Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu rootkin

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
baibarosa
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 říj 2011 08:15

Prosim o kontrolu rootkin

#1 Příspěvek od baibarosa »

Přeji dobrý den,
po zapnuti pocitace mi Avast hlasi nasledujici problem:

Obrázek

Nevim, jak tento problem resit, proto Vas poprosim o pomoc.

Logfile of random's system information tool 1.09 (written by random/random)
Run by kurva uz at 2011-10-01 10:13:10
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 27 GB (14%) free of 191 GB
Total RAM: 2047 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:17, on 1.10.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\zumpa\RSIT.exe
C:\Program Files\trend micro\kurva uz.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sweetim.com/uninstallim.asp? ... 138F407D88}
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\borisek.BORIS\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (file missing)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: SuggestMeYesBHO - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\borisek.BORIS\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (file missing)
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: DVDVideoSoftTB - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\prxtbDVD0.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - (no file)
O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
O3 - Toolbar: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
O3 - Toolbar: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\prxtbDVD0.dll
O3 - Toolbar: Nuclear Games Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: (no name) - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-823518204-113007714-839522115-1010\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: TP-LINK
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinTrusted - Unknown owner - C:\Program Files\iWin Games\iWinTrusted.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 8652 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\kurva uz\Data aplikací\Mozilla\Firefox\Profiles\z6x4p65v.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "extensions.enabledItems" - "DTToolbar@toolbarnet.com:1.0.7.0088, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5, {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, {20a82645-c095-46ed-80e3-08825760534b}:1.1, jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.3"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... id=afex&q="

"{98e34367-8df7-42b4-837b-20b892ff0848}"=C:\Program Files\iWin Games\firefox\
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"support@predictad.com"=C:\Program Files\AutocompletePro\support@predictad.com


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ahnlab.com/asp/npmkd25aos]
"Description"=AhnLab Online Security
"Path"=C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@zylom.com/ZylomGamesPlayer]
"Description"=Zylom Games Player 1.00
"Path"=C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
searchsettings@spigot.com
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{B13721C7-F507-4982-B2E5-502A71474FED}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
npwachk.xpt
nsIZylomPlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
np32dsw.dll
npdeploytk.dll
npDivxPlayerPlugin.dll
npkimi.dll
npmkd25aos.xpt
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
npzylomgamesplayer.dll
nsIDivxPlayerPlugin.xpt
QuickTimePlugin.class
ShockwavePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\kurva uz\Data aplikací\Mozilla\Firefox\Profiles\z6x4p65v.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}

C:\Documents and Settings\kurva uz\Data aplikací\Mozilla\Firefox\Profiles\z6x4p65v.default\searchplugins\
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
AC-Pro

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}]
IE to GetRight Helper - C:\Program Files\GetRight\xx2gr.dll [2007-07-18 246848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\borisek.BORIS\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-07-07 1152776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nuclear Games Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-20 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-20 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
DVDVideoSoftTB Toolbar - C:\Program Files\DVDVideoSoft\prxtbDVD0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046}
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{EEE6C35B-6118-11DC-9C72-001320C79847} -
{ba14329e-9550-4989-b3f2-9732e92d17cc}
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - DVDVideoSoftTB Toolbar - C:\Program Files\DVDVideoSoft\prxtbDVD0.dll [2011-01-17 175912]
{D4027C7F-154A-4066-A1AD-4243D8127440} -
{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-07-07 1152776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-11-11 417792]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-08-03 13892200]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-07-05 1632360]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bgsmsnd.exe]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMIMZMHMFM]
C:\DOCUME~1\BORISE~1.BOR\LOCALS~1\Temp\Yhx.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fsm]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.1\ICQ.exe silent loginmode=4 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MP4 Player]
C:\Program Files\MP4 Player\mp4Player.exe hmw []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2011-08-03 13892200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2011-08-03 111208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-07-05 1632360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\WINDOWS\system32\oodtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
C:\Program Files\Pando Networks\Media Booster\PMB.exe [2011-08-08 3077528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe -onlytray []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Real Desktop]
C:\Program Files\Real Desktop\Real Desktop.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\YouTube Downloader Toolbar\SearchSettings.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seznam Postak]
c:\Program Files\Seznam.cz\postak.exe -s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Software Informer]
C:\Program Files\Software Informer\softinfo.exe -autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-04-15 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe [2011-08-13 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\SweetIM\Messenger\SweetIM.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Turbine Download Manager Tray Icon]
C:\Program Files\Turbine\Turbine Download Manager\TurbineDownloadManagerIcon.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VC10Player]
C:\Program Files\Virtual CD v10\System\VC10Play.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2010-01-14 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^GetRight.lnk]
C:\PROGRA~1\GetRight\GetRight.exe [2008-06-23 4628752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^borisek.BORIS^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.1.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2010-02-16 384512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^borisek.BORIS^Nabídka Start^Programy^Po spuštění^Real Desktop.lnk]
C:\Program Files\Real Desktop\Real Desktop.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VC10SecS"=2
"O&O Defrag"=2
"npggsvc"=3
"LogMeIn"=2
"LMIMaint"=2
"LiveTurbineNetworkService"=3
"LiveTurbineMessageService"=3
"ICQ Service"=2
"avast! Web Scanner"=3
"avast! Mail Scanner"=3
"avast! Antivirus"=2
"aswUpdSv"=2

C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
TP-LINK

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
C:\WINDOWS\system32\LMIinit.dll [2008-10-02 87352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Dragon Age\bin_ship\daorigins.exe"="C:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Prameny Hra"
"C:\Program Files\Dragon Age\DAOriginsLauncher.exe"="C:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Prameny Spustit"
"C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe"="C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Prameny Aktualizovat"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Documents and Settings\borisek.BORIS\Dokumenty\Vuze Downloads\Race.Driver.GRID.Multi-5.Full-Rip.Skullptura\Grid\GRID.exe"="C:\Documents and Settings\borisek.BORIS\Dokumenty\Vuze Downloads\Race.Driver.GRID.Multi-5.Full-Rip.Skullptura\Grid\GRID.exe:*:Disabled:GRID Executable"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Monte Cristo\Silverfall\Silverfall.exe"="C:\Program Files\Monte Cristo\Silverfall\Silverfall.exe:*:Disabled:Silverfall"
"C:\games\FreeSpace\FS.exe"="C:\games\FreeSpace\FS.exe:*:Disabled:FreeSpace"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe"="C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe:*:Enabled:lotroclient"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Steam\steamapps\common\overlord\Config.exe"="C:\Program Files\Steam\steamapps\common\overlord\Config.exe:*:Enabled:Overlord"
"C:\Program Files\Steam\steamapps\common\overlord\Overlord.exe"="C:\Program Files\Steam\steamapps\common\overlord\Overlord.exe:*:Enabled:Overlord: Raising Hell"
"C:\Program Files\Lionhead Studios Ltd\Black & White\CreatureIsle\CreatureIsle.exe"="C:\Program Files\Lionhead Studios Ltd\Black & White\CreatureIsle\CreatureIsle.exe:*:Disabled:lh"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\Steam\steamapps\common\robin hood\Game.exe"="C:\Program Files\Steam\steamapps\common\robin hood\Game.exe:*:Enabled:Robin Hood"
"C:\Games\Mass Effect\Binaries\MassEffect.exe"="C:\Games\Mass Effect\Binaries\MassEffect.exe:*:Enabled:Mass Effect Game"
"C:\Games\Mass Effect\MassEffectLauncher.exe"="C:\Games\Mass Effect\MassEffectLauncher.exe:*:Enabled:Mass Effect Launcher"
"C:\Program Files\Steam\steamapps\common\borderlands\Binaries\Borderlands.exe"="C:\Program Files\Steam\steamapps\common\borderlands\Binaries\Borderlands.exe:*:Enabled:Borderlands"
"C:\Game\Rock of Ages\Binaries\Win32\RoA.exe"="C:\Game\Rock of Ages\Binaries\Win32\RoA.exe:*:Enabled:RoA"
"C:\Program Files\Monte Cristo\CrazyFactory\CrazyFactory.exe"="C:\Program Files\Monte Cristo\CrazyFactory\CrazyFactory.exe:*:Enabled:CrazyFactory"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.XVID"=xvidvfw.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"vidc.tscc"=tsccvid.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3filter"=ac3filter.acm
"msacm.avis"=ff_acm.acm
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll

======List of files/folders created in the last 1 month======

2011-10-01 10:13:11 ----D---- C:\Program Files\trend micro
2011-10-01 10:13:10 ----D---- C:\rsit
2011-10-01 09:13:33 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-10-01 09:13:04 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\Malwarebytes
2011-10-01 09:12:52 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2011-10-01 09:12:48 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-10-01 09:12:48 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-09-30 21:21:20 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\runic games
2011-09-30 21:15:39 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\InstallShield
2011-09-30 19:47:38 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\DMCache
2011-09-26 21:48:45 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\YoudaGames
2011-09-25 23:47:59 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\RescueFrenzy
2011-09-25 23:45:58 ----D---- C:\Program Files\Alawar
2011-09-21 05:10:58 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\OpenOffice.org
2011-09-20 22:06:30 ----D---- C:\Program Files\Drakensang - The River of Time
2011-09-18 22:11:58 ----D---- C:\Program Files\Monte Cristo
2011-09-17 01:47:18 ----D---- C:\Program Files\Paradox Interactive
2011-09-17 00:39:35 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\A2 Entertainment
2011-09-15 22:04:35 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\FarmFrenzy_Vikings
2011-09-14 08:25:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-14 08:24:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-07 06:04:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2607712$
2011-09-06 22:48:38 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\Meridian93
2011-09-04 21:45:43 ----RHD---- C:\Documents and Settings\kurva uz\Data aplikací\SecuROM
2011-09-04 21:28:39 ----D---- C:\Program Files\Atari

======List of files/folders modified in the last 1 month======

2011-10-01 10:13:13 ----D---- C:\WINDOWS\Prefetch
2011-10-01 10:13:11 ----RD---- C:\Program Files
2011-10-01 10:13:02 ----RD---- C:\zumpa
2011-10-01 10:12:21 ----D---- C:\WINDOWS\Temp
2011-10-01 09:29:06 ----D---- C:\WINDOWS\system32
2011-10-01 09:24:52 ----D---- C:\WINDOWS\system32\drivers
2011-09-30 22:37:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-30 22:21:25 ----D---- C:\WINDOWS
2011-09-30 22:20:00 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-30 22:19:45 ----D---- C:\Program Files\Steam
2011-09-30 21:19:49 ----D---- C:\WINDOWS\system32\DirectX
2011-09-30 21:19:47 ----HD---- C:\WINDOWS\inf
2011-09-30 21:18:35 ----RSD---- C:\WINDOWS\assembly
2011-09-30 21:17:38 ----SHD---- C:\Config.Msi
2011-09-30 21:17:37 ----SHD---- C:\WINDOWS\Installer
2011-09-30 21:17:36 ----D---- C:\WINDOWS\WinSxS
2011-09-30 21:15:58 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-30 19:50:07 ----D---- C:\Program Files\Mozilla Firefox
2011-09-30 19:00:23 ----D---- C:\Games
2011-09-30 18:38:17 ----D---- C:\Game
2011-09-28 22:14:30 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-28 21:03:57 ----D---- C:\Documents and Settings\kurva uz\Data aplikací\PriceGong
2011-09-22 21:13:26 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2011-09-14 08:25:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-14 08:24:55 ----A---- C:\WINDOWS\imsins.BAK
2011-09-14 08:24:29 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-11 15:07:26 ----RSH---- C:\boot.ini
2011-09-11 15:07:26 ----A---- C:\WINDOWS\win.ini
2011-09-11 15:07:26 ----A---- C:\WINDOWS\system.ini
2011-09-09 11:12:04 ----A---- C:\WINDOWS\system32\crypt32.dll
2011-09-06 22:45:29 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-09-04 21:45:42 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2011-09-03 23:19:10 ----D---- C:\Program Files\Common Files\BioWare

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys [2011-07-21 64512]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2009-02-03 59000]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-01-07 721904]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-09-06 30808]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 prodrv04;Star Force copy protection driver v4; C:\WINDOWS\System32\drivers\prodrv04.sys [2011-01-11 114496]
R1 tidnet;TID NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\tidnet.sys [2009-09-15 19200]
R1 vdrv1000;vdrv1000; C:\WINDOWS\system32\DRIVERS\vdrv1000.sys [2009-11-09 183832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-09-06 110552]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-10-25 278984]
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-10-25 25416]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-19 2317504]
R3 FStarForce;FStarForce; C:\WINDOWS\system32\DRIVERS\FStarForce.sys [2009-04-08 8704]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 lmimirr;lmimirr; C:\WINDOWS\system32\DRIVERS\lmimirr.sys [2008-07-24 10144]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-08-03 12542592]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 ZD1211BU(TP-LINK);TL-WN322G Wireless USB Adapter Driver(TP-LINK); C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2007-06-25 500736]
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
S3 ae8vrh1j;ae8vrh1j; C:\WINDOWS\system32\drivers\ae8vrh1j.sys []
S3 BRGSp50;BRGSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\BRGSp50.sys [2005-06-08 20608]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 GMSIPCI;GMSIPCI; \??\H:\INSTALL\GMSIPCI.SYS []
S3 HH10Help.sys;HH10Help.sys; \??\C:\WINDOWS\system32\drivers\HH10Help.sys []
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\WINDOWS\system32\DRIVERS\ewdcsc.sys [2009-12-15 24448]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-12-15 102528]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\WINDOWS\system32\DRIVERS\ewusbdev.sys [2009-12-15 100736]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 Mkd2kfNt;Mkd2kfNt; C:\WINDOWS\system32\drivers\Mkd2kfNt.sys [2008-10-17 131072]
S3 Mkd2Nadr;Mkd2Nadr; C:\WINDOWS\system32\drivers\Mkd2Nadr.sys [2008-10-17 79104]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 SiSGbeXP;SiS191/SiS190 Ethernet Device NDIS 5.1 Driver; C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys [2005-02-18 124160]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 XDva285;XDva285; \??\C:\WINDOWS\system32\XDva285.sys []
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2004-10-25 17664]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-20 153376]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2011-08-03 146024]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-11-21 66872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 iWinTrusted;iWinTrusted; C:\Program Files\iWin Games\iWinTrusted.exe []
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2011-07-21 2151640]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe []
S4 LiveTurbineMessageService;Turbine Message Service - Live; C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe []
S4 LiveTurbineNetworkService;Turbine Network Service - Live; C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe []
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2010-02-17 3305708]
S4 VC10SecS;Virtual CD v10 Management Service; C:\Program Files\Virtual CD v10\System\VC10SecS.exe []

-----------------EOF-----------------


RootkitRevealer log


HKLM\SECURITY\Policy\Secrets\SAC* 18.10.2009 21:32 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 18.10.2009 21:32 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System* 24.5.2010 21:03 0 bytes Key name contains embedded nulls (*)
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 24.10.2009 21:40 0 bytes Access is denied.
C:\WINDOWS\system32\config\systemprofile\Cookies\48DQSYNF.txt 1.10.2011 9:29 1.73 KB Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Cookies\CI9TRD7I.txt 1.10.2011 9:28 812 bytes Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Cookies\GI8DG8HL.txt 1.10.2011 9:29 101 bytes Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Cookies\JRJ3QO6H.txt 1.10.2011 9:32 875 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Cookies\N3N8XDFP.txt 1.10.2011 9:32 1.78 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Cookies\QTEK07W5.txt 1.10.2011 9:28 876 bytes Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Cookies\UI5UQBV1.txt 1.10.2011 9:32 1.35 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Cookies\VKHG31SL.txt 1.10.2011 9:28 1.68 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Internet Explorer\Recovery\Active\{A14E3F44-EBFF-11E0-9179-001D0FDE0545}.dat 1.10.2011 9:33 4.00 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\a87806b99f34fcdaa7bba323b68441f3CALUWNAH.swf 1.10.2011 9:30 25.53 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\adCABKPY87.htm 1.10.2011 9:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\iframe3[2].htm 1.10.2011 9:28 1.28 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\impCA0T1EM7 1.10.2011 9:29 731 bytes Hidden from Windows API.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\impCA3L9O7E 1.10.2011 9:32 856 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\impCA9JJ7FB 1.10.2011 9:32 1.55 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\impCABCWGP6 1.10.2011 9:29 719 bytes Hidden from Windows API.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\impCAWSFHNK 1.10.2011 9:32 63 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\index[3].htm 1.10.2011 9:30 0 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\st[1].htm 1.10.2011 9:28 580 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\st[2].htm 1.10.2011 9:28 574 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\stCA0WVD6L 1.10.2011 9:28 4.48 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\stCA67MA8H 1.10.2011 9:29 4.48 KB Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\stCA8T5HKZ 1.10.2011 9:28 4.47 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\stCAHCVTA9 1.10.2011 9:32 4.46 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\stCAOWS3R9 1.10.2011 9:29 4.48 KB Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\stCAQSADZ2 1.10.2011 9:29 4.48 KB Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\stCAWR9JTZ 1.10.2011 9:29 4.48 KB Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\7FZO10DK\text_group[5].php 1.10.2011 9:32 1.87 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\9c509b2712a1de7e1803ae226b311eb8[1].gif 1.10.2011 9:29 17.68 KB Hidden from Windows API.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\a87806b99f34fcdaa7bba323b68441f3CAKLYI83.swf 1.10.2011 9:32 25.53 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\b71baeaa689a1e239956bab30a6577dc[2].swf 1.10.2011 9:30 16.83 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\iframe3[1].htm 1.10.2011 9:32 1.44 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\impCAFSNRR2 1.10.2011 9:32 926 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\impCAKLJBCF 1.10.2011 9:32 63 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\impCALW6K90 1.10.2011 9:32 1.39 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KFIDW6KB\impCASZ2MSV 1.10.2011 9:30 1.32 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NCLC8XOR\adCAACA263.htm 1.10.2011 9:29 0 bytes Hidden from Windows API.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NCLC8XOR\adCAEVU1QO 1.10.2011 9:32 307 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NCLC8XOR\clkCAUAH846 1.10.2011 9:29 8.07 KB Hidden from Windows API.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NCLC8XOR\impCAG7IRKH 1.10.2011 9:30 1.33 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NCLC8XOR\stCACX5VR6 1.10.2011 9:32 4.21 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NCLC8XOR\stCARJ8HA8 1.10.2011 9:32 4.21 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NCLC8XOR\text_groupCA8U15GZ.php 1.10.2011 9:32 1.87 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\adCA2DNC3J 1.10.2011 9:32 307 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\f014a7659648d920a2eae2ac287a9366[8].swf 1.10.2011 9:32 25.58 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\iframe3[1].htm 1.10.2011 9:32 1.44 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\impCA8Q8QK0 1.10.2011 9:29 726 bytes Hidden from Windows API.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\impCAATZV32 1.10.2011 9:30 736 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\impCAPY03XE 1.10.2011 9:30 743 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\index[5].htm 1.10.2011 9:18 0 bytes Visible in Windows API, MFT, but not in directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\ptjCAN9PRA2 1.10.2011 9:32 165 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\ptjCAZP9OON 1.10.2011 9:32 165 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\st[6].htm 1.10.2011 9:32 574 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\st[7].htm 1.10.2011 9:32 578 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\st[8].htm 1.10.2011 9:32 578 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\stCA3Q6G9V 1.10.2011 9:28 4.47 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\stCAEN95QT 1.10.2011 9:32 4.48 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\stCAT8UTBY 1.10.2011 9:32 4.46 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\stCAWYW4NN 1.10.2011 9:32 4.21 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OZTPV6MK\text_groupCAJ0Q5ZS.php 1.10.2011 9:12 1.87 KB Visible in Windows API, MFT, but not in directory index.


Předem děkuji za typ, co s tim. Hezky den.

baibarosa
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 říj 2011 08:15

Re: Prosim o kontrolu rootkin

#2 Příspěvek od baibarosa »

Dobrý den, necekal jsem tak rychlou odpoved :)

10:54:06.0531 3340 TDSS rootkit removing tool 2.6.2.0 Sep 26 2011 18:56:43
10:54:07.0140 3340 ============================================================
10:54:07.0140 3340 Current date / time: 2011/10/01 10:54:07.0140
10:54:07.0140 3340 SystemInfo:
10:54:07.0140 3340
10:54:07.0140 3340 OS Version: 5.1.2600 ServicePack: 3.0
10:54:07.0140 3340 Product type: Workstation
10:54:07.0140 3340 ComputerName: BORIS
10:54:07.0140 3340 UserName: kurva uz
10:54:07.0140 3340 Windows directory: C:\WINDOWS
10:54:07.0140 3340 System windows directory: C:\WINDOWS
10:54:07.0140 3340 Processor architecture: Intel x86
10:54:07.0140 3340 Number of processors: 1
10:54:07.0140 3340 Page size: 0x1000
10:54:07.0140 3340 Boot type: Normal boot
10:54:07.0140 3340 ============================================================
10:54:08.0062 3340 Initialize success
10:54:39.0218 2136 ============================================================
10:54:39.0218 2136 Scan started
10:54:39.0218 2136 Mode: Manual; SigCheck; TDLFS;
10:54:39.0218 2136 ============================================================
10:54:39.0796 2136 Aavmker4 (95d1de2a6613494e853a9738d5d9acd4) C:\WINDOWS\system32\drivers\Aavmker4.sys
10:54:39.0937 2136 Aavmker4 - ok
10:54:39.0984 2136 Abiosdsk - ok
10:54:40.0015 2136 abp480n5 - ok
10:54:40.0093 2136 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:54:41.0203 2136 ACPI - ok
10:54:41.0328 2136 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
10:54:41.0546 2136 ACPIEC - ok
10:54:41.0593 2136 adpu160m - ok
10:54:41.0656 2136 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
10:54:41.0812 2136 aec - ok
10:54:41.0875 2136 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
10:54:41.0921 2136 AFD - ok
10:54:41.0937 2136 Aha154x - ok
10:54:41.0968 2136 aic78u2 - ok
10:54:41.0984 2136 aic78xx - ok
10:54:42.0109 2136 ALCXWDM (95aa37bec6c72c277c2caeaee736dd2d) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
10:54:42.0375 2136 ALCXWDM - ok
10:54:42.0468 2136 AliIde - ok
10:54:42.0546 2136 AmdK8 (fcffa85cfd4bf7a4711012847048dca3) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
10:54:42.0593 2136 AmdK8 - ok
10:54:42.0609 2136 amsint - ok
10:54:42.0640 2136 asc - ok
10:54:42.0656 2136 asc3350p - ok
10:54:42.0671 2136 asc3550 - ok
10:54:42.0750 2136 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\WINDOWS\system32\drivers\aswFsBlk.sys
10:54:42.0765 2136 aswFsBlk - ok
10:54:42.0781 2136 aswMon2 (fff2dbb17a3c89f87f78d5fa72ca47fd) C:\WINDOWS\system32\drivers\aswMon2.sys
10:54:42.0812 2136 aswMon2 - ok
10:54:42.0843 2136 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\WINDOWS\system32\drivers\aswRdr.sys
10:54:42.0843 2136 aswRdr - ok
10:54:42.0906 2136 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\WINDOWS\system32\drivers\aswSnx.sys
10:54:42.0937 2136 aswSnx - ok
10:54:42.0984 2136 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\WINDOWS\system32\drivers\aswSP.sys
10:54:43.0000 2136 aswSP - ok
10:54:43.0062 2136 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\WINDOWS\system32\drivers\aswTdi.sys
10:54:43.0078 2136 aswTdi - ok
10:54:43.0125 2136 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:54:43.0281 2136 AsyncMac - ok
10:54:43.0328 2136 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:54:43.0500 2136 atapi - ok
10:54:43.0515 2136 Atdisk - ok
10:54:43.0562 2136 atksgt (3c4b9850a2631c2263507400d029057b) C:\WINDOWS\system32\DRIVERS\atksgt.sys
10:54:43.0609 2136 atksgt - ok
10:54:43.0671 2136 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:54:43.0875 2136 Atmarpc - ok
10:54:43.0937 2136 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:54:44.0187 2136 audstub - ok
10:54:44.0250 2136 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:54:44.0500 2136 Beep - ok
10:54:44.0562 2136 BRGSp50 (ee0f41fa0466189a2c8b9caf7d1cddd5) C:\WINDOWS\system32\Drivers\BRGSp50.sys
10:54:44.0578 2136 BRGSp50 ( UnsignedFile.Multi.Generic ) - warning
10:54:44.0578 2136 BRGSp50 - detected UnsignedFile.Multi.Generic (1)
10:54:44.0687 2136 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:54:44.0906 2136 cbidf2k - ok
10:54:44.0937 2136 cd20xrnt - ok
10:54:45.0000 2136 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:54:45.0203 2136 Cdaudio - ok
10:54:45.0281 2136 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
10:54:45.0406 2136 Cdfs - ok
10:54:45.0437 2136 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:54:45.0593 2136 Cdrom - ok
10:54:45.0609 2136 Changer - ok
10:54:45.0656 2136 CmdIde - ok
10:54:45.0687 2136 Cpqarray - ok
10:54:45.0718 2136 dac2w2k - ok
10:54:45.0734 2136 dac960nt - ok
10:54:45.0765 2136 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
10:54:45.0906 2136 Disk - ok
10:54:45.0968 2136 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
10:54:46.0203 2136 dmboot - ok
10:54:46.0218 2136 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
10:54:46.0375 2136 dmio - ok
10:54:46.0406 2136 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:54:46.0578 2136 dmload - ok
10:54:46.0609 2136 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
10:54:46.0750 2136 DMusic - ok
10:54:46.0781 2136 dpti2o - ok
10:54:46.0796 2136 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
10:54:46.0921 2136 drmkaud - ok
10:54:46.0953 2136 EagleNT - ok
10:54:47.0000 2136 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
10:54:47.0171 2136 Fastfat - ok
10:54:47.0203 2136 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
10:54:47.0359 2136 Fdc - ok
10:54:47.0390 2136 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
10:54:47.0531 2136 Fips - ok
10:54:47.0546 2136 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
10:54:47.0718 2136 Flpydisk - ok
10:54:47.0750 2136 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
10:54:47.0906 2136 FltMgr - ok
10:54:47.0968 2136 FStarForce (e626f53e373e521f75b59936a31a4124) C:\WINDOWS\system32\DRIVERS\FStarForce.sys
10:54:47.0968 2136 FStarForce ( UnsignedFile.Multi.Generic ) - warning
10:54:47.0968 2136 FStarForce - detected UnsignedFile.Multi.Generic (1)
10:54:48.0031 2136 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:54:48.0171 2136 Fs_Rec - ok
10:54:48.0187 2136 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:54:48.0375 2136 Ftdisk - ok
10:54:48.0421 2136 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
10:54:48.0578 2136 gameenum - ok
10:54:48.0625 2136 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
10:54:48.0703 2136 GEARAspiWDM - ok
10:54:48.0703 2136 GMSIPCI - ok
10:54:48.0734 2136 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:54:48.0875 2136 Gpc - ok
10:54:48.0953 2136 Hardlock (d95554949082fd29a04d351b58396718) C:\WINDOWS\system32\drivers\hardlock.sys
10:54:49.0031 2136 Hardlock - ok
10:54:49.0078 2136 HH10Help.sys (d1c92d1e1620da2e22e3f483a73729d7) C:\WINDOWS\system32\drivers\HH10Help.sys
10:54:49.0093 2136 HH10Help.sys ( UnsignedFile.Multi.Generic ) - warning
10:54:49.0093 2136 HH10Help.sys - detected UnsignedFile.Multi.Generic (1)
10:54:49.0140 2136 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:54:49.0281 2136 hidusb - ok
10:54:49.0312 2136 hpn - ok
10:54:49.0375 2136 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
10:54:49.0421 2136 HTTP - ok
10:54:49.0500 2136 Huawei (4183be439981bbc77ef2c1d66629f124) C:\WINDOWS\system32\DRIVERS\ewdcsc.sys
10:54:49.0562 2136 Huawei - ok
10:54:49.0609 2136 hwdatacard (20330198554b7ddb44403af21d6ae179) C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys
10:54:49.0625 2136 hwdatacard - ok
10:54:49.0656 2136 hwusbdev (922065957563d851b5a68b95aadac6ad) C:\WINDOWS\system32\DRIVERS\ewusbdev.sys
10:54:49.0687 2136 hwusbdev - ok
10:54:49.0718 2136 i2omgmt - ok
10:54:49.0734 2136 i2omp - ok
10:54:49.0796 2136 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:54:49.0953 2136 i8042prt - ok
10:54:49.0984 2136 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:54:50.0125 2136 Imapi - ok
10:54:50.0156 2136 ini910u - ok
10:54:50.0171 2136 IntelIde - ok
10:54:50.0218 2136 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
10:54:50.0359 2136 Ip6Fw - ok
10:54:50.0406 2136 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:54:50.0578 2136 IpFilterDriver - ok
10:54:50.0593 2136 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:54:50.0765 2136 IpInIp - ok
10:54:50.0796 2136 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:54:50.0953 2136 IpNat - ok
10:54:50.0984 2136 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:54:51.0109 2136 IPSec - ok
10:54:51.0125 2136 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:54:51.0265 2136 IRENUM - ok
10:54:51.0296 2136 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:54:51.0453 2136 isapnp - ok
10:54:51.0484 2136 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:54:51.0640 2136 Kbdclass - ok
10:54:51.0671 2136 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
10:54:51.0812 2136 kmixer - ok
10:54:51.0875 2136 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
10:54:51.0906 2136 KSecDD - ok
10:54:52.0000 2136 Lavasoft Kernexplorer - ok
10:54:52.0125 2136 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
10:54:52.0140 2136 Lbd - ok
10:54:52.0187 2136 lbrtfdc - ok
10:54:52.0265 2136 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
10:54:52.0265 2136 lirsgt - ok
10:54:52.0328 2136 LMIInfo - ok
10:54:52.0390 2136 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
10:54:52.0406 2136 lmimirr - ok
10:54:52.0421 2136 LMIRfsClientNP - ok
10:54:52.0453 2136 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
10:54:52.0468 2136 LMIRfsDriver - ok
10:54:52.0515 2136 Mkd2kfNt (277b8b3536c1179fe432ef2dde294a97) C:\WINDOWS\system32\drivers\Mkd2kfNt.sys
10:54:52.0531 2136 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - warning
10:54:52.0531 2136 Mkd2kfNt - detected UnsignedFile.Multi.Generic (1)
10:54:52.0562 2136 Mkd2Nadr (0716efda4769995c67a3450fcd36e47e) C:\WINDOWS\system32\drivers\Mkd2Nadr.sys
10:54:52.0578 2136 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - warning
10:54:52.0578 2136 Mkd2Nadr - detected UnsignedFile.Multi.Generic (1)
10:54:52.0640 2136 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:54:52.0796 2136 mnmdd - ok
10:54:52.0843 2136 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
10:54:52.0984 2136 Modem - ok
10:54:53.0000 2136 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:54:53.0140 2136 Mouclass - ok
10:54:53.0203 2136 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:54:53.0375 2136 mouhid - ok
10:54:53.0406 2136 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
10:54:53.0546 2136 MountMgr - ok
10:54:53.0562 2136 mraid35x - ok
10:54:53.0609 2136 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:54:53.0750 2136 MRxDAV - ok
10:54:53.0812 2136 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:54:53.0890 2136 MRxSmb - ok
10:54:53.0937 2136 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
10:54:54.0078 2136 Msfs - ok
10:54:54.0125 2136 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:54:54.0250 2136 MSKSSRV - ok
10:54:54.0281 2136 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:54:54.0406 2136 MSPCLOCK - ok
10:54:54.0421 2136 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
10:54:54.0562 2136 MSPQM - ok
10:54:54.0609 2136 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:54:54.0750 2136 mssmbios - ok
10:54:54.0812 2136 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
10:54:54.0859 2136 Mup - ok
10:54:54.0921 2136 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
10:54:55.0046 2136 NDIS - ok
10:54:55.0109 2136 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:54:55.0140 2136 NdisTapi - ok
10:54:55.0171 2136 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:54:55.0296 2136 Ndisuio - ok
10:54:55.0312 2136 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:54:55.0453 2136 NdisWan - ok
10:54:55.0515 2136 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
10:54:55.0531 2136 NDProxy - ok
10:54:55.0562 2136 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:54:55.0703 2136 NetBIOS - ok
10:54:55.0734 2136 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:54:55.0875 2136 NetBT - ok
10:54:55.0937 2136 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
10:54:56.0046 2136 Npfs - ok
10:54:56.0093 2136 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
10:54:56.0265 2136 Ntfs - ok
10:54:56.0328 2136 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:54:56.0484 2136 Null - ok
10:54:56.0937 2136 nv (6733e80a193fc36f41c24142b0c45c0e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:54:57.0703 2136 nv - ok
10:54:57.0812 2136 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:54:57.0984 2136 NwlnkFlt - ok
10:54:58.0015 2136 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:54:58.0171 2136 NwlnkFwd - ok
10:54:58.0234 2136 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
10:54:58.0359 2136 Parport - ok
10:54:58.0375 2136 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
10:54:58.0515 2136 PartMgr - ok
10:54:58.0578 2136 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
10:54:58.0734 2136 ParVdm - ok
10:54:58.0750 2136 pccsmcfd - ok
10:54:58.0765 2136 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
10:54:58.0906 2136 PCI - ok
10:54:58.0937 2136 PCIDump - ok
10:54:58.0968 2136 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:54:59.0125 2136 PCIIde - ok
10:54:59.0156 2136 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
10:54:59.0296 2136 Pcmcia - ok
10:54:59.0312 2136 PDCOMP - ok
10:54:59.0328 2136 PDFRAME - ok
10:54:59.0343 2136 PDRELI - ok
10:54:59.0359 2136 PDRFRAME - ok
10:54:59.0390 2136 perc2 - ok
10:54:59.0406 2136 perc2hib - ok
10:54:59.0484 2136 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:54:59.0640 2136 PptpMiniport - ok
10:54:59.0671 2136 Processor (7eb15dce4ec3a0220bd796a15c18186e) C:\WINDOWS\system32\DRIVERS\processr.sys
10:54:59.0796 2136 Processor - ok
10:54:59.0843 2136 prodrv04 (4aa86b6f5fdf5ed32adc723b0e5b052d) C:\WINDOWS\System32\drivers\prodrv04.sys
10:54:59.0875 2136 prodrv04 ( UnsignedFile.Multi.Generic ) - warning
10:54:59.0875 2136 prodrv04 - detected UnsignedFile.Multi.Generic (1)
10:54:59.0906 2136 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
10:55:00.0046 2136 PSched - ok
10:55:00.0078 2136 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:55:00.0250 2136 Ptilink - ok
10:55:00.0296 2136 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:55:00.0312 2136 PxHelp20 - ok
10:55:00.0328 2136 ql1080 - ok
10:55:00.0343 2136 Ql10wnt - ok
10:55:00.0359 2136 ql12160 - ok
10:55:00.0375 2136 ql1240 - ok
10:55:00.0406 2136 ql1280 - ok
10:55:00.0437 2136 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:55:00.0609 2136 RasAcd - ok
10:55:00.0656 2136 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:55:00.0796 2136 Rasl2tp - ok
10:55:00.0843 2136 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:55:00.0968 2136 RasPppoe - ok
10:55:01.0015 2136 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:55:01.0156 2136 Raspti - ok
10:55:01.0218 2136 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:55:01.0359 2136 Rdbss - ok
10:55:01.0390 2136 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:55:01.0562 2136 RDPCDD - ok
10:55:01.0640 2136 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
10:55:01.0687 2136 RDPWD - ok
10:55:01.0750 2136 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:55:01.0875 2136 redbook - ok
10:55:01.0953 2136 SASKUTIL - ok
10:55:02.0000 2136 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:55:02.0125 2136 Secdrv - ok
10:55:02.0156 2136 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:55:02.0281 2136 serenum - ok
10:55:02.0296 2136 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
10:55:02.0437 2136 Serial - ok
10:55:02.0515 2136 sfdrv01 (b7018644e132a8dfb12ed90106e06739) C:\WINDOWS\system32\drivers\sfdrv01.sys
10:55:02.0531 2136 sfdrv01 - ok
10:55:02.0546 2136 sfhlp02 (daad4c099ebf5094d32c373ac1ac0f3c) C:\WINDOWS\system32\drivers\sfhlp02.sys
10:55:02.0562 2136 sfhlp02 - ok
10:55:02.0593 2136 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:55:02.0718 2136 Sfloppy - ok
10:55:02.0765 2136 sfsync02 (6dc03269f4c71e4ab313c3597f42a340) C:\WINDOWS\system32\drivers\sfsync02.sys
10:55:02.0781 2136 sfsync02 - ok
10:55:02.0796 2136 Simbad - ok
10:55:02.0843 2136 SiSGbeXP (5f6105266cc85f05a481f740012b2e0e) C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys
10:55:02.0906 2136 SiSGbeXP - ok
10:55:02.0921 2136 Sparrow - ok
10:55:02.0984 2136 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
10:55:03.0125 2136 splitter - ok
10:55:03.0203 2136 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\WINDOWS\system32\Drivers\sptd.sys
10:55:03.0203 2136 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9
10:55:03.0203 2136 sptd ( LockedFile.Multi.Generic ) - warning
10:55:03.0203 2136 sptd - detected LockedFile.Multi.Generic (1)
10:55:03.0234 2136 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
10:55:03.0375 2136 sr - ok
10:55:03.0437 2136 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
10:55:03.0500 2136 Srv - ok
10:55:03.0546 2136 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:55:03.0687 2136 swenum - ok
10:55:03.0718 2136 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
10:55:03.0859 2136 swmidi - ok
10:55:03.0890 2136 symc810 - ok
10:55:03.0906 2136 symc8xx - ok
10:55:03.0921 2136 sym_hi - ok
10:55:03.0937 2136 sym_u3 - ok
10:55:03.0968 2136 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
10:55:04.0109 2136 sysaudio - ok
10:55:04.0187 2136 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:55:04.0281 2136 Tcpip - ok
10:55:04.0328 2136 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:55:04.0468 2136 TDPIPE - ok
10:55:04.0500 2136 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
10:55:04.0625 2136 TDTCP - ok
10:55:04.0656 2136 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:55:04.0796 2136 TermDD - ok
10:55:04.0859 2136 tidnet (8044c4e4448d115f67a9fc1b67ce677f) C:\WINDOWS\system32\DRIVERS\tidnet.sys
10:55:04.0890 2136 tidnet ( UnsignedFile.Multi.Generic ) - warning
10:55:04.0890 2136 tidnet - detected UnsignedFile.Multi.Generic (1)
10:55:04.0906 2136 TosIde - ok
10:55:04.0953 2136 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
10:55:05.0109 2136 Udfs - ok
10:55:05.0125 2136 ultra - ok
10:55:05.0171 2136 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
10:55:05.0359 2136 Update - ok
10:55:05.0375 2136 upperdev - ok
10:55:05.0437 2136 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:55:05.0578 2136 usbccgp - ok
10:55:05.0625 2136 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:55:05.0750 2136 usbehci - ok
10:55:05.0796 2136 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:55:05.0937 2136 usbhub - ok
10:55:05.0968 2136 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
10:55:06.0109 2136 usbohci - ok
10:55:06.0140 2136 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:55:06.0281 2136 usbstor - ok
10:55:06.0328 2136 vdrv1000 (12ecc28400d4070d75fe115485256fde) C:\WINDOWS\system32\DRIVERS\vdrv1000.sys
10:55:06.0343 2136 vdrv1000 - ok
10:55:06.0375 2136 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
10:55:06.0484 2136 VgaSave - ok
10:55:06.0515 2136 ViaIde - ok
10:55:06.0531 2136 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
10:55:06.0671 2136 VolSnap - ok
10:55:06.0718 2136 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:55:06.0843 2136 Wanarp - ok
10:55:06.0906 2136 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
10:55:06.0937 2136 Wdf01000 - ok
10:55:06.0953 2136 WDICA - ok
10:55:06.0984 2136 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
10:55:07.0140 2136 wdmaud - ok
10:55:07.0265 2136 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:55:07.0312 2136 WudfPf - ok
10:55:07.0359 2136 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:55:07.0390 2136 WudfRd - ok
10:55:07.0421 2136 XDva285 - ok
10:55:07.0500 2136 ZD1211BU(TP-LINK) (d125e1445bb9dc951c250d4192e70841) C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys
10:55:07.0546 2136 ZD1211BU(TP-LINK) ( UnsignedFile.Multi.Generic ) - warning
10:55:07.0546 2136 ZD1211BU(TP-LINK) - detected UnsignedFile.Multi.Generic (1)
10:55:07.0593 2136 ZDPSp50 (00ae175b903d45ed4a62384d3315dc2a) C:\WINDOWS\system32\Drivers\ZDPSp50.sys
10:55:07.0625 2136 ZDPSp50 ( UnsignedFile.Multi.Generic ) - warning
10:55:07.0625 2136 ZDPSp50 - detected UnsignedFile.Multi.Generic (1)
10:55:07.0656 2136 MBR (0x1B8) (9c603bc3977968c891de319283e1e7af) \Device\Harddisk0\DR0
10:55:07.0687 2136 \Device\Harddisk0\DR0 ( Trojan-Clicker.Win32.Wistler.c ) - infected
10:55:07.0687 2136 \Device\Harddisk0\DR0 - detected Trojan-Clicker.Win32.Wistler.c (0)
10:55:07.0734 2136 Boot (0x1200) (7419a5bfe754d8b31401234ccd7ce48c) \Device\Harddisk0\DR0\Partition0
10:55:07.0734 2136 \Device\Harddisk0\DR0\Partition0 - ok
10:55:07.0750 2136 ============================================================
10:55:07.0750 2136 Scan finished
10:55:07.0750 2136 ============================================================
10:55:07.0859 1356 Detected object count: 11
10:55:07.0859 1356 Actual detected object count: 11
10:55:46.0515 1356 BRGSp50 ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0515 1356 BRGSp50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0515 1356 FStarForce ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0515 1356 FStarForce ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0515 1356 HH10Help.sys ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0515 1356 HH10Help.sys ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0515 1356 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0515 1356 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0515 1356 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0531 1356 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0531 1356 prodrv04 ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0531 1356 prodrv04 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0531 1356 sptd ( LockedFile.Multi.Generic ) - skipped by user
10:55:46.0531 1356 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
10:55:46.0531 1356 tidnet ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0531 1356 tidnet ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0531 1356 ZD1211BU(TP-LINK) ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0531 1356 ZD1211BU(TP-LINK) ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0531 1356 ZDPSp50 ( UnsignedFile.Multi.Generic ) - skipped by user
10:55:46.0531 1356 ZDPSp50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:55:46.0531 1356 \Device\Harddisk0\DR0 ( Trojan-Clicker.Win32.Wistler.c ) - skipped by user
10:55:46.0531 1356 \Device\Harddisk0\DR0 ( Trojan-Clicker.Win32.Wistler.c ) - User select action: Skip

baibarosa
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 říj 2011 08:15

Re: Prosim o kontrolu rootkin

#3 Příspěvek od baibarosa »

Priznam se, ze kdyz bezel ComboFix, tak jsem se i bal :)

11:57:01.0671 2320 TDSS rootkit removing tool 2.6.2.0 Sep 26 2011 18:56:43
11:57:01.0734 2320 ============================================================
11:57:01.0734 2320 Current date / time: 2011/10/01 11:57:01.0734
11:57:01.0734 2320 SystemInfo:
11:57:01.0734 2320
11:57:01.0734 2320 OS Version: 5.1.2600 ServicePack: 3.0
11:57:01.0734 2320 Product type: Workstation
11:57:01.0750 2320 ComputerName: BORIS
11:57:01.0750 2320 UserName: kurva uz
11:57:01.0750 2320 Windows directory: C:\WINDOWS
11:57:01.0750 2320 System windows directory: C:\WINDOWS
11:57:01.0750 2320 Processor architecture: Intel x86
11:57:01.0750 2320 Number of processors: 1
11:57:01.0750 2320 Page size: 0x1000
11:57:01.0750 2320 Boot type: Normal boot
11:57:01.0750 2320 ============================================================
11:57:02.0593 2320 Initialize success
11:57:08.0656 2980 ============================================================
11:57:08.0656 2980 Scan started
11:57:08.0656 2980 Mode: Manual; SigCheck; TDLFS;
11:57:08.0656 2980 ============================================================
11:57:08.0968 2980 05647685 - ok
11:57:09.0015 2980 Aavmker4 (95d1de2a6613494e853a9738d5d9acd4) C:\WINDOWS\system32\drivers\Aavmker4.sys
11:57:09.0140 2980 Aavmker4 - ok
11:57:09.0171 2980 Abiosdsk - ok
11:57:09.0203 2980 abp480n5 - ok
11:57:09.0281 2980 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:57:09.0515 2980 ACPI - ok
11:57:09.0656 2980 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
11:57:09.0812 2980 ACPIEC - ok
11:57:09.0843 2980 adpu160m - ok
11:57:09.0921 2980 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
11:57:10.0062 2980 aec - ok
11:57:10.0203 2980 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
11:57:10.0312 2980 AFD - ok
11:57:10.0468 2980 Aha154x - ok
11:57:10.0500 2980 aic78u2 - ok
11:57:10.0531 2980 aic78xx - ok
11:57:10.0656 2980 ALCXWDM (95aa37bec6c72c277c2caeaee736dd2d) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
11:57:10.0875 2980 ALCXWDM - ok
11:57:10.0890 2980 AliIde - ok
11:57:10.0937 2980 AmdK8 (fcffa85cfd4bf7a4711012847048dca3) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
11:57:10.0968 2980 AmdK8 - ok
11:57:10.0984 2980 amsint - ok
11:57:11.0015 2980 asc - ok
11:57:11.0031 2980 asc3350p - ok
11:57:11.0046 2980 asc3550 - ok
11:57:11.0125 2980 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\WINDOWS\system32\drivers\aswFsBlk.sys
11:57:11.0140 2980 aswFsBlk - ok
11:57:11.0156 2980 aswMon2 (fff2dbb17a3c89f87f78d5fa72ca47fd) C:\WINDOWS\system32\drivers\aswMon2.sys
11:57:11.0171 2980 aswMon2 - ok
11:57:11.0218 2980 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\WINDOWS\system32\drivers\aswRdr.sys
11:57:11.0218 2980 aswRdr - ok
11:57:11.0265 2980 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\WINDOWS\system32\drivers\aswSnx.sys
11:57:11.0296 2980 aswSnx - ok
11:57:11.0343 2980 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\WINDOWS\system32\drivers\aswSP.sys
11:57:11.0359 2980 aswSP - ok
11:57:11.0375 2980 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\WINDOWS\system32\drivers\aswTdi.sys
11:57:11.0390 2980 aswTdi - ok
11:57:11.0453 2980 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:57:11.0593 2980 AsyncMac - ok
11:57:11.0640 2980 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
11:57:11.0781 2980 atapi - ok
11:57:11.0796 2980 Atdisk - ok
11:57:11.0859 2980 atksgt (3c4b9850a2631c2263507400d029057b) C:\WINDOWS\system32\DRIVERS\atksgt.sys
11:57:11.0875 2980 atksgt - ok
11:57:11.0906 2980 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:57:12.0046 2980 Atmarpc - ok
11:57:12.0093 2980 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
11:57:12.0265 2980 audstub - ok
11:57:12.0343 2980 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
11:57:12.0515 2980 Beep - ok
11:57:12.0593 2980 BRGSp50 (ee0f41fa0466189a2c8b9caf7d1cddd5) C:\WINDOWS\system32\Drivers\BRGSp50.sys
11:57:12.0625 2980 BRGSp50 ( UnsignedFile.Multi.Generic ) - warning
11:57:12.0625 2980 BRGSp50 - detected UnsignedFile.Multi.Generic (1)
11:57:12.0640 2980 catchme - ok
11:57:12.0734 2980 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
11:57:12.0953 2980 cbidf2k - ok
11:57:13.0250 2980 cd20xrnt - ok
11:57:13.0390 2980 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
11:57:13.0593 2980 Cdaudio - ok
11:57:13.0687 2980 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
11:57:13.0796 2980 Cdfs - ok
11:57:13.0828 2980 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:57:13.0953 2980 Cdrom - ok
11:57:13.0984 2980 Changer - ok
11:57:14.0015 2980 CmdIde - ok
11:57:14.0046 2980 Cpqarray - ok
11:57:14.0078 2980 dac2w2k - ok
11:57:14.0093 2980 dac960nt - ok
11:57:14.0125 2980 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
11:57:14.0265 2980 Disk - ok
11:57:14.0328 2980 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
11:57:14.0515 2980 dmboot - ok
11:57:14.0531 2980 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
11:57:14.0671 2980 dmio - ok
11:57:14.0703 2980 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
11:57:14.0875 2980 dmload - ok
11:57:14.0906 2980 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
11:57:15.0031 2980 DMusic - ok
11:57:15.0046 2980 dpti2o - ok
11:57:15.0078 2980 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
11:57:15.0187 2980 drmkaud - ok
11:57:15.0203 2980 EagleNT - ok
11:57:15.0265 2980 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
11:57:15.0406 2980 Fastfat - ok
11:57:15.0750 2980 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
11:57:15.0890 2980 Fdc - ok
11:57:16.0500 2980 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
11:57:17.0031 2980 Fips - ok
11:57:17.0296 2980 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
11:57:17.0828 2980 Flpydisk - ok
11:57:18.0109 2980 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
11:57:18.0296 2980 FltMgr - ok
11:57:18.0703 2980 FStarForce (e626f53e373e521f75b59936a31a4124) C:\WINDOWS\system32\DRIVERS\FStarForce.sys
11:57:18.0750 2980 FStarForce ( UnsignedFile.Multi.Generic ) - warning
11:57:18.0750 2980 FStarForce - detected UnsignedFile.Multi.Generic (1)
11:57:19.0078 2980 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:57:19.0250 2980 Fs_Rec - ok
11:57:19.0484 2980 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:57:19.0671 2980 Ftdisk - ok
11:57:19.0750 2980 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
11:57:19.0875 2980 gameenum - ok
11:57:19.0906 2980 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
11:57:19.0921 2980 GEARAspiWDM - ok
11:57:19.0937 2980 GMSIPCI - ok
11:57:19.0968 2980 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:57:20.0093 2980 Gpc - ok
11:57:20.0156 2980 Hardlock (d95554949082fd29a04d351b58396718) C:\WINDOWS\system32\drivers\hardlock.sys
11:57:20.0187 2980 Hardlock - ok
11:57:20.0250 2980 HH10Help.sys (d1c92d1e1620da2e22e3f483a73729d7) C:\WINDOWS\system32\drivers\HH10Help.sys
11:57:20.0265 2980 HH10Help.sys ( UnsignedFile.Multi.Generic ) - warning
11:57:20.0265 2980 HH10Help.sys - detected UnsignedFile.Multi.Generic (1)
11:57:20.0312 2980 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:57:20.0437 2980 hidusb - ok
11:57:20.0468 2980 hpn - ok
11:57:20.0546 2980 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
11:57:20.0578 2980 HTTP - ok
11:57:20.0656 2980 Huawei (4183be439981bbc77ef2c1d66629f124) C:\WINDOWS\system32\DRIVERS\ewdcsc.sys
11:57:20.0671 2980 Huawei - ok
11:57:20.0718 2980 hwdatacard (20330198554b7ddb44403af21d6ae179) C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys
11:57:20.0734 2980 hwdatacard - ok
11:57:20.0765 2980 hwusbdev (922065957563d851b5a68b95aadac6ad) C:\WINDOWS\system32\DRIVERS\ewusbdev.sys
11:57:20.0796 2980 hwusbdev - ok
11:57:20.0812 2980 i2omgmt - ok
11:57:20.0828 2980 i2omp - ok
11:57:20.0875 2980 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:57:21.0000 2980 i8042prt - ok
11:57:21.0031 2980 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
11:57:21.0171 2980 Imapi - ok
11:57:21.0203 2980 ini910u - ok
11:57:21.0234 2980 IntelIde - ok
11:57:21.0328 2980 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
11:57:21.0468 2980 Ip6Fw - ok
11:57:21.0828 2980 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:57:22.0000 2980 IpFilterDriver - ok
11:57:22.0093 2980 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:57:22.0218 2980 IpInIp - ok
11:57:22.0296 2980 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:57:22.0437 2980 IpNat - ok
11:57:22.0453 2980 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:57:22.0578 2980 IPSec - ok
11:57:22.0593 2980 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
11:57:22.0718 2980 IRENUM - ok
11:57:22.0765 2980 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:57:22.0890 2980 isapnp - ok
11:57:22.0921 2980 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:57:23.0062 2980 Kbdclass - ok
11:57:23.0093 2980 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
11:57:23.0234 2980 kmixer - ok
11:57:23.0281 2980 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
11:57:23.0312 2980 KSecDD - ok
11:57:23.0406 2980 Lavasoft Kernexplorer - ok
11:57:23.0437 2980 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
11:57:23.0453 2980 Lbd - ok
11:57:23.0468 2980 lbrtfdc - ok
11:57:23.0515 2980 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
11:57:23.0531 2980 lirsgt - ok
11:57:23.0578 2980 LMIInfo - ok
11:57:23.0625 2980 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
11:57:23.0625 2980 lmimirr - ok
11:57:23.0640 2980 LMIRfsClientNP - ok
11:57:23.0671 2980 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
11:57:23.0671 2980 LMIRfsDriver - ok
11:57:23.0718 2980 Mkd2kfNt (277b8b3536c1179fe432ef2dde294a97) C:\WINDOWS\system32\drivers\Mkd2kfNt.sys
11:57:23.0734 2980 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - warning
11:57:23.0734 2980 Mkd2kfNt - detected UnsignedFile.Multi.Generic (1)
11:57:23.0765 2980 Mkd2Nadr (0716efda4769995c67a3450fcd36e47e) C:\WINDOWS\system32\drivers\Mkd2Nadr.sys
11:57:23.0781 2980 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - warning
11:57:23.0781 2980 Mkd2Nadr - detected UnsignedFile.Multi.Generic (1)
11:57:23.0828 2980 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
11:57:23.0968 2980 mnmdd - ok
11:57:24.0031 2980 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
11:57:24.0171 2980 Modem - ok
11:57:24.0218 2980 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:57:24.0343 2980 Mouclass - ok
11:57:24.0406 2980 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:57:24.0578 2980 mouhid - ok
11:57:24.0750 2980 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
11:57:24.0875 2980 MountMgr - ok
11:57:24.0890 2980 mraid35x - ok
11:57:24.0921 2980 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:57:25.0062 2980 MRxDAV - ok
11:57:25.0125 2980 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:57:25.0187 2980 MRxSmb - ok
11:57:25.0234 2980 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
11:57:25.0343 2980 Msfs - ok
11:57:25.0375 2980 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:57:25.0500 2980 MSKSSRV - ok
11:57:25.0531 2980 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:57:25.0640 2980 MSPCLOCK - ok
11:57:25.0656 2980 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:57:25.0765 2980 MSPQM - ok
11:57:25.0812 2980 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:57:25.0921 2980 mssmbios - ok
11:57:25.0968 2980 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:57:26.0000 2980 Mup - ok
11:57:26.0062 2980 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:57:26.0218 2980 NDIS - ok
11:57:26.0265 2980 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:57:26.0296 2980 NdisTapi - ok
11:57:26.0328 2980 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:57:26.0437 2980 Ndisuio - ok
11:57:26.0562 2980 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:57:26.0718 2980 NdisWan - ok
11:57:27.0078 2980 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:57:27.0109 2980 NDProxy - ok
11:57:27.0187 2980 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:57:27.0312 2980 NetBIOS - ok
11:57:27.0343 2980 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:57:27.0468 2980 NetBT - ok
11:57:27.0500 2980 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:57:27.0625 2980 Npfs - ok
11:57:27.0656 2980 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:57:27.0812 2980 Ntfs - ok
11:57:27.0859 2980 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:57:28.0000 2980 Null - ok
11:57:28.0468 2980 nv (6733e80a193fc36f41c24142b0c45c0e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
11:57:29.0203 2980 nv - ok
11:57:29.0328 2980 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:57:29.0484 2980 NwlnkFlt - ok
11:57:29.0765 2980 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:57:29.0921 2980 NwlnkFwd - ok
11:57:30.0000 2980 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
11:57:30.0109 2980 Parport - ok
11:57:30.0125 2980 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:57:30.0234 2980 PartMgr - ok
11:57:30.0281 2980 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
11:57:30.0437 2980 ParVdm - ok
11:57:30.0453 2980 pccsmcfd - ok
11:57:30.0468 2980 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
11:57:30.0578 2980 PCI - ok
11:57:30.0593 2980 PCIDump - ok
11:57:30.0625 2980 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
11:57:30.0781 2980 PCIIde - ok
11:57:30.0796 2980 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
11:57:30.0921 2980 Pcmcia - ok
11:57:30.0937 2980 PDCOMP - ok
11:57:30.0953 2980 PDFRAME - ok
11:57:30.0984 2980 PDRELI - ok
11:57:31.0000 2980 PDRFRAME - ok
11:57:31.0015 2980 perc2 - ok
11:57:31.0015 2980 perc2hib - ok
11:57:31.0078 2980 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:57:31.0203 2980 PptpMiniport - ok
11:57:31.0234 2980 Processor (7eb15dce4ec3a0220bd796a15c18186e) C:\WINDOWS\system32\DRIVERS\processr.sys
11:57:31.0343 2980 Processor - ok
11:57:31.0375 2980 prodrv04 (4aa86b6f5fdf5ed32adc723b0e5b052d) C:\WINDOWS\System32\drivers\prodrv04.sys
11:57:31.0390 2980 prodrv04 ( UnsignedFile.Multi.Generic ) - warning
11:57:31.0406 2980 prodrv04 - detected UnsignedFile.Multi.Generic (1)
11:57:31.0437 2980 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:57:31.0562 2980 PSched - ok
11:57:31.0593 2980 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:57:31.0718 2980 Ptilink - ok
11:57:31.0765 2980 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
11:57:31.0781 2980 PxHelp20 - ok
11:57:31.0796 2980 ql1080 - ok
11:57:31.0812 2980 Ql10wnt - ok
11:57:31.0828 2980 ql12160 - ok
11:57:31.0843 2980 ql1240 - ok
11:57:31.0859 2980 ql1280 - ok
11:57:31.0890 2980 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:57:32.0031 2980 RasAcd - ok
11:57:32.0078 2980 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:57:32.0203 2980 Rasl2tp - ok
11:57:32.0234 2980 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:57:32.0359 2980 RasPppoe - ok
11:57:32.0406 2980 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:57:32.0562 2980 Raspti - ok
11:57:32.0625 2980 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:57:32.0750 2980 Rdbss - ok
11:57:32.0765 2980 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:57:32.0890 2980 RDPCDD - ok
11:57:32.0953 2980 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
11:57:32.0968 2980 RDPWD - ok
11:57:33.0031 2980 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:57:33.0156 2980 redbook - ok
11:57:33.0218 2980 SASKUTIL - ok
11:57:33.0265 2980 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:57:33.0375 2980 Secdrv - ok
11:57:33.0390 2980 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:57:33.0531 2980 serenum - ok
11:57:33.0546 2980 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
11:57:33.0671 2980 Serial - ok
11:57:33.0734 2980 sfdrv01 (b7018644e132a8dfb12ed90106e06739) C:\WINDOWS\system32\drivers\sfdrv01.sys
11:57:33.0734 2980 sfdrv01 - ok
11:57:33.0843 2980 sfhlp02 (daad4c099ebf5094d32c373ac1ac0f3c) C:\WINDOWS\system32\drivers\sfhlp02.sys
11:57:33.0859 2980 sfhlp02 - ok
11:57:33.0984 2980 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
11:57:34.0125 2980 Sfloppy - ok
11:57:34.0296 2980 sfsync02 (6dc03269f4c71e4ab313c3597f42a340) C:\WINDOWS\system32\drivers\sfsync02.sys
11:57:34.0312 2980 sfsync02 - ok
11:57:34.0359 2980 Simbad - ok
11:57:34.0468 2980 SiSGbeXP (5f6105266cc85f05a481f740012b2e0e) C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys
11:57:34.0484 2980 SiSGbeXP - ok
11:57:34.0531 2980 Sparrow - ok
11:57:34.0578 2980 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:57:34.0687 2980 splitter - ok
11:57:34.0765 2980 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\WINDOWS\system32\Drivers\sptd.sys
11:57:34.0765 2980 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9
11:57:34.0781 2980 sptd ( LockedFile.Multi.Generic ) - warning
11:57:34.0781 2980 sptd - detected LockedFile.Multi.Generic (1)
11:57:34.0796 2980 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
11:57:34.0921 2980 sr - ok
11:57:34.0984 2980 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
11:57:35.0031 2980 Srv - ok
11:57:35.0093 2980 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:57:35.0218 2980 swenum - ok
11:57:35.0250 2980 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:57:35.0375 2980 swmidi - ok
11:57:35.0390 2980 symc810 - ok
11:57:35.0406 2980 symc8xx - ok
11:57:35.0421 2980 sym_hi - ok
11:57:35.0437 2980 sym_u3 - ok
11:57:35.0468 2980 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:57:35.0593 2980 sysaudio - ok
11:57:35.0656 2980 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:57:35.0734 2980 Tcpip - ok
11:57:35.0781 2980 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:57:35.0890 2980 TDPIPE - ok
11:57:35.0921 2980 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:57:36.0046 2980 TDTCP - ok
11:57:36.0078 2980 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:57:36.0203 2980 TermDD - ok
11:57:36.0312 2980 tidnet (8044c4e4448d115f67a9fc1b67ce677f) C:\WINDOWS\system32\DRIVERS\tidnet.sys
11:57:36.0359 2980 tidnet ( UnsignedFile.Multi.Generic ) - warning
11:57:36.0359 2980 tidnet - detected UnsignedFile.Multi.Generic (1)
11:57:36.0421 2980 TosIde - ok
11:57:36.0484 2980 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:57:36.0625 2980 Udfs - ok
11:57:36.0640 2980 ultra - ok
11:57:36.0703 2980 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:57:36.0859 2980 Update - ok
11:57:36.0875 2980 upperdev - ok
11:57:36.0921 2980 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:57:37.0031 2980 usbccgp - ok
11:57:37.0093 2980 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:57:37.0203 2980 usbehci - ok
11:57:37.0250 2980 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:57:37.0375 2980 usbhub - ok
11:57:37.0406 2980 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
11:57:37.0531 2980 usbohci - ok
11:57:37.0562 2980 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:57:37.0687 2980 usbstor - ok
11:57:37.0734 2980 vdrv1000 (12ecc28400d4070d75fe115485256fde) C:\WINDOWS\system32\DRIVERS\vdrv1000.sys
11:57:37.0734 2980 vdrv1000 - ok
11:57:37.0765 2980 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
11:57:37.0875 2980 VgaSave - ok
11:57:37.0890 2980 ViaIde - ok
11:57:37.0921 2980 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
11:57:38.0046 2980 VolSnap - ok
11:57:38.0093 2980 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:57:38.0203 2980 Wanarp - ok
11:57:38.0265 2980 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
11:57:38.0296 2980 Wdf01000 - ok
11:57:38.0312 2980 WDICA - ok
11:57:38.0359 2980 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
11:57:38.0484 2980 wdmaud - ok
11:57:38.0609 2980 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:57:38.0656 2980 WudfPf - ok
11:57:38.0937 2980 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:57:38.0968 2980 WudfRd - ok
11:57:39.0140 2980 XDva285 - ok
11:57:39.0234 2980 ZD1211BU(TP-LINK) (d125e1445bb9dc951c250d4192e70841) C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys
11:57:39.0281 2980 ZD1211BU(TP-LINK) ( UnsignedFile.Multi.Generic ) - warning
11:57:39.0281 2980 ZD1211BU(TP-LINK) - detected UnsignedFile.Multi.Generic (1)
11:57:39.0375 2980 ZDPSp50 (00ae175b903d45ed4a62384d3315dc2a) C:\WINDOWS\system32\Drivers\ZDPSp50.sys
11:57:39.0390 2980 ZDPSp50 ( UnsignedFile.Multi.Generic ) - warning
11:57:39.0390 2980 ZDPSp50 - detected UnsignedFile.Multi.Generic (1)
11:57:39.0437 2980 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
11:57:39.0578 2980 \Device\Harddisk0\DR0 - ok
11:57:39.0593 2980 Boot (0x1200) (7419a5bfe754d8b31401234ccd7ce48c) \Device\Harddisk0\DR0\Partition0
11:57:39.0593 2980 \Device\Harddisk0\DR0\Partition0 - ok
11:57:39.0593 2980 ============================================================
11:57:39.0593 2980 Scan finished
11:57:39.0593 2980 ============================================================
11:57:39.0718 2844 Detected object count: 10
11:57:39.0718 2844 Actual detected object count: 10
11:58:06.0359 2844 BRGSp50 ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0359 2844 BRGSp50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0359 2844 FStarForce ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0359 2844 FStarForce ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0359 2844 HH10Help.sys ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0359 2844 HH10Help.sys ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0359 2844 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0359 2844 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0375 2844 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0375 2844 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0375 2844 prodrv04 ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0375 2844 prodrv04 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0375 2844 sptd ( LockedFile.Multi.Generic ) - skipped by user
11:58:06.0375 2844 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
11:58:06.0375 2844 tidnet ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0375 2844 tidnet ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0375 2844 ZD1211BU(TP-LINK) ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0375 2844 ZD1211BU(TP-LINK) ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:06.0390 2844 ZDPSp50 ( UnsignedFile.Multi.Generic ) - skipped by user
11:58:06.0390 2844 ZDPSp50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:58:08.0796 1316 Deinitialize success


----------------------------------------------------------------------------------
ComboFix 11-09-30.05 - kurva uz 01.10.2011 11:32:58.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1611 [GMT 2:00]
Spuštěný z: c:\zumpa\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\WINDOWS
c:\program files\filesubmit
c:\program files\filesubmit\fallenangelscreen\fallenangelscreen.zip
c:\program files\filesubmit\Lost In Reefs.lnk
C:\Thumbs.db
c:\windows\IsUn0405.exe
c:\windows\iun6002.exe
c:\windows\system32\bgspmnt.dll.delme
c:\windows\system32\BReWErS.dll
c:\windows\system32\ccrpTmr6.dll
c:\windows\system32\d3d9caps.dat
c:\windows\system32\UNWISE.EXE
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SSHNAS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-01 do 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 08:13 . 2011-10-01 08:13 -------- d-----w- c:\program files\trend micro
2011-10-01 08:13 . 2011-10-01 08:13 -------- d-----w- C:\rsit
2011-10-01 07:13 . 2011-10-01 07:13 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\Malwarebytes
2011-10-01 07:12 . 2011-10-01 07:12 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2011-10-01 07:12 . 2011-10-01 07:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-01 07:12 . 2011-08-31 15:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-30 19:21 . 2011-09-30 19:21 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\runic games
2011-09-30 19:15 . 2011-09-30 19:15 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\InstallShield
2011-09-30 17:47 . 2011-09-30 18:01 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\DMCache
2011-09-30 15:11 . 2011-09-30 15:12 -------- d-----w- c:\documents and settings\kurva uz\Local Settings\Data aplikací\GOGDownloader
2011-09-29 04:49 . 2011-09-29 04:49 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2011-09-29 04:48 . 2011-09-29 04:48 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Conduit
2011-09-29 04:48 . 2011-09-29 04:49 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\DVDVideoSoft
2011-09-29 04:48 . 2011-09-29 04:48 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-09-26 19:48 . 2011-09-26 19:48 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\YoudaGames
2011-09-25 21:47 . 2011-09-25 22:34 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\RescueFrenzy
2011-09-25 21:45 . 2011-09-25 21:46 -------- d-----w- c:\program files\Alawar
2011-09-21 03:10 . 2011-09-21 03:10 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\OpenOffice.org
2011-09-20 20:06 . 2011-09-27 17:27 -------- d-----w- c:\program files\Drakensang - The River of Time
2011-09-18 20:11 . 2011-09-18 20:11 -------- d-----w- c:\program files\Monte Cristo
2011-09-16 23:47 . 2011-09-16 23:47 -------- d-----w- c:\program files\Paradox Interactive
2011-09-16 22:39 . 2011-09-16 22:39 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\A2 Entertainment
2011-09-15 20:04 . 2011-09-15 20:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\FarmFrenzy_Vikings
2011-09-06 20:48 . 2011-09-06 20:48 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\Meridian93
2011-09-04 19:45 . 2011-09-04 19:45 -------- d--h--r- c:\documents and settings\kurva uz\Data aplikací\SecuROM
2011-09-04 19:28 . 2011-09-04 19:28 -------- d-----w- c:\program files\Atari
2011-09-03 14:28 . 2011-09-30 15:36 -------- d-----w- c:\documents and settings\kurva uz\Local Settings\Data aplikací\Deployment
2011-09-01 17:12 . 2011-09-01 17:12 -------- d-----w- c:\program files\Infogrames
2011-09-01 12:02 . 2011-09-01 12:02 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\NVIDIA
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-13 20:06 . 2011-09-13 20:04 924695394 ----a-w- C:\zump.zip
2011-09-09 09:12 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 20:45 . 2011-08-10 18:18 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2009-10-21 17:09 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-08-10 18:18 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:37 . 2009-10-21 17:10 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2009-10-21 17:10 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2009-10-21 17:10 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2009-10-21 17:10 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-09-06 20:36 . 2009-10-21 17:10 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-09-06 20:36 . 2009-10-21 17:10 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-06 20:33 . 2009-10-21 17:10 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-09-04 19:45 . 2010-01-15 19:06 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-08-23 15:23 . 2011-08-23 15:23 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-08-07 23:48 . 2010-05-24 19:05 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-08-07 23:48 . 2011-08-09 14:52 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-08-03 11:49 . 2011-08-29 10:18 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-08-03 11:49 . 2011-08-29 10:18 914024 ----a-w- c:\windows\system32\nvdispco32.dll
2011-08-03 11:49 . 2011-08-29 10:18 875112 ----a-w- c:\windows\system32\nvgenco32.dll
2011-08-03 11:49 . 2011-08-29 10:18 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:49 . 2011-08-29 10:18 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-03 11:49 . 2009-09-27 16:20 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-03 11:49 . 2009-09-27 16:19 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-03 11:49 . 2009-09-27 16:19 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-08-03 11:49 . 2009-09-27 16:19 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:49 . 2009-09-27 16:19 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:49 . 2009-09-27 14:12 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-08-03 11:49 . 2009-09-27 14:12 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-08-03 11:49 . 2009-09-27 14:12 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49 . 2009-09-27 14:12 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-08-03 11:49 . 2009-09-27 14:12 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-08-03 11:49 . 2009-09-27 14:12 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-03 11:49 . 2009-09-27 14:12 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-07-21 12:59 . 2011-08-07 23:43 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-07-15 13:29 . 2004-08-18 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2004-08-18 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-09-29 07:07 . 2011-08-08 22:17 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2011-01-17 14:54 175912 ----a-w- c:\program files\DVDVideoSoft\prxtbDVD0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\prxtbDVD0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\prxtbDVD0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
"NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\TP-LINK
TL-WN322G Wireless Utility.lnk - c:\program files\TP-LINK\TL-WN322G Wireless Utility\ZDWlan.exe [2011-8-7 491520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-02 17:45 87352 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^GetRight.lnk]
path=c:\documents and settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění\GetRight.lnk
backup=c:\windows\pss\GetRight.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^borisek.BORIS^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\borisek.BORIS\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^borisek.BORIS^Nabídka Start^Programy^Po spuštění^Real Desktop.lnk]
path=c:\documents and settings\borisek.BORIS\Nabídka Start\Programy\Po spuštění\Real Desktop.lnk
backup=c:\windows\pss\Real Desktop.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40 687560 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-08-03 11:49 13892200 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-08-03 11:49 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-07-05 08:08 1632360 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2011-08-08 21:54 3077528 ----a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-10-09 12:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-04-15 09:01 77824 ----a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-08-13 14:31 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 14:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-01-13 22:44 37888 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VC10SecS"=2 (0x2)
"O&O Defrag"=2 (0x2)
"npggsvc"=3 (0x3)
"LogMeIn"=2 (0x2)
"LMIMaint"=2 (0x2)
"LiveTurbineNetworkService"=3 (0x3)
"LiveTurbineMessageService"=3 (0x3)
"ICQ Service"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\overlord\\Config.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\overlord\\Overlord.exe"=
"c:\\Program Files\\Lionhead Studios Ltd\\Black & White\\CreatureIsle\\CreatureIsle.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\robin hood\\Game.exe"=
"c:\\Games\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Games\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\Monte Cristo\\CrazyFactory\\CrazyFactory.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56201:TCP"= 56201:TCP:Pando Media Booster
"56201:UDP"= 56201:UDP:Pando Media Booster
"56454:TCP"= 56454:TCP:Pando Media Booster
"56454:UDP"= 56454:UDP:Pando Media Booster
.
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [x]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-07-21 2151640]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
R3 05647685;05647685; [x]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
R3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys [2008-11-06 18432]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 24448]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 100736]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2008-10-17 131072]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2008-10-17 79104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 XDva285;XDva285;c:\windows\system32\XDva285.sys [x]
R4 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [x]
R4 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe [x]
R4 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe [x]
R4 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-02-16 3305708]
R4 VC10SecS;Virtual CD v10 Management Service;c:\program files\Virtual CD v10\System\VC10SecS.exe [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-07-21 64512]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-06 721904]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 prodrv04;Star Force copy protection driver v4;c:\windows\System32\drivers\prodrv04.sys [2011-01-11 114496]
S1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\DRIVERS\tidnet.sys [2009-09-15 19200]
S1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys [2009-11-09 183832]
S2 aswFsBlk;aswFsBlk; [x]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S3 FStarForce;FStarForce;c:\windows\system32\DRIVERS\FStarForce.sys [2009-04-08 8704]
S3 ZD1211BU(TP-LINK);TL-WN322G Wireless USB Adapter Driver(TP-LINK);c:\windows\system32\DRIVERS\zd1211Bu.sys [2007-06-25 500736]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.sweetim.com/uninstallim.asp?simappi ... 138F407D88}
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 10.0.0.1 192.168.1.1
FF - ProfilePath - c:\documents and settings\kurva uz\Data aplikací\Mozilla\Firefox\Profiles\z6x4p65v.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
BHO-{EEE6C35C-6118-11DC-9C72-001320C79847} - (no file)
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
Toolbar-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - (no file)
SafeBoot-Wdf01000.sys
MSConfigStartUp-bgsmsnd - c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe
MSConfigStartUp-BMIMZMHMFM - c:\docume~1\BORISE~1.BOR\LOCALS~1\Temp\Yhx.exe
MSConfigStartUp-ICQ - c:\program files\ICQ7.1\ICQ.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-LogMeIn GUI - c:\program files\LogMeIn\x86\LogMeInSystray.exe
MSConfigStartUp-MP4 Player - c:\program files\MP4 Player\mp4Player.exe
MSConfigStartUp-OODefragTray - c:\windows\system32\oodtray.exe
MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
MSConfigStartUp-Real Desktop - c:\program files\Real Desktop\Real Desktop.exe
MSConfigStartUp-SearchSettings - c:\program files\YouTube Downloader Toolbar\SearchSettings.exe
MSConfigStartUp-Seznam Postak - c:\program files\Seznam.cz\postak.exe
MSConfigStartUp-Software Informer - c:\program files\Software Informer\softinfo.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSConfigStartUp-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
MSConfigStartUp-Turbine Download Manager Tray Icon - c:\program files\Turbine\Turbine Download Manager\TurbineDownloadManagerIcon.exe
MSConfigStartUp-VC10Player - c:\program files\Virtual CD v10\System\VC10Play.exe
AddRemove-Divinity II - Ego Draconis_is1 - c:\program files\Divinity II - Ego Draconis\unins000.exe
AddRemove-Hardlock Device Drivers - c:\windows\system32\UNWISE.EXE
AddRemove-X-treme King Air B200v.2.0.1 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 11:48
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5b,fd,d3,28,67,01,f8,4b,b8,d3,ba,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5b,fd,d3,28,67,01,f8,4b,b8,d3,ba,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="82D29EEE6E38F91718D1D4CB875C41291DC4087E4AD699288AA769F6CCA15D114B4907A583AC65773C1CCDE9D7914FB155DF1CDE50265AC253116377485A4F1B7530DA61B25BFDAA5153C53EF09AC6422A90BE30BF953242652B21ADA570211A851DF72C7A67011BB9EA801B06871D1A7E46BDA41B3CF0DAC6821AD056AC1B55C0DC1D656065D0C59F8BA6214859EC0A7BA6C9C665AB88D343D92AF051C9282B346CEE3EEB5E6F3CED10C7CAF387F3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808FEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D14078A45773D77F3D27A3C8311E72F549C596913C42B387841CBC8516D1D597DA1FAEE554801DF30A15B1D7E474620A46477E29438A0BAD755C98C753626AF6E09A86750ED8353F365414C7BB7BDF633A19E07CAF486811F90C60104C91D3AC6BEE6C5D99EC0FA5EDD89D27EF43323D181E333BA0C4CE26EACB17824D89BD019AA9AF459C41B579341B2CCCE4671E7542801D9AC4244866BD81C5ABF431CA17A28D16EF800D53A3B37E46C7927A35E932AD582AD0EA36BBFB8BEA1059FFD2F86093B4429A119CB80DDE677CD48DC706C11E246101E05DF9A62735EE6B6044EDC0F2C199C30718593C5A6C6610C92DEBFDCCC54E8D2E80A2B61B9341A85D6A91E731CA74966CF37287434488A8A9C3DF17DDF6D90BEAE6228343459993E803EF26225B9EAB30802F4E1C47C678F3A746BD9096925AC1F364D4FA91923C671DD057B8931813952DDB6FAB178D61A0B3F98CCD8B18719E326549884533938FCAE02D22C02CF4FCB95ADA2F665FCDD96ACEB238745DBB20AA582EBD4FAA160D9AA9EF015B45CFD74489B2CB68142C245A1D61F6DB58B5F067E1B16CC97E6BF241F8F50EF657306B0E74962B41ED262E3D555760929C4372DCD68DD44C4D70EDBAD12620D4324D9C9BA027F5B9E1F8F24D462D47C5A78873A04B8F634B0053262CDE18BDF93409E6ADC16B635FEDB4B1BFE7E560E19DA4FCB665D0EBC20C4CB81C6C32380AE5F2FA43C58ADF4CA7ECD4386AE8EA5C3E544630CAB41A1E8B22BE1B77CF4AA015D9A6B9C217AEFA3C603F9F4FB81D254564EE7637D24C7F62CD5161159C0BF8A592398144CAC1DBE328A7F2572ABC6D32E0B24AC303E3CC8D2058E9BA63C41DEB5BEE68C38451BE406B6F947A2F9D8DF32C9C5FCA689AC730E28A4ED378D58A69A1AF847C8B7AA754B1072DDA24D01AB6A10DF3D4475EA9C87DF9377E251D11FF190D15466EDAEDE4BD256C2097D5EFCA4946929F4E47080AC807AF904189B18EBB7D91CFC4533281A6D78207354322EF246BA5326AF56EDAF155C8B78E54BF57BD35DD77C8EE2EA87030C77038EE22EA9C4949EC7205C4887D9A015A3B118AF"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(872)
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(2644)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\RunDLL32.exe
.
**************************************************************************
.
Celkový čas: 2011-10-01 11:54:23 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-01 09:54
.
Před spuštěním: Volných bajtů: 28 179 374 080
Po spuštění: Volných bajtů: 28 615 892 992
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - A8CCDE7731AC89066EB890370B5265C3

baibarosa
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 říj 2011 08:15

Re: Prosim o kontrolu rootkin

#4 Příspěvek od baibarosa »

Spoustil jsem avast, kouknul na net a problem zda se je uz fuc.

Mam s tim jeste neco delat?

baibarosa
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 říj 2011 08:15

Re: Prosim o kontrolu rootkin

#5 Příspěvek od baibarosa »

Staci to takhle?

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\05647685]
"Type"=dword:00000001
"ErrorControl"=dword:00000001
"Start"=dword:00000003

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\05647685\Enum]
"0"="Root\\LEGACY_05647685\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001

baibarosa
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 říj 2011 08:15

Re: Prosim o kontrolu rootkin

#6 Příspěvek od baibarosa »

Ad: Krom kravin, různého balastu - vim ze PC neni v dobrem stavu. Mam ho uz dlouho a pri jednom z mnoha mych stehovani jsem prisel o klic k XPckum co byl nalepenej bedne PC. Takze to nemuzu ani zformatovat a nainstalovat znovu coz se uz asi docela hodilo :(

Jde to prosim nejakym zpusobem vycistit?

baibarosa
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 říj 2011 08:15

Re: Prosim o kontrolu rootkin

#7 Příspěvek od baibarosa »

omlouvam se, ze pisu az ted, mel jsem povinosti

ComboFix 11-09-30.05 - kurva uz 01.10.2011 16:12:47.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1605 [GMT 2:00]
Spuštěný z: c:\zumpa\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\reg.reg
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_05647685
-------\Service_05647685
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-01 do 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 08:13 . 2011-10-01 08:13 -------- d-----w- c:\program files\trend micro
2011-10-01 08:13 . 2011-10-01 08:13 -------- d-----w- C:\rsit
2011-10-01 07:13 . 2011-10-01 07:13 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\Malwarebytes
2011-10-01 07:12 . 2011-10-01 07:12 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2011-10-01 07:12 . 2011-10-01 07:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-01 07:12 . 2011-08-31 15:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-30 19:21 . 2011-09-30 19:21 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\runic games
2011-09-30 19:15 . 2011-09-30 19:15 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\InstallShield
2011-09-30 17:47 . 2011-09-30 18:01 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\DMCache
2011-09-30 15:11 . 2011-09-30 15:12 -------- d-----w- c:\documents and settings\kurva uz\Local Settings\Data aplikací\GOGDownloader
2011-09-29 04:49 . 2011-09-29 04:49 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2011-09-29 04:48 . 2011-09-29 04:48 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Conduit
2011-09-29 04:48 . 2011-09-29 04:49 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\DVDVideoSoft
2011-09-29 04:48 . 2011-09-29 04:48 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-09-26 19:48 . 2011-09-26 19:48 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\YoudaGames
2011-09-25 21:47 . 2011-09-25 22:34 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\RescueFrenzy
2011-09-25 21:45 . 2011-09-25 21:46 -------- d-----w- c:\program files\Alawar
2011-09-21 03:10 . 2011-09-21 03:10 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\OpenOffice.org
2011-09-20 20:06 . 2011-09-27 17:27 -------- d-----w- c:\program files\Drakensang - The River of Time
2011-09-18 20:11 . 2011-09-18 20:11 -------- d-----w- c:\program files\Monte Cristo
2011-09-16 23:47 . 2011-09-16 23:47 -------- d-----w- c:\program files\Paradox Interactive
2011-09-16 22:39 . 2011-09-16 22:39 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\A2 Entertainment
2011-09-15 20:04 . 2011-09-15 20:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\FarmFrenzy_Vikings
2011-09-06 20:48 . 2011-09-06 20:48 -------- d-----w- c:\documents and settings\kurva uz\Data aplikací\Meridian93
2011-09-04 19:45 . 2011-09-04 19:45 -------- d--h--r- c:\documents and settings\kurva uz\Data aplikací\SecuROM
2011-09-04 19:28 . 2011-09-04 19:28 -------- d-----w- c:\program files\Atari
2011-09-03 14:28 . 2011-09-30 15:36 -------- d-----w- c:\documents and settings\kurva uz\Local Settings\Data aplikací\Deployment
2011-09-01 17:12 . 2011-09-01 17:12 -------- d-----w- c:\program files\Infogrames
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-13 20:06 . 2011-09-13 20:04 924695394 ----a-w- C:\zump.zip
2011-09-09 09:12 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 20:45 . 2011-08-10 18:18 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2009-10-21 17:09 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-08-10 18:18 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:37 . 2009-10-21 17:10 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2009-10-21 17:10 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2009-10-21 17:10 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2009-10-21 17:10 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-09-06 20:36 . 2009-10-21 17:10 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-09-06 20:36 . 2009-10-21 17:10 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-06 20:33 . 2009-10-21 17:10 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-09-04 19:45 . 2010-01-15 19:06 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-08-23 15:23 . 2011-08-23 15:23 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-08-07 23:48 . 2010-05-24 19:05 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-08-07 23:48 . 2011-08-09 14:52 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-08-03 11:49 . 2011-08-29 10:18 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-08-03 11:49 . 2011-08-29 10:18 914024 ----a-w- c:\windows\system32\nvdispco32.dll
2011-08-03 11:49 . 2011-08-29 10:18 875112 ----a-w- c:\windows\system32\nvgenco32.dll
2011-08-03 11:49 . 2011-08-29 10:18 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:49 . 2011-08-29 10:18 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-03 11:49 . 2009-09-27 16:20 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-03 11:49 . 2009-09-27 16:19 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-03 11:49 . 2009-09-27 16:19 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-08-03 11:49 . 2009-09-27 16:19 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:49 . 2009-09-27 16:19 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:49 . 2009-09-27 14:12 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-08-03 11:49 . 2009-09-27 14:12 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-08-03 11:49 . 2009-09-27 14:12 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49 . 2009-09-27 14:12 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-08-03 11:49 . 2009-09-27 14:12 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-08-03 11:49 . 2009-09-27 14:12 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-03 11:49 . 2009-09-27 14:12 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-07-21 12:59 . 2011-08-07 23:43 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-07-15 13:29 . 2004-08-18 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2004-08-18 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-09-29 07:07 . 2011-08-08 22:17 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-01_09.48.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-01 14:27 . 2011-10-01 14:27 16384 c:\windows\Temp\Perflib_Perfdata_25c.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2011-01-17 14:54 175912 ----a-w- c:\program files\DVDVideoSoft\prxtbDVD0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\prxtbDVD0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\prxtbDVD0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
"NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\TP-LINK
TL-WN322G Wireless Utility.lnk - c:\program files\TP-LINK\TL-WN322G Wireless Utility\ZDWlan.exe [2011-8-7 491520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-02 17:45 87352 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^GetRight.lnk]
path=c:\documents and settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění\GetRight.lnk
backup=c:\windows\pss\GetRight.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^borisek.BORIS^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\borisek.BORIS\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^borisek.BORIS^Nabídka Start^Programy^Po spuštění^Real Desktop.lnk]
path=c:\documents and settings\borisek.BORIS\Nabídka Start\Programy\Po spuštění\Real Desktop.lnk
backup=c:\windows\pss\Real Desktop.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40 687560 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-08-03 11:49 13892200 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-08-03 11:49 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-07-05 08:08 1632360 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2011-08-08 21:54 3077528 ----a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-10-09 12:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-04-15 09:01 77824 ----a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-08-13 14:31 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 14:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-01-13 22:44 37888 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VC10SecS"=2 (0x2)
"O&O Defrag"=2 (0x2)
"npggsvc"=3 (0x3)
"LogMeIn"=2 (0x2)
"LMIMaint"=2 (0x2)
"LiveTurbineNetworkService"=3 (0x3)
"LiveTurbineMessageService"=3 (0x3)
"ICQ Service"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\overlord\\Config.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\overlord\\Overlord.exe"=
"c:\\Program Files\\Lionhead Studios Ltd\\Black & White\\CreatureIsle\\CreatureIsle.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\robin hood\\Game.exe"=
"c:\\Games\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Games\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\Monte Cristo\\CrazyFactory\\CrazyFactory.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56201:TCP"= 56201:TCP:Pando Media Booster
"56201:UDP"= 56201:UDP:Pando Media Booster
"56454:TCP"= 56454:TCP:Pando Media Booster
"56454:UDP"= 56454:UDP:Pando Media Booster
.
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [x]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-07-21 2151640]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
R3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys [2008-11-06 18432]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 24448]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 100736]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2008-10-17 131072]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2008-10-17 79104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 XDva285;XDva285;c:\windows\system32\XDva285.sys [x]
R4 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [x]
R4 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe [x]
R4 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe [x]
R4 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-02-16 3305708]
R4 VC10SecS;Virtual CD v10 Management Service;c:\program files\Virtual CD v10\System\VC10SecS.exe [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-07-21 64512]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-06 721904]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 prodrv04;Star Force copy protection driver v4;c:\windows\System32\drivers\prodrv04.sys [2011-01-11 114496]
S1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\DRIVERS\tidnet.sys [2009-09-15 19200]
S1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys [2009-11-09 183832]
S2 aswFsBlk;aswFsBlk; [x]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S3 FStarForce;FStarForce;c:\windows\system32\DRIVERS\FStarForce.sys [2009-04-08 8704]
S3 ZD1211BU(TP-LINK);TL-WN322G Wireless USB Adapter Driver(TP-LINK);c:\windows\system32\DRIVERS\zd1211Bu.sys [2007-06-25 500736]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.sweetim.com/uninstallim.asp?simappi ... 138F407D88}
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 10.0.0.1 192.168.1.1
FF - ProfilePath - c:\documents and settings\kurva uz\Data aplikací\Mozilla\Firefox\Profiles\z6x4p65v.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 16:28
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5b,fd,d3,28,67,01,f8,4b,b8,d3,ba,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5b,fd,d3,28,67,01,f8,4b,b8,d3,ba,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="82D29EEE6E38F91718D1D4CB875C41291DC4087E4AD699288AA769F6CCA15D114B4907A583AC65773C1CCDE9D7914FB155DF1CDE50265AC253116377485A4F1B7530DA61B25BFDAA5153C53EF09AC6422A90BE30BF953242652B21ADA570211A851DF72C7A67011BB9EA801B06871D1A7E46BDA41B3CF0DAC6821AD056AC1B55C0DC1D656065D0C59F8BA6214859EC0A7BA6C9C665AB88D343D92AF051C9282B346CEE3EEB5E6F3CED10C7CAF387F3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808FEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D14078A45773D77F3D27A3C8311E72F549C596913C42B387841CBC8516D1D597DA1FAEE554801DF30A15B1D7E474620A46477E29438A0BAD755C98C753626AF6E09A86750ED8353F365414C7BB7BDF633A19E07CAF486811F90C60104C91D3AC6BEE6C5D99EC0FA5EDD89D27EF43323D181E333BA0C4CE26EACB17824D89BD019AA9AF459C41B579341B2CCCE4671E7542801D9AC4244866BD81C5ABF431CA17A28D16EF800D53A3B37E46C7927A35E932AD582AD0EA36BBFB8BEA1059FFD2F86093B4429A119CB80DDE677CD48DC706C11E246101E05DF9A62735EE6B6044EDC0F2C199C30718593C5A6C6610C92DEBFDCCC54E8D2E80A2B61B9341A85D6A91E731CA74966CF37287434488A8A9C3DF17DDF6D90BEAE6228343459993E803EF26225B9EAB30802F4E1C47C678F3A746BD9096925AC1F364D4FA91923C671DD057B8931813952DDB6FAB178D61A0B3F98CCD8B18719E326549884533938FCAE02D22C02CF4FCB95ADA2F665FCDD96ACEB238745DBB20AA582EBD4FAA160D9AA9EF015B45CFD74489B2CB68142C245A1D61F6DB58B5F067E1B16CC97E6BF241F8F50EF657306B0E74962B41ED262E3D555760929C4372DCD68DD44C4D70EDBAD12620D4324D9C9BA027F5B9E1F8F24D462D47C5A78873A04B8F634B0053262CDE18BDF93409E6ADC16B635FEDB4B1BFE7E560E19DA4FCB665D0EBC20C4CB81C6C32380AE5F2FA43C58ADF4CA7ECD4386AE8EA5C3E544630CAB41A1E8B22BE1B77CF4AA015D9A6B9C217AEFA3C603F9F4FB81D254564EE7637D24C7F62CD5161159C0BF8A592398144CAC1DBE328A7F2572ABC6D32E0B24AC303E3CC8D2058E9BA63C41DEB5BEE68C38451BE406B6F947A2F9D8DF32C9C5FCA689AC730E28A4ED378D58A69A1AF847C8B7AA754B1072DDA24D01AB6A10DF3D4475EA9C87DF9377E251D11FF190D15466EDAEDE4BD256C2097D5EFCA4946929F4E47080AC807AF904189B18EBB7D91CFC4533281A6D78207354322EF246BA5326AF56EDAF155C8B78E54BF57BD35DD77C8EE2EA87030C77038EE22EA9C4949EC7205C4887D9A015A3B118AF"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(872)
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(764)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\RunDLL32.exe
.
**************************************************************************
.
Celkový čas: 2011-10-01 16:33:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-01 14:33
ComboFix2.txt 2011-10-01 09:54
.
Před spuštěním: Volných bajtů: 28 620 267 520
Po spuštění: Volných bajtů: 28 604 518 400
.
- - End Of File - - 4640146744F79769E2934DECD7C83BAC

Odpovědět