15:11.0896 0504 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/07/29 15:15:12.0756 0504 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/07/29 15:15:14.0116 0504 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/07/29 15:15:15.0054 0504 RegKill (e20d35b8a0e9f80c058f5d8a3195c8ab) C:\WINDOWS\system32\Drivers\RegKill.sys
2011/07/29 15:15:16.0493 0504 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/07/29 15:15:17.0134 0504 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/07/29 15:15:17.0744 0504 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/07/29 15:15:18.0526 0504 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/07/29 15:15:18.0963 0504 setup_9.0.0.722_15.03.2011_11-34drv (66ef49622baa18e4d4f1fe4bae1d51b8) C:\WINDOWS\system32\DRIVERS\8358773.sys
2011/07/29 15:15:19.0167 0504 sfdrv01 (55c6ed71470eb14a1d9bb62def5731ca) C:\WINDOWS\system32\drivers\sfdrv01.sys
2011/07/29 15:15:19.0667 0504 sfhlp02 (daad4c099ebf5094d32c373ac1ac0f3c) C:\WINDOWS\system32\drivers\sfhlp02.sys
2011/07/29 15:15:19.0948 0504 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/07/29 15:15:21.0153 0504 sfsync04 (79979779710dd1195ffb16f2456bbb97) C:\WINDOWS\system32\drivers\sfsync04.sys
2011/07/29 15:15:21.0919 0504 sfvfs02 (5dc0d3978b2c98f370bd8a5c9fd86092) C:\WINDOWS\system32\drivers\sfvfs02.sys
2011/07/29 15:15:22.0403 0504 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
2011/07/29 15:15:22.0544 0504 snapman (e78c98378a071ce4d48a7c514fa98fa1) C:\WINDOWS\system32\DRIVERS\snapman.sys
2011/07/29 15:15:22.0966 0504 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/07/29 15:15:23.0279 0504 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\WINDOWS\system32\speedfan.sys
2011/07/29 15:15:24.0155 0504 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/07/29 15:15:24.0905 0504 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
2011/07/29 15:15:24.0921 0504 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/07/29 15:15:24.0937 0504 sptd - detected LockedFile.Multi.Generic (1)
2011/07/29 15:15:25.0171 0504 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/07/29 15:15:25.0468 0504 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/07/29 15:15:26.0125 0504 STHDA (31ba85e1cff39a57f702a2a0877bb8e1) C:\WINDOWS\system32\drivers\sthda.sys
2011/07/29 15:15:26.0703 0504 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
2011/07/29 15:15:26.0938 0504 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/07/29 15:15:27.0266 0504 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/07/29 15:15:27.0642 0504 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
2011/07/29 15:15:27.0939 0504 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
2011/07/29 15:15:28.0392 0504 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
2011/07/29 15:15:28.0627 0504 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
2011/07/29 15:15:29.0065 0504 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/07/29 15:15:29.0409 0504 tap0801 (0c82061920a2de35d33c2c2bb83b1e98) C:\WINDOWS\system32\DRIVERS\tap0801.sys
2011/07/29 15:15:30.0284 0504 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/07/29 15:15:31.0082 0504 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/07/29 15:15:32.0223 0504 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/07/29 15:15:33.0443 0504 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/07/29 15:15:33.0975 0504 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
2011/07/29 15:15:34.0178 0504 tosporte (8d624d3bd1f2d78bd1c01a2d4e954b4e) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/07/29 15:15:34.0569 0504 tosrfbd (435ac6cc2abed508ac5a495658cbaf0f) C:\WINDOWS\system32\DRIVERS\tosrfbd.sys
2011/07/29 15:15:36.0508 0504 tosrfbnp (90c8525bc578aaffe87c2d0ed4379e9e) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/07/29 15:15:37.0211 0504 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/07/29 15:15:38.0024 0504 Tosrfhid (28099a4e52148319afa685d93a2244d0) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/07/29 15:15:38.0665 0504 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/07/29 15:15:39.0041 0504 Tosrfusb (6bc529c5eca0c7654943fd6fab21c5fa) C:\WINDOWS\system32\DRIVERS\tosrfusb.sys
2011/07/29 15:15:39.0744 0504 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/07/29 15:15:40.0745 0504 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
2011/07/29 15:15:41.0042 0504 UnlockerDriver5 (4847639d852763ee39415c929470f672) C:\Program Files\Unlocker\UnlockerDriver5.sys
2011/07/29 15:15:41.0855 0504 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/07/29 15:15:42.0559 0504 upperdev (587e643a4e2ffd9a00f114b057ceb773) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
2011/07/29 15:15:43.0591 0504 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/07/29 15:15:44.0232 0504 usbbus (9419faac6552a51542dbba02971c841c) C:\WINDOWS\system32\DRIVERS\lgusbbus.sys
2011/07/29 15:15:45.0092 0504 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/07/29 15:15:45.0905 0504 UsbDiag (c0a466fa4ffec464320e159bc1bbdc0c) C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys
2011/07/29 15:15:46.0515 0504 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/07/29 15:15:47.0015 0504 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/07/29 15:15:47.0657 0504 USBModem (f74a54774a9b0afeb3c40adec68aa600) C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys
2011/07/29 15:15:48.0188 0504 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/07/29 15:15:48.0751 0504 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys
2011/07/29 15:15:49.0267 0504 UsbserFilt (fca6a196d47cb972a0e4adc0db9cd17c) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
2011/07/29 15:15:49.0799 0504 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/07/29 15:15:50.0237 0504 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/07/29 15:15:50.0706 0504 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/07/29 15:15:51.0534 0504 vhidmini (4a2c339b9e848e5099411577be01e0ff) C:\WINDOWS\system32\DRIVERS\walvhid.sys
2011/07/29 15:15:52.0035 0504 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
2011/07/29 15:15:52.0254 0504 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/07/29 15:15:52.0504 0504 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/07/29 15:15:53.0036 0504 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/07/29 15:15:53.0645 0504 WaveFDE (db626c46997c2430d4958da5c7ffb969) C:\WINDOWS\system32\DRIVERS\WaveFDE.sys
2011/07/29 15:15:54.0537 0504 WavxDMgr (51e756f2bfb5e3adcb15f966ad293231) C:\WINDOWS\system32\DRIVERS\WavxDMgr.sys
2011/07/29 15:15:55.0381 0504 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
2011/07/29 15:15:56.0569 0504 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/07/29 15:15:57.0601 0504 winachsf (a8596cf86d445269a42ecc08b7066a4c) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/07/29 15:15:58.0665 0504 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
2011/07/29 15:15:59.0306 0504 WpdUsb (1385e5aa9c9821790d33a9563b8d2dd0) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/07/29 15:16:00.0072 0504 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/07/29 15:16:00.0572 0504 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/07/29 15:16:01.0432 0504 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/07/29 15:16:03.0184 0504 MBR (0x1B8) (f381baacfc1778337c007982b0c32d82) \Device\Harddisk0\DR0
2011/07/29 15:16:03.0199 0504 \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0)
2011/07/29 15:16:03.0762 0504 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk1\DR33
2011/07/29 15:16:03.0840 0504 Boot (0x1200) (86bdbe005392109a2e3af145e535c08d) \Device\Harddisk0\DR0\Partition0
2011/07/29 15:16:03.0950 0504 Boot (0x1200) (fabfc6b99d792214f9abcb7a36b1813d) \Device\Harddisk1\DR33\Partition0
2011/07/29 15:16:03.0966 0504 ================================================================================
2011/07/29 15:16:03.0966 0504 Scan finished
2011/07/29 15:16:03.0966 0504 ================================================================================
2011/07/29 15:16:04.0122 6360 Detected object count: 2
2011/07/29 15:16:04.0122 6360 Actual detected object count: 2
2011/07/29 15:16:32.0815 6360 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/07/29 15:16:33.0112 6360 \Device\Harddisk0\DR0 (Backdoor.Win32.Sinowal.knf) - will be cured after reboot
2011/07/29 15:16:33.0128 6360 \Device\Harddisk0\DR0 - ok
2011/07/29 15:16:33.0128 6360 Backdoor.Win32.Sinowal.knf(\Device\Harddisk0\DR0) - User select action: Cure
2011/07/29 15:23:19.0242 6348 Deinitialize success

TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Re: Torpig?

#4 Příspěvek od TomPerys »

Tady ještě ten RSIT:


Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomi at 2011-07-29 15:43:42
Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (8%) free of 114 GB
Total RAM: 2046 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:44:16, on 29.7.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG10\avgfws.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\Explorer.EXE
C:\xampp\mysql\bin\mysqld-nt.exe
C:\Program Files\AVG\AVG10\avgam.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\StacSV.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\atwtusb.exe
C:\WINDOWS\system32\atwtusb.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\I8kfanGUI\I8kfanGUI.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Miranda_noninstall\miranda32.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\___Viry\RSIT.exe
C:\Program Files\trend micro\Tomi.exe

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Recordpad] "C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe" -logon
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [i8kfangui] C:\Program Files\I8kfanGUI\I8kfanGUI.exe /startup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 2359510684
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - C:\WINDOWS\system32\OOD2000.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: WTService - Unknown owner - C:\WINDOWS\system32\atwtusb.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\xampp\service.exe

--
End of file - 12053 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\mixpadShakeIcon.job
C:\WINDOWS\tasks\recordpadShakeIcon.job
C:\WINDOWS\tasks\switchShakeIcon.job
C:\WINDOWS\tasks\wavepadDowngrade.job
C:\WINDOWS\tasks\wavepadShakeIcon.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\be9sv9dw.default

prefs.js - "browser.startup.homepage" - "seznam.cz"
prefs.js - "extensions.enabledItems" - "{e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6, {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\Program Files\Real\RealPlayer\browserrecord
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\AVG10\Firefox4\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@idsoftware.com/QuakeLive]
"Description"=
"Path"=C:\Documents and Settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46]
"Description"=6.0.12.46
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=8]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsIQTScriptablePlugin.xpt
nsJSRealPlayerPlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
NPLV80Win32.dll
NPLV82Win32.dll
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Tomi\Application Data\Mozilla\Firefox\Profiles\be9sv9dw.default\extensions\
cs@dictionaries.addons.mozilla.org
{20a82645-c095-46ed-80e3-08825760534b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG10\avgssie.dll [2011-07-08 2274144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-26 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-26 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2007-09-19 159744]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-05-31 8429568]
"nwiz"=nwiz.exe /installquiet []
"NVHotkey"=nvHotkey.dll,Start []
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2007-10-09 2183168]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-05-31 81920]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\Quickset.exe [2007-07-20 1228800]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2007-02-19 303104]
"AVG_TRAY"=C:\Program Files\AVG\AVG10\avgtray.exe [2011-04-18 2334560]
"Recordpad"=C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe [2011-06-08 1314308]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"i8kfangui"=C:\Program Files\I8kfanGUI\I8kfanGUI.exe [2006-09-08 835584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-09-08 94208]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2008-06-12 640376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2008-06-12 37232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\B2C_AGENT]
C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [2010-03-17 300992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\boincmgr]
C:\Program Files\BOINC\boincmgr.exe [2010-07-01 4862720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\boinctray]
C:\Program Files\BOINC\boinctray.exe [2010-07-01 58112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\combofix]
C:\WINDOWS\system32\kmd.exe [2004-08-04 388608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe [2007-08-16 167368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe [2007-03-15 460784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\f430d990]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-09-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
C:\Program Files\Spyware Doctor\pctsTray.exe [2009-11-18 1243088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-04-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MacrokeyManager]
C:\WINDOWS\system32\WTMKM.exe [2009-08-11 5586664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\WINDOWS\system32\oodtray.exe [2009-04-08 2553088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
C:\Program Files\OpenVPN\bin\openvpn-gui.exe [2005-08-18 99328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]
C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe [2007-03-15 2225208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2006-10-20 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillElbyCheck]
C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe [2001-12-06 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillTray]
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe [2002-04-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe [2006-08-17 1116920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
C:\WINDOWS\stsystra.exe [2007-02-19 303104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartPatrol]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Valve\Steam\steam.exe [2011-04-04 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-09-19 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup 2.5]
C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe [2004-11-12 245760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WavXMgr]
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe [2007-09-10 92160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yodm3D]
C:\Program Files\yodm3DII\Yodm3D.exe [2007-06-26 2058752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
C:\PROGRA~1\DIGITA~1\DLG.exe [2006-11-03 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VideoCam Suite 2.0.lnk]
C:\PROGRA~1\PANASO~1\VIDEOC~1\VIDEOC~2.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Tomi^Start Menu^Programs^Startup^setup_9.0.0.722_15.03.2011_11-34.lnk]
C:\DOCUME~1\Tomi\Desktop\INSTAL~1\VIRUSR~1\SETUP_~1.201\startup.exe [2009-10-01 72208]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"=C:\PROGRA~1\DVDIDL~1\DVDShell.dll [2004-10-09 49152]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
wvauth
C:\WINDOWS\system32\awtqnkhe
"notification packages"=scecli
scecli
scecli
scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSecurityTab"=1
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoSecurityTab"=1
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\games\RedFaction\PF.exe"="C:\games\RedFaction\PF.exe:*:Enabled:PF"
"C:\xampp\apache\bin\apache.exe"="C:\xampp\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Disabled:µTorrent"
"C:\games\RedFaction\rf.exe"="C:\games\RedFaction\rf.exe:*:Disabled:Red Faction"
"C:\games\RedFaction\RedFaction.exe"="C:\games\RedFaction\RedFaction.exe:*:Disabled:Red Faction Launcher"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG10\avgdiagex.exe"="C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostika 2011"
"C:\Program Files\AVG\AVG10\avgnsx.exe"="C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG10\avgam.exe"="C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:Správce událostí AVG"
"C:\Program Files\AVG\AVG10\avgemcx.exe"="C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Obecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\games\RedFaction\rf.exe"="C:\games\RedFaction\rf.exe:*:Disabled:Red Faction"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\_Download\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124.exe"="C:\_Download\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124.exe:*:Enabled:C:\_Download\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124\Xilisoft.AVI.To.DVD.Converter.v3.0.34.Build.0124.exe"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\PRTG Network Monitor\PRTG Server.exe"="C:\Program Files\PRTG Network Monitor\PRTG Server.exe:*:Enabled:PRTG_Network_Monitor_Server"
"C:\Program Files\PRTG Network Monitor\PRTG Probe.exe"="C:\Program Files\PRTG Network Monitor\PRTG Probe.exe:*:Enabled:PRTG_Network_Monitor_Probe"
"C:\Program Files\PRTG Network Monitor\PRTG Server Administrator.exe"="C:\Program Files\PRTG Network Monitor\PRTG Server Administrator.exe:*:Enabled:PRTG_Network_Monitor_Admin_Tool"
"C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG10\avgdiagex.exe"="C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostika 2011"
"C:\Program Files\AVG\AVG10\avgnsx.exe"="C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG10\avgam.exe"="C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:Správce událostí AVG"
"C:\Program Files\AVG\AVG10\avgemcx.exe"="C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Obecná kontrola pošty"
"C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe"="C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe"="C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi"
"C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe"="C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"midi1"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"vidc.ffds"=C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.XVID"=xvidvfw.dll
"mixer1"=wdmaud.drv
"wave1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"vidc.mjpg"=pvmjpg30.dll

======List of files/folders created in the last 1 month======

2011-07-29 15:43:42 ----D---- C:\rsit
2011-07-29 15:34:02 ----A---- C:\TDSSKiller.2.5.12.0_29.07.2011_15.34.02_log.txt
2011-07-29 15:11:49 ----A---- C:\TDSSKiller.2.5.12.0_29.07.2011_15.11.49_log.txt
2011-07-29 15:11:25 ----D---- C:\___Viry
2011-07-29 11:50:04 ----D---- C:\Program Files\LSoft Technologies
2011-07-29 11:39:41 ----A---- C:\KillDiskSuiteFree-Setup.exe
2011-07-28 14:23:53 ----D---- C:\_Download
2011-07-28 13:28:27 ----D---- C:\aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
2011-07-27 14:26:50 ----D---- C:\_GF
2011-07-21 17:44:09 ----D---- C:\gggggggggggggggggggggg
2011-07-19 06:52:37 ----D---- C:\_Fotky a jine prijate souory
2011-07-18 03:09:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-07-18 03:02:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-06-30 09:52:56 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-06-30 03:02:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$

======List of files/folders modified in the last 1 month======

2011-07-29 15:44:07 ----D---- C:\Program Files\trend micro
2011-07-29 15:43:33 ----D---- C:\WINDOWS\TEMP
2011-07-29 15:34:06 ----D---- C:\WINDOWS\system32\drivers
2011-07-29 15:33:27 ----A---- C:\WINDOWS\WINCMD.INI
2011-07-29 15:33:10 ----SD---- C:\WINDOWS\Tasks
2011-07-29 15:31:11 ----D---- C:\WINDOWS\Prefetch
2011-07-29 15:30:01 ----D---- C:\WINDOWS\system32\CatRoot2
2011-07-29 15:29:39 ----D---- C:\WINDOWS\Registration
2011-07-29 15:29:33 ----D---- C:\WINDOWS\system32
2011-07-29 15:28:45 ----A---- C:\WINDOWS\ModemLog_Standard 33600 bps Modem.txt
2011-07-29 15:28:45 ----A---- C:\WINDOWS\ModemLog_LGE Virtual Modem.txt
2011-07-29 15:28:39 ----A---- C:\WINDOWS\ModemLog_Conexant HDA D330 MDC V.92 Modem.txt
2011-07-29 15:28:37 ----A---- C:\WINDOWS\win.ini
2011-07-29 15:28:32 ----D---- C:\WINDOWS
2011-07-29 15:24:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-07-29 15:01:07 ----D---- C:\Program Files\Opera
2011-07-29 12:28:16 ----D---- C:\Temp
2011-07-29 11:50:04 ----RD---- C:\Program Files
2011-07-29 10:45:44 ----D---- C:\Program Files\Mozilla Thunderbird
2011-07-29 10:30:12 ----D---- C:\WINDOWS\security
2011-07-29 03:38:05 ----D---- C:\WINDOWS\system32\drivers\AVG
2011-07-29 03:02:26 ----SHD---- C:\WINDOWS\Installer
2011-07-28 13:32:30 ----A---- C:\WINDOWS\NeroDigital.ini
2011-07-28 13:18:08 ----D---- C:\_Private
2011-07-28 13:13:25 ----A---- C:\WINDOWS\wcx_ftp.ini
2011-07-28 08:43:36 ----D---- C:\___EXP
2011-07-28 07:12:01 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-22 17:44:12 ----HD---- C:\WINDOWS\inf
2011-07-21 16:36:23 ----D---- C:\WINDOWS\system32\FxsTmp
2011-07-19 10:48:00 ----SHD---- C:\Config.Msi
2011-07-18 03:20:34 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-07-18 03:04:20 ----A---- C:\WINDOWS\system32\MRT.exe
2011-07-18 03:02:53 ----A---- C:\WINDOWS\imsins.BAK
2011-07-17 16:01:20 ----HD---- C:\WINDOWS\$hf_mig$
2011-07-07 09:41:47 ----SHD---- C:\WINDOWS\CSC
2011-07-01 12:37:55 ----D---- C:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 83587732;83587732 Boot Guard Driver; C:\WINDOWS\system32\DRIVERS\83587732.sys [2009-10-22 37392]
R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2011-03-16 32592]
R0 DRVMCDB;DRVMCDB; C:\WINDOWS\System32\Drivers\DRVMCDB.SYS [2006-07-21 99176]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys [2010-11-22 64288]
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PBADRV;PBADRV; C:\WINDOWS\system32\DRIVERS\PBADRV.sys [2007-09-07 26608]
R0 PCTCore;PCTools KDS; C:\WINDOWS\system32\drivers\PCTCore.sys [2009-11-09 207792]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2006-06-14 58232]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS\System32\drivers\sfsync04.sys [2006-06-14 59264]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2006-06-14 78184]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-04-23 114048]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-04-15 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-16 76544]
R1 83587731;83587731; C:\WINDOWS\system32\DRIVERS\83587731.sys [2009-09-25 128016]
R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2011-01-07 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2011-03-01 34896]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2011-04-05 297168]
R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2006-08-11 12920]
R1 DLARTL_M;DLARTL_M; C:\WINDOWS\System32\Drivers\DLARTL_M.SYS [2006-08-11 28184]
R1 fanio;FanIO driver; \??\C:\WINDOWS\system32\drivers\fanio.sys []
R1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys [2005-09-07 30464]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 setup_9.0.0.722_15.03.2011_11-34drv;setup_9.0.0.722_15.03.2011_11-34drv; C:\WINDOWS\system32\DRIVERS\8358773.sys [2009-10-10 315408]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2007-04-26 64896]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-09-04 279712]
R2 BASFND;BASFND; \??\C:\Program Files\Broadcom\ASFIPMon\BASFND.sys []
R2 cvintdrv;cvintdrv; C:\WINDOWS\system32\drivers\cvintdrv.sys [2006-07-27 4096]
R2 DLABMFSM;DLABMFSM; C:\WINDOWS\System32\DLA\DLABMFSM.SYS [2006-08-18 35096]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2006-08-18 32472]
R2 DLADResM;DLADResM; C:\WINDOWS\System32\DLA\DLADResM.SYS [2006-08-18 9400]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2006-08-18 104472]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2006-08-18 26008]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2006-08-18 14520]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2006-08-18 97848]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2006-08-18 94648]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2006-08-11 51768]
R2 dsunidrv;DellSupport UniDriver; C:\WINDOWS\system32\DRIVERS\dsunidrv.sys [2007-02-25 5376]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2002-04-04 13300]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-09-04 25888]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2007-12-02 12672]
R2 PDRJNDL;PDRJNDL; \??\C:\Program Files\Dekart\Private Disk Light\PDRJNDL.SYS []
R2 PRVDISK;PRVDISK; \??\C:\Program Files\Dekart\Private Disk Light\PRVDISK.SYS []
R2 WavxDMgr;WavxDMgr; C:\WINDOWS\system32\DRIVERS\WavxDMgr.sys [2007-09-10 161280]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2007-09-19 155136]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-07-12 30432]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2011-04-14 134480]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2011-02-10 24144]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2011-02-10 27216]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2007-03-13 160256]
R3 BCM43XX;Ovladač bezdrátové karty Dell WLAN; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2007-10-09 1123328]
R3 genmcmnUSB;USB Scroll Mouse Driver; C:\WINDOWS\system32\DRIVERS\gflmouhid.sys [2004-04-19 6656]
R3 guardian2;guardian2; C:\WINDOWS\System32\Drivers\oz776.sys [2007-11-28 62208]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-12-02 989952]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-12-02 211200]
R3 LgBttPort;LGE Bluetooth TransPort; C:\WINDOWS\system32\DRIVERS\lgbtport.sys [2009-09-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\lgbtbus.sys [2009-09-29 10496]
R3 LGVMODEM;LGE Virtual Modem; C:\WINDOWS\system32\DRIVERS\lgvmodem.sys [2009-09-29 12928]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 moufiltr;Tablet Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\moufiltr.sys [2009-03-08 6144]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 NCHSSVAD;SoundTap Recorder; C:\WINDOWS\system32\drivers\nchssvad.sys [2008-11-11 27136]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-05-31 6727136]
R3 OOTextMode;OOTextMode; C:\WINDOWS\System32\drivers\oobctm.sys [2009-04-07 37896]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-11-18 47360]
R3 RegKill;RegKill; C:\WINDOWS\System32\Drivers\RegKill.sys [2002-03-10 6144]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2007-02-19 1228296]
R3 StillCam;Still Serial Digital Camera Driver; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-17 6784]
R3 tap0801;TAP-Win32 Adapter V8; C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2007-04-26 41600]
R3 tosrfbd;Bluetooth RFBUS; C:\WINDOWS\system32\DRIVERS\tosrfbd.sys [2007-04-26 113920]
R3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2007-04-26 36480]
R3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-04-26 73600]
R3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2007-04-26 18612]
R3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\system32\DRIVERS\tosrfusb.sys [2007-04-26 41856]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 vhidmini;Generic Virtual HID Driver; C:\WINDOWS\system32\DRIVERS\walvhid.sys [2009-04-16 6144]
R3 WaveFDE;Wave System Power Monitor Device Driver; C:\WINDOWS\system32\DRIVERS\WaveFDE.sys [2007-09-06 18176]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-12-02 731136]
S0 cercsr6;cercsr6; C:\WINDOWS\system32\drivers\cercsr6.sys [2004-12-13 39904]
S0 qhcend;qhcend; C:\WINDOWS\system32\drivers\bdbgq.sys []
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 a0f9n7s2;a0f9n7s2; C:\WINDOWS\system32\drivers\a0f9n7s2.sys []
S3 a0u0olnq;a0u0olnq; C:\WINDOWS\system32\drivers\a0u0olnq.sys []
S3 a63oiyph;a63oiyph; C:\WINDOWS\system32\drivers\a63oiyph.sys []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-07-12 30432]
S3 cpuz132;cpuz132; \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys []
S3 DSproct;DSproct; \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys []
S3 DXEC01;DXEC01; C:\WINDOWS\system32\drivers\dxec01.sys [2006-11-02 97536]
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 esihdrv;esihdrv; \??\C:\DOCUME~1\Tomi\LOCALS~1\Temp\esihdrv.sys []
S3 FlashUSB;FlashUSB; C:\WINDOWS\system32\DRIVERS\FlashUSB.sys [2009-05-12 16896]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\Tomi\LOCALS~1\Temp\mbr.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2009-03-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2009-03-19 8320]
S3 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2011-02-12 35088]
S3 npkcrypt;npkcrypt; C:\WINDOWS\system32\drivers\npkcrypt.sys []
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 PSSDK42;PSSDK42; \??\C:\WINDOWS\system32\Drivers\pssdk42.sys []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys []
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2008-11-19 13056]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2008-11-19 19968]
S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2008-11-19 24832]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 utm4ode5;AVZ Kernel Driver; \??\C:\WINDOWS\system32\Drivers\utm4ode5.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2005-01-28 18944]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-16 82688]
S3 xcpip;TCP/IP Protocol Driver; C:\WINDOWS\system32\drivers\xcpip.sys []
S3 xpsec;IPSEC driver; C:\WINDOWS\system32\drivers\xpsec.sys []
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2004-08-04 13952]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys [2005-09-07 101760]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG10\avgfws.exe [2011-03-09 2708024]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-26 153376]
R2 LkCitadelServer;Lookout Citadel Server; C:\WINDOWS\system32\lkcitdl.exe [2006-06-19 688190]
R2 lkClassAds;National Instruments PSP Server Locator; C:\WINDOWS\system32\lkads.exe [2006-07-25 45056]
R2 lkTimeSync;National Instruments Time Synchronization; C:\WINDOWS\system32\lktsrv.exe [2006-07-25 57344]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
R2 mysql;mysql; C:\xampp\mysql\bin\mysqld-nt.exe [2007-12-21 4653056]
R2 NICCONFIGSVC;NICCONFIGSVC; C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [2007-07-20 475136]
R2 niSvcLoc;NI Service Locator; C:\WINDOWS\system32\nisvcloc.exe [2006-02-06 49152]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-05-31 163908]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-12-24 69632]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-06-30 75064]
R2 STacSV;SigmaTel Audio Service; C:\WINDOWS\system32\StacSV.exe [2007-02-19 90112]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 tcsd_win32.exe;NTRU TSS v1.2.1.25 TCS; C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [2007-11-09 1552384]
R2 TdmService;TdmService; C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe [2007-09-07 737280]
R2 Wave UCSPlus;Wave UCSPlus; C:\WINDOWS\system32\dllhost.exe [2008-04-14 5120]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2007-10-09 24064]
R2 WTService;WTService; C:\WINDOWS\system32\atwtusb.exe [2009-08-06 397032]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S2 OOD2000;O&O Defrag 2000; C:\WINDOWS\system32\OOD2000.exe [2001-04-06 238080]
S2 r_server;Remote Administrator Service; C:\WINDOWS\system32\r_server.exe /service []
S2 XAMPP;XAMPP Service; C:\xampp\service.exe [2007-12-21 60928]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DSBrokerService;DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [2007-03-19 70656]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-16 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NILM License Manager;NILM License Manager; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2006-06-27 1007616]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2006-10-01 16384]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-10-30 359624]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-11-06 1141712]
S3 SecureStorageService;SecureStorageService; C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe [2007-08-31 486400]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 WaveEnrollmentService;WaveEnrollmentService; C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe [2007-09-13 192512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 Apache2.2;Apache2.2; c:\xampp\apache\bin\apache.exe [2007-12-21 17920]
S4 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor; C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe [2006-12-19 79432]
S4 IJOGH;IJOGH; C:\DOCUME~1\Tomi\LOCALS~1\Temp\IJOGH.exe []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2009-04-08 1377536]
S4 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-09-14 73728]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Torpig?

#5 Příspěvek od vyosek »

:arrow: No jo, byl tam fesak jeden :boxed: Ale jeste tam neco je :arcisit:

:arrow: Pri stahovani combofixu - navod a postup nize, jej ulozte jako Beruska.com

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Re: Torpig?

#6 Příspěvek od TomPerys »

Tak combofix sem si jednou stáhl a prý blbou verzi a smazala mi půlku systému. trvali mi dva dny než jsem to dal zase dohromady. Snad se to nestane opět.

Jinak jsem si teda stáhl tu Aviru a vyzkouším. Můžete doporučit i nějaký dobrý FW?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Torpig?

#7 Příspěvek od vyosek »

Tak radeji se CF vyhneme, ale dnesni verze co autor vydal je OK...

Udelejte tedy sken avptoolem http://www.viry.cz/forum/viewtopic.php?f=29&t=58179

Z FW si vyberte zde http://www.viry.cz/forum/viewtopic.php?f=41&t=6523 , mohu doporucit ZA nebo PCT
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Re: Torpig?

#8 Příspěvek od TomPerys »

No já už ho spustil takže mám asi smůlu co

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Torpig?

#9 Příspěvek od vyosek »

Aha, no tak jej nechte bezet...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Re: Torpig?

#10 Příspěvek od TomPerys »

combofix:

ComboFix 11-07-29.01 - Tomi 29.07.2011 16:24:48.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.2046.979 [GMT 2:00]
Spuštěný z: c:\___viry\Beruska.com.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Tomi\Application Data\inst.exe
C:\hosts
c:\windows\IsUn0405.exe
c:\windows\iun6002.exe
c:\windows\My.ini
c:\windows\system32\kmd.exe
c:\windows\system32\wsaupdater.exe
c:\windows\XSxS
.
---- Předchozí spuštění -------
.
c:\documents and settings\Administrator\Desktop\ComboFix.exe
c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
c:\documents and settings\Tomi\Application Data\inst.exe
c:\documents and settings\Tomi\Application Data\pcouffin.sys
c:\documents and settings\Tomi\WINDOWS
c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe
c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe
c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\program files\CyberLink\PowerDVD\Language\Language.exe
c:\program files\DellSupport\brkrsvc.exe
c:\program files\DellSupport\GTAction\triggers\DSproct.sys
c:\program files\HP\HP Software Update\HPWuSchd2.exe
c:\program files\I8kfanGUI\I8kfanGUI.exe
c:\program files\InstallShield Installation Information\{3B62526F-6C6C-4337-908D-A0A549CEFCC0}\setup.exe
c:\program files\Internet Explorer\ExtExport.exe
c:\program files\Internet Explorer\iecompat.dll
c:\program files\Internet Explorer\iedvtool.dll
c:\program files\Internet Explorer\ieproxy.dll
c:\program files\Internet Explorer\iexplore.exe.mui
c:\program files\Internet Explorer\jsdbgui.dll
c:\program files\Internet Explorer\jsdebuggeride.dll
c:\program files\Internet Explorer\JSProfilerCore.dll
c:\program files\Internet Explorer\jsprofilerui.dll
c:\program files\Internet Explorer\Plugins\LV80ActiveXControl.dll
c:\program files\Internet Explorer\Plugins\LV82ActiveXControl.dll
c:\program files\Internet Explorer\Plugins\nppdf32.dll
c:\program files\Internet Explorer\sqmapi.dll
c:\program files\Internet Explorer\xpshims.dll
c:\program files\Messenger\custsat.dll
c:\program files\Mozilla Firefox\freebl3.dll
c:\program files\Mozilla Firefox\nss3.dll
c:\program files\Mozilla Firefox\nssdbm3.dll
c:\program files\Mozilla Firefox\Plugins\NPLV80Win32.dll
c:\program files\Mozilla Firefox\Plugins\NPLV82Win32.dll
c:\program files\Mozilla Firefox\Plugins\npnul32.dll
c:\program files\Mozilla Firefox\Plugins\nppdf32.dll
c:\program files\Mozilla Firefox\Plugins\nppl3260.dll
c:\program files\Mozilla Firefox\smime3.dll
c:\program files\Mozilla Firefox\softokn3.dll
c:\program files\Mozilla Firefox\ssl3.dll
c:\program files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
c:\program files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmProxy.dll
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmUtil.dll
c:\program files\Windows NT\Accessories\mswrd6.wpc
c:\program files\Windows NT\Accessories\mswrd8.wpc
c:\program files\Windows NT\Accessories\write.wpc
c:\program files\Windows NT\hypertrm.exe
C:\Thumbs.db
c:\windows\apppatch\acadproc.dll
c:\windows\eSellerateControl350.dll
c:\windows\eSellerateControl365.dll
c:\windows\iun6002.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\windows\My.ini
c:\windows\Setup1.exe
c:\windows\ST6UNST.EXE
c:\windows\System\tfmessbsp.dll
c:\windows\system32\acelpdec.ax
c:\windows\system32\AdobePDF.dll
c:\windows\system32\AdobePDFUI.dll
c:\windows\system32\ADsSecurity.dll
c:\windows\system32\advpack.dll.mui
c:\windows\system32\aspnet_counters.dll
c:\windows\system32\ATSC51.dll
c:\windows\system32\ATSC70.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\BCGCBPRO730.dll
c:\windows\System32\bcmwlpkt.dll
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\biolsp.dll
c:\windows\system32\BMAPI.dll
c:\windows\system32\browserchoice.exe
c:\windows\system32\CddbCleanRoxio.dll
c:\windows\system32\CDDBControlRoxio.dll
c:\windows\system32\CddbFileTaggerRoxio.dll
c:\windows\system32\CddbMusicIDRoxio.dll
c:\windows\system32\CddbPlaylist2Roxio.dll
c:\windows\system32\CDDBUIRoxio.dll
c:\windows\system32\CmdLineExt.dll
c:\windows\system32\comsdupd.exe
c:\windows\system32\cvi_lvrt.dll
c:\windows\system32\cviauto.dll
c:\windows\system32\cvidotnetv1.1.4322.dll
c:\windows\system32\cvintwrk.dll
c:\windows\system32\cvirt.dll
c:\windows\system32\cvirte.dll
c:\windows\system32\cviUSI.dll
c:\windows\system32\D3DCompiler_33.dll
c:\windows\system32\D3DCompiler_34.dll
c:\windows\system32\D3DCompiler_35.dll
c:\windows\system32\D3DCompiler_36.dll
c:\windows\system32\D3DCompiler_37.dll
c:\windows\system32\D3DCompiler_38.dll
c:\windows\system32\D3DCompiler_39.dll
c:\windows\system32\D3DCompiler_40.dll
c:\windows\system32\D3DCompiler_41.dll
c:\windows\system32\d3dx10_33.dll
c:\windows\system32\d3dx10_34.dll
c:\windows\system32\d3dx10_35.dll
c:\windows\system32\d3dx10_36.dll
c:\windows\system32\d3dx10_37.dll
c:\windows\system32\d3dx10_38.dll
c:\windows\system32\d3dx10_39.dll
c:\windows\system32\d3dx10_40.dll
c:\windows\system32\d3dx10_41.dll
c:\windows\system32\d3dx9_26.dll
c:\windows\system32\d3dx9_31.dll
c:\windows\system32\d3dx9_32.dll
c:\windows\system32\d3dx9_33.dll
c:\windows\system32\d3dx9_34.dll
c:\windows\system32\d3dx9_35.dll
c:\windows\system32\d3dx9_36.dll
c:\windows\system32\D3DX9_37.dll
c:\windows\system32\D3DX9_38.dll
c:\windows\system32\D3DX9_39.dll
c:\windows\system32\D3DX9_40.dll
c:\windows\system32\D3DX9_41.dll
c:\windows\system32\dataskt.dll
c:\windows\system32\dbghelp.dll.old
c:\windows\system32\dfshim.dll
c:\windows\system32\diskcomp.com
c:\windows\system32\diskcopy.com
c:\windows\system32\DLA\DLABMFSM.SYS
c:\windows\system32\DLA\DLABOIOM.SYS
c:\windows\system32\DLA\DLADResM.SYS
c:\windows\system32\DLA\DLAIFS_M.SYS
c:\windows\system32\DLA\DLAOPIOM.SYS
c:\windows\system32\DLA\DLAPoolM.SYS
c:\windows\system32\DLA\DLAUDF_M.SYS
c:\windows\system32\DLA\DLAUDFAM.SYS
c:\windows\system32\DRIVERS\8358773.sys
c:\windows\system32\DRIVERS\83587731.sys
c:\windows\system32\DRIVERS\83587732.sys
c:\windows\system32\DRIVERS\Apfiltr.sys
c:\windows\SYSTEM32\DRIVERS\APPDRV.SYS
c:\windows\system32\DRIVERS\atksgt.sys
c:\windows\system32\DRIVERS\bcmwl5.sys
c:\windows\system32\drivers\ccdcmb.sys
c:\windows\system32\drivers\ccdcmbo.sys
c:\windows\system32\drivers\cpuz132_x32.sys
c:\windows\system32\driVERs\cvintdrv.sys
c:\windows\system32\Drivers\DLACDBHM.SYS
c:\windows\system32\Drivers\DLARTL_M.SYS
c:\windows\system32\Drivers\DRVMCDB.SYS
c:\windows\system32\Drivers\DRVNDDM.SYS
c:\windows\system32\DRIVERS\dsunidrv.sys
c:\windows\system32\drivers\dxec01.sys
c:\windows\system32\Drivers\ElbyCDIO.sys
c:\windows\system32\DRIVERS\FlashUSB.sys
c:\windows\system32\DRIVERS\gflmouhid.sys
c:\windows\system32\DRIVERS\HDAudBus.sys
c:\windows\system32\DRIVERS\HSF_CNXT.sys
c:\windows\system32\DRIVERS\HSF_DPV.sys
c:\windows\system32\DRIVERS\HSFHWAZL.sys
c:\windows\system32\drivers\InCDFs.sys
c:\windows\system32\drivers\InCDRm.sys
c:\windows\system32\DRIVERS\Lbd.sys
c:\windows\system32\DRIVERS\lgbtbus.sys
c:\windows\system32\DRIVERS\lgbtport.sys
c:\windows\system32\DRIVERS\lgusbbus.sys
c:\windows\system32\DRIVERS\lgusbdiag.sys
c:\windows\system32\DRIVERS\lgusbmodem.sys
c:\windows\system32\DRIVERS\lgvmodem.sys
c:\windows\system32\DRIVERS\lirsgt.sys
c:\windows\system32\DRIVERS\mdmxsdk.sys
c:\windows\system32\DRIVERS\moufiltr.sys
c:\windows\system32\drivers\nchssvad.sys
c:\windows\system32\drivers\nmwcdnsu.sys
c:\windows\system32\drivers\nmwcdnsuc.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Drivers\oz776.sys
c:\windows\system32\DRIVERS\PBADRV.sys
c:\windows\system32\Drivers\pcouffin.sys
c:\windows\system32\drivers\PCTCore.sys
c:\windows\system32\driVERs\PQNTDrv.sys
c:\windows\system32\Drivers\PxHelp20.sys
c:\windows\system32\Drivers\RegKill.sys
c:\windows\system32\DRIVERS\secdrv.sys
c:\windows\system32\drivers\sfdrv01.sys
c:\windows\system32\drivers\sfhlp02.sys
c:\windows\system32\drivers\sfsync04.sys
c:\windows\system32\drivers\sfvfs02.sys
c:\windows\system32\DRIVERS\snapman.sys
c:\windows\system32\Drivers\sptd.sys
c:\windows\system32\drivers\sthda.sys
c:\windows\system32\DRIVERS\tap0801.sys
c:\windows\system32\DRIVERS\tosporte.sys
c:\windows\system32\DRIVERS\tosrfbd.sys
c:\windows\system32\Drivers\tosrfbnp.sys
c:\windows\system32\Drivers\tosrfcom.sys
c:\windows\system32\DRIVERS\Tosrfhid.sys
c:\windows\system32\DRIVERS\tosrfnds.sys
c:\windows\system32\DRIVERS\tosrfusb.sys
c:\windows\system32\DRIVERS\usbser_lowerflt.sys
c:\windows\system32\DRIVERS\usbser_lowerfltj.sys
c:\windows\system32\DRIVERS\walvhid.sys
c:\windows\system32\DRIVERS\WaveFDE.sys
c:\windows\system32\DRIVERS\WavxDMgr.sys
c:\windows\system32\DRIVERS\Wdf01000.sys
c:\windows\system32\DRIVERS\wpdusb.sys
c:\windows\system32\DRIVERS\WudfPf.sys
c:\windows\system32\DRIVERS\wudfrd.sys
c:\windows\system32\drmupgds.exe
c:\windows\system32\DxCpl.cpl
c:\windows\system32\dxdllreg.exe
c:\windows\system32\dxva2.dll
c:\windows\system32\evr.dll
c:\windows\system32\faxpatch.exe
c:\windows\system32\FlexLMCOM.dll
c:\windows\system32\format.com
c:\windows\system32\gdiplus.dll
c:\windows\system32\giveio.sys
c:\windows\system32\graftabl.com
c:\windows\system32\Hdaudprop.dll
c:\windows\system32\Hdaudpropres.dll
c:\windows\system32\Hdaudpropshortcut.exe
c:\windows\system32\hpbmiapi.dll
c:\windows\system32\HPBPRO.EXE
c:\windows\system32\hpptpml2.dll
c:\windows\system32\hptcpmib.dll
c:\windows\system32\hptcpmon.dll
c:\windows\system32\HPZinw12.exe
c:\windows\system32\HPZipt12.dll
c:\windows\system32\HPZisn12.dll
c:\windows\system32\html.iec
c:\windows\system32\chcp.com
c:\windows\system32\icardagt.exe
c:\windows\system32\icardres.dll
c:\windows\system32\icardres.dll.mui
c:\windows\system32\ie4uinit.exe.mui
c:\windows\system32\iedkcs32.dll.mui
c:\windows\system32\ieframe.dll.mui
c:\windows\system32\imaadp32.acm
c:\windows\system32\infocardapi.dll
c:\windows\system32\infocardcpl.cpl
c:\windows\system32\INKED.DLL
c:\windows\system32\instrsup.dll
c:\windows\system32\Internationalization_de.dll
c:\windows\system32\Internationalization_en.dll
c:\windows\system32\Internationalization_es.dll
c:\windows\system32\Internationalization_fr.dll
c:\windows\system32\Internationalization_it.dll
c:\windows\system32\Internationalization_ja.dll
c:\windows\system32\Internationalization_ko.dll
c:\windows\system32\Internationalization_pt.dll
c:\windows\system32\Internationalization_ru.dll
c:\windows\system32\Internationalization_zh-CHS.dll
c:\windows\system32\Internationalization_zh-CHT.dll
c:\windows\system32\ivfsrc.ax
c:\windows\system32\KADxMain.exe
c:\windows\system32\keystone.exe
c:\windows\system32\kmd.exe
c:\windows\system32\ksolay.ax
c:\windows\system32\LCWizard.dll
c:\windows\system32\M3.dll
c:\windows\system32\MFPLAT.dll
c:\windows\system32\migpwd.exe
c:\windows\system32\mode.com
c:\windows\system32\more.com
c:\windows\system32\MP43DECD.dll
c:\windows\system32\mp4sdecd.dll
c:\windows\system32\mp4sds32.ax
c:\windows\system32\nvapi.dll
c:\windows\system32\nvsvc32.exe
c:\windows\system32\raddrv.dll
c:\windows\system32\speedfan.sys
c:\windows\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll
c:\windows\System32\spool\PRTPROCS\W32X86\hpzpp034.dll
c:\windows\System32\spool\PRTPROCS\W32X86\mdippr.dll
c:\windows\system32\tbtmon.dll
c:\windows\system32\tbtmon98Language.dll
c:\windows\system32\TosBdAPI.dll
c:\windows\system32\TosBtAPI.dll
c:\windows\System32\wltrynt.dll
c:\windows\System32\WLTRYSVC.EXE
c:\windows\system32\WTMKM.exe
c:\windows\system32\WUDFPlatform.dll
c:\windows\System32\WUDFSvc.dll
.
-- Předchozí spuštění --
.
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\$NtServicePackUninstall$\userinit.exe
.
--------
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SSHNAS
-------\Legacy_83587731
-------\Legacy_83587732
-------\Legacy_APPDRV
-------\Legacy_ASFIPmon
-------\Legacy_atksgt
-------\Legacy_clr_optimization_v4.0.30319_32
-------\Legacy_cpuz132
-------\Legacy_cvintdrv
-------\Legacy_DLABMFSM
-------\Legacy_DLABOIOM
-------\Legacy_DLADResM
-------\Legacy_DLAIFS_M
-------\Legacy_DLAOPIOM
-------\Legacy_DLAPoolM
-------\Legacy_DLARTL_M
-------\Legacy_DLAUDF_M
-------\Legacy_DLAUDFAM
-------\Legacy_DRVNDDM
-------\Legacy_DSproct
-------\Legacy_dsunidrv
-------\Legacy_ElbyCDIO
-------\Legacy_Lbd
-------\Legacy_lirsgt
-------\Legacy_npf
-------\Legacy_NVSvc
-------\Legacy_PBADRV
-------\Legacy_PQNTDrv
-------\Legacy_setup_9.0.0.722_15.03.2011_11-34drv
-------\Legacy_sfdrv01
-------\Legacy_sfhlp02
-------\Legacy_sfsync04
-------\Legacy_sfvfs02
-------\Legacy_sptd
-------\Legacy_TdmService
-------\Legacy_WavxDMgr
-------\Legacy_Wdf01000
-------\Legacy_wltrysvc
-------\Service_83587731
-------\Service_83587732
-------\Service_ApfiltrService
-------\Service_APPDRV
-------\Service_ASFIPmon
-------\Service_atksgt
-------\Service_BCM43XX
-------\Service_clr_optimization_v4.0.30319_32
-------\Service_cpuz132
-------\Service_cvintdrv
-------\Service_DLABMFSM
-------\Service_DLABOIOM
-------\Service_DLACDBHM
-------\Service_DLADResM
-------\Service_DLAIFS_M
-------\Service_DLAOPIOM
-------\Service_DLAPoolM
-------\Service_DLARTL_M
-------\Service_DLAUDF_M
-------\Service_DLAUDFAM
-------\Service_DRVMCDB
-------\Service_DRVNDDM
-------\Service_DSBrokerService
-------\Service_DSproct
-------\Service_dsunidrv
-------\Service_DXEC01
-------\Service_ElbyCDIO
-------\Service_FlashUSB
-------\Service_genmcmnUSB
-------\Service_guardian2
-------\Service_HSF_DPV
-------\Service_HSFHWAZL
-------\Service_Lbd
-------\Service_LgBttPort
-------\Service_lgbusenum
-------\Service_LGVMODEM
-------\Service_lirsgt
-------\Service_moufiltr
-------\Service_NCHSSVAD
-------\Service_nmwcd
-------\Service_nmwcdc
-------\Service_nmwcdnsu
-------\Service_nmwcdnsuc
-------\Service_npf
-------\Service_NVSvc
-------\Service_PBADRV
-------\Service_pcouffin
-------\Service_PCTCore
-------\Service_PQNTDrv
-------\Service_RegKill
-------\Service_SecureStorageService
-------\Service_setup_9.0.0.722_15.03.2011_11-34drv
-------\Service_sfdrv01
-------\Service_sfhlp02
-------\Service_sfsync04
-------\Service_sfvfs02
-------\Service_snapman
-------\Service_sptd
-------\Service_STHDA
-------\Service_tap0801
-------\Service_TdmService
-------\Service_tosporte
-------\Service_tosrfbd
-------\Service_tosrfbnp
-------\Service_Tosrfcom
-------\Service_Tosrfhid
-------\Service_tosrfnds
-------\Service_Tosrfusb
-------\Service_upperdev
-------\Service_usbbus
-------\Service_UsbDiag
-------\Service_USBModem
-------\Service_UsbserFilt
-------\Service_vhidmini
-------\Service_WaveEnrollmentService
-------\Service_WaveFDE
-------\Service_WavxDMgr
-------\Service_Wdf01000
-------\Service_wltrysvc
-------\Service_WpdUsb
-------\Legacy_SSHNAS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-28 do 2011-07-29 )))))))))))))))))))))))))))))))
.
.
2011-07-29 13:43 . 2011-07-29 13:44 -------- d-----w- C:\rsit
2011-07-29 13:11 . 2011-07-29 14:36 -------- d-----w- C:\___Viry
2011-07-29 09:50 . 2011-07-29 09:50 -------- d-----w- c:\program files\LSoft Technologies
2011-07-29 09:39 . 2011-07-29 09:40 11787264 ----a-w- C:\KillDiskSuiteFree-Setup.exe
2011-07-28 12:23 . 2011-07-28 12:23 -------- d-----w- C:\_Download
2011-07-28 11:28 . 2011-07-28 11:30 -------- d-----w- C:\aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
2011-07-27 12:26 . 2011-07-28 14:04 -------- d-----w- C:\_GF
2011-07-21 15:44 . 2011-07-28 11:05 -------- d-----w- C:\gggggggggggggggggggggg
2011-07-19 04:52 . 2011-07-20 08:23 -------- d-----w- C:\_Fotky a jine prijate souory
2011-07-01 10:37 . 2011-07-01 10:37 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-07-01 10:37 . 2011-07-01 10:37 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-06-30 07:52 . 2011-06-30 07:52 -------- d--h--w- c:\windows\system32\GroupPolicy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-06 17:52 . 2011-04-09 18:54 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 17:52 . 2011-04-09 18:54 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-02 14:02 . 2004-08-04 10:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-26 07:07 . 2011-05-26 05:07 1350656 ---h--w- C:\~WRL0005.tmp
2011-05-11 09:57 . 2011-04-09 09:20 249856 ------w- c:\windows\Setup1.exe
2011-05-11 09:57 . 2011-04-09 09:20 73216 ----a-w- c:\windows\ST6UNST.EXE
2011-05-11 00:45 . 2010-04-15 14:46 110592 ----a-w- c:\windows\LGMobileDL.dll
2011-05-02 15:31 . 2004-08-11 17:12 692736 ----a-w- c:\windows\system32\inetcomm.dll
2001-10-25 06:29 . 2011-01-21 17:31 13824 ----a-w- c:\program files\ColGet.exe
2006-01-23 11:32 . 2011-04-09 09:20 131072 ----a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2006-06-07 15:40 . 2011-04-09 09:20 132848 ----a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2011-07-01 10:37 . 2011-05-31 18:26 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"i8kfangui"="c:\program files\I8kfanGUI\I8kfanGUI.exe" [2006-09-08 835584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-19 159744]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-31 8429568]
"nwiz"="nwiz.exe" [2008-02-22 1626112]
"NVHotkey"="nvHotkey.dll" [2007-05-31 67584]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-31 81920]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [2007-07-20 1228800]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-18 303104]
"Recordpad"="c:\program files\NCH Swift Sound\Recordpad\recordpad.exe" [2011-06-08 1314308]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-6-15 110592]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\progra~1\DVDIDL~1\DVDShell.dll" [2004-10-09 49152]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ ooddrmbs\0autocheck autochk *\0oodbs
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VideoCam Suite 2.0.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VideoCam Suite 2.0.lnk
backup=c:\windows\pss\VideoCam Suite 2.0.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomi^Start Menu^Programs^Startup^setup_9.0.0.722_15.03.2011_11-34.lnk]
path=c:\documents and settings\Tomi\Start Menu\Programs\Startup\setup_9.0.0.722_15.03.2011_11-34.lnk
backup=c:\windows\pss\setup_9.0.0.722_15.03.2011_11-34.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\f430d990
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartPatrol
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-06-11 23:43 640376 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2008-06-12 03:25 37232 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\B2C_AGENT]
2010-03-17 00:29 300992 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\boincmgr]
2010-07-01 12:27 4862720 ----a-w- c:\program files\BOINC\boincmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\boinctray]
2010-07-01 12:27 58112 ----a-w- c:\program files\BOINC\boinctray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-08-16 11:24 167368 ----a-w- c:\program files\DAEMON Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 12:09 460784 ----a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2004-09-13 15:49 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 10:47 1243088 ----a-w- c:\program files\Spyware Doctor\pctsTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-04-13 12:09 49152 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MacrokeyManager]
2009-08-11 15:51 5586664 ----a-w- c:\windows\system32\WTMKM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2009-04-07 23:39 2553088 ----a-w- c:\windows\system32\oodtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
2005-08-18 08:55 99328 ----a-w- c:\program files\OpenVPN\bin\openvpn-gui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]
2007-03-15 08:06 2225208 ----a-w- c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2006-10-20 17:23 118784 ----a-w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 14:09 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillElbyCheck]
2001-12-06 12:09 45056 ----a-w- c:\program files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillTray]
2002-04-13 13:42 49152 ----a-w- c:\program files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 09:00 1116920 ----a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2007-02-18 23:26 303104 ----a-w- c:\windows\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-04-04 10:53 1242448 ----a-w- c:\program files\Valve\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 13:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-09-19 13:39 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup 2.5]
2004-11-12 16:57 245760 ----a-w- c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WavXMgr]
2007-09-10 11:55 92160 ----a-w- c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yodm3D]
2007-06-26 17:26 2058752 ----a-w- c:\program files\yodm3DII\Yodm3D.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\totalcmd\\TOTALCMD.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\xampp\\apache\\bin\\apache.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
.
R0 83587732;83587732 Boot Guard Driver;c:\windows\system32\drivers\83587732.sys [9.4.2011 11:21 37392]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9.4.2011 11:21 64288]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9.4.2011 11:21 207792]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.4.2011 11:21 691696]
R1 83587731;83587731;c:\windows\system32\drivers\83587731.sys [9.4.2011 11:21 128016]
R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [10.8.2009 12:30 20480]
R1 setup_9.0.0.722_15.03.2011_11-34drv;setup_9.0.0.722_15.03.2011_11-34drv;c:\windows\system32\drivers\8358773.sys [9.4.2011 11:21 315408]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9.4.2011 20:54 366640]
R2 PDRJNDL;PDRJNDL;c:\program files\Dekart\Private Disk Light\pdrjndl.sys [8.11.2002 9:42 16512]
R2 PRVDISK;PRVDISK;c:\program files\Dekart\Private Disk Light\prvdisk.sys [8.11.2002 9:42 15616]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [4.8.2004 12:00 5120]
R2 WTService;WTService;c:\windows\system32\atwtusb.exe -s --> c:\windows\system32\atwtusb.exe -s [?]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [9.4.2011 11:21 6656]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [9.4.2011 11:21 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [9.4.2011 11:21 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [9.4.2011 11:21 12928]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9.4.2011 20:54 22712]
R3 NCHSSVAD;SoundTap Recorder;c:\windows\system32\drivers\nchssvad.sys [9.4.2011 11:21 27136]
R3 OOTextMode;OOTextMode;c:\windows\system32\drivers\oobctm.sys [7.4.2009 15:00 37896]
R3 RegKill;RegKill;c:\windows\system32\drivers\RegKill.sys [9.4.2011 11:21 6144]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [9.4.2011 11:21 26624]
S0 qhcend;qhcend;c:\windows\system32\drivers\bdbgq.sys --> c:\windows\system32\drivers\bdbgq.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [9.4.2011 11:20 130384]
S2 ekrn;ESET Service;"c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe" --> c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [?]
S2 r_server;Remote Administrator Service;"c:\windows\system32\r_server.exe" /service --> c:\windows\system32\r_server.exe [?]
S2 XAMPP;XAMPP Service;c:\xampp\service.exe [21.12.2007 4:01 60928]
S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [9.4.2011 11:21 97536]
S3 esihdrv;esihdrv;\??\c:\docume~1\Tomi\LOCALS~1\Temp\esihdrv.sys --> c:\docume~1\Tomi\LOCALS~1\Temp\esihdrv.sys [?]
S3 FlashUSB;FlashUSB;c:\windows\system32\drivers\FlashUsb.sys [9.4.2011 11:21 16896]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [9.4.2011 11:21 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [9.4.2011 11:21 8320]
S3 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [9.4.2011 11:21 35088]
S3 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [28.4.2011 12:22 38976]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7.4.2011 16:39 359624]
S3 utm4ode5;AVZ Kernel Driver;\??\c:\windows\system32\Drivers\utm4ode5.sys --> c:\windows\system32\Drivers\utm4ode5.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 14:16 753504]
S3 xcpip;TCP/IP Protocol Driver;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
S3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S4 Apache2.2;Apache2.2;c:\xampp\apache\bin\apache.exe [21.12.2007 4:00 17920]
S4 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [9.4.2011 11:20 79432]
S4 IJOGH;IJOGH;c:\docume~1\Tomi\LOCALS~1\Temp\IJOGH.exe --> c:\docume~1\Tomi\LOCALS~1\Temp\IJOGH.exe [?]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-19 c:\windows\Tasks\mixpadShakeIcon.job
- c:\program files\NCH Swift Sound\MixPad\mixpad.exe [2011-06-09 03:49]
.
2011-07-29 c:\windows\Tasks\recordpadShakeIcon.job
- c:\program files\NCH Swift Sound\Recordpad\recordpad.exe [2011-06-08 13:56]
.
2011-06-11 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2008-11-11 13:56]
.
2011-07-07 c:\windows\Tasks\wavepadDowngrade.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2008-11-11 03:48]
.
2011-06-09 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2008-11-11 03:48]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Poevést cíl vazby do Adobe PDF
IE: Poevést do Adobe PDF
IE: Poipojit cíl vazby k existujícímu PDF
IE: Poipojit k existujícímu PDF
IE: Poevést cíl vazby do Adobe PDF
IE: Poevést do Adobe PDF
IE: Poipojit cíl vazby k existujícímu PDF
IE: Poipojit k existujícímu PDF
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
Trusted Zone: microsoft.com\windowsupdate
TCP: DhcpNameServer = 192.168.100.20 192.168.100.30
FF - ProfilePath - c:\documents and settings\Tomi\Application Data\Mozilla\Firefox\Profiles\be9sv9dw.default\
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - prefs.js: network.proxy.type - 4
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - (no file)
MSConfigStartUp-combofix - c:\windows\system32\kmd.exe
AddRemove-Product_Name - c:\windows\iun6002.exe
AddRemove-Windows Media Format Runtime - c:\program files\Windows Media Player\wmsetsdk.exe
AddRemove-{7769B33B-81A4-49F8-895B-E9C234B56981}_is1 - c:\games\Runaway\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-29 16:48
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1284850223-1950775006-3319849090-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5F26B2F8-C94F-1F20-B8E0-1A3A2366167E}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"haipfdeinamohbnm"=hex:61,62,63,6d,6e,61,6d,6b,61,6b,61,61,68,67,6d,6a,6e,61,
68,6f,64,66,62,66,66,66,63,6d,62,62,67,6a,69,68,00,dc
"jajpcdckchplflfgmjog"=hex:6f,61,65,6d,67,62,6d,62,6e,63,6a,6a,62,70,69,64,6b,
6a,61,6b,67,70,61,67,6a,61,6b,67,6a,6c,00,77
.
[HKEY_USERS\S-1-5-21-1284850223-1950775006-3319849090-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:82,ac,4c,bc,32,f1,5d,55,c3,ee,b6,26,c5,3a,5a,2b,b2,99,7f,60,61,72,3e,
a4,93,20,84,3f,e6,68,e1,95,98,6c,e5,e9,f5,34,55,6e,4f,62,8d,99,aa,c0,5b,77,\
"??"=hex:2f,27,d3,c6,f3,8c,d6,6b,40,32,7e,e4,c4,1f,8a,85
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="9631130CE4F2A2D33D0292EC10C4553C170EB6E23AFEFD4B3530414696BA265E8C698B6413B9EDE073E976DA37B914366A2B8C87DCD5CCAE3D9F8B07357AEA0CEBE6B2401665D71EE81BE10827BCDE61A3290B4C53A943BBE741F2528815A5BE0AC9C28755614601DFEE65FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D1407BA7FD869164D6794A2D97226D213B55538BE693FCC783C076C99A7735530636CE1B6A6252CF501E2D58BE59F1C67C71DC6E3469883735037C168CCE3ACD31A1CC10E768235DBAE2E1BC41AF68212C7507F005BED4C200AB087052C362C0ED16C52965F0E4C4C8BFA38E54D3417139CF7015482D5828EE329BC1007C6E1DA3CE6966DAB0752D0A0C84E27F19BA99FCA26B05978BC06BFF8E8A55B82C45DA831ABD1E2898225619EA9C4775EC90CDD7B0533395BDFBBA50C4D4B7028B4B3D6A7EA0FFB0DE82E70D646C4F8D0A994EAF84FF5503252892C01C8F90B666D7D3E406C9A6FA979D4DDC1D83DFE667E1ED634D5A6B364FA5C2FDFDEC0180D1C5728BA88052B3BC186037931E015A3DD88A5BF7C38A83E15A201572AF43E51BEE1517E30A4D0812836293DB224776FB0B34ED43DE2AA70AE51E4B7D6AD52CE2A41EC94E311B11CE559116FD3421915360ABECF22A1E68E2BDF9475A748E081869E222A3BA8599407E8EC1721B89DC30073552ECCB2C012C0C83DA97064AA4A4E278713DE0C83536C63E25FB8CAE010F25EE616F099CDD6FA0C00919B65226FD20BAEC48E219FA54A490F964EFCEDEFC93FBACED71F5A1EB72E718E2674ED1AB67E17D79A1153C02AA18030A91B08C0908C0E44DB4B638AA9B69BA321FC6BD6F1BA398B6BC776B9E875B944A5B124BF2B3F1086EF701C25593079FAB1302898D0FBFBC07A77960B3752B20BB0946B114ED665C89520EA5C1F2C7EE11180E934F20441FD5514739299C854E44FD9BC3D8357A563E6B06A7DAB3C8E488CA727E24B16D7ED9F58019368717FD5985A282DA9C45C538F3FE83F0179034306A08AC1A2FA07DC0F40E8B3D0620802B73573B3F12D0A364F2A69B8F47F270DF2ACF3D21500093D6D0E077D543C3237EB4B1981611CA351FB932267B4EC3F81DBCFF7FB90F58AA51AC56CDF471F3B6309C4C52E52258F0D7C647DAA3DE6FC205DD15D05DAB030CE0631DD2D52B05197740B5AB6F3DFAAF34DC51AC661130C90A9BEA09B0B898D9738DD521C721B180D2B4B6D79C56645B77FA8CA65C81E889A06E6EE538CDCAD02C99B77C5770B261EBB77493A1ED6A2A9B63F15926DB8822A4C5EAD9E1F8B8EB36B01AE2A07B406494A47E99F28D47BC4AA0134BD1E95005169FC7558D67AA2755D660AA91A4AB7B10EB402B5DF067B2329A9973CFE6B"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\SCardSvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\xampp\mysql\bin\mysqld-nt.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\nisvcloc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\StacSV.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\atwtusb.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
c:\windows\AS2VER~1.SCR
.
**************************************************************************
.
Celkový čas: 2011-07-29 16:58:23 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-29 14:58
.
Před spuštěním: 9 707 978 752 bytes free
Po spuštění: 13 266 735 104 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 792D4315A00928D6D685CFC7D8F85990

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Torpig?

#11 Příspěvek od vyosek »

:o Prezil to v poradku :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Re: Torpig?

#12 Příspěvek od TomPerys »

přežil, jinak bych sem ten log neměl jak dát. Takže hádám že už je asi po havěti :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Torpig?

#13 Příspěvek od vyosek »

Jeste ne, dejte mi chvili, napisu docistovaci skript...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Torpig?

#14 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    RegLockDel::
    [HKEY_USERS\S-1-5-21-1284850223-1950775006-3319849090-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5F26B2F8-C94F-1F20-B8E0-1A3A2366167E}*]
    
    RegLock::
    [HKEY_USERS\S-1-5-21-1284850223-1950775006-3319849090-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
    
    Driver::
    IJOGH
    esihdrv
    qhcend
    xcpip
    xpsec
    
    Rootkit::
    c:\docume~1\Tomi\LOCALS~1\Temp\IJOGH.exe 
    c:\docume~1\Tomi\LOCALS~1\Temp\esihdrv.sys
    c:\windows\system32\drivers\bdbgq.sys
    c:\windows\system32\Drivers\utm4ode5.sys
    c:\windows\system32\drivers\xcpip.sys
    c:\windows\system32\drivers\xpsec.sys
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"=-
    "65533:TCP"=-
    "52344:TCP"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillElbyCheck]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegKillTray]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    
    AtJob::
    
    FixCSet::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TomPerys
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 29 říj 2006 10:47

Re: Torpig?

#15 Příspěvek od TomPerys »

Tak se deje neco uplne jineho..... pri tom postupu nabehne combofix tak, ze to tam opet napise ze skenovani muze trvat 10 minut ale uz nic jineho. Jako kdyby se to zaseklo. I po pul hodine je to porad stejne a nic se nedeje......

Avira mi na oplatku nedokonci vubec skenovani. Pokazde se to zhruba pri 45% vypne s chybou viz prilozeny obrazek. Kdyz jsem chtel projistotu spustit nouzovy rezim a udelal to tam, tak se tam taky nedostanu. Pri nacitani tech ovladacu se to zastavi na jedne knihovne a nehne se to dal......
Přílohy
avira1.jpg
avira1.jpg (83.06 KiB) Zobrazeno 1558 x

Odpovědět