UFA.exe - facebook vir
Napsal: 17 lis 2011 16:50
Zdravím, známý chytl tohle svinstvo a žádám někoho o pomoc.
Děkuji.
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Hráč [Admin rights]
Mode: Remove -- Date : 11/17/2011 16:37:43
¤¤¤ Bad processes: 13 ¤¤¤
[SUSP PATH] StopHid.exe -- F:\WINDOWS\StopHid.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- F:\WINDOWS\update.tray-3-0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- F:\WINDOWS\sysdriver32.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32_.exe -- F:\WINDOWS\sysdriver32_.exe -> KILLED [TermProc]
[SUSP PATH] l1rezerv.exe -- F:\WINDOWS\l1rezerv.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- F:\WINDOWS\update.3\svchost.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- F:\WINDOWS\update.5.0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- F:\WINDOWS\update.5.0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- F:\WINDOWS\sysdriver32.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- F:\WINDOWS\update.1\svchost.exe -> KILLED [TermProc]
[SERVICE] srvbtcclient -- F:\WINDOWS\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- F:\WINDOWS\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- F:\WINDOWS\update.1\svchost.exe srv -> STOPPED
¤¤¤ Registry Entries: 93 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Uotkte (F:\Documents and Settings\Hráč\Data aplikací\Uotkte.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Run : Omtkty (F:\Documents and Settings\Hráč\Data aplikací\Omtkty.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : DXM6Patch_981116 (F:\WINDOWS\p_981116.exe /Q:A) -> DELETED
[SUSP PATH] HKLM\[...]\Run : wxpdrv (F:\WINDOWS\services32.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico0 (F:\WINDOWS\update.tray-3-0\svchost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9501776.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\9501776.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("F:\WINDOWS\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("F:\WINDOWS\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3308440.exe ("F:\WINDOWS\TEMP\3308440.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1067014.exe ("F:\WINDOWS\TEMP\1067014.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3659457-loader2.exe ("F:\WINDOWS\TEMP\3659457-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("F:\WINDOWS\l1rezerv.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : systemup ("F:\WINDOWS\systemup.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 23756631-loader2.exe ("F:\WINDOWS\TEMP\23756631-loader2.exe") -> DELETED
[HJ NAME] HKLM\[...]\Run : w_distrib.exe ("F:\WINDOWS\update.3\svchost.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 79154369-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\79154369-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 68521600-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\68521600-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 54711977-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\54711977-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 85800985-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\85800985-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 62985480-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\62985480-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 43057816-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\43057816-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 64868765-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\64868765-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 88942682-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\88942682-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 64500453-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\64500453-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 58769685-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\58769685-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 29061953-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\29061953-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 84434504-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\84434504-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 69118419-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\69118419-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 14554222-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\14554222-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1836417-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\1836417-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1931953-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\1931953-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 44238365-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\44238365-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 63677580-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\63677580-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 40731808-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\40731808-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 80558824-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\80558824-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 61010374-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\61010374-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 87330591-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\87330591-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 92304847-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\92304847-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 36439857-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\36439857-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 66984320-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\66984320-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 57437761-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\57437761-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 79430081-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\79430081-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 67147326-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\67147326-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 62296996-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\62296996-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 18555611-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\18555611-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 20342660-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\20342660-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 10981127-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\10981127-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9196429-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\9196429-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 47822081-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\47822081-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 56577796-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\56577796-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 86660935-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\86660935-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 95563721-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\95563721-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 89302941-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\89302941-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4198798-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\4198798-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 36386879-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\36386879-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 32797927-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\32797927-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 15763892-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\15763892-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 18221591-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\18221591-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 22888279-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\22888279-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 55705160-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\55705160-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 38802445-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\38802445-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 69166817-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\69166817-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 38345915-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\38345915-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 70938846-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\70938846-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 45583511-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\45583511-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 62319116-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\62319116-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 43347497-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\43347497-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 19541427-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\19541427-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 55413196-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\55413196-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 55579100-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\55579100-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3402587-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\3402587-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 26178157-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\26178157-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 14939848-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\14939848-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 24863444-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\24863444-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 45774143-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\45774143-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3178519-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\3178519-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4536381-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\4536381-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 76729140-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\76729140-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 95691310-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\95691310-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 21645040-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\21645040-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 65911145-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\65911145-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 17095023-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\17095023-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 35104330-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\35104330-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 7339468.exe ("F:\WINDOWS\TEMP\7339468.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : Microsoft Config Setup (F:\WINDOWS\jodrive32.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : Microsoft Driver Setup (F:\WINDOWS\aadrive32.exe) -> DELETED
[SUSP PATH] Updater.job : F:\Documents and Settings\All Users\Data aplikací\WombatUpdater\WombatUpdater.exe -> ERROR
[HJ] HKCU\[...]\Internet Settings : WarnOnHTTPSToHTTPRedirect (0) -> REPLACED (1)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[241] : NtSetSystemPowerState @ 0x80665527 -> HOOKED (vax347b.sys @ 0xF748B450)
SSDT[177] : NtQueryValueKey @ 0x8056B0BB -> HOOKED (vax347b.sys @ 0xF748BC06)
SSDT[160] : NtQueryKey @ 0x8056EB71 -> HOOKED (vax347b.sys @ 0xF748051E)
SSDT[119] : NtOpenKey @ 0x80567AFB -> HOOKED (vax347b.sys @ 0xF748BB34)
SSDT[73] : NtEnumerateValueKey @ 0x8057EB28 -> HOOKED (vax347b.sys @ 0xF748BCB0)
SSDT[71] : NtEnumerateKey @ 0x8056EE68 -> HOOKED (vax347b.sys @ 0xF74804FE)
SSDT[45] : NtCreatePagingFile @ 0x805B77B8 -> HOOKED (vax347b.sys @ 0xF747FC70)
SSDT[41] : NtCreateKey @ 0x8056E761 -> HOOKED (vax347b.sys @ 0xF748BB70)
SSDT[25] : NtClose @ 0x80566B49 -> HOOKED (vax347b.sys @ 0xF748BBB8)
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Hráč [Admin rights]
Mode: HOSTSFix -- Date : 11/17/2011 16:38:42
¤¤¤ Bad processes: 4 ¤¤¤
[SUSP PATH] HKNTDLL.dll -- F:\WINDOWS\HKNTDLL.dll -> UNLOADED
[SERVICE] srvbtcclient -- F:\WINDOWS\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- F:\WINDOWS\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- F:\WINDOWS\update.1\svchost.exe srv -> STOPPED
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Hráč [Admin rights]
Mode: ProxyFix -- Date : 11/17/2011 16:40:20
¤¤¤ Bad processes: 3 ¤¤¤
[SERVICE] srvbtcclient -- F:\WINDOWS\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- F:\WINDOWS\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- F:\WINDOWS\update.1\svchost.exe srv -> STOPPED
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Děkuji.
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Hráč [Admin rights]
Mode: Remove -- Date : 11/17/2011 16:37:43
¤¤¤ Bad processes: 13 ¤¤¤
[SUSP PATH] StopHid.exe -- F:\WINDOWS\StopHid.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- F:\WINDOWS\update.tray-3-0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- F:\WINDOWS\sysdriver32.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32_.exe -- F:\WINDOWS\sysdriver32_.exe -> KILLED [TermProc]
[SUSP PATH] l1rezerv.exe -- F:\WINDOWS\l1rezerv.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- F:\WINDOWS\update.3\svchost.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- F:\WINDOWS\update.5.0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- F:\WINDOWS\update.5.0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- F:\WINDOWS\sysdriver32.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- F:\WINDOWS\update.1\svchost.exe -> KILLED [TermProc]
[SERVICE] srvbtcclient -- F:\WINDOWS\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- F:\WINDOWS\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- F:\WINDOWS\update.1\svchost.exe srv -> STOPPED
¤¤¤ Registry Entries: 93 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Uotkte (F:\Documents and Settings\Hráč\Data aplikací\Uotkte.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Run : Omtkty (F:\Documents and Settings\Hráč\Data aplikací\Omtkty.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : DXM6Patch_981116 (F:\WINDOWS\p_981116.exe /Q:A) -> DELETED
[SUSP PATH] HKLM\[...]\Run : wxpdrv (F:\WINDOWS\services32.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico0 (F:\WINDOWS\update.tray-3-0\svchost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9501776.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\9501776.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("F:\WINDOWS\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("F:\WINDOWS\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3308440.exe ("F:\WINDOWS\TEMP\3308440.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1067014.exe ("F:\WINDOWS\TEMP\1067014.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3659457-loader2.exe ("F:\WINDOWS\TEMP\3659457-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("F:\WINDOWS\l1rezerv.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : systemup ("F:\WINDOWS\systemup.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 23756631-loader2.exe ("F:\WINDOWS\TEMP\23756631-loader2.exe") -> DELETED
[HJ NAME] HKLM\[...]\Run : w_distrib.exe ("F:\WINDOWS\update.3\svchost.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 79154369-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\79154369-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 68521600-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\68521600-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 54711977-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\54711977-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 85800985-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\85800985-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 62985480-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\62985480-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 43057816-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\43057816-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 64868765-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\64868765-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 88942682-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\88942682-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 64500453-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\64500453-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 58769685-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\58769685-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 29061953-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\29061953-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 84434504-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\84434504-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 69118419-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\69118419-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 14554222-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\14554222-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1836417-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\1836417-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1931953-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\1931953-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 44238365-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\44238365-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 63677580-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\63677580-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 40731808-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\40731808-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 80558824-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\80558824-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 61010374-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\61010374-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 87330591-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\87330591-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 92304847-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\92304847-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 36439857-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\36439857-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 66984320-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\66984320-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 57437761-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\57437761-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 79430081-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\79430081-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 67147326-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\67147326-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 62296996-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\62296996-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 18555611-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\18555611-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 20342660-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\20342660-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 10981127-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\10981127-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9196429-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\9196429-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 47822081-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\47822081-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 56577796-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\56577796-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 86660935-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\86660935-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 95563721-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\95563721-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 89302941-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\89302941-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4198798-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\4198798-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 36386879-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\36386879-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 32797927-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\32797927-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 15763892-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\15763892-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 18221591-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\18221591-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 22888279-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\22888279-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 55705160-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\55705160-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 38802445-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\38802445-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 69166817-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\69166817-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 38345915-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\38345915-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 70938846-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\70938846-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 45583511-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\45583511-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 62319116-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\62319116-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 43347497-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\43347497-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 19541427-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\19541427-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 55413196-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\55413196-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 55579100-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\55579100-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3402587-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\3402587-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 26178157-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\26178157-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 14939848-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\14939848-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 24863444-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\24863444-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 45774143-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\45774143-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3178519-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\3178519-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4536381-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\4536381-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 76729140-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\76729140-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 95691310-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\95691310-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 21645040-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\21645040-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 65911145-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\65911145-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 17095023-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\17095023-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 35104330-loader2.exe ("F:\DOCUME~1\HR6460~1\LOCALS~1\Temp\35104330-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 7339468.exe ("F:\WINDOWS\TEMP\7339468.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : Microsoft Config Setup (F:\WINDOWS\jodrive32.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : Microsoft Driver Setup (F:\WINDOWS\aadrive32.exe) -> DELETED
[SUSP PATH] Updater.job : F:\Documents and Settings\All Users\Data aplikací\WombatUpdater\WombatUpdater.exe -> ERROR
[HJ] HKCU\[...]\Internet Settings : WarnOnHTTPSToHTTPRedirect (0) -> REPLACED (1)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[241] : NtSetSystemPowerState @ 0x80665527 -> HOOKED (vax347b.sys @ 0xF748B450)
SSDT[177] : NtQueryValueKey @ 0x8056B0BB -> HOOKED (vax347b.sys @ 0xF748BC06)
SSDT[160] : NtQueryKey @ 0x8056EB71 -> HOOKED (vax347b.sys @ 0xF748051E)
SSDT[119] : NtOpenKey @ 0x80567AFB -> HOOKED (vax347b.sys @ 0xF748BB34)
SSDT[73] : NtEnumerateValueKey @ 0x8057EB28 -> HOOKED (vax347b.sys @ 0xF748BCB0)
SSDT[71] : NtEnumerateKey @ 0x8056EE68 -> HOOKED (vax347b.sys @ 0xF74804FE)
SSDT[45] : NtCreatePagingFile @ 0x805B77B8 -> HOOKED (vax347b.sys @ 0xF747FC70)
SSDT[41] : NtCreateKey @ 0x8056E761 -> HOOKED (vax347b.sys @ 0xF748BB70)
SSDT[25] : NtClose @ 0x80566B49 -> HOOKED (vax347b.sys @ 0xF748BBB8)
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Hráč [Admin rights]
Mode: HOSTSFix -- Date : 11/17/2011 16:38:42
¤¤¤ Bad processes: 4 ¤¤¤
[SUSP PATH] HKNTDLL.dll -- F:\WINDOWS\HKNTDLL.dll -> UNLOADED
[SERVICE] srvbtcclient -- F:\WINDOWS\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- F:\WINDOWS\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- F:\WINDOWS\update.1\svchost.exe srv -> STOPPED
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Hráč [Admin rights]
Mode: ProxyFix -- Date : 11/17/2011 16:40:20
¤¤¤ Bad processes: 3 ¤¤¤
[SERVICE] srvbtcclient -- F:\WINDOWS\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- F:\WINDOWS\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- F:\WINDOWS\update.1\svchost.exe srv -> STOPPED
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt