Stránka 1 z 10

Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 17 lis 2011 17:59
od chris.h
Prosím o pomoc, vůbec si s tímto virem nevím rady. Našel mi ho NOD 32. Hlásí mi:

Operační paměť » services.exe(1600) - varianta infiltrace Win32/Rootkit.Agent.NUS trojský kůň - nelze léčit

Od té doby, co ho antivirový program našel mi vyskakují samá okna, kde musím všechno odblokovat a neustále mi přibývají v PC další viry, které sice program vyléčí, ale znovu se objevují další. A to jsem dříve na notebooku s viry problémy nemívala.
Děkuji za případnou pomoc :)

Zde uvádím log z RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by OEM at 2011-11-17 17:38:57
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 15 GB (10%) free of 148 GB
Total RAM: 1014 MB (34% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
C:\WINDOWS\tasks\PMTask.job
C:\WINDOWS\tasks\Připomenutí registrace 1.job
C:\WINDOWS\tasks\Připomenutí registrace 2.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\SmartDefrag_Startup.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\OEM\Data aplikací\Mozilla\Firefox\Profiles\6jts2rqn.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "extensions.enabledItems" - "{3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872, smartwebprinting@hp.com:4.5, {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, jqs@sun.com:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... ^YY^CZ&&q="

"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1]
"Description"=Yahoo! activeX Plug-in Bridge
"Path"=C:\Program Files\Yahoo!\Common\npyaxmpb.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll
npqtplugin.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml

C:\Documents and Settings\OEM\Data aplikací\Mozilla\Firefox\Profiles\6jts2rqn.default\extensions\
toolbar@ask.com

C:\Documents and Settings\OEM\Data aplikací\Mozilla\Firefox\Profiles\6jts2rqn.default\searchplugins\
askcom.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F}]
IObit Toolbar - C:\Program Files\IObit Toolbar\IE\4.7\iobitToolbarIE.dll [2011-09-27 1050464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
MHTBPos00 Class - C:\Program Files\Family Toolbar\tbcore3.dll [2009-05-07 2642432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-09-28 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-17 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-03-17 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-10-14 863688]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-09-28 520192]
{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - Family Toolbar - C:\Program Files\Family Toolbar\tbcore3.dll [2009-05-07 2642432]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]
{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - IObit Toolbar - C:\Program Files\IObit Toolbar\IE\4.7\iobitToolbarIE.dll [2011-09-27 1050464]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor []
"BLOG"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog []
"TPFNF7"=C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe [2007-04-09 58416]
"TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2007-03-09 66176]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-03-05 172032]
"TpShocks"=C:\WINDOWS\system32\TpShocks.exe [2007-03-29 181808]
"EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2007-03-28 243248]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-02-26 131072]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-02-26 155648]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-02-26 131072]
"TVT Scheduler Proxy"=C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2007-02-08 536576]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"ISUSPM Startup"=C:\Program Files\Common Files\Installshield\UpdateService\isuspm.exe [2005-08-11 249856]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-08-11 81920]
"AwaySch"=C:\Program Files\Lenovo\AwayTask\AwaySch.EXE [2006-11-07 91688]
"LPManager"=C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe [2007-03-22 120368]
"AMSG"=C:\Program Files\ThinkVantage\AMSG\Amsg.exe [2007-02-01 419376]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2011-08-23 887976]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-08 3076144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.894 []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-12-23 143360]
"Advanced SystemCare 4"=C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe [2011-08-09 417112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray]
C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe [2009-02-27 278016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2009-01-14 113680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ6.5\ICQ.exe silent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
C:\Program Files\PDF24\pdf24.exe [2011-04-28 220552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\Digital Imaging\bin\hpqtra08.exe [2009-05-21 275768]

C:\Documents and Settings\OEM\Nabídka Start\Programy\Po spuštění
AccuWeather.lnk - C:\Documents and Settings\OEM\Dokumenty\AccuWeather.com Stratus\AccuWeather.com Stratus.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-02-26 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\WINDOWS\system32\psqlpwd.dll [2007-03-14 89600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
C:\Program Files\Lenovo\HOTKEY\notifyf2.dll [2006-09-06 34344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
C:\Program Files\Lenovo\HOTKEY\tphklock.dll [2006-12-14 28672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Trackmania Sunrise Extreme\TmSunrise.exe"="D:\Trackmania Sunrise Extreme\TmSunrise.exe:*:Enabled:TmSunrise"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe"="C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\HPWUCli.exe"="C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\CulinatiX\SQL Anywhere 7\win32\rteng7.exe"="C:\Program Files\CulinatiX\SQL Anywhere 7\win32\rteng7.exe:*:Enabled:Adaptive Server Anywhere Database Engine"
"C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe"="C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe:*:Disabled:Adobe AIR Installer"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe"="C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe:*:Enabled:Advanced SystemCare 4"
"C:\Program Files\IObit\Advanced SystemCare 4\AutoUpdate.exe"="C:\Program Files\IObit\Advanced SystemCare 4\AutoUpdate.exe:*:Enabled:Advanced SystemCare Updater"
"C:\Documents and Settings\OEM\Dokumenty\AccuWeather.com Stratus\AccuWeather.com Stratus.exe"="C:\Documents and Settings\OEM\Dokumenty\AccuWeather.com Stratus\AccuWeather.com Stratus.exe:*:Enabled:AccuWeather.com Stratus"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Průzkumník Windows"
"C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"="C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe:*:Enabled:Search Settings"
"C:\WINDOWS\system32\msiexec.exe"="C:\WINDOWS\system32\msiexec.exe:*:Enabled:Windows® installer"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS54.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS54.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\All Users\Data aplikací\MFAData\SelfUpd\avgmfapx.exe"="C:\Documents and Settings\All Users\Data aplikací\MFAData\SelfUpd\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS8D.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS8D.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS1.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS1.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zS2.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zS2.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Local Settings\Temp\7zSA.tmp\avgmfapx.exe"="C:\Documents and Settings\OEM\Local Settings\Temp\7zSA.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application"
"C:\Documents and Settings\OEM\Dokumenty\Stažené soubory\RSIT.exe"="C:\Documents and Settings\OEM\Dokumenty\Stažené soubory\RSIT.exe:*:Enabled:RSIT"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe"="C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\HPWUCli.exe"="C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 3 months======

2011-11-17 17:38:58 ----D---- C:\Program Files\trend micro
2011-11-17 17:38:57 ----D---- C:\rsit
2011-11-17 15:59:01 ----D---- C:\Documents and Settings\OEM\Data aplikací\AVI ReComp
2011-11-17 15:58:41 ----D---- C:\Program Files\Gabest
2011-11-17 15:58:30 ----D---- C:\Program Files\Xvid
2011-11-17 15:57:49 ----D---- C:\Program Files\AviSynth 2.5
2011-11-17 15:54:44 ----D---- C:\Program Files\AVI ReComp
2011-11-17 12:48:20 ----D---- C:\Program Files\ESET
2011-11-17 12:48:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-11-17 10:09:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2011-11-08 09:54:37 ----D---- C:\Program Files\WAS
2011-10-30 19:14:12 ----D---- C:\Documents and Settings\OEM\Data aplikací\Search Settings
2011-10-30 19:13:53 ----D---- C:\Program Files\Application Updater
2011-10-30 19:13:52 ----D---- C:\Program Files\IObit Toolbar
2011-10-24 19:31:40 ----D---- C:\Documents and Settings\OEM\Data aplikací\Sonic
2011-10-24 19:31:15 ----D---- C:\Documents and Settings\OEM\Data aplikací\Leadertech
2011-09-21 17:28:17 ----D---- C:\Program Files\AoA Video Joiner
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomwave.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomtran.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomrmencoder.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomqtde.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscommpgenc.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscommpgdec.dll
2011-09-21 14:24:01 ----A---- C:\WINDOWS\system32\viscomframe.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomflvenc.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomflvdec.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomflashenc.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomdata2.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomdata1.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomaudioencoder.dll
2011-09-21 14:24:00 ----A---- C:\WINDOWS\system32\viscomaudiodata.dll
2011-09-21 14:23:59 ----A---- C:\WINDOWS\system32\videotrans.dll
2011-09-21 14:23:59 ----A---- C:\WINDOWS\system32\videoformat.dll
2011-09-21 14:23:59 ----A---- C:\WINDOWS\system32\videocore.dll
2011-09-21 14:23:57 ----A---- C:\WINDOWS\system32\imgscaler.dll
2011-09-21 14:23:57 ----A---- C:\WINDOWS\system32\img_utils.dll
2011-09-21 14:23:55 ----D---- C:\Program Files\Zealot Software
2011-09-21 14:23:55 ----A---- C:\WINDOWS\system32\xvid.dll
2011-09-21 14:23:55 ----A---- C:\WINDOWS\system32\divx.dll
2011-09-21 13:07:05 ----D---- C:\OutputFolder
2011-08-18 21:26:47 ----AD---- C:\Documents and Settings\OEM\Data aplikací\com.AccuWeather.air.stratus.6AF67E59E785A9A644FCA43BED05A7731922EF40.1

======List of files/folders modified in the last 3 months======

2011-11-17 17:38:58 ----AD---- C:\Program Files
2011-11-17 17:38:33 ----D---- C:\WINDOWS\Prefetch
2011-11-17 17:35:12 ----ASHD---- C:\WINDOWS\system32\dllcache
2011-11-17 17:35:07 ----AD---- C:\WINDOWS\system32
2011-11-17 16:07:52 ----AC---- C:\WINDOWS\NeroDigital.ini
2011-11-17 15:55:23 ----D---- C:\WINDOWS\Temp
2011-11-17 15:50:01 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-17 15:47:10 ----A---- C:\TPHKLOCK.TXT
2011-11-17 15:45:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-17 15:42:56 ----D---- C:\WINDOWS
2011-11-17 14:16:53 ----D---- C:\WINDOWS\system32\drivers
2011-11-17 12:49:34 ----SHD---- C:\WINDOWS\Installer
2011-11-17 12:49:30 ----HD---- C:\Config.Msi
2011-11-17 12:49:14 ----HD---- C:\WINDOWS\inf
2011-11-17 08:50:19 ----AD---- C:\Documents and Settings\OEM\Data aplikací\Media Player Classic
2011-11-17 07:42:18 ----A---- C:\WINDOWS\system32\PROCDB.INI
2011-11-17 07:41:37 ----A---- C:\WINDOWS\system32\IPSCtrl.INI
2011-11-17 07:03:02 ----A---- C:\WINDOWS\system32\bscs.ini
2011-11-17 07:02:52 ----A---- C:\WINDOWS\system32\LOCALSERVICE.INI
2011-11-17 07:02:49 ----A---- C:\WINDOWS\system32\LOCALDEVICE.INI
2011-11-16 19:59:35 ----AD---- C:\Program Files\Common Files\Lenovo
2011-11-13 06:32:42 ----D---- C:\SWSHARE
2011-11-11 23:09:20 ----AD---- C:\Program Files\Mozilla Firefox
2011-11-10 20:57:28 ----AC---- C:\WINDOWS\wincmd.ini
2011-11-10 20:53:02 ----AC---- C:\WINDOWS\wcx_ftp.ini
2011-10-30 19:13:55 ----D---- C:\WINDOWS\WinSxS
2011-10-30 19:13:52 ----D---- C:\Program Files\Common Files\Spigot
2011-10-30 10:53:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-26 07:03:09 ----A---- C:\WINDOWS\system32\REMOTEDEVICE.INI
2011-10-11 08:26:29 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-10 16:31:29 ----D---- C:\Program Files\Electronic Arts
2011-10-01 13:22:43 ----A---- C:\WINDOWS\MyHeritage.INI
2011-09-14 12:01:21 ----D---- C:\Program Files\Ask.com
2011-09-14 12:01:19 ----SD---- C:\WINDOWS\Tasks
2011-09-07 13:20:55 ----D---- C:\WINDOWS\system32\config
2011-08-28 08:29:16 ----RASH---- C:\boot.ini
2011-08-28 08:29:16 ----AC---- C:\WINDOWS\win.ini
2011-08-28 08:29:16 ----AC---- C:\WINDOWS\system.ini
2011-08-23 21:04:21 ----AD---- C:\Documents and Settings\OEM\Data aplikací\HPAppData
2011-08-23 18:33:47 ----A---- C:\WINDOWS\system32\SHORTCUT.INI
2011-08-22 11:54:41 ----D---- C:\Program Files\dm
2011-08-18 20:44:15 ----AD---- C:\Documents and Settings\OEM\Data aplikací\IObit

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BtHidBus;Bluetooth HID Bus Service; C:\WINDOWS\System32\Drivers\BtHidBus.sys [2009-01-07 20744]
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\DRIVERS\iaStor.sys [2007-02-12 277784]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-11-20 36624]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 Shockprf;Shockprf; C:\WINDOWS\System32\DRIVERS\Apsx86.sys [2007-03-02 100656]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-10-14 717296]
R0 TPDIGIMN;TPDIGIMN; C:\WINDOWS\System32\DRIVERS\ApsHM86.sys [2007-03-02 19760]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2011-08-04 103112]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-27 39936]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys [2006-10-23 17778]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwrif.sys [2007-04-12 4442]
R1 TSMAPIP;TSMAPIP; C:\WINDOWS\System32\drivers\TSMAPIP.SYS [2007-04-09 12848]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.6.0.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2007-11-20 21425]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 pmem;pmem; \??\C:\WINDOWS\System32\drivers\pmemnt.sys []
R2 PROCDD;IPS Helper Driver; C:\WINDOWS\system32\DRIVERS\PROCDD.SYS [2006-11-06 12080]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2006-11-15 32256]
R2 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2006-11-15 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2006-11-15 37376]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-02-21 12416]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys []
R2 tvtfilter;tvtfilter; C:\WINDOWS\system32\DRIVERS\tvtfilter.sys [2007-11-20 33536]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2007-03-04 146432]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-18 60800]
R3 atmeltpm;atmeltpm; C:\WINDOWS\system32\DRIVERS\atmeltpm.sys [2005-05-17 15872]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2006-03-09 152064]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2009-01-03 39304]
R3 btnetBUs;Bluetooth PAN Bus Service; C:\WINDOWS\System32\Drivers\btnetBus.sys [2008-12-07 30088]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDAudN.sys [2007-04-27 666112]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-03-25 988032]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-03-25 210688]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-02-26 5700096]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2007-02-27 21040]
R3 IvtBtBUs;IVT Bluetooth Bus Service; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
R3 NETw4x32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-03-28 2204672]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-12-08 61824]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\WINDOWS\system32\DRIVERS\psadd.sys [2006-09-13 28224]
R3 TcUsb;TC USB Kernel Driver; C:\WINDOWS\System32\Drivers\tcusb.sys [2007-03-14 40848]
R3 TVTI2C;Lenovo SM bus driver; C:\WINDOWS\system32\DRIVERS\Tvti2c.sys [2006-09-13 35264]
R3 TVTPktFilter;TVT Packet Filter Service; C:\WINDOWS\system32\DRIVERS\tvtpktfilter.sys [2007-02-08 17664]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-10-23 20608]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2009-01-08 31880]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-03-25 731136]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-18 14848]
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys []
S3 ar56yf9i;ar56yf9i; C:\WINDOWS\system32\drivers\ar56yf9i.sys []
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2008-12-07 14088]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-03 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-10-24 117760]
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2008-10-28 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2008-10-28 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2008-10-28 21568]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2008-01-21 14856]
S4 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Filtr Compaq sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;Filtr ALI sběrnice AGP; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;Ovladač filtru AMD portu AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-09-08 962560]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
S2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe []
S2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe []
S2 BlueSoleilCS;BlueSoleilCS; C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe []
S2 BsMobileCS;BsMobileCS; C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe []
S2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe []
S2 IBMPMSVC;ThinkPad PM Service; C:\WINDOWS\system32\ibmpmsvc.exe []
S2 IPSSVC;IPS Core Service; C:\WINDOWS\system32\IPSSVC.EXE []
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf []
S2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe []
S2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe []
S2 SUService;System Update; c:\program files\lenovo\system update\suservice.exe []
S2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe []
S2 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\WINDOWS\System32\TPHDEXLG.exe []
S2 TVT Backup Protection Service;TVT Backup Protection Service; C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe []
S2 TVT Backup Service;TVT Backup Service; C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe []
S2 TVT Scheduler;TVT Scheduler; c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe []
S2 tvtnetwk;tvtnetwk; C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 BsHelpCS;BsHelpCS; C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe [2009-02-27 98407]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 HCYDLAH;HCYDLAH; C:\DOCUME~1\OEM\LOCALS~1\Temp\HCYDLAH.exe [2011-11-17 524288]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMConnectCDS;Služba Windows Media Connect; C:\Program Files\Windows Media Connect 2\wmccds.exe [2005-10-06 855552]
S4 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]

-----------------EOF-----------------

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 17 lis 2011 18:17
od Rudy
Stáhněte a spusťte TDSSKiller: http://support.kaspersky.com/downloads/ ... killer.zip . Ponechte pracovat a po skončení dejte log.

Obrázek

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 17 lis 2011 18:35
od chris.h
Nevím, jestli jsem zkopírovala správný log, ale snad jo...

18:30:16.0015 2480 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
18:30:16.0796 2480 ============================================================
18:30:16.0796 2480 Current date / time: 2011/11/17 18:30:16.0796
18:30:16.0796 2480 SystemInfo:
18:30:16.0796 2480
18:30:16.0796 2480 OS Version: 5.1.2600 ServicePack: 2.0
18:30:16.0796 2480 Product type: Workstation
18:30:16.0796 2480 ComputerName: LENOVO-551F1D3E
18:30:16.0796 2480 UserName: OEM
18:30:16.0796 2480 Windows directory: C:\WINDOWS
18:30:16.0796 2480 System windows directory: C:\WINDOWS
18:30:16.0796 2480 Processor architecture: Intel x86
18:30:16.0796 2480 Number of processors: 2
18:30:16.0796 2480 Page size: 0x1000
18:30:16.0796 2480 Boot type: Normal boot
18:30:16.0796 2480 ============================================================
18:30:24.0828 2480 Initialize success
18:30:40.0796 3288 ============================================================
18:30:40.0796 3288 Scan started
18:30:40.0796 3288 Mode: Manual;
18:30:40.0796 3288 ============================================================
18:30:45.0046 3288 Abiosdsk - ok
18:30:45.0125 3288 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
18:30:45.0140 3288 abp480n5 - ok
18:30:45.0156 3288 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys
18:30:45.0218 3288 ac97intc - ok
18:30:45.0250 3288 ACPI (fa2fbcda96d2385f773b059fe5a125a6) C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:30:45.0296 3288 ACPI - ok
18:30:45.0312 3288 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
18:30:45.0343 3288 ACPIEC - ok
18:30:45.0343 3288 Ad-Watch Connect Filter - ok
18:30:45.0375 3288 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
18:30:45.0375 3288 adpu160m - ok
18:30:45.0406 3288 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys
18:30:45.0406 3288 aec - ok
18:30:45.0453 3288 AegisP (375eb0b97e3950adef3633c27a82438b) C:\WINDOWS\system32\DRIVERS\AegisP.sys
18:30:45.0500 3288 AegisP - ok
18:30:45.0562 3288 AFD (04b0575e52a55f04f4fb84f4ae8fa752) C:\WINDOWS\System32\drivers\afd.sys
18:30:45.0562 3288 AFD - ok
18:30:45.0718 3288 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
18:30:45.0765 3288 agp440 - ok
18:30:45.0812 3288 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
18:30:45.0843 3288 agpCPQ - ok
18:30:45.0859 3288 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
18:30:45.0875 3288 Aha154x - ok
18:30:45.0890 3288 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
18:30:45.0921 3288 aic78u2 - ok
18:30:45.0937 3288 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
18:30:45.0953 3288 aic78xx - ok
18:30:45.0968 3288 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
18:30:46.0000 3288 AliIde - ok
18:30:46.0015 3288 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys
18:30:46.0046 3288 alim1541 - ok
18:30:46.0062 3288 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys
18:30:46.0078 3288 amdagp - ok
18:30:46.0109 3288 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
18:30:46.0125 3288 amsint - ok
18:30:46.0156 3288 ApfiltrService (348055c4afff8e60c01aa6bdc8c58ca7) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
18:30:46.0156 3288 ApfiltrService - ok
18:30:46.0187 3288 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
18:30:46.0234 3288 Arp1394 - ok
18:30:46.0250 3288 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
18:30:46.0296 3288 asc - ok
18:30:46.0312 3288 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
18:30:46.0328 3288 asc3350p - ok
18:30:46.0359 3288 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
18:30:46.0390 3288 asc3550 - ok
18:30:46.0421 3288 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:30:46.0453 3288 AsyncMac - ok
18:30:46.0484 3288 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
18:30:46.0515 3288 atapi - ok
18:30:46.0531 3288 Atdisk - ok
18:30:46.0562 3288 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:30:46.0578 3288 Atmarpc - ok
18:30:46.0656 3288 atmeltpm (dbf0d7e2df33b469eb55406fea759350) C:\WINDOWS\system32\DRIVERS\atmeltpm.sys
18:30:46.0656 3288 atmeltpm - ok
18:30:46.0750 3288 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
18:30:46.0781 3288 audstub - ok
18:30:46.0828 3288 b57w2k (bb1a2a73f993b623f99e03ed2f9e014c) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
18:30:46.0890 3288 b57w2k - ok
18:30:46.0890 3288 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
18:30:46.0921 3288 Beep - ok
18:30:46.0984 3288 BT (8e2d9ece59dfe7d310201e0d65d97ecb) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
18:30:47.0015 3288 BT - ok
18:30:47.0046 3288 Btcsrusb (942c602296119d758547808221c85a2c) C:\WINDOWS\system32\Drivers\btcusb.sys
18:30:47.0046 3288 Btcsrusb - ok
18:30:47.0093 3288 BthEnum (d24b8d1784c68a25060fffbe8ed34b76) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
18:30:47.0125 3288 BthEnum - ok
18:30:47.0265 3288 BtHidBus (ce441ccd98c5ecb10cb12fcaf97322ec) C:\WINDOWS\system32\Drivers\BtHidBus.sys
18:30:47.0265 3288 BtHidBus - ok
18:30:47.0281 3288 BthPan (10355270be12641b9764235da39dcf0f) C:\WINDOWS\system32\DRIVERS\bthpan.sys
18:30:47.0328 3288 BthPan - ok
18:30:47.0390 3288 BTHPORT (28d8eb74c2f2480518c59807a59cd1e2) C:\WINDOWS\system32\Drivers\BTHport.sys
18:30:47.0406 3288 BTHPORT - ok
18:30:47.0437 3288 BTHUSB (f06d4cb9918b462a84d9ac00027efc30) C:\WINDOWS\system32\Drivers\BTHUSB.sys
18:30:47.0468 3288 BTHUSB - ok
18:30:47.0515 3288 btnetBUs (d3c277a51ef9e2ec972d6221f99c0b6d) C:\WINDOWS\system32\Drivers\btnetBus.sys
18:30:47.0531 3288 btnetBUs - ok
18:30:47.0625 3288 BTNetFilter (4f26303becbb7cc5ca8ff39593124cf2) C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys
18:30:47.0625 3288 BTNetFilter - ok
18:30:47.0625 3288 BTWUSB - ok
18:30:47.0656 3288 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
18:30:47.0687 3288 cbidf - ok
18:30:47.0828 3288 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
18:30:47.0828 3288 cbidf2k - ok
18:30:47.0828 3288 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
18:30:47.0859 3288 cd20xrnt - ok
18:30:47.0890 3288 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
18:30:47.0906 3288 Cdaudio - ok
18:30:47.0937 3288 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
18:30:47.0953 3288 Cdfs - ok
18:30:47.0984 3288 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:30:48.0031 3288 Cdrom - ok
18:30:48.0046 3288 Changer - ok
18:30:48.0078 3288 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
18:30:48.0109 3288 CmBatt - ok
18:30:48.0140 3288 CmdIde (964d0f042aca51d5644779eb9d9ee40f) C:\WINDOWS\system32\DRIVERS\cmdide.sys
18:30:48.0171 3288 CmdIde - ok
18:30:48.0187 3288 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
18:30:48.0218 3288 Compbatt - ok
18:30:48.0234 3288 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
18:30:48.0265 3288 Cpqarray - ok
18:30:48.0296 3288 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
18:30:48.0343 3288 dac2w2k - ok
18:30:48.0359 3288 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
18:30:48.0390 3288 dac960nt - ok
18:30:48.0515 3288 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
18:30:48.0546 3288 Disk - ok
18:30:48.0593 3288 dmboot (e1968edec81c430108feb23ab07bdb14) C:\WINDOWS\system32\drivers\dmboot.sys
18:30:48.0656 3288 dmboot - ok
18:30:48.0687 3288 dmio (1b1520a82e396e46b9ae9fa6b03ff6c6) C:\WINDOWS\system32\drivers\dmio.sys
18:30:48.0718 3288 dmio - ok
18:30:48.0734 3288 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
18:30:48.0750 3288 dmload - ok
18:30:48.0781 3288 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
18:30:48.0796 3288 DMusic - ok
18:30:48.0828 3288 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
18:30:48.0843 3288 dpti2o - ok
18:30:48.0890 3288 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
18:30:48.0937 3288 drmkaud - ok
18:30:49.0046 3288 dtscsi - ok
18:30:49.0078 3288 E100B (866b8ee30e4504c11ae0d29ed6f8824b) C:\WINDOWS\system32\DRIVERS\e100b325.sys
18:30:49.0156 3288 E100B - ok
18:30:49.0218 3288 eamon (9309c5c9831203436e64cf2ae605c5d7) C:\WINDOWS\system32\DRIVERS\eamon.sys
18:30:49.0218 3288 eamon - ok
18:30:49.0250 3288 ehdrv (deff87f04ab5f6dd5edf2b80853bbe10) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
18:30:49.0250 3288 ehdrv - ok
18:30:49.0281 3288 epfwtdir (06c65ac0a703cf8eea4f284d901a1550) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
18:30:49.0281 3288 epfwtdir - ok
18:30:49.0359 3288 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
18:30:49.0390 3288 Fastfat - ok
18:30:49.0531 3288 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
18:30:49.0562 3288 Fdc - ok
18:30:49.0671 3288 Fips (266dab58619b17bdf37fabbd48d875ca) C:\WINDOWS\system32\drivers\Fips.sys
18:30:49.0671 3288 Fips - ok
18:30:49.0687 3288 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:30:49.0718 3288 Flpydisk - ok
18:30:49.0734 3288 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
18:30:49.0843 3288 FltMgr - ok
18:30:49.0890 3288 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:30:49.0906 3288 Fs_Rec - ok
18:30:49.0968 3288 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:30:50.0000 3288 Ftdisk - ok
18:30:50.0125 3288 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:30:50.0187 3288 Gpc - ok
18:30:50.0250 3288 HdAudAddService (8dc8b34992131eb4b4c71b1a47fdd21c) C:\WINDOWS\system32\drivers\CHDAudN.sys
18:30:50.0265 3288 HdAudAddService - ok
18:30:50.0296 3288 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:30:50.0328 3288 HDAudBus - ok
18:30:50.0375 3288 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:30:50.0421 3288 hidusb - ok
18:30:50.0593 3288 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
18:30:50.0625 3288 hpn - ok
18:30:50.0671 3288 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
18:30:50.0687 3288 HPZid412 - ok
18:30:50.0703 3288 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
18:30:50.0734 3288 HPZipr12 - ok
18:30:50.0765 3288 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
18:30:50.0796 3288 HPZius12 - ok
18:30:50.0843 3288 HSFHWAZL (26d99cb5d30f79e4459d855af690decd) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
18:30:50.0843 3288 HSFHWAZL - ok
18:30:50.0906 3288 HSF_DPV (491b8f394e56ff31d6740f7a34540716) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
18:30:50.0953 3288 HSF_DPV - ok
18:30:51.0140 3288 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys
18:30:51.0140 3288 HTTP - ok
18:30:51.0171 3288 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys
18:30:51.0203 3288 i2omgmt - ok
18:30:51.0234 3288 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys
18:30:51.0250 3288 i2omp - ok
18:30:51.0296 3288 i8042prt (0f42de9909b5dbf2c48dd1a79d491af5) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:30:51.0328 3288 i8042prt - ok
18:30:51.0531 3288 ialm (c1c2d6940d6ec2f247b0f3c11e0a18e0) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
18:30:51.0687 3288 ialm - ok
18:30:51.0750 3288 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\WINDOWS\system32\DRIVERS\iaStor.sys
18:30:51.0750 3288 iaStor - ok
18:30:51.0890 3288 IBMPMDRV (326edb99d2b509f6c48bf723c1817292) C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
18:30:51.0890 3288 IBMPMDRV - ok
18:30:51.0921 3288 Imapi (12c59b8929121ace2f55acc86682cf12) C:\WINDOWS\system32\DRIVERS\imapi.sys
18:30:51.0953 3288 Imapi - ok
18:30:52.0031 3288 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
18:30:52.0062 3288 ini910u - ok
18:30:52.0062 3288 IntelIde (ef4fda4841001a4b98c411797db8894a) C:\WINDOWS\system32\DRIVERS\intelide.sys
18:30:52.0093 3288 IntelIde - ok
18:30:52.0125 3288 intelppm (d72a67a4ab80f7f74dc5dbbc36db12c9) C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:30:52.0156 3288 intelppm - ok
18:30:52.0171 3288 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
18:30:52.0203 3288 Ip6Fw - ok
18:30:52.0218 3288 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:30:52.0265 3288 IpFilterDriver - ok
18:30:52.0281 3288 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:30:52.0296 3288 IpInIp - ok
18:30:52.0328 3288 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:30:52.0328 3288 IpNat - ok
18:30:52.0343 3288 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:30:52.0375 3288 IPSec - ok
18:30:52.0421 3288 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
18:30:52.0453 3288 IRENUM - ok
18:30:52.0484 3288 isapnp (1091528512e4dd7ed5fddcc4df1c53d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:30:52.0515 3288 isapnp - ok
18:30:52.0640 3288 IvtBtBUs (71e1fc547cc488d5cd7bf0860c96f5af) C:\WINDOWS\system32\Drivers\IvtBtBus.sys
18:30:52.0671 3288 IvtBtBUs - ok
18:30:52.0718 3288 Kbdclass (6f877bf8dc01a550cd666f3bedb2213c) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:30:52.0750 3288 Kbdclass - ok
18:30:52.0765 3288 kbdhid (065b5a83aa78c0c7047bf22e0ab5c821) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:30:52.0796 3288 kbdhid - ok
18:30:52.0843 3288 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
18:30:52.0843 3288 kmixer - ok
18:30:52.0875 3288 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys
18:30:52.0875 3288 KSecDD - ok
18:30:52.0890 3288 lbrtfdc - ok
18:30:52.0937 3288 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
18:30:52.0937 3288 mdmxsdk - ok
18:30:53.0062 3288 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
18:30:53.0093 3288 mnmdd - ok
18:30:53.0140 3288 Modem (60210deb037846afe521ebf349964f6b) C:\WINDOWS\system32\drivers\Modem.sys
18:30:53.0171 3288 Modem - ok
18:30:53.0203 3288 Mouclass (b160ec94114715675509115986400fd9) C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:30:53.0234 3288 Mouclass - ok
18:30:53.0265 3288 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:30:53.0281 3288 mouhid - ok
18:30:53.0328 3288 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
18:30:53.0359 3288 MountMgr - ok
18:30:53.0375 3288 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
18:30:53.0406 3288 mraid35x - ok
18:30:53.0437 3288 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:30:53.0437 3288 MRxDAV - ok
18:30:53.0500 3288 MRxSmb (6f2d483b97b395544e59749c47963c6a) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:30:53.0515 3288 MRxSmb - ok
18:30:53.0640 3288 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
18:30:53.0671 3288 Msfs - ok
18:30:53.0718 3288 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:30:53.0734 3288 MSKSSRV - ok
18:30:53.0750 3288 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:30:53.0781 3288 MSPCLOCK - ok
18:30:53.0781 3288 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
18:30:53.0812 3288 MSPQM - ok
18:30:53.0843 3288 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:30:53.0859 3288 mssmbios - ok
18:30:53.0906 3288 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
18:30:53.0937 3288 Mup - ok
18:30:53.0984 3288 NDIS (bc84c4f67d0e880b0c46dc0ce2b8cbaa) C:\WINDOWS\system32\drivers\NDIS.sys
18:30:53.0984 3288 NDIS - ok
18:30:54.0015 3288 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:30:54.0015 3288 NdisTapi - ok
18:30:54.0062 3288 Ndisuio (8d3ce6b579cde8d37acc690b67dc2106) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:30:54.0093 3288 Ndisuio - ok
18:30:54.0109 3288 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:30:54.0140 3288 NdisWan - ok
18:30:54.0171 3288 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
18:30:54.0203 3288 NDProxy - ok
18:30:54.0328 3288 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
18:30:54.0343 3288 NetBIOS - ok
18:30:54.0359 3288 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
18:30:54.0421 3288 NetBT - ok
18:30:54.0546 3288 NETw4x32 (9b18806954cb7f33b538cbf090562db2) C:\WINDOWS\system32\DRIVERS\NETw4x32.sys
18:30:54.0609 3288 NETw4x32 - ok
18:30:54.0671 3288 NIC1394 (e1532ad506e0e874d1e6b4581c4f64ae) C:\WINDOWS\system32\DRIVERS\nic1394.sys
18:30:54.0671 3288 NIC1394 - ok
18:30:54.0734 3288 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
18:30:54.0750 3288 Npfs - ok
18:30:54.0781 3288 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys
18:30:54.0796 3288 Ntfs - ok
18:30:54.0812 3288 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
18:30:54.0843 3288 Null - ok
18:30:54.0921 3288 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
18:30:54.0984 3288 nv - ok
18:30:55.0140 3288 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:30:55.0171 3288 NwlnkFlt - ok
18:30:55.0187 3288 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:30:55.0218 3288 NwlnkFwd - ok
18:30:55.0265 3288 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
18:30:55.0296 3288 ohci1394 - ok
18:30:55.0343 3288 Parport (76a18caa2fefb28a4ced38d76837e86e) C:\WINDOWS\system32\DRIVERS\parport.sys
18:30:55.0375 3288 Parport - ok
18:30:55.0406 3288 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
18:30:55.0437 3288 PartMgr - ok
18:30:55.0437 3288 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
18:30:55.0468 3288 ParVdm - ok
18:30:55.0484 3288 PCI (b7979f37bb7b9df2230046134955e6e7) C:\WINDOWS\system32\DRIVERS\pci.sys
18:30:55.0515 3288 PCI - ok
18:30:55.0656 3288 PCIDump - ok
18:30:55.0671 3288 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
18:30:55.0703 3288 PCIIde - ok
18:30:55.0718 3288 Pcmcia (90505755634407d4ef4c6dea60fc1df9) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
18:30:56.0468 3288 Pcmcia - ok
18:30:56.0609 3288 PDCOMP - ok
18:30:56.0625 3288 PDFRAME - ok
18:30:56.0625 3288 PDRELI - ok
18:30:56.0640 3288 PDRFRAME - ok
18:30:56.0687 3288 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
18:30:56.0718 3288 perc2 - ok
18:30:56.0734 3288 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
18:30:56.0765 3288 perc2hib - ok
18:30:56.0828 3288 pmem (dedef40e1d05842639491365cb2c069e) C:\WINDOWS\System32\drivers\pmemnt.sys
18:30:56.0906 3288 pmem - ok
18:30:56.0953 3288 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:30:56.0984 3288 PptpMiniport - ok
18:30:57.0031 3288 PROCDD (1d80309fed4babf8ea9e7b84a394348b) C:\WINDOWS\system32\DRIVERS\PROCDD.SYS
18:30:57.0046 3288 PROCDD - ok
18:30:57.0109 3288 Processor (b6c55157fac7858b6a500fb206dda8dc) C:\WINDOWS\system32\DRIVERS\processr.sys
18:30:57.0140 3288 Processor - ok
18:30:57.0281 3288 psadd (ce5114c9d3ab67e6f6f8017c5f975292) C:\WINDOWS\system32\DRIVERS\psadd.sys
18:30:57.0281 3288 psadd - ok
18:30:57.0312 3288 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
18:30:57.0375 3288 PSched - ok
18:30:57.0375 3288 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:30:57.0406 3288 Ptilink - ok
18:30:57.0453 3288 PxHelp20 (1962166e0ceb740704f30fa55ad3d509) C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:30:57.0453 3288 PxHelp20 - ok
18:30:57.0484 3288 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
18:30:57.0531 3288 ql1080 - ok
18:30:57.0546 3288 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
18:30:57.0578 3288 Ql10wnt - ok
18:30:57.0578 3288 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
18:30:57.0609 3288 ql12160 - ok
18:30:57.0625 3288 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
18:30:57.0671 3288 ql1240 - ok
18:30:57.0687 3288 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
18:30:57.0703 3288 ql1280 - ok
18:30:57.0734 3288 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:30:57.0765 3288 RasAcd - ok
18:30:57.0781 3288 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:30:57.0828 3288 Rasl2tp - ok
18:30:57.0828 3288 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:30:57.0859 3288 RasPppoe - ok
18:30:57.0875 3288 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
18:30:57.0906 3288 Raspti - ok
18:30:57.0937 3288 Rdbss (809ca45caa9072b3176ad44579d7f688) C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:30:57.0937 3288 Rdbss - ok
18:30:57.0953 3288 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:30:57.0984 3288 RDPCDD - ok
18:30:58.0156 3288 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:30:58.0250 3288 rdpdr - ok
18:30:58.0281 3288 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
18:30:58.0281 3288 RDPWD - ok
18:30:58.0312 3288 redbook (aba13d33e1f888c9a68599a48a8840d6) C:\WINDOWS\system32\DRIVERS\redbook.sys
18:30:58.0343 3288 redbook - ok
18:30:58.0406 3288 RFCOMM (99c4b74981a1413f142a3903130088cb) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
18:30:58.0437 3288 RFCOMM - ok
18:30:58.0484 3288 rimmptsk (d85e3fa9f5b1f29bb4ed185c450d1470) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
18:30:58.0515 3288 rimmptsk - ok
18:30:58.0531 3288 rimsptsk (db8eb01c58c9fada00c70b1775278ae0) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
18:30:58.0562 3288 rimsptsk - ok
18:30:58.0718 3288 risdptsk (ace2ce73d7b04eac48fb80482e05e770) C:\WINDOWS\system32\DRIVERS\risdptsk.sys
18:30:58.0734 3288 risdptsk - ok
18:30:58.0765 3288 rismxdp (6c1f93c0760c9f79a1869d07233df39d) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
18:30:58.0812 3288 rismxdp - ok
18:30:58.0859 3288 s24trans (e2c6abcbefb1d44f6aaeb1cd5d6062d4) C:\WINDOWS\system32\DRIVERS\s24trans.sys
18:30:58.0859 3288 s24trans - ok
18:30:58.0906 3288 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:30:58.0906 3288 Secdrv - ok
18:30:58.0937 3288 Ser2pl (6ce397c482bede91a38e56a8c4a0dc6d) C:\WINDOWS\system32\DRIVERS\ser2pl.sys
18:30:58.0968 3288 Ser2pl - ok
18:30:58.0968 3288 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
18:30:59.0000 3288 serenum - ok
18:30:59.0031 3288 Serial (c1ddbc85251551a840212999da3d95f3) C:\WINDOWS\system32\DRIVERS\serial.sys
18:30:59.0062 3288 Serial - ok
18:30:59.0078 3288 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
18:30:59.0109 3288 sfdrv01 - ok
18:30:59.0140 3288 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
18:30:59.0171 3288 sfhlp02 - ok
18:30:59.0328 3288 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
18:30:59.0375 3288 Sfloppy - ok
18:30:59.0406 3288 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\WINDOWS\system32\drivers\sfvfs02.sys
18:30:59.0437 3288 sfvfs02 - ok
18:30:59.0468 3288 Shockprf (6873edc0d75e1e255208442ea3e018c1) C:\WINDOWS\system32\DRIVERS\Apsx86.sys
18:30:59.0546 3288 Shockprf - ok
18:30:59.0546 3288 Simbad - ok
18:30:59.0578 3288 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys
18:30:59.0609 3288 sisagp - ok
18:30:59.0671 3288 smihlp (350483c5a139f8a39ed3191aff39bed0) C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys
18:30:59.0671 3288 smihlp - ok
18:30:59.0687 3288 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
18:30:59.0718 3288 Sparrow - ok
18:30:59.0765 3288 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
18:30:59.0765 3288 splitter - ok
18:30:59.0968 3288 sptd (71e276f6d189413266ea22171806597b) C:\WINDOWS\system32\Drivers\sptd.sys
18:30:59.0968 3288 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
18:30:59.0968 3288 sptd ( LockedFile.Multi.Generic ) - warning
18:30:59.0968 3288 sptd - detected LockedFile.Multi.Generic (1)
18:31:00.0000 3288 sr (a74035ea526db97d9d50d2143a55f5cf) C:\WINDOWS\system32\DRIVERS\sr.sys
18:31:00.0031 3288 sr - ok
18:31:00.0078 3288 Srv (e03b4ea274c9e509cca7f9f0cec24232) C:\WINDOWS\system32\DRIVERS\srv.sys
18:31:00.0125 3288 Srv - ok
18:31:00.0171 3288 StillCam (06cda2a5a549bc455d004461e6bc5b33) C:\WINDOWS\system32\DRIVERS\serscan.sys
18:31:00.0203 3288 StillCam - ok
18:31:00.0359 3288 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
18:31:00.0390 3288 swenum - ok
18:31:00.0421 3288 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
18:31:00.0453 3288 swmidi - ok
18:31:00.0484 3288 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
18:31:00.0515 3288 symc810 - ok
18:31:00.0531 3288 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
18:31:00.0562 3288 symc8xx - ok
18:31:00.0562 3288 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
18:31:00.0593 3288 sym_hi - ok
18:31:00.0609 3288 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
18:31:00.0640 3288 sym_u3 - ok
18:31:00.0656 3288 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
18:31:00.0671 3288 sysaudio - ok
18:31:00.0734 3288 Tcpip (744e57c99232201ae98c49168b918f48) C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:31:00.0750 3288 Tcpip - ok
18:31:00.0781 3288 TcUsb (109d1f5cd9cc370a87901db3ddd533f1) C:\WINDOWS\system32\Drivers\tcusb.sys
18:31:00.0781 3288 TcUsb - ok
18:31:00.0937 3288 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
18:31:00.0984 3288 TDPIPE - ok
18:31:01.0015 3288 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
18:31:01.0046 3288 TDTCP - ok
18:31:01.0140 3288 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
18:31:01.0171 3288 TermDD - ok
18:31:01.0187 3288 TosIde (fd4fd7d6fda5c019ed86025d7be1510f) C:\WINDOWS\system32\DRIVERS\toside.sys
18:31:01.0218 3288 TosIde - ok
18:31:01.0250 3288 TPDIGIMN (9c72fdd0fa2d3be3bd5cca211fb19916) C:\WINDOWS\system32\DRIVERS\ApsHM86.sys
18:31:01.0281 3288 TPDIGIMN - ok
18:31:01.0328 3288 TPHKDRV (542770c8925e13b29b1ba63f05898058) C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys
18:31:01.0328 3288 TPHKDRV - ok
18:31:01.0375 3288 TPPWRIF (44672de6cea9569c21c4b7a8d2560750) C:\WINDOWS\system32\drivers\Tppwrif.sys
18:31:01.0390 3288 TPPWRIF - ok
18:31:01.0546 3288 TSMAPIP (ea856d91b3c088ce331e7740c72f43a3) C:\WINDOWS\system32\drivers\TSMAPIP.SYS
18:31:01.0562 3288 TSMAPIP - ok
18:31:01.0593 3288 tvtfilter (49258a02a1e8d304ed88b0f1c56b1738) C:\WINDOWS\system32\DRIVERS\tvtfilter.sys
18:31:01.0656 3288 tvtfilter - ok
18:31:01.0671 3288 TVTI2C (c254bff0a928ea7d5ccdc2522d56fd01) C:\WINDOWS\system32\DRIVERS\Tvti2c.sys
18:31:01.0703 3288 TVTI2C - ok
18:31:01.0750 3288 TVTPktFilter (0727cce3ff1a4446f4a1d507361567ab) C:\WINDOWS\system32\DRIVERS\tvtpktfilter.sys
18:31:01.0750 3288 TVTPktFilter - ok
18:31:01.0796 3288 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
18:31:01.0828 3288 Udfs - ok
18:31:01.0859 3288 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
18:31:01.0906 3288 ultra - ok
18:31:01.0953 3288 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
18:31:02.0000 3288 Update - ok
18:31:02.0203 3288 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:31:02.0250 3288 usbccgp - ok
18:31:02.0265 3288 usbehci (a45ea1550ea4b368c4fba7ca9d056bc9) C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:31:02.0296 3288 usbehci - ok
18:31:02.0343 3288 usbhub (6d46b1f89134892a862ac56b00ac11fe) C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:31:02.0375 3288 usbhub - ok
18:31:02.0421 3288 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
18:31:02.0453 3288 usbprint - ok
18:31:02.0640 3288 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:31:02.0671 3288 usbscan - ok
18:31:02.0765 3288 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:31:02.0796 3288 USBSTOR - ok
18:31:02.0968 3288 usbuhci (0ee1925590ba1abec14254d54d9870f4) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:31:03.0000 3288 usbuhci - ok
18:31:03.0109 3288 VComm (0955553090e0a88614e5b8a02af9324c) C:\WINDOWS\system32\DRIVERS\VComm.sys
18:31:03.0140 3288 VComm - ok
18:31:03.0296 3288 VcommMgr (ea0d7c68dc77b478f1c08022b8afe8ca) C:\WINDOWS\system32\Drivers\VcommMgr.sys
18:31:03.0296 3288 VcommMgr - ok
18:31:03.0453 3288 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
18:31:03.0484 3288 VgaSave - ok
18:31:03.0593 3288 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys
18:31:03.0640 3288 viaagp - ok
18:31:03.0687 3288 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
18:31:03.0718 3288 ViaIde - ok
18:31:03.0765 3288 VolSnap (cd8cce067f7e9cbd762c00bdddecaa34) C:\WINDOWS\system32\drivers\VolSnap.sys
18:31:03.0812 3288 VolSnap - ok
18:31:03.0984 3288 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:31:04.0015 3288 Wanarp - ok
18:31:04.0140 3288 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
18:31:04.0187 3288 Wdf01000 - ok
18:31:04.0234 3288 WDICA - ok
18:31:04.0421 3288 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
18:31:04.0421 3288 wdmaud - ok
18:31:04.0687 3288 winachsf (458b2e703b210683194158d639770588) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
18:31:04.0765 3288 winachsf - ok
18:31:04.0859 3288 MBR (0x1B8) (507e7d82a79f999ec2451e50872feca3) \Device\Harddisk0\DR0
18:31:04.0875 3288 \Device\Harddisk0\DR0 - ok
18:31:04.0875 3288 Boot (0x1200) (84c34d5c5fcb8782a43088a7eb373592) \Device\Harddisk0\DR0\Partition0
18:31:04.0875 3288 \Device\Harddisk0\DR0\Partition0 - ok
18:31:04.0875 3288 ============================================================
18:31:04.0875 3288 Scan finished
18:31:04.0875 3288 ============================================================
18:31:04.0890 2808 Detected object count: 1
18:31:04.0890 2808 Actual detected object count: 1
18:31:37.0750 2808 sptd ( LockedFile.Multi.Generic ) - skipped by user
18:31:37.0750 2808 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 17 lis 2011 19:30
od Rudy
Našlo to jen sptd.sys, což je ovladač od DaemonTools. Ještě poprosím o oba logy z GMER: http://www.viry.cz/forum/viewtopic.php?f=29&t=62878 .

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 17 lis 2011 20:33
od chris.h
GMER1:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-11-17 19:43:56
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0084
Running: gmer.exe; Driver: C:\DOCUME~1\OEM\LOCALS~1\Temp\uftcqpob.sys


---- System - GMER 1.0.15 ----

SSDT spsr.sys ZwEnumerateKey [0xF73DBCA2]
SSDT spsr.sys ZwEnumerateValueKey [0xF73DC030]

---- Devices - GMER 1.0.15 ----

Device \Driver\iaStor \Device\Ide\iaStor0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 86F611F8
Device \Driver\atapi \Device\Ide\IdePort0 86F611F8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1 862BD1F8
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1Port2Path0Target0Lun0 862BD1F8
Device \FileSystem\Ntfs \Ntfs 86FD21F8

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)

Device \FileSystem\Fastfat \Fat 847E21F8

AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

---- Threads - GMER 1.0.15 ----

Thread System [4:1352] 9DA013E0
Thread System [4:1356] 9DA013E0
Thread System [4:1360] 84831330
Thread System [4:1364] 84831330

---- EOF - GMER 1.0.15 ----

GMER2:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-17 20:29:03
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 FUJITSU_ rev.0084
Running: gmer.exe; Driver: C:\DOCUME~1\OEM\LOCALS~1\Temp\uftcqpob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xA39CC4B0]
SSDT spsr.sys ZwCreateKey [0xF73BD0E0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwCreateThread [0xA39CC7F0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xA39CCAB0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xA39CC5D0]
SSDT spsr.sys ZwEnumerateKey [0xF73DBCA2]
SSDT spsr.sys ZwEnumerateValueKey [0xF73DC030]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwLoadDriver [0xA39CC8B0]
SSDT spsr.sys ZwOpenKey [0xF73BD0C0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xA39CC350]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xA39CC410]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xA39CC570]
SSDT spsr.sys ZwQueryKey [0xF73DC108]
SSDT spsr.sys ZwQueryValueKey [0xF73DBF88]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwQueueApcThread [0xA39CC630]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xA39CC530]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xA39CC4F0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xA39CC670]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSystemInformation [0xA39CC870]
SSDT spsr.sys ZwSetValueKey [0xF73DC19A]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xA39CC3B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xA39CC430]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSystemDebugControl [0xA39CC830]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateProcess [0xA39CC370]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xA39CC470]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xA39CC5F0]

INT 0x62 ? 86F61BF8
INT 0x63 ? 863BDBF8
INT 0x73 ? 863BDBF8
INT 0x74 ? 863BDBF8
INT 0x83 ? 863BDBF8
INT 0x84 ? 863BDBF8
INT 0x94 ? 863BDBF8
INT 0xA4 ? 86FD3BF8
INT 0xA4 ? 863BDBF8

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwCallbackReturn + 2FB0 8050481C 12 Bytes [B0, C3, 9C, A3, 30, C4, 9C, ...]
? spsr.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload F54FC80C 5 Bytes JMP 863BD1D8
.text ar56yf9i.SYS F4E8D386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text ar56yf9i.SYS F4E8D3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ar56yf9i.SYS F4E8D3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text ar56yf9i.SYS F4E8D3C9 1 Byte [2E]
.text ar56yf9i.SYS F4E8D3C9 11 Bytes [2E, 00, 00, 00, 5A, 02, 00, ...]
.text ...
.text afd.sys 9CFE8300 1031 Bytes [08, 04, 00, 00, 00, FC, 01, ...]
.text afd.sys 9CFE8708 2575 Bytes [9C, 0F, 85, 69, 0B, 00, 00, ...]
.text afd.sys 9CFE9118 484 Bytes [93, FE, 9C, 8B, 43, 10, 8D, ...]
.text afd.sys 9CFE92FD 632 Bytes [95, FE, 9C, 90, 90, 90, 90, ...]
.text afd.sys 9CFE9576 38 Bytes [5C, 80, 28, B3, 5B, 80, 22, ...]
.text ...
.PAGE1 C:\WINDOWS\System32\drivers\afd.sys unknown last section [0x9CFF5F00, 0x100, 0xC0000040]
? C:\WINDOWS\System32\drivers\afd.sys suspicious PE modification

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1072] kernel32.dll!SetUnhandledExceptionFilter 7C84479D 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 00475550 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!DeviceIoControl 7C801625 7 Bytes JMP 00475890 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00475600 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00475770 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] kernel32.dll!IsDebuggerPresent 7C813093 6 Bytes JMP 00414F50 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] USER32.dll!ChangeDisplaySettingsExA 7E37A2DA 5 Bytes JMP 0047A650 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] USER32.dll!ChangeDisplaySettingsExW 7E3A950D 5 Bytes JMP 0047A680 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyExW 77DC6A78 5 Bytes JMP 00419860 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCloseKey 77DC6BF0 5 Bytes JMP 00419590 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueExW 77DC6FC8 5 Bytes JMP 00419980 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyExW 77DC7535 5 Bytes JMP 00419650 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyExA 77DC761B 5 Bytes JMP 00419830 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyW 77DC770F 5 Bytes JMP 00419810 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueExA 77DC7883 5 Bytes JMP 00419950 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumKeyExW 77DC79A1 5 Bytes JMP 00419760 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumValueW 77DC8081 5 Bytes JMP 004197C0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueExW 77DCD7CC 7 Bytes JMP 00419A40 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueW 77DCD8E2 5 Bytes JMP 00419920 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyExA 77DCEAF4 5 Bytes JMP 00419630 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueExA 77DCEBE7 7 Bytes JMP 00419A10 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteValueA 77DCEDE5 5 Bytes JMP 004196D0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteValueW 77DCEEF1 5 Bytes JMP 00419700 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueA 77DD6F49 5 Bytes JMP 004199B0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegFlushKey 77DDB908 5 Bytes JMP 004195C0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumValueA 77DDCF4A 5 Bytes JMP 00419790 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyW 77DE8F7D 5 Bytes JMP 00419610 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteKeyW 77DE9884 5 Bytes JMP 004196A0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegDeleteKeyA 77DEC123 5 Bytes JMP 00419670 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryInfoKeyA 77DEC1B5 5 Bytes JMP 00419890 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegOpenKeyA 77DEC41B 5 Bytes JMP 004197F0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegEnumKeyExA 77DEC8C1 5 Bytes JMP 00419730 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryValueA 77DECC10 5 Bytes JMP 004198F0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegQueryInfoKeyW 77DECCEF 5 Bytes JMP 004198C0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegCreateKeyA 77DED5BB 5 Bytes JMP 004195F0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ADVAPI32.dll!RegSetValueW 77E25FC2 5 Bytes JMP 004199E0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe[2772] ole32.dll!CoCreateInstance 774EFAC3 5 Bytes JMP 00419CB0 C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe (Media Player Classic - Home Cinema/MPC-HC Team)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2824] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 012A2EC0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!SetWindowLongA 7E36D5F5 5 Bytes JMP 106AC350 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!SetWindowLongW 7E36D613 5 Bytes JMP 106AC2E2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!GetWindowInfo 7E36DE7C 5 Bytes JMP 1045E363 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3448] USER32.dll!TrackPopupMenu 7E3B526E 5 Bytes JMP 1045E91C C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73BE040] spsr.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73BE13C] spsr.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73BE0BE] spsr.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73BE7FC] spsr.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73BE6D2] spsr.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73CE048] spsr.sys
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\ar56yf9i.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfReleaseSpinLock] 3BD44D8B
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfLowerIrql] FEA0180D
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfRaiseIrql] 8B6C769C
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KeGetCurrentIrql] 47C6B07D
IAT \SystemRoot\System32\drivers\afd.sys[HAL.dll!KfAcquireSpinLock] 006A012F

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 86FD21F8

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)

Device \FileSystem\Fastfat \FatCdrom 847E21F8
Device \Driver\usbuhci \Device\USBPDO-0 863BC1F8
Device \Driver\usbuhci \Device\USBPDO-1 863BC1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86FD41F8
Device \Driver\dmio \Device\DmControl\DmConfig 86FD41F8
Device \Driver\dmio \Device\DmControl\DmPnP 86FD41F8
Device \Driver\dmio \Device\DmControl\DmInfo 86FD41F8
Device \Driver\usbehci \Device\USBPDO-2 864521F8
Device \Driver\usbuhci \Device\USBPDO-3 863BC1F8
Device \Driver\usbehci \Device\USBPDO-4 864521F8

AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

Device \Driver\usbuhci \Device\USBPDO-5 863BC1F8
Device \Driver\usbuhci \Device\USBPDO-6 863BC1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F621F8
Device \Driver\sptd \Device\2970688920 spsr.sys
Device \Driver\Cdrom \Device\CdRom0 862F31F8
Device \Driver\USBSTOR \Device\000000b0 8475E500
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F621F8
Device \Driver\iaStor \Device\Ide\iaStor0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 86F611F8
Device \Driver\atapi \Device\Ide\IdePort0 86F611F8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [F7269D30] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 862F31F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 849F5500
Device \Driver\NetBT \Device\NetbiosSmb 849F5500
Device \Driver\PCI_PNP0170 \Device\0000005d spsr.sys
Device \Driver\PCI_PNP0170 \Device\0000005d spsr.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{40A18DDA-0AC0-4179-AE59-846FB99DEC0B} 849F5500
Device \Driver\usbuhci \Device\USBFDO-0 863BC1F8
Device \Driver\usbuhci \Device\USBFDO-1 863BC1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{D02AAEDC-F72D-48B2-9C14-EF72D848CF68} 849F5500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8634F2E8
Device \Driver\usbehci \Device\USBFDO-2 864521F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8634F2E8
Device \Driver\usbuhci \Device\USBFDO-3 863BC1F8
Device \Driver\USBSTOR \Device\000000af 8475E500
Device \Driver\usbuhci \Device\USBFDO-4 863BC1F8
Device \Driver\Ftdisk \Device\FtControl 86F621F8
Device \Driver\usbuhci \Device\USBFDO-5 863BC1F8
Device \Driver\usbehci \Device\USBFDO-6 864521F8
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1 862BD1F8
Device \Driver\ar56yf9i \Device\Scsi\ar56yf9i1Port2Path0Target0Lun0 862BD1F8
Device \FileSystem\Fastfat \Fat 847E21F8

AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)

Device \FileSystem\Cdfs \Cdfs 84AE9368

---- Modules - GMER 1.0.15 ----

Module (noname) (*** hidden *** ) 9E0D9000-9E0E7000 (57344 bytes)
Module (noname) (*** hidden *** ) 9D9FD000-9DA06000 (36864 bytes)


---- Threads - GMER 1.0.15 ----

Thread System [4:1352] 9DA013E0
Thread System [4:1356] 9DA013E0
Thread System [4:1360] 84831330
Thread System [4:1364] 84831330

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\001c26eceaed (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x35 0x94 0x33 0xDC ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x89 0x04 0x48 0x3A ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0x34 0xC1 0x31 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x74 0xDC 0x09 0x25 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0x13 0xF0 0x6D ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x7A 0xF0 0x0C 0x6A ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3F 0x2D 0x8D 0x53 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x00 0x06 0x71 0x37 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x30 0x71 0x7C 0x14 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001c26eceaed (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x35 0x94 0x33 0xDC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x89 0x04 0x48 0x3A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0x34 0xC1 0x31 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x74 0xDC 0x09 0x25 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0x13 0xF0 0x6D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x42 0x68 0xC0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3F 0x2D 0x8D 0x53 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x00 0x06 0x71 0x37 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x30 0x71 0x7C 0x14 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001c26eceaed
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 1042669753
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 764169717
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x35 0x94 0x33 0xDC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x89 0x04 0x48 0x3A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0x34 0xC1 0x31 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x74 0xDC 0x09 0x25 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0x13 0xF0 0x6D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x42 0x68 0xC0 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3F 0x2D 0x8D 0x53 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x00 0x06 0x71 0x37 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x30 0x71 0x7C 0x14 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109A10050400000000000F01FEC\Usage@OutlookMAPI2Intl_1029 1064372994

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\$NtUninstallKB28038$\1664086358 0 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\L 0 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\L\dtfihjfc 138368 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\loader.tlb 2632 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U 0 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@00000001 45968 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@000000c0 3072 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@000000cb 3072 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@000000cf 1536 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@80000000 23040 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@800000c0 35840 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@800000cb 24064 bytes
File C:\WINDOWS\$NtUninstallKB28038$\1664086358\U\@800000cf 31744 bytes
File C:\WINDOWS\$NtUninstallKB28038$\3760065385 0 bytes

---- EOF - GMER 1.0.15 ----

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 17 lis 2011 20:53
od Rudy
Ani toto není zcela jednoznačné. Udělejte sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 a dejte log.

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 19:43
od chris.h
Status: Will be deleted when the computer is restarted (events: 1)
18.11.2011 13:38:51 Will be deleted when the computer is restarted Trojan program Backdoor.Win32.ZAccess.ang C:\WINDOWS\assembly\GAC_MSIL\Desktop.ini High
Status: Deleted (events: 6)
18.11.2011 14:30:45 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114182.ini High
18.11.2011 14:30:44 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114201.ini High
18.11.2011 14:30:45 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114272.ini High
18.11.2011 14:30:48 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114307.ini High
18.11.2011 14:30:48 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP434\A0114321.ini High
18.11.2011 14:30:50 Deleted Trojan program Backdoor.Win32.ZAccess.ang C:\System Volume Information\_restore{FB03446A-C652-43E2-A8EA-F1A49232F318}\RP435\A0114346.ini High

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 20:02
od Rudy
OK, smazáno. Nastala nějaká změna?

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 20:24
od chris.h
Tak, NOD mi stále hlásí ten rootkit na operační paměti.

Operační paměť » services.exe(1604) - varianta infiltrace Win32/Rootkit.Agent.NUS trojský kůň - nelze léčit

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 21:01
od Rudy
Je to rebus, tenhle šmejd jsme tu ještě neměli. Zkuste otestovat tento soubor : C: \ WINDOWS \ system32 \ spoolsv.exe na www.virustotal.com . Výsledek oznamte.

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 21:08
od chris.h
File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis:
MD5: da81ec57acd4cdc3d4c51cf3d409af9f
Date first seen: 2007-09-14 17:29:17 (UTC)
Date last seen: 2011-11-05 13:20:05 (UTC)
Detection ratio: 1/43

What do you wish to do?

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 21:11
od Rudy
V jednom případě něco detekoval. Který AV a jaký virus?

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 21:18
od chris.h
eSafe 7.0.17.0 2011.11.02 Win32.Banker

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 22:07
od Rudy
Tak to nic. Dejte ještě jeden log z ComboFix.

Re: Prosím o pomoc, vir Rootkit.Agent.NUS Trojský kůň

Napsal: 18 lis 2011 23:19
od chris.h
Tak hlásí mi to, že mám vypnout rezidentní štíty u NODU, ale já ani za nic nemůžu přijít na to, jak je vypnout. Pořád mi to nejde, poradíte???