sitova karta se nepripoji k internetu+nefunkcni klavesnice
Napsal: 21 led 2012 10:07
Dobrý den,
žena si prohlédla azbukou psaný spam a zřejmě ta nahrála nějaký vir,avast ma deaktivivaný webový štít a nejde zapnout. našel tyto viry win64:Sirefef-A, Win32:Sirefef-KB, Win32: Sirefef-F, Win32:Trojan-gen, Win32:Bamital-AG, Win32:Zbooter-C
zasílám vytvořené logy.
Děkuji za pomoc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tobi at 2012-01-19 19:24:22
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 853 MB (6%) free of 13 GB
Total RAM: 511 MB (33% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Tobi\Data aplikací\Mozilla\Firefox\Profiles\9ssd5uko.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "2020Player_IKEA@2020Technologies.com:5.0.93.0, xmlfiller@software602.cz:3.16.2, {A0A87DB2-80BA-493a-B22F-FAFBAEA3E0A2}:0.3.7, {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.21, {A4732521-77D9-447E-A557-B279AC923F06}:0.6.7, {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2, wrc@avast.com:6.0.1367, {cc6ef5ab-35be-4300-bd07-d12850fc97ff}:4.0.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"wrc@avast.com"=C:\Program Files\Alwil Software\Avast5\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=D:\PROGRA~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=D:\PROGRA~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
xmlfiller@software602.cz
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
npCortona.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIFillerPlugin.xpt
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
npCortona.dll
npdeployJava1.dll
npfiller.dll
npnul32.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
plywood.jar
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Tobi\Data aplikací\Mozilla\Firefox\Profiles\9ssd5uko.default\extensions\
2020Player_IKEA@2020Technologies.com
staged-xpis
temp
xmlfiller@software602.cz
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
{20a82645-c095-46ed-80e3-08825760534b}
{37E4D8EA-8BDA-4831-8EA1-89053939A250}
{A0A87DB2-80BA-493a-B22F-FAFBAEA3E0A2}
{A4732521-77D9-447E-A557-B279AC923F06}
{cc6ef5ab-35be-4300-bd07-d12850fc97ff}
{FB5A4470-185E-442a-AF55-7F4669A5FF9F}
{FireCat-e3170330-0f65-11d9-9669-0800200c9a66}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-11-28 809040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - D:\PROGRA~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-18 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-18 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-11-28 809040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-08-25 339968]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-01-11 577536]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"avast"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-11-28 3744552]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"BCSSync"=D:\PROGRAMKY\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Advanced SystemCare 4"=C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe [2011-05-28 412560]
"Spyware Doctor"=C:\Documents and Settings\Tobi\Plocha\sdsetup_revwire207[1].exe -min []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ioloDelayModule]
C:\Program Files\iolo\System Mechanic Professional 6\delay.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [2003-05-08 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Tobi^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.0.lnk]
C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe []
C:\Documents and Settings\Tobi\Nabídka Start\Programy\Po spuštění
_uninst_87978010.lnk - C:\Documents and Settings\Tobi\Local Settings\Temp\_uninst_87978010.bat
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2004-08-25 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"G:\winbox.exe"="G:\winbox.exe:*:Enabled:winbox"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\PROGRAMKY\strong dc\StrongDC.exe"="D:\PROGRAMKY\strong dc\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\FileZilla FTP Client\filezilla.exe"="C:\Program Files\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla FTP Client"
"D:\PROGRAMKY\Archicad13\ArchiCAD.exe"="D:\PROGRAMKY\Archicad13\ArchiCAD.exe:*:Enabled:ArchiCAD 13.0.0 Component"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Průzkumník Windows"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Documents and Settings\Tobi\Local Settings\Temporary Internet Files\Content.IE5\9NBPGLCK\sdsetup_revwire207[1].exe"="C:\Documents and Settings\Tobi\Local Settings\Temporary Internet Files\Content.IE5\9NBPGLCK\sdsetup_revwire207[1].exe:*:Enabled:PC Tools Installer"
"C:\Documents and Settings\Tobi\Local Settings\Temp\is-C761Q.tmp\sdsetup_revwire207_aff_dl.tmp"="C:\Documents and Settings\Tobi\Local Settings\Temp\is-C761Q.tmp\sdsetup_revwire207_aff_dl.tmp:*:Enabled:Setup/Uninstall"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=serwvdrv.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"VIDC.HFYU"=huffyuv.dll
"VIDC.VIFP"=VFCodec.dll
"vidc.CDVC"=cdvccodc.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - open - NOTEPAD.EXE %1
.vbs - open - NOTEPAD.EXE %1
======List of files/folders created in the last 1 month======
2012-01-19 19:01:39 ----D---- C:\WINDOWS\LastGood
2012-01-19 19:00:47 ----A---- C:\TDSSKiller.2.7.5.0_19.01.2012_19.00.47_log.txt
2012-01-19 18:54:41 ----A---- C:\TDSSKiller.2.7.5.0_19.01.2012_18.54.41_log.txt
2012-01-19 18:53:42 ----D---- C:\Program Files\trend micro
2012-01-19 18:53:41 ----D---- C:\rsit
2012-01-19 18:51:19 ----A---- C:\WINDOWS\system32\drivers\TrueSight.sys
2012-01-16 21:33:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-01-16 21:31:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\PC Tools
2012-01-16 21:27:51 ----A---- C:\WINDOWS\ntbtlog.txt
2012-01-16 20:23:36 ----ASH---- C:\WINDOWS\system32\dds_log_trash.cmd
2012-01-11 14:07:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-01-11 14:06:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-01-11 14:02:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-01-11 13:56:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-01-11 13:56:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
======List of files/folders modified in the last 1 month======
2012-01-19 19:23:11 ----D---- C:\Program Files\Mozilla Firefox
2012-01-19 19:22:10 ----D---- C:\WINDOWS\Temp
2012-01-19 19:22:10 ----D---- C:\WINDOWS\system32\drivers
2012-01-19 19:15:36 ----D---- C:\WINDOWS
2012-01-19 19:06:53 ----D---- C:\WINDOWS\Prefetch
2012-01-19 19:03:14 ----SHD---- C:\System Volume Information
2012-01-19 19:01:47 ----HD---- C:\WINDOWS\inf
2012-01-19 19:01:37 ----D---- C:\WINDOWS\system32\CatRoot2
2012-01-19 19:00:21 ----AC---- C:\WINDOWS\NeroDigital.ini
2012-01-19 18:58:19 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-01-19 18:53:42 ----D---- C:\Program Files
2012-01-18 19:59:11 ----D---- C:\WINDOWS\system32
2012-01-18 07:57:48 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-01-17 20:27:30 ----SD---- C:\WINDOWS\Tasks
2012-01-17 20:27:30 ----D---- C:\WINDOWS\AutoKMS
2012-01-17 12:52:27 ----A---- C:\WINDOWS\KMSEmulator.exe
2012-01-15 13:43:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-01-14 19:46:42 ----D---- C:\Program Files\Mozilla Thunderbird
2012-01-11 16:26:23 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-11 16:26:17 ----RSD---- C:\WINDOWS\assembly
2012-01-11 14:07:06 ----A---- C:\WINDOWS\imsins.BAK
2012-01-11 14:02:39 ----A---- C:\WINDOWS\system32\MRT.exe
2012-01-11 14:02:07 ----SHD---- C:\WINDOWS\Installer
2012-01-11 14:02:07 ----HD---- C:\Config.Msi
2012-01-11 14:00:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-01-11 14:00:17 ----D---- C:\WINDOWS\WinSxS
2012-01-11 13:56:13 ----HD---- C:\WINDOWS\$hf_mig$
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2002-09-06 13568]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2005-01-20 88960]
R0 nvidesm;nvidesm; C:\WINDOWS\system32\drivers\nvidesm.sys [2002-11-13 20224]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-05-13 111808]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2003-09-06 6944]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-12-05 20640]
R0 RecAgent;RecAgent; C:\WINDOWS\system32\DRIVERS\RecAgent.sys [2004-08-03 13776]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 xmasbus;xmasbus; C:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-25 141184]
R0 xmasscsi;xmasscsi; C:\WINDOWS\System32\Drivers\xmasscsi.sys [2003-12-23 5248]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 cpuidlep;CpuIdle Pro System Driver; C:\WINDOWS\system32\drivers\cpuidlep.sys [2006-04-01 4484]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R1 mbmiodrvr;mbmiodrvr; \??\C:\WINDOWS\system32\mbmiodrvr.sys []
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2005-11-21 16512]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2005-04-21 10624]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey.sys [2006-11-22 72704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-17 3846848]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-08-25 787456]
R3 atinevxx;ATI WDM Rage Theater Video NSP; C:\WINDOWS\system32\DRIVERS\atinevxx.sys [2005-02-01 165888]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MVDCODEC;ATI WDM Specialized MVD Codec; C:\WINDOWS\system32\DRIVERS\atinmdxx.sys [2005-02-01 15360]
R3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys [2006-04-29 47360]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 .afd;.afd; \? []
S3 .i8042prt;.i8042prt; \? []
S3 .ipsec;.ipsec; \? []
S3 .meiudf;.meiudf; \? []
S3 .mrxsmb;.mrxsmb; \? []
S3 .netbt;.netbt; \? []
S3 .prodrv06;.prodrv06; \? []
S3 .serial;.serial; \? []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-11 391424]
S3 ATICDSDr;ATICDSDr; \??\C:\Program Files\ATI Technologies\ATI Control Panel\atiicdxx.sys []
S3 atinrvxx;ATI WDM Rage Theater Video; C:\WINDOWS\system32\DRIVERS\atinrvxx.sys [2003-01-21 102400]
S3 ATITool;ATITool; \??\E:\zaloha thunderbird\Skype\atitool.sys []
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
S3 ElbyDelay;ElbyDelay; C:\WINDOWS\System32\Drivers\ElbyDelay.sys [2005-04-12 4608]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-31 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-31 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-31 21568]
S3 kvpndev;Kerio VPN adapter; C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2005-07-26 66048]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 Mtlmnt5;Mtlmnt5; C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys [2004-08-03 126686]
S3 Mtlstrm;Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [2004-08-03 1309184]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 NtMtlFax;NtMtlFax; C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys [2004-08-03 180360]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2005-01-26 53376]
S3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2005-01-26 414336]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 Slntamr;Smart Link 56K Modem Driver; C:\WINDOWS\system32\DRIVERS\slntamr.sys [2004-08-03 404990]
S3 SlNtHal;SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [2004-08-03 95424]
S3 SlWdmSup;SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [2004-08-03 13240]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TrueSight;TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;Motorola USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 ZD1211U(OvisLink);OvisLink WL-5480USB WLAN USB Driver(OvisLink); C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-09-29 247296]
S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\ZDPNDIS5.SYS []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe [2011-05-28 353168]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2004-08-25 389120]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-11-28 44768]
R2 DVD-RAM_Service;DVD-RAM_Service; C:\WINDOWS\system32\DVDRAMSV.exe [2003-05-23 106496]
R2 GhostStartService;GhostStartService; C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe [2002-08-14 200704]
R2 HNetInfo FTP Server;HNetInfo FTP Server; C:\Program Files\HNetInfo2\HServer\startsrv.exe [2004-11-20 57344]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-08-18 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 ofcservice;Lpds; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SLService;SmartLinkService; C:\WINDOWS\system32\slserv.exe [2008-04-14 73796]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2004-08-25 516096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
RogueKiller V6.2.4 [01/12/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Tobi [Admin rights]
Mode: Scan -- Date : 01/19/2012 19:23:12
¤¤¤ Bad processes: 2 ¤¤¤
[BLACKLIST] setup_11.0.0.1245.x01_2012_01_18_22_41.exe -- G:\viry\setup_11.0.0.1245.x01_2012_01_18_22_41.exe -> KILLED [TermProc]
[ROGUE ST] 2149787.exe -- C:\DOCUME~1\Tobi\LOCALS~1\Temp\RarSFX0\2149787.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 7 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Spyware Doctor (C:\Documents and Settings\Tobi\Plocha\sdsetup_revwire207[1].exe -min) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-839522115-436374069-2146926659-1003[...]\Run : Spyware Doctor (C:\Documents and Settings\Tobi\Plocha\sdsetup_revwire207[1].exe -min) -> FOUND
[SUSP PATH] _uninst_87978010.lnk : C:\Documents and Settings\Tobi\Local Settings\Temp\_uninst_87978010.bat -> FOUND
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (219.93.174.108:553) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{724F97BB-5BE7-4E0F-A164-823B131CE347} : NameServer (212.158.128.2,212.158.128.3) -> FOUND
[DNS] HKLM\[...]\ControlSet003\Parameters\Interfaces\{724F97BB-5BE7-4E0F-A164-823B131CE347} : NameServer (212.158.128.2,212.158.128.3) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[277] : NtWriteVirtualMemory @ 0x8057F712 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977B52)
SSDT[267] : NtUnmapViewOfSection @ 0x8057A81E -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B552)
SSDT[258] : NtTerminateThread @ 0x80577F1F -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09779C8)
SSDT[257] : NtTerminateProcess @ 0x805839B9 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977A68)
SSDT[255] : NtSystemDebugControl @ 0x8064AA57 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AA3E)
SSDT[254] : NtSuspendThread @ 0x805E05AB -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097BA2A)
SSDT[253] : NtSuspendProcess @ 0x8062FF21 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B8F0)
SSDT[247] : NtSetValueKey @ 0x8057BC5B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976816)
SSDT[240] : NtSetSystemInformation @ 0x805A8349 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B7FE)
SSDT[237] : NtSetSecurityObject @ 0x8059D2BD -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097ADAA)
SSDT[230] : NtSetInformationToken @ 0x805A8E5C -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097A154)
SSDT[213] : NtSetContextThread @ 0x8062E33F -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977E38)
SSDT[210] : NtSecureConnectPort @ 0x80599040 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978B0E)
SSDT[207] : NtSaveKey @ 0x8064FB1A -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0975EAE)
SSDT[206] : NtResumeThread @ 0x80578E76 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097BBC8)
SSDT[204] : NtRestoreKey @ 0x8064FA19 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097628E)
SSDT[200] : NtRequestWaitReplyPort @ 0x8056DC86 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097A8B4)
SSDT[195] : NtReplyWaitReceivePort @ 0x8056BC24 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09796F2)
SSDT[194] : NtReplyPort @ 0x8057E67C -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097982C)
SSDT[193] : NtReplaceKey @ 0x8064FE82 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0975F16)
SSDT[192] : NtRenameKey @ 0x8064F526 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976C2C)
SSDT[180] : NtQueueApcThread @ 0x8058F954 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AFA0)
SSDT[177] : NtQueryValueKey @ 0x8056A419 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097699C)
SSDT[167] : NtQuerySection @ 0x8057EE6E -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B6AE)
SSDT[161] : NtQueryMultipleValueKey @ 0x8064F0A7 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976D72)
SSDT[160] : NtQueryKey @ 0x80573B86 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097713A)
SSDT[128] : NtOpenThread @ 0x8059323B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09777BE)
SSDT[126] : NtOpenSemaphore @ 0x805DD9AC -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09794C8)
SSDT[125] : NtOpenSection @ 0x8056E467 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B10E)
SSDT[122] : NtOpenProcess @ 0x80574AA9 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09778CC)
SSDT[120] : NtOpenMutant @ 0x80577676 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979288)
SSDT[119] : NtOpenKey @ 0x80568F68 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09766C0)
SSDT[116] : NtOpenFile @ 0x8056F7FF -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978016)
SSDT[114] : NtOpenEvent @ 0x8057FC98 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09793A8)
SSDT[111] : NtNotifyChangeKey @ 0x80593FAA -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09771CE)
SSDT[108] : NtMapViewOfSection @ 0x8057AC99 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B374)
SSDT[99] : NtLoadKey2 @ 0x805AF400 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09764EE)
SSDT[98] : NtLoadKey @ 0x805AF5C3 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09764DC)
SSDT[97] : NtLoadDriver @ 0x805A425D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AC0C)
SSDT[84] : NtFsControlFile @ 0x805770E0 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978500)
SSDT[73] : NtEnumerateValueKey @ 0x8057FB2B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09770A2)
SSDT[71] : NtEnumerateKey @ 0x80573E7D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097700A)
SSDT[68] : NtDuplicateObject @ 0x805748C2 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097BD26)
SSDT[66] : NtDeviceIoControlFile @ 0x805795B9 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09786F2)
SSDT[65] : NtDeleteValueKey @ 0x80595C1A -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976EBE)
SSDT[63] : NtDeleteKey @ 0x80597FFA -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976B0A)
SSDT[57] : NtDebugActiveProcess @ 0x8065BF7D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AB1A)
SSDT[56] : NtCreateWaitablePort @ 0x805DB3E4 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979162)
SSDT[53] : NtCreateThread @ 0x80578803 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977C1C)
SSDT[51] : NtCreateSemaphore @ 0x8057B80D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979432)
SSDT[50] : NtCreateSection @ 0x80565333 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977426)
SSDT[46] : NtCreatePort @ 0x805893C7 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09790CC)
SSDT[44] : NtCreateNamedPipeFile @ 0x80585619 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097727E)
SSDT[43] : NtCreateMutant @ 0x805775C8 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09791F8)
SSDT[41] : NtCreateKey @ 0x8057376F -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976500)
SSDT[37] : NtCreateFile @ 0x8056F864 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978270)
SSDT[35] : NtCreateEvent @ 0x80570022 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979312)
SSDT[31] : NtConnectPort @ 0x8059110B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978DC8)
SSDT[25] : NtClose @ 0x80567AED -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977F94)
SSDT[11] : NtAdjustPrivilegesToken @ 0x8059B554 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977690)
S_SSDT[552] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987CE8)
S_SSDT[549] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987C90)
S_SSDT[529] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0988698)
S_SSDT[502] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987EEE)
S_SSDT[491] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987FD2)
S_SSDT[476] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987E36)
S_SSDT[475] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987DE2)
S_SSDT[460] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987E8E)
S_SSDT[416] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987D96)
S_SSDT[414] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB098804A)
S_SSDT[383] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987D4A)
S_SSDT[378] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987F3C)
S_SSDT[312] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09882C6)
S_SSDT[307] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09887E6)
S_SSDT[292] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0988182)
S_SSDT[237] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB098825E)
S_SSDT[227] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09881EE)
S_SSDT[13] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0988118)
¤¤¤ Infection : ZeroAccess ¤¤¤
[ZeroAccess] (LOCKED) windir\NtUpdateKBxxxx present!
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 3272c7ebfa7a61b8aaa974765e9b6d54
[BSP] c21399dcc2413c7f81cfdaea07eba051 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 63 | Size: 14155 Mo
1 - [XXXXXX] UNKNW [VISIBLE] Offset (sectors): 27647865 | Size: 235901 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
+++++ PhysicalDrive1: +++++
--- User ---
[MBR] 566e4ce2aaab807a903a45caea1d6724
[BSP] 33a07a59d299ab4ea9f4ab0156f9d86f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32 [VISIBLE] Offset (sectors): 63 | Size: 4051 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
žena si prohlédla azbukou psaný spam a zřejmě ta nahrála nějaký vir,avast ma deaktivivaný webový štít a nejde zapnout. našel tyto viry win64:Sirefef-A, Win32:Sirefef-KB, Win32: Sirefef-F, Win32:Trojan-gen, Win32:Bamital-AG, Win32:Zbooter-C
zasílám vytvořené logy.
Děkuji za pomoc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tobi at 2012-01-19 19:24:22
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 853 MB (6%) free of 13 GB
Total RAM: 511 MB (33% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Tobi\Data aplikací\Mozilla\Firefox\Profiles\9ssd5uko.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "2020Player_IKEA@2020Technologies.com:5.0.93.0, xmlfiller@software602.cz:3.16.2, {A0A87DB2-80BA-493a-B22F-FAFBAEA3E0A2}:0.3.7, {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.21, {A4732521-77D9-447E-A557-B279AC923F06}:0.6.7, {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2, wrc@avast.com:6.0.1367, {cc6ef5ab-35be-4300-bd07-d12850fc97ff}:4.0.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"wrc@avast.com"=C:\Program Files\Alwil Software\Avast5\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=D:\PROGRA~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=D:\PROGRA~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
xmlfiller@software602.cz
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
npCortona.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIFillerPlugin.xpt
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
npCortona.dll
npdeployJava1.dll
npfiller.dll
npnul32.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
plywood.jar
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Tobi\Data aplikací\Mozilla\Firefox\Profiles\9ssd5uko.default\extensions\
2020Player_IKEA@2020Technologies.com
staged-xpis
temp
xmlfiller@software602.cz
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
{20a82645-c095-46ed-80e3-08825760534b}
{37E4D8EA-8BDA-4831-8EA1-89053939A250}
{A0A87DB2-80BA-493a-B22F-FAFBAEA3E0A2}
{A4732521-77D9-447E-A557-B279AC923F06}
{cc6ef5ab-35be-4300-bd07-d12850fc97ff}
{FB5A4470-185E-442a-AF55-7F4669A5FF9F}
{FireCat-e3170330-0f65-11d9-9669-0800200c9a66}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-11-28 809040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - D:\PROGRA~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-18 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-18 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-11-28 809040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-08-25 339968]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-01-11 577536]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"avast"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-11-28 3744552]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"BCSSync"=D:\PROGRAMKY\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Advanced SystemCare 4"=C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe [2011-05-28 412560]
"Spyware Doctor"=C:\Documents and Settings\Tobi\Plocha\sdsetup_revwire207[1].exe -min []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ioloDelayModule]
C:\Program Files\iolo\System Mechanic Professional 6\delay.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [2003-05-08 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Tobi^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.0.lnk]
C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe []
C:\Documents and Settings\Tobi\Nabídka Start\Programy\Po spuštění
_uninst_87978010.lnk - C:\Documents and Settings\Tobi\Local Settings\Temp\_uninst_87978010.bat
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2004-08-25 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"G:\winbox.exe"="G:\winbox.exe:*:Enabled:winbox"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\PROGRAMKY\strong dc\StrongDC.exe"="D:\PROGRAMKY\strong dc\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\FileZilla FTP Client\filezilla.exe"="C:\Program Files\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla FTP Client"
"D:\PROGRAMKY\Archicad13\ArchiCAD.exe"="D:\PROGRAMKY\Archicad13\ArchiCAD.exe:*:Enabled:ArchiCAD 13.0.0 Component"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Průzkumník Windows"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Documents and Settings\Tobi\Local Settings\Temporary Internet Files\Content.IE5\9NBPGLCK\sdsetup_revwire207[1].exe"="C:\Documents and Settings\Tobi\Local Settings\Temporary Internet Files\Content.IE5\9NBPGLCK\sdsetup_revwire207[1].exe:*:Enabled:PC Tools Installer"
"C:\Documents and Settings\Tobi\Local Settings\Temp\is-C761Q.tmp\sdsetup_revwire207_aff_dl.tmp"="C:\Documents and Settings\Tobi\Local Settings\Temp\is-C761Q.tmp\sdsetup_revwire207_aff_dl.tmp:*:Enabled:Setup/Uninstall"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=serwvdrv.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"VIDC.HFYU"=huffyuv.dll
"VIDC.VIFP"=VFCodec.dll
"vidc.CDVC"=cdvccodc.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - open - NOTEPAD.EXE %1
.vbs - open - NOTEPAD.EXE %1
======List of files/folders created in the last 1 month======
2012-01-19 19:01:39 ----D---- C:\WINDOWS\LastGood
2012-01-19 19:00:47 ----A---- C:\TDSSKiller.2.7.5.0_19.01.2012_19.00.47_log.txt
2012-01-19 18:54:41 ----A---- C:\TDSSKiller.2.7.5.0_19.01.2012_18.54.41_log.txt
2012-01-19 18:53:42 ----D---- C:\Program Files\trend micro
2012-01-19 18:53:41 ----D---- C:\rsit
2012-01-19 18:51:19 ----A---- C:\WINDOWS\system32\drivers\TrueSight.sys
2012-01-16 21:33:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-01-16 21:31:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\PC Tools
2012-01-16 21:27:51 ----A---- C:\WINDOWS\ntbtlog.txt
2012-01-16 20:23:36 ----ASH---- C:\WINDOWS\system32\dds_log_trash.cmd
2012-01-11 14:07:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-01-11 14:06:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-01-11 14:02:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-01-11 13:56:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-01-11 13:56:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
======List of files/folders modified in the last 1 month======
2012-01-19 19:23:11 ----D---- C:\Program Files\Mozilla Firefox
2012-01-19 19:22:10 ----D---- C:\WINDOWS\Temp
2012-01-19 19:22:10 ----D---- C:\WINDOWS\system32\drivers
2012-01-19 19:15:36 ----D---- C:\WINDOWS
2012-01-19 19:06:53 ----D---- C:\WINDOWS\Prefetch
2012-01-19 19:03:14 ----SHD---- C:\System Volume Information
2012-01-19 19:01:47 ----HD---- C:\WINDOWS\inf
2012-01-19 19:01:37 ----D---- C:\WINDOWS\system32\CatRoot2
2012-01-19 19:00:21 ----AC---- C:\WINDOWS\NeroDigital.ini
2012-01-19 18:58:19 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-01-19 18:53:42 ----D---- C:\Program Files
2012-01-18 19:59:11 ----D---- C:\WINDOWS\system32
2012-01-18 07:57:48 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-01-17 20:27:30 ----SD---- C:\WINDOWS\Tasks
2012-01-17 20:27:30 ----D---- C:\WINDOWS\AutoKMS
2012-01-17 12:52:27 ----A---- C:\WINDOWS\KMSEmulator.exe
2012-01-15 13:43:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-01-14 19:46:42 ----D---- C:\Program Files\Mozilla Thunderbird
2012-01-11 16:26:23 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-11 16:26:17 ----RSD---- C:\WINDOWS\assembly
2012-01-11 14:07:06 ----A---- C:\WINDOWS\imsins.BAK
2012-01-11 14:02:39 ----A---- C:\WINDOWS\system32\MRT.exe
2012-01-11 14:02:07 ----SHD---- C:\WINDOWS\Installer
2012-01-11 14:02:07 ----HD---- C:\Config.Msi
2012-01-11 14:00:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-01-11 14:00:17 ----D---- C:\WINDOWS\WinSxS
2012-01-11 13:56:13 ----HD---- C:\WINDOWS\$hf_mig$
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2002-09-06 13568]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2005-01-20 88960]
R0 nvidesm;nvidesm; C:\WINDOWS\system32\drivers\nvidesm.sys [2002-11-13 20224]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-05-13 111808]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2003-09-06 6944]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-12-05 20640]
R0 RecAgent;RecAgent; C:\WINDOWS\system32\DRIVERS\RecAgent.sys [2004-08-03 13776]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 xmasbus;xmasbus; C:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-25 141184]
R0 xmasscsi;xmasscsi; C:\WINDOWS\System32\Drivers\xmasscsi.sys [2003-12-23 5248]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 cpuidlep;CpuIdle Pro System Driver; C:\WINDOWS\system32\drivers\cpuidlep.sys [2006-04-01 4484]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R1 mbmiodrvr;mbmiodrvr; \??\C:\WINDOWS\system32\mbmiodrvr.sys []
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2005-11-21 16512]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2005-04-21 10624]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey.sys [2006-11-22 72704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-17 3846848]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-08-25 787456]
R3 atinevxx;ATI WDM Rage Theater Video NSP; C:\WINDOWS\system32\DRIVERS\atinevxx.sys [2005-02-01 165888]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MVDCODEC;ATI WDM Specialized MVD Codec; C:\WINDOWS\system32\DRIVERS\atinmdxx.sys [2005-02-01 15360]
R3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys [2006-04-29 47360]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 .afd;.afd; \? []
S3 .i8042prt;.i8042prt; \? []
S3 .ipsec;.ipsec; \? []
S3 .meiudf;.meiudf; \? []
S3 .mrxsmb;.mrxsmb; \? []
S3 .netbt;.netbt; \? []
S3 .prodrv06;.prodrv06; \? []
S3 .serial;.serial; \? []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-11 391424]
S3 ATICDSDr;ATICDSDr; \??\C:\Program Files\ATI Technologies\ATI Control Panel\atiicdxx.sys []
S3 atinrvxx;ATI WDM Rage Theater Video; C:\WINDOWS\system32\DRIVERS\atinrvxx.sys [2003-01-21 102400]
S3 ATITool;ATITool; \??\E:\zaloha thunderbird\Skype\atitool.sys []
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
S3 ElbyDelay;ElbyDelay; C:\WINDOWS\System32\Drivers\ElbyDelay.sys [2005-04-12 4608]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-31 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-31 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-31 21568]
S3 kvpndev;Kerio VPN adapter; C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2005-07-26 66048]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 Mtlmnt5;Mtlmnt5; C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys [2004-08-03 126686]
S3 Mtlstrm;Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [2004-08-03 1309184]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 NtMtlFax;NtMtlFax; C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys [2004-08-03 180360]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2005-01-26 53376]
S3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2005-01-26 414336]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 Slntamr;Smart Link 56K Modem Driver; C:\WINDOWS\system32\DRIVERS\slntamr.sys [2004-08-03 404990]
S3 SlNtHal;SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [2004-08-03 95424]
S3 SlWdmSup;SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [2004-08-03 13240]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TrueSight;TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;Motorola USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 ZD1211U(OvisLink);OvisLink WL-5480USB WLAN USB Driver(OvisLink); C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-09-29 247296]
S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\ZDPNDIS5.SYS []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe [2011-05-28 353168]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2004-08-25 389120]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-11-28 44768]
R2 DVD-RAM_Service;DVD-RAM_Service; C:\WINDOWS\system32\DVDRAMSV.exe [2003-05-23 106496]
R2 GhostStartService;GhostStartService; C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe [2002-08-14 200704]
R2 HNetInfo FTP Server;HNetInfo FTP Server; C:\Program Files\HNetInfo2\HServer\startsrv.exe [2004-11-20 57344]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-08-18 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 ofcservice;Lpds; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SLService;SmartLinkService; C:\WINDOWS\system32\slserv.exe [2008-04-14 73796]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2004-08-25 516096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
RogueKiller V6.2.4 [01/12/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Tobi [Admin rights]
Mode: Scan -- Date : 01/19/2012 19:23:12
¤¤¤ Bad processes: 2 ¤¤¤
[BLACKLIST] setup_11.0.0.1245.x01_2012_01_18_22_41.exe -- G:\viry\setup_11.0.0.1245.x01_2012_01_18_22_41.exe -> KILLED [TermProc]
[ROGUE ST] 2149787.exe -- C:\DOCUME~1\Tobi\LOCALS~1\Temp\RarSFX0\2149787.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 7 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Spyware Doctor (C:\Documents and Settings\Tobi\Plocha\sdsetup_revwire207[1].exe -min) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-839522115-436374069-2146926659-1003[...]\Run : Spyware Doctor (C:\Documents and Settings\Tobi\Plocha\sdsetup_revwire207[1].exe -min) -> FOUND
[SUSP PATH] _uninst_87978010.lnk : C:\Documents and Settings\Tobi\Local Settings\Temp\_uninst_87978010.bat -> FOUND
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (219.93.174.108:553) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{724F97BB-5BE7-4E0F-A164-823B131CE347} : NameServer (212.158.128.2,212.158.128.3) -> FOUND
[DNS] HKLM\[...]\ControlSet003\Parameters\Interfaces\{724F97BB-5BE7-4E0F-A164-823B131CE347} : NameServer (212.158.128.2,212.158.128.3) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[277] : NtWriteVirtualMemory @ 0x8057F712 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977B52)
SSDT[267] : NtUnmapViewOfSection @ 0x8057A81E -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B552)
SSDT[258] : NtTerminateThread @ 0x80577F1F -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09779C8)
SSDT[257] : NtTerminateProcess @ 0x805839B9 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977A68)
SSDT[255] : NtSystemDebugControl @ 0x8064AA57 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AA3E)
SSDT[254] : NtSuspendThread @ 0x805E05AB -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097BA2A)
SSDT[253] : NtSuspendProcess @ 0x8062FF21 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B8F0)
SSDT[247] : NtSetValueKey @ 0x8057BC5B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976816)
SSDT[240] : NtSetSystemInformation @ 0x805A8349 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B7FE)
SSDT[237] : NtSetSecurityObject @ 0x8059D2BD -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097ADAA)
SSDT[230] : NtSetInformationToken @ 0x805A8E5C -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097A154)
SSDT[213] : NtSetContextThread @ 0x8062E33F -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977E38)
SSDT[210] : NtSecureConnectPort @ 0x80599040 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978B0E)
SSDT[207] : NtSaveKey @ 0x8064FB1A -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0975EAE)
SSDT[206] : NtResumeThread @ 0x80578E76 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097BBC8)
SSDT[204] : NtRestoreKey @ 0x8064FA19 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097628E)
SSDT[200] : NtRequestWaitReplyPort @ 0x8056DC86 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097A8B4)
SSDT[195] : NtReplyWaitReceivePort @ 0x8056BC24 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09796F2)
SSDT[194] : NtReplyPort @ 0x8057E67C -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097982C)
SSDT[193] : NtReplaceKey @ 0x8064FE82 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0975F16)
SSDT[192] : NtRenameKey @ 0x8064F526 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976C2C)
SSDT[180] : NtQueueApcThread @ 0x8058F954 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AFA0)
SSDT[177] : NtQueryValueKey @ 0x8056A419 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097699C)
SSDT[167] : NtQuerySection @ 0x8057EE6E -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B6AE)
SSDT[161] : NtQueryMultipleValueKey @ 0x8064F0A7 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976D72)
SSDT[160] : NtQueryKey @ 0x80573B86 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097713A)
SSDT[128] : NtOpenThread @ 0x8059323B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09777BE)
SSDT[126] : NtOpenSemaphore @ 0x805DD9AC -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09794C8)
SSDT[125] : NtOpenSection @ 0x8056E467 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B10E)
SSDT[122] : NtOpenProcess @ 0x80574AA9 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09778CC)
SSDT[120] : NtOpenMutant @ 0x80577676 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979288)
SSDT[119] : NtOpenKey @ 0x80568F68 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09766C0)
SSDT[116] : NtOpenFile @ 0x8056F7FF -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978016)
SSDT[114] : NtOpenEvent @ 0x8057FC98 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09793A8)
SSDT[111] : NtNotifyChangeKey @ 0x80593FAA -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09771CE)
SSDT[108] : NtMapViewOfSection @ 0x8057AC99 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097B374)
SSDT[99] : NtLoadKey2 @ 0x805AF400 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09764EE)
SSDT[98] : NtLoadKey @ 0x805AF5C3 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09764DC)
SSDT[97] : NtLoadDriver @ 0x805A425D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AC0C)
SSDT[84] : NtFsControlFile @ 0x805770E0 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978500)
SSDT[73] : NtEnumerateValueKey @ 0x8057FB2B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09770A2)
SSDT[71] : NtEnumerateKey @ 0x80573E7D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097700A)
SSDT[68] : NtDuplicateObject @ 0x805748C2 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097BD26)
SSDT[66] : NtDeviceIoControlFile @ 0x805795B9 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09786F2)
SSDT[65] : NtDeleteValueKey @ 0x80595C1A -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976EBE)
SSDT[63] : NtDeleteKey @ 0x80597FFA -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976B0A)
SSDT[57] : NtDebugActiveProcess @ 0x8065BF7D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097AB1A)
SSDT[56] : NtCreateWaitablePort @ 0x805DB3E4 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979162)
SSDT[53] : NtCreateThread @ 0x80578803 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977C1C)
SSDT[51] : NtCreateSemaphore @ 0x8057B80D -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979432)
SSDT[50] : NtCreateSection @ 0x80565333 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977426)
SSDT[46] : NtCreatePort @ 0x805893C7 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09790CC)
SSDT[44] : NtCreateNamedPipeFile @ 0x80585619 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB097727E)
SSDT[43] : NtCreateMutant @ 0x805775C8 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09791F8)
SSDT[41] : NtCreateKey @ 0x8057376F -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0976500)
SSDT[37] : NtCreateFile @ 0x8056F864 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978270)
SSDT[35] : NtCreateEvent @ 0x80570022 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0979312)
SSDT[31] : NtConnectPort @ 0x8059110B -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0978DC8)
SSDT[25] : NtClose @ 0x80567AED -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977F94)
SSDT[11] : NtAdjustPrivilegesToken @ 0x8059B554 -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0977690)
S_SSDT[552] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987CE8)
S_SSDT[549] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987C90)
S_SSDT[529] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0988698)
S_SSDT[502] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987EEE)
S_SSDT[491] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987FD2)
S_SSDT[476] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987E36)
S_SSDT[475] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987DE2)
S_SSDT[460] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987E8E)
S_SSDT[416] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987D96)
S_SSDT[414] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB098804A)
S_SSDT[383] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987D4A)
S_SSDT[378] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0987F3C)
S_SSDT[312] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09882C6)
S_SSDT[307] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09887E6)
S_SSDT[292] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0988182)
S_SSDT[237] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB098825E)
S_SSDT[227] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB09881EE)
S_SSDT[13] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\2149787drv.sys @ 0xB0988118)
¤¤¤ Infection : ZeroAccess ¤¤¤
[ZeroAccess] (LOCKED) windir\NtUpdateKBxxxx present!
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 3272c7ebfa7a61b8aaa974765e9b6d54
[BSP] c21399dcc2413c7f81cfdaea07eba051 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 63 | Size: 14155 Mo
1 - [XXXXXX] UNKNW [VISIBLE] Offset (sectors): 27647865 | Size: 235901 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
+++++ PhysicalDrive1: +++++
--- User ---
[MBR] 566e4ce2aaab807a903a45caea1d6724
[BSP] 33a07a59d299ab4ea9f4ab0156f9d86f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32 [VISIBLE] Offset (sectors): 63 | Size: 4051 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt