Stránka 1 z 2

win32/sinoval.gen!y

Napsal: 02 srp 2012 05:39
od jaroslav.24
Dobrý den. Prosím o pomoc s virem win32/sinoval.gen!y
Ale asi není sám ,drží se v páru potvůrky.
Můj antivir ho najde izoluje a vyžaduje restart a takto se to opakuje neustále dokola.


Logfile of random's system information tool 1.09 (written by random/random)
Run by Kryton at 2012-08-02 06:31:16
Microsoft Windows XP Home Edition Service Pack 3
System drive D: has 97 GB (63%) free of 153 GB
Total RAM: 1023 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:31:26, on 2.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
d:\Program Files\Microsoft Security Client\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\Mixer.exe
D:\Program Files\Microsoft Security Client\msseces.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Documents and Settings\Kryton\Plocha\RSIT.exe
D:\Program Files\trend micro\Kryton.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [MSC] "d:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HP Software Update] "D:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "d:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "d:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7943405625
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe

--
End of file - 5209 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Java\jre6\bin\ssv.dll [2012-03-02 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-03-02 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-03-02 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=D:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"Adobe ARM"=D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"C-Media Mixer"=Mixer.exe /startup []
"ATICCC"=D:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [2006-09-25 90112]
"MSC"=d:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]
"KernelFaultCheck"=D:\WINDOWS\system32\dumprep 0 -k []
"HP Software Update"=D:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-02-12 49152]
"HP Component Manager"=D:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Rychlé spuštění aplikace HP Image Zone.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2006-12-17 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\ICQ7.7\ICQ.exe"="D:\Program Files\ICQ7.7\ICQ.exe:*:Enabled:ICQ7.7"
"D:\Program Files\Diablo II\Diablo II.exe"="D:\Program Files\Diablo II\Diablo II.exe:*:Enabled:Diablo II - Lord of Destruction"
"D:\Program Files\VideoLAN\VLC\vlc.exe"="D:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player 2.0.0"
"D:\Documents and Settings\Kryton\Plocha\HRY\DOTA\Warcraft III\w3l.exe"="D:\Documents and Settings\Kryton\Plocha\HRY\DOTA\Warcraft III\w3l.exe:*:Enabled:w3l"
"D:\Program Files\Diablo II\Game.exe"="D:\Program Files\Diablo II\Game.exe:*:Enabled:Diablo II"
"D:\WINDOWS\system32\dpnsvr.exe"="D:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\HRY\Lionheart\Lionheart.exe"="C:\HRY\Lionheart\Lionheart.exe:*:Enabled:Lionheart"
"D:\Program Files\PANDORA.TV\PanService\PandoraService.exe"="D:\Program Files\PANDORA.TV\PanService\PandoraService.exe:*:Enabled:PandoraService"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\ICQ7.7\ICQ.exe"="D:\Program Files\ICQ7.7\ICQ.exe:*:Enabled:ICQ7.7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=D:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=D:\WINDOWS\system32\l3codeca.acm
"vidc.VP60"=D:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=D:\WINDOWS\system32\vp6vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.LEAD"=LCODCCMP.DLL

======List of files/folders created in the last 1 month======

2012-08-02 06:31:16 ----D---- D:\rsit
2012-08-02 06:29:07 ----A---- D:\WINDOWS\system32\drivers\urhbyldj.sys
2012-07-15 11:46:57 ----D---- D:\Program Files\Common Files\HP
2012-07-15 11:44:00 ----D---- D:\Program Files\Hewlett-Packard
2012-07-15 11:43:59 ----D---- D:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2012-07-15 11:37:02 ----N---- D:\WINDOWS\hpomdl04.dat
2012-07-15 11:37:02 ----A---- D:\WINDOWS\hpoins04.dat
2012-07-15 11:36:23 ----A---- D:\WINDOWS\system32\hpovst08.dll
2012-07-15 11:36:22 ----A---- D:\WINDOWS\system32\hpotscl.dll
2012-07-15 11:36:09 ----A---- D:\WINDOWS\system32\hpzsnt10.dll
2012-07-15 11:15:28 ----A---- D:\WINDOWS\HP_48BitScanUpdatePatch.ini
2012-07-11 20:33:05 ----HDC---- D:\WINDOWS\$NtUninstallKB2691442$
2012-07-11 20:32:55 ----HDC---- D:\WINDOWS\$NtUninstallKB2718523$
2012-07-11 20:32:48 ----HDC---- D:\WINDOWS\$NtUninstallKB2655992$
2012-07-11 20:32:39 ----HDC---- D:\WINDOWS\$NtUninstallKB2719985$
2012-07-11 20:29:31 ----HDC---- D:\WINDOWS\$NtUninstallKB2698365$
2012-07-07 21:29:26 ----A---- D:\WINDOWS\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2012-07-07 21:08:09 ----A---- D:\WINDOWS\eReg.dat
2012-07-07 21:08:00 ----D---- D:\Program Files\Maxis
2012-07-06 16:51:22 ----D---- D:\WINDOWS\Minidump
2012-07-06 16:01:05 ----A---- D:\WINDOWS\system32\drivers\AegisP.sys
2012-07-06 16:00:52 ----A---- D:\WINDOWS\system32\drivers\rt73.sys
2012-07-06 16:00:39 ----D---- D:\Program Files\EDIMAX

======List of files/folders modified in the last 1 month======

2012-08-02 06:31:23 ----D---- D:\Program Files\trend micro
2012-08-02 06:31:22 ----D---- D:\WINDOWS\Prefetch
2012-08-02 06:29:07 ----D---- D:\WINDOWS\system32\drivers
2012-08-02 06:28:33 ----D---- D:\WINDOWS\Temp
2012-08-02 06:25:47 ----D---- D:\WINDOWS\system32\CatRoot2
2012-08-02 06:25:37 ----D---- D:\WINDOWS
2012-08-02 06:23:10 ----A---- D:\WINDOWS\SchedLgU.Txt
2012-08-01 19:36:56 ----A---- D:\WINDOWS\win.ini
2012-08-01 19:36:56 ----A---- D:\WINDOWS\system.ini
2012-08-01 19:06:41 ----D---- D:\WINDOWS\system32
2012-07-30 19:21:21 ----A---- D:\Documents and Settings\Kryton\Data aplikací\trueburner.ini
2012-07-29 11:43:18 ----A---- D:\WINDOWS\NeroDigital.ini
2012-07-28 08:16:50 ----D---- D:\Documents and Settings\Kryton\Data aplikací\ICQ
2012-07-27 13:36:16 ----SD---- D:\WINDOWS\Tasks
2012-07-27 13:36:03 ----A---- D:\WINDOWS\system32\FlashPlayerApp.exe
2012-07-22 16:29:23 ----RSHDC---- D:\WINDOWS\system32\dllcache
2012-07-22 16:29:17 ----HD---- D:\WINDOWS\inf
2012-07-21 17:44:40 ----D---- D:\WINDOWS\system32\CatRoot
2012-07-21 17:31:47 ----RD---- D:\Program Files
2012-07-21 17:30:07 ----D---- D:\Program Files\Outlook Express
2012-07-21 17:30:07 ----D---- D:\Program Files\Common Files\System
2012-07-21 17:30:06 ----D---- D:\WINDOWS\system32\Restore
2012-07-21 17:30:06 ----D---- D:\Program Files\Windows Media Player
2012-07-21 17:30:06 ----D---- D:\Program Files\Movie Maker
2012-07-21 17:30:05 ----D---- D:\WINDOWS\system32\usmt
2012-07-21 17:30:05 ----D---- D:\Program Files\Windows NT
2012-07-21 17:30:05 ----D---- D:\Program Files\Internet Explorer
2012-07-21 17:30:04 ----D---- D:\WINDOWS\srchasst
2012-07-21 17:27:56 ----RSD---- D:\WINDOWS\Fonts
2012-07-20 08:24:58 ----D---- D:\Program Files\The KMPlayer
2012-07-17 19:18:06 ----SHD---- D:\WINDOWS\Installer
2012-07-15 12:50:24 ----HD---- D:\Config.Msi
2012-07-15 11:49:19 ----RSD---- D:\WINDOWS\assembly
2012-07-15 11:47:22 ----D---- D:\WINDOWS\WinSxS
2012-07-15 11:46:57 ----D---- D:\Program Files\Common Files
2012-07-15 11:43:59 ----D---- D:\Program Files\HP
2012-07-15 11:43:09 ----SD---- D:\Documents and Settings\Kryton\Data aplikací\Microsoft
2012-07-15 11:40:03 ----D---- D:\WINDOWS\twain_32
2012-07-12 16:01:23 ----D---- D:\WINDOWS\Debug
2012-07-11 20:32:54 ----HD---- D:\WINDOWS\$hf_mig$
2012-07-11 20:29:44 ----A---- D:\WINDOWS\system32\MRT.exe
2012-07-08 19:38:15 ----D---- D:\Documents and Settings\Kryton\Data aplikací\vlc
2012-07-06 16:00:52 ----DC---- D:\WINDOWS\system32\DRVSTORE
2012-07-06 16:00:38 ----HD---- D:\Program Files\InstallShield Installation Information

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; D:\WINDOWS\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 sptd;sptd; D:\WINDOWS\System32\Drivers\sptd.sys [2012-01-29 664064]
R0 uagp35;Filtr Microsoft AGPv3.5; D:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R1 AmdK7;Ovladač procesoru AMD K7; D:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; D:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2012-07-06 21361]
R3 ati2mtag;ati2mtag; D:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-12-17 1918464]
R3 cmpci;C-Media PCI Audio Driver (WDM); D:\WINDOWS\system32\drivers\cmaudio.sys [2002-11-18 377358]
R3 dtscsi;dtscsi; D:\WINDOWS\System32\Drivers\dtscsi.sys [2012-01-29 223128]
R3 RT73;RT73 USB Wireless LAN Card Driver; D:\WINDOWS\system32\DRIVERS\rt73.sys [2008-01-15 459520]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; D:\WINDOWS\system32\DRIVERS\sisnic.sys [2004-08-04 32768]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; D:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 xcpip;Ovladač protokolu TCP/IP; D:\WINDOWS\system32\drivers\xcpip.sys []
R3 xpsec;Ovladač IPSEC; D:\WINDOWS\system32\drivers\xpsec.sys []
S1 urhbyldj;urhbyldj; \??\D:\WINDOWS\system32\drivers\urhbyldj.sys []
S3 gda2amy7.sys;gda2amy7.sys; \??\D:\WINDOWS\system32\drivers\gda2amy7.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; D:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-21 51088]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; D:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-21 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; D:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-21 21744]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\D:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\D:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\D:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\D:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\D:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\D:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\system32\Ati2evxx.exe [2006-12-17 434176]
R2 MsMpSvc;Microsoft Antimalware Service; d:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
S2 ATI Smart;ATI Smart; D:\WINDOWS\system32\ati2sgag.exe [2006-12-20 520192]
S2 gupdate;Služba Google Update (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-27 136176]
S3 aspnet_state;Stavová služba ASP.NET; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); D:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-27 136176]
S3 idsvc;Windows CardSpace; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; D:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
S3 WinRM;Windows Remote Management (WS-Management); D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 06:04
od vyosek
Zdravim a pekny den preji :)

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 06:38
od jaroslav.24
Přeskočeno - dokončeno - vloženo


07:31:46.0562 1172 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
07:31:46.0968 1172 ============================================================
07:31:46.0968 1172 Current date / time: 2012/08/02 07:31:46.0968
07:31:46.0968 1172 SystemInfo:
07:31:46.0968 1172
07:31:46.0968 1172 OS Version: 5.1.2600 ServicePack: 3.0
07:31:46.0968 1172 Product type: Workstation
07:31:46.0968 1172 ComputerName: JARDA
07:31:46.0968 1172 UserName: Kryton
07:31:46.0968 1172 Windows directory: D:\WINDOWS
07:31:46.0968 1172 System windows directory: D:\WINDOWS
07:31:46.0968 1172 Processor architecture: Intel x86
07:31:46.0968 1172 Number of processors: 1
07:31:46.0968 1172 Page size: 0x1000
07:31:46.0968 1172 Boot type: Normal boot
07:31:46.0968 1172 ============================================================
07:31:48.0656 1172 Drive \Device\Harddisk0\DR0 - Size: 0x4A94F0000 (18.65 Gb), SectorSize: 0x200, Cylinders: 0x982, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
07:31:48.0656 1172 Drive \Device\Harddisk1\DR1 - Size: 0x25432CDE00 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
07:31:48.0656 1172 ============================================================
07:31:48.0656 1172 \Device\Harddisk0\DR0:
07:31:48.0671 1172 MBR partitions:
07:31:48.0671 1172 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2546802
07:31:48.0671 1172 \Device\Harddisk1\DR1:
07:31:48.0671 1172 MBR partitions:
07:31:48.0671 1172 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1
07:31:48.0671 1172 ============================================================
07:31:48.0703 1172 C: <-> \Device\Harddisk0\DR0\Partition0
07:31:48.0718 1172 D: <-> \Device\Harddisk1\DR1\Partition0
07:31:48.0718 1172 ============================================================
07:31:48.0718 1172 Initialize success
07:31:48.0718 1172 ============================================================
07:32:37.0687 2664 ============================================================
07:32:37.0687 2664 Scan started
07:32:37.0687 2664 Mode: Manual; SigCheck; TDLFS;
07:32:37.0687 2664 ============================================================
07:32:38.0062 2664 6to4 (d76e9f5a991458a9f7e28395479b3150) D:\WINDOWS\System32\6to4svc.dll
07:32:38.0281 2664 6to4 - ok
07:32:38.0312 2664 Abiosdsk - ok
07:32:38.0328 2664 abp480n5 - ok
07:32:38.0375 2664 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) D:\WINDOWS\system32\DRIVERS\ACPI.sys
07:32:39.0062 2664 ACPI - ok
07:32:39.0109 2664 ACPIEC (afdff022a01f0b11c776f0860c3b282f) D:\WINDOWS\system32\drivers\ACPIEC.sys
07:32:39.0437 2664 ACPIEC - ok
07:32:39.0453 2664 adpu160m - ok
07:32:39.0484 2664 aec (8bed39e3c35d6a489438b8141717a557) D:\WINDOWS\system32\drivers\aec.sys
07:32:39.0796 2664 aec - ok
07:32:39.0828 2664 AegisP (023867b6606fbabcdd52e089c4a507da) D:\WINDOWS\system32\DRIVERS\AegisP.sys
07:32:39.0859 2664 AegisP ( UnsignedFile.Multi.Generic ) - warning
07:32:39.0859 2664 AegisP - detected UnsignedFile.Multi.Generic (1)
07:32:39.0906 2664 AFD (1e44bc1e83d8fd2305f8d452db109cf9) D:\WINDOWS\System32\drivers\afd.sys
07:32:39.0968 2664 AFD - ok
07:32:39.0984 2664 Aha154x - ok
07:32:40.0015 2664 aic78u2 - ok
07:32:40.0031 2664 aic78xx - ok
07:32:40.0062 2664 Alerter (e0a6fa244b8624d78fe5ff6f56a33bae) D:\WINDOWS\system32\alrsvc.dll
07:32:40.0359 2664 Alerter - ok
07:32:40.0406 2664 ALG (88842de939a827577bf24243699ac80a) D:\WINDOWS\System32\alg.exe
07:32:40.0531 2664 ALG - ok
07:32:40.0546 2664 AliIde - ok
07:32:40.0578 2664 AmdK7 (3980814f8027d27ea003e2e3d9d4f604) D:\WINDOWS\system32\DRIVERS\amdk7.sys
07:32:40.0843 2664 AmdK7 - ok
07:32:40.0859 2664 amsint - ok
07:32:40.0875 2664 AppMgmt - ok
07:32:40.0906 2664 asc - ok
07:32:40.0921 2664 asc3350p - ok
07:32:40.0953 2664 asc3550 - ok
07:32:41.0046 2664 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
07:32:41.0093 2664 aspnet_state - ok
07:32:41.0125 2664 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) D:\WINDOWS\system32\DRIVERS\asyncmac.sys
07:32:41.0421 2664 AsyncMac - ok
07:32:41.0453 2664 atapi (9f3a2f5aa6875c72bf062c712cfa2674) D:\WINDOWS\system32\DRIVERS\atapi.sys
07:32:41.0796 2664 atapi - ok
07:32:41.0812 2664 Atdisk - ok
07:32:41.0890 2664 Ati HotKey Poller (c27a0a876e7277428ab894cd58600686) D:\WINDOWS\system32\Ati2evxx.exe
07:32:42.0015 2664 Ati HotKey Poller - ok
07:32:42.0109 2664 ATI Smart (bfbe2f559eba2aaff58235760fc1ecba) D:\WINDOWS\system32\ati2sgag.exe
07:32:42.0187 2664 ATI Smart ( UnsignedFile.Multi.Generic ) - warning
07:32:42.0187 2664 ATI Smart - detected UnsignedFile.Multi.Generic (1)
07:32:42.0343 2664 ati2mtag (633d22a45283762dc05989751cc1397c) D:\WINDOWS\system32\DRIVERS\ati2mtag.sys
07:32:42.0609 2664 ati2mtag - ok
07:32:42.0718 2664 Atmarpc (9916c1225104ba14794209cfa8012159) D:\WINDOWS\system32\DRIVERS\atmarpc.sys
07:32:43.0015 2664 Atmarpc - ok
07:32:43.0046 2664 AudioSrv (de31b88962a8645dba5a37b993e7b0f1) D:\WINDOWS\System32\audiosrv.dll
07:32:43.0437 2664 AudioSrv - ok
07:32:43.0484 2664 audstub (d9f724aa26c010a217c97606b160ed68) D:\WINDOWS\system32\DRIVERS\audstub.sys
07:32:43.0812 2664 audstub - ok
07:32:43.0843 2664 Beep (da1f27d85e0d1525f6621372e7b685e9) D:\WINDOWS\system32\drivers\Beep.sys
07:32:44.0218 2664 Beep - ok
07:32:44.0265 2664 BITS (19395d092fd85ddc2d9c7729cf5a2ac8) D:\WINDOWS\system32\qmgr.dll
07:32:44.0640 2664 BITS - ok
07:32:44.0671 2664 Browser (249276d3ef1e74b992299cb96099e4d7) D:\WINDOWS\System32\browser.dll
07:32:45.0046 2664 Browser - ok
07:32:45.0078 2664 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) D:\WINDOWS\system32\drivers\cbidf2k.sys
07:32:45.0484 2664 cbidf2k - ok
07:32:45.0500 2664 cd20xrnt - ok
07:32:45.0531 2664 Cdaudio (c1b486a7658353d33a10cc15211a873b) D:\WINDOWS\system32\drivers\Cdaudio.sys
07:32:45.0921 2664 Cdaudio - ok
07:32:45.0953 2664 Cdfs (c885b02847f5d2fd45a24e219ed93b32) D:\WINDOWS\system32\drivers\Cdfs.sys
07:32:46.0296 2664 Cdfs - ok
07:32:46.0328 2664 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) D:\WINDOWS\system32\DRIVERS\cdrom.sys
07:32:46.0718 2664 Cdrom - ok
07:32:46.0750 2664 cebdpdcw (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\cebdpdcw.sys
07:32:46.0859 2664 cebdpdcw - ok
07:32:46.0890 2664 Changer - ok
07:32:46.0921 2664 CiSvc (e390dc1d7c461d7d56ec53402f329928) D:\WINDOWS\system32\cisvc.exe
07:32:47.0281 2664 CiSvc - ok
07:32:47.0312 2664 ClipSrv (064507a8dfa8c5c7e2ffddd3e6f424fa) D:\WINDOWS\system32\clipsrv.exe
07:32:47.0671 2664 ClipSrv - ok
07:32:47.0734 2664 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
07:32:47.0812 2664 clr_optimization_v2.0.50727_32 - ok
07:32:47.0843 2664 CmdIde - ok
07:32:47.0906 2664 cmpci (e5842ccf0953d3d46d5e26427b67e901) D:\WINDOWS\system32\drivers\cmaudio.sys
07:32:48.0015 2664 cmpci - ok
07:32:48.0031 2664 COMSysApp - ok
07:32:48.0078 2664 Cpqarray - ok
07:32:48.0109 2664 CryptSvc (f3ab0933cbd166d271992f411c27ccaf) D:\WINDOWS\System32\cryptsvc.dll
07:32:48.0453 2664 CryptSvc - ok
07:32:48.0468 2664 dac2w2k - ok
07:32:48.0500 2664 dac960nt - ok
07:32:48.0562 2664 DcomLaunch (be27674d1cbc3214aec84b4336a38bbf) D:\WINDOWS\system32\rpcss.dll
07:32:48.0625 2664 DcomLaunch - ok
07:32:48.0671 2664 Dhcp (8c9a53e285ac5e6704844d0459ec85be) D:\WINDOWS\System32\dhcpcsvc.dll
07:32:49.0046 2664 Dhcp - ok
07:32:49.0078 2664 Disk (044452051f3e02e7963599fc8f4f3e25) D:\WINDOWS\system32\DRIVERS\disk.sys
07:32:49.0437 2664 Disk - ok
07:32:49.0453 2664 dmadmin - ok
07:32:49.0546 2664 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) D:\WINDOWS\system32\drivers\dmboot.sys
07:32:49.0921 2664 dmboot - ok
07:32:49.0953 2664 dmio (fff1720af51171f32f1ead5cf71f2810) D:\WINDOWS\system32\drivers\dmio.sys
07:32:50.0375 2664 dmio - ok
07:32:50.0406 2664 dmload (e9317282a63ca4d188c0df5e09c6ac5f) D:\WINDOWS\system32\drivers\dmload.sys
07:32:50.0796 2664 dmload - ok
07:32:50.0828 2664 dmserver (2bfefe9e865655a76982f050450b9591) D:\WINDOWS\System32\dmserver.dll
07:32:51.0218 2664 dmserver - ok
07:32:51.0265 2664 DMusic (8a208dfcf89792a484e76c40e5f50b45) D:\WINDOWS\system32\drivers\DMusic.sys
07:32:51.0609 2664 DMusic - ok
07:32:51.0656 2664 Dnscache (dfaa406bf19f4ee806a6f8d4342137f7) D:\WINDOWS\System32\dnsrslvr.dll
07:32:51.0703 2664 Dnscache - ok
07:32:51.0750 2664 Dot3svc (4a3e2bd20157a0946751229e92eb8621) D:\WINDOWS\System32\dot3svc.dll
07:32:52.0046 2664 Dot3svc - ok
07:32:52.0062 2664 dpti2o - ok
07:32:52.0140 2664 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) D:\WINDOWS\system32\drivers\drmkaud.sys
07:32:52.0468 2664 drmkaud - ok
07:32:52.0546 2664 dtscsi (6461e57bb51a848aae26f52427b7cf9e) D:\WINDOWS\System32\Drivers\dtscsi.sys
07:32:52.0546 2664 Suspicious file (NoAccess): D:\WINDOWS\System32\Drivers\dtscsi.sys. md5: 6461e57bb51a848aae26f52427b7cf9e
07:32:52.0546 2664 dtscsi ( LockedFile.Multi.Generic ) - warning
07:32:52.0546 2664 dtscsi - detected LockedFile.Multi.Generic (1)
07:32:52.0578 2664 EapHost (0887d9c2be8d940778cad1e3b85f2a41) D:\WINDOWS\System32\eapsvc.dll
07:32:52.0937 2664 EapHost - ok
07:32:52.0968 2664 ERSvc (a2a4912798f2be706abadd3d30800d16) D:\WINDOWS\System32\ersvc.dll
07:32:53.0343 2664 ERSvc - ok
07:32:53.0390 2664 Eventlog (9ef697af07bb8dd82c3b02ca953a95b7) D:\WINDOWS\system32\services.exe
07:32:53.0437 2664 Eventlog - ok
07:32:53.0500 2664 EventSystem (a371f11ef07653591c8de26afb13ce7f) D:\WINDOWS\system32\es.dll
07:32:53.0562 2664 EventSystem - ok
07:32:53.0609 2664 Fastfat (38d332a6d56af32635675f132548343e) D:\WINDOWS\system32\drivers\Fastfat.sys
07:32:53.0906 2664 Fastfat - ok
07:32:53.0953 2664 FastUserSwitchingCompatibility (ee9a2b9ea968a792a053c9d1a86bf870) D:\WINDOWS\System32\shsvcs.dll
07:32:54.0000 2664 FastUserSwitchingCompatibility - ok
07:32:54.0046 2664 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) D:\WINDOWS\system32\DRIVERS\fdc.sys
07:32:54.0406 2664 Fdc - ok
07:32:54.0437 2664 Fips (ac366695a0796560aa37215ad5762aaf) D:\WINDOWS\system32\drivers\Fips.sys
07:32:54.0812 2664 Fips - ok
07:32:54.0843 2664 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) D:\WINDOWS\system32\DRIVERS\flpydisk.sys
07:32:55.0156 2664 Flpydisk - ok
07:32:55.0203 2664 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) D:\WINDOWS\system32\drivers\fltmgr.sys
07:32:55.0531 2664 FltMgr - ok
07:32:55.0609 2664 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
07:32:55.0640 2664 FontCache3.0.0.0 - ok
07:32:55.0671 2664 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) D:\WINDOWS\system32\drivers\Fs_Rec.sys
07:32:56.0109 2664 Fs_Rec - ok
07:32:56.0156 2664 Ftdisk (4e664d8541db4a66b73a24257e322e1f) D:\WINDOWS\system32\DRIVERS\ftdisk.sys
07:32:56.0437 2664 Ftdisk - ok
07:32:56.0468 2664 gameenum (065639773d8b03f33577f6cdaea21063) D:\WINDOWS\system32\DRIVERS\gameenum.sys
07:32:56.0828 2664 gameenum - ok
07:32:56.0843 2664 gda2amy7.sys - ok
07:32:56.0890 2664 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) D:\WINDOWS\system32\DRIVERS\msgpc.sys
07:32:57.0250 2664 Gpc - ok
07:32:57.0359 2664 gupdate (f02a533f517eb38333cb12a9e8963773) D:\Program Files\Google\Update\GoogleUpdate.exe
07:32:57.0406 2664 gupdate - ok
07:32:57.0421 2664 gupdatem (f02a533f517eb38333cb12a9e8963773) D:\Program Files\Google\Update\GoogleUpdate.exe
07:32:57.0453 2664 gupdatem - ok
07:32:57.0500 2664 helpsvc (fcfe31fb75f8a6295b6b0af87a626282) D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
07:32:57.0890 2664 helpsvc - ok
07:32:57.0906 2664 HidServ - ok
07:32:57.0968 2664 hkmsvc (7a6b320928f86bc851530d63c82965d9) D:\WINDOWS\System32\kmsvc.dll
07:32:58.0359 2664 hkmsvc - ok
07:32:58.0375 2664 hpn - ok
07:32:58.0421 2664 HPZid412 (5faba4775d4c61e55ec669d643ffc71f) D:\WINDOWS\system32\DRIVERS\HPZid412.sys
07:32:58.0484 2664 HPZid412 - ok
07:32:58.0515 2664 HPZipr12 (a3c43980ee1f1beac778b44ea65dbdd4) D:\WINDOWS\system32\DRIVERS\HPZipr12.sys
07:32:58.0578 2664 HPZipr12 - ok
07:32:58.0625 2664 HPZius12 (2906949bd4e206f2bb0dd1896ce9f66f) D:\WINDOWS\system32\DRIVERS\HPZius12.sys
07:32:58.0687 2664 HPZius12 - ok
07:32:58.0750 2664 HTTP (f80a415ef82cd06ffaf0d971528ead38) D:\WINDOWS\system32\Drivers\HTTP.sys
07:32:58.0796 2664 HTTP - ok
07:32:58.0828 2664 HTTPFilter (58fe2f2da3bc5573f4a35b3760d3125f) D:\WINDOWS\System32\w3ssl.dll
07:32:59.0125 2664 HTTPFilter - ok
07:32:59.0156 2664 i2omgmt - ok
07:32:59.0171 2664 i2omp - ok
07:32:59.0218 2664 i8042prt (c528e27945367191e7bae364930b6932) D:\WINDOWS\system32\DRIVERS\i8042prt.sys
07:32:59.0578 2664 i8042prt - ok
07:32:59.0687 2664 idsvc (c01ac32dc5c03076cfb852cb5da5229c) d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
07:32:59.0796 2664 idsvc - ok
07:32:59.0843 2664 Imapi (083a052659f5310dd8b6a6cb05edcf8e) D:\WINDOWS\system32\DRIVERS\imapi.sys
07:33:00.0187 2664 Imapi - ok
07:33:00.0234 2664 ImapiService (f7b93aafad33b2320954c17e26c8d361) D:\WINDOWS\system32\imapi.exe
07:33:00.0546 2664 ImapiService - ok
07:33:00.0578 2664 ini910u - ok
07:33:00.0609 2664 IntelIde - ok
07:33:00.0656 2664 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) D:\WINDOWS\system32\drivers\ip6fw.sys
07:33:01.0046 2664 Ip6Fw - ok
07:33:01.0078 2664 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) D:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
07:33:01.0453 2664 IpFilterDriver - ok
07:33:01.0484 2664 IpInIp (b87ab476dcf76e72010632b5550955f5) D:\WINDOWS\system32\DRIVERS\ipinip.sys
07:33:01.0875 2664 IpInIp - ok
07:33:01.0921 2664 IpNat (cc748ea12c6effde940ee98098bf96bb) D:\WINDOWS\system32\DRIVERS\ipnat.sys
07:33:02.0250 2664 IpNat - ok
07:33:02.0281 2664 IPSec (23c74d75e36e7158768dd63d92789a91) D:\WINDOWS\system32\DRIVERS\ipsec.sys
07:33:02.0656 2664 IPSec - ok
07:33:02.0687 2664 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) D:\WINDOWS\system32\DRIVERS\irenum.sys
07:33:02.0781 2664 IRENUM - ok
07:33:02.0843 2664 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) D:\WINDOWS\system32\DRIVERS\isapnp.sys
07:33:03.0156 2664 isapnp - ok
07:33:03.0171 2664 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) D:\WINDOWS\system32\DRIVERS\kbdclass.sys
07:33:03.0484 2664 Kbdclass - ok
07:33:03.0531 2664 kmixer (692bcf44383d056aed41b045a323d378) D:\WINDOWS\system32\drivers\kmixer.sys
07:33:03.0812 2664 kmixer - ok
07:33:03.0859 2664 KSecDD (b467646c54cc746128904e1654c750c1) D:\WINDOWS\system32\drivers\KSecDD.sys
07:33:03.0921 2664 KSecDD - ok
07:33:03.0968 2664 lanmanserver (3428e8f86f8add36b42fb23542c7b3e4) D:\WINDOWS\System32\srvsvc.dll
07:33:04.0015 2664 lanmanserver - ok
07:33:04.0062 2664 lanmanworkstation (936c1d110232d23b621cb0196e4f80f0) D:\WINDOWS\System32\wkssvc.dll
07:33:04.0125 2664 lanmanworkstation - ok
07:33:04.0140 2664 lbrtfdc - ok
07:33:04.0203 2664 LmHosts (0ab159f536e3e8f7f07113702a07cca5) D:\WINDOWS\System32\lmhsvc.dll
07:33:04.0609 2664 LmHosts - ok
07:33:04.0656 2664 Messenger (221cd1c815b8a6b79389c3f5d1018de8) D:\WINDOWS\System32\msgsvc.dll
07:33:05.0000 2664 Messenger - ok
07:33:05.0031 2664 mhpylftc (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\mhpylftc.sys
07:33:05.0109 2664 mhpylftc - ok
07:33:05.0156 2664 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) D:\WINDOWS\system32\drivers\mnmdd.sys
07:33:05.0468 2664 mnmdd - ok
07:33:05.0515 2664 mnmsrvc (9a57d046f88f4b69751b11fd40088a61) D:\WINDOWS\system32\mnmsrvc.exe
07:33:05.0875 2664 mnmsrvc - ok
07:33:05.0921 2664 Modem (44032b0c6d9954d3fd26438330b99ee7) D:\WINDOWS\system32\drivers\Modem.sys
07:33:06.0234 2664 Modem - ok
07:33:06.0265 2664 Mouclass (4cb582831dbde63ce43b45d771218374) D:\WINDOWS\system32\DRIVERS\mouclass.sys
07:33:06.0734 2664 Mouclass - ok
07:33:06.0781 2664 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) D:\WINDOWS\system32\drivers\MountMgr.sys
07:33:07.0125 2664 MountMgr - ok
07:33:07.0171 2664 MpFilter (d993bea500e7382dc4e760bf4f35efcb) D:\WINDOWS\system32\DRIVERS\MpFilter.sys
07:33:07.0203 2664 MpFilter - ok
07:33:07.0359 2664 MpKslba39dc34 (a69630d039c38018689190234f866d77) d:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E9ECE111-8918-42C5-9733-4E6F4B0C17B0}\MpKslba39dc34.sys
07:33:07.0375 2664 MpKslba39dc34 - ok
07:33:07.0390 2664 mraid35x - ok
07:33:07.0468 2664 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) D:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
07:33:07.0500 2664 MREMP50 ( UnsignedFile.Multi.Generic ) - warning
07:33:07.0500 2664 MREMP50 - detected UnsignedFile.Multi.Generic (1)
07:33:07.0515 2664 MREMP50a64 - ok
07:33:07.0531 2664 MREMPR5 - ok
07:33:07.0546 2664 MRENDIS5 - ok
07:33:07.0578 2664 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) D:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
07:33:07.0593 2664 MRESP50 ( UnsignedFile.Multi.Generic ) - warning
07:33:07.0593 2664 MRESP50 - detected UnsignedFile.Multi.Generic (1)
07:33:07.0609 2664 MRESP50a64 - ok
07:33:07.0656 2664 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) D:\WINDOWS\system32\DRIVERS\mrxdav.sys
07:33:07.0968 2664 MRxDAV - ok
07:33:08.0031 2664 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) D:\WINDOWS\system32\DRIVERS\mrxsmb.sys
07:33:08.0140 2664 MRxSmb - ok
07:33:08.0156 2664 MSDTC (6db4d1521caba9a5ffab54ade0ae867d) D:\WINDOWS\system32\msdtc.exe
07:33:08.0500 2664 MSDTC - ok
07:33:08.0531 2664 Msfs (c941ea2454ba8350021d774daf0f1027) D:\WINDOWS\system32\drivers\Msfs.sys
07:33:08.0796 2664 Msfs - ok
07:33:08.0812 2664 MSIServer - ok
07:33:08.0859 2664 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) D:\WINDOWS\system32\drivers\MSKSSRV.sys
07:33:09.0250 2664 MSKSSRV - ok
07:33:09.0296 2664 MsMpSvc (24516bf4e12a46cb67302e2cdcb8cddf) d:\Program Files\Microsoft Security Client\MsMpEng.exe
07:33:09.0328 2664 MsMpSvc - ok
07:33:09.0343 2664 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) D:\WINDOWS\system32\drivers\MSPCLOCK.sys
07:33:09.0640 2664 MSPCLOCK - ok
07:33:09.0671 2664 MSPQM (bad59648ba099da4a17680b39730cb3d) D:\WINDOWS\system32\drivers\MSPQM.sys
07:33:10.0015 2664 MSPQM - ok
07:33:10.0062 2664 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) D:\WINDOWS\system32\DRIVERS\mssmbios.sys
07:33:10.0390 2664 mssmbios - ok
07:33:10.0437 2664 Mup (de6a75f5c270e756c5508d94b6cf68f5) D:\WINDOWS\system32\drivers\Mup.sys
07:33:10.0484 2664 Mup - ok
07:33:10.0531 2664 napagent (6ea362e9db03d44f6b996f4d8be237e9) D:\WINDOWS\System32\qagentrt.dll
07:33:10.0843 2664 napagent - ok
07:33:10.0890 2664 NDIS (1df7f42665c94b825322fae71721130d) D:\WINDOWS\system32\drivers\NDIS.sys
07:33:11.0250 2664 NDIS - ok
07:33:11.0281 2664 NdisTapi (0109c4f3850dfbab279542515386ae22) D:\WINDOWS\system32\DRIVERS\ndistapi.sys
07:33:11.0328 2664 NdisTapi - ok
07:33:11.0359 2664 Ndisuio (f927a4434c5028758a842943ef1a3849) D:\WINDOWS\system32\DRIVERS\ndisuio.sys
07:33:11.0765 2664 Ndisuio - ok
07:33:11.0796 2664 NdisWan (edc1531a49c80614b2cfda43ca8659ab) D:\WINDOWS\system32\DRIVERS\ndiswan.sys
07:33:12.0156 2664 NdisWan - ok
07:33:12.0187 2664 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) D:\WINDOWS\system32\drivers\NDProxy.sys
07:33:12.0234 2664 NDProxy - ok
07:33:12.0265 2664 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) D:\WINDOWS\system32\DRIVERS\netbios.sys
07:33:12.0640 2664 NetBIOS - ok
07:33:12.0671 2664 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) D:\WINDOWS\system32\DRIVERS\netbt.sys
07:33:12.0968 2664 NetBT - ok
07:33:13.0000 2664 NetDDE (933de774986ec85e48210c44ab431de6) D:\WINDOWS\system32\netdde.exe
07:33:13.0359 2664 NetDDE - ok
07:33:13.0375 2664 NetDDEdsdm (933de774986ec85e48210c44ab431de6) D:\WINDOWS\system32\netdde.exe
07:33:13.0750 2664 NetDDEdsdm - ok
07:33:13.0781 2664 Netlogon (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
07:33:14.0109 2664 Netlogon - ok
07:33:14.0171 2664 Netman (72e1e9e2977be08bdeedb6d8fd9d4d40) D:\WINDOWS\System32\netman.dll
07:33:14.0500 2664 Netman - ok
07:33:14.0578 2664 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
07:33:14.0609 2664 NetTcpPortSharing - ok
07:33:14.0671 2664 Nla (39ee7c3bfbc64ba87cc8cf67386e814c) D:\WINDOWS\System32\mswsock.dll
07:33:14.0718 2664 Nla - ok
07:33:14.0765 2664 Npfs (3182d64ae053d6fb034f44b6def8034a) D:\WINDOWS\system32\drivers\Npfs.sys
07:33:15.0109 2664 Npfs - ok
07:33:15.0203 2664 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) D:\WINDOWS\system32\drivers\Ntfs.sys
07:33:15.0656 2664 Ntfs - ok
07:33:15.0687 2664 NtLmSsp (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
07:33:16.0000 2664 NtLmSsp - ok
07:33:16.0109 2664 NtmsSvc (023dd70573d644f3d9c8b1258a7bfd08) D:\WINDOWS\system32\ntmssvc.dll
07:33:16.0500 2664 NtmsSvc - ok
07:33:16.0546 2664 Null (73c1e1f395918bc2c6dd67af7591a3ad) D:\WINDOWS\system32\drivers\Null.sys
07:33:16.0906 2664 Null - ok
07:33:16.0937 2664 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) D:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
07:33:17.0328 2664 NwlnkFlt - ok
07:33:17.0359 2664 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) D:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
07:33:17.0703 2664 NwlnkFwd - ok
07:33:17.0765 2664 ose (7a56cf3e3f12e8af599963b16f50fb6a) D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
07:33:17.0796 2664 ose - ok
07:33:17.0843 2664 Parport (46f8db73b4a53e543f8e371dc7c75bae) D:\WINDOWS\system32\DRIVERS\parport.sys
07:33:18.0203 2664 Parport - ok
07:33:18.0234 2664 PartMgr (beb3ba25197665d82ec7065b724171c6) D:\WINDOWS\system32\drivers\PartMgr.sys
07:33:18.0531 2664 PartMgr - ok
07:33:18.0562 2664 ParVdm (1fae19d0457176318bba4a8795656ebc) D:\WINDOWS\system32\drivers\ParVdm.sys
07:33:18.0875 2664 ParVdm - ok
07:33:18.0937 2664 PCI (6ce351d149cb4befc702951e471e1730) D:\WINDOWS\system32\DRIVERS\pci.sys
07:33:19.0296 2664 PCI - ok
07:33:19.0312 2664 PCIDump - ok
07:33:19.0359 2664 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) D:\WINDOWS\system32\DRIVERS\pciide.sys
07:33:19.0640 2664 PCIIde - ok
07:33:19.0687 2664 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) D:\WINDOWS\system32\drivers\Pcmcia.sys
07:33:20.0000 2664 Pcmcia - ok
07:33:20.0031 2664 PDCOMP - ok
07:33:20.0046 2664 PDFRAME - ok
07:33:20.0078 2664 PDRELI - ok
07:33:20.0093 2664 PDRFRAME - ok
07:33:20.0125 2664 perc2 - ok
07:33:20.0156 2664 perc2hib - ok
07:33:20.0234 2664 PlugPlay (9ef697af07bb8dd82c3b02ca953a95b7) D:\WINDOWS\system32\services.exe
07:33:20.0250 2664 PlugPlay - ok
07:33:20.0296 2664 Pml Driver HPZ12 (901c43516504cbe582e4c4193e00876a) D:\WINDOWS\system32\HPZipm12.exe
07:33:20.0312 2664 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
07:33:20.0312 2664 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
07:33:20.0328 2664 PolicyAgent (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
07:33:20.0671 2664 PolicyAgent - ok
07:33:20.0718 2664 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) D:\WINDOWS\system32\DRIVERS\raspptp.sys
07:33:21.0109 2664 PptpMiniport - ok
07:33:21.0140 2664 ProtectedStorage (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
07:33:21.0406 2664 ProtectedStorage - ok
07:33:21.0437 2664 PSched (09298ec810b07e5d582cb3a3f9255424) D:\WINDOWS\system32\DRIVERS\psched.sys
07:33:21.0796 2664 PSched - ok
07:33:21.0843 2664 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) D:\WINDOWS\system32\DRIVERS\ptilink.sys
07:33:22.0140 2664 Ptilink - ok
07:33:22.0203 2664 PxHelp20 (d86b4a68565e444d76457f14172c875a) D:\WINDOWS\system32\Drivers\PxHelp20.sys
07:33:22.0265 2664 PxHelp20 - ok
07:33:22.0281 2664 ql1080 - ok
07:33:22.0312 2664 Ql10wnt - ok
07:33:22.0328 2664 ql12160 - ok
07:33:22.0343 2664 ql1240 - ok
07:33:22.0375 2664 ql1280 - ok
07:33:22.0406 2664 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) D:\WINDOWS\system32\DRIVERS\rasacd.sys
07:33:22.0718 2664 RasAcd - ok
07:33:22.0750 2664 RasAuto (2b5e44ea009f2f374b980e1e9a70635d) D:\WINDOWS\System32\rasauto.dll
07:33:23.0125 2664 RasAuto - ok
07:33:23.0156 2664 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) D:\WINDOWS\system32\DRIVERS\rasl2tp.sys
07:33:23.0453 2664 Rasl2tp - ok
07:33:23.0500 2664 RasMan (d57554c664b64604bd1ee13ea2c07e77) D:\WINDOWS\System32\rasmans.dll
07:33:23.0828 2664 RasMan - ok
07:33:23.0875 2664 RasPppoe (5bc962f2654137c9909c3d4603587dee) D:\WINDOWS\system32\DRIVERS\raspppoe.sys
07:33:24.0171 2664 RasPppoe - ok
07:33:24.0203 2664 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) D:\WINDOWS\system32\DRIVERS\raspti.sys
07:33:24.0500 2664 Raspti - ok
07:33:24.0546 2664 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) D:\WINDOWS\system32\DRIVERS\rdbss.sys
07:33:24.0843 2664 Rdbss - ok
07:33:24.0875 2664 RDPCDD (4912d5b403614ce99c28420f75353332) D:\WINDOWS\system32\DRIVERS\RDPCDD.sys
07:33:25.0171 2664 RDPCDD - ok
07:33:25.0250 2664 RDPWD (6589db6e5969f8eee594cf71171c5028) D:\WINDOWS\system32\drivers\RDPWD.sys
07:33:25.0296 2664 RDPWD - ok
07:33:25.0343 2664 RDSessMgr (c0d9d9711cb74ee9bc66353d8cbdab0e) D:\WINDOWS\system32\sessmgr.exe
07:33:25.0625 2664 RDSessMgr - ok
07:33:25.0656 2664 redbook (611bfd220305be3a85ae876ea47d4aa5) D:\WINDOWS\system32\DRIVERS\redbook.sys
07:33:25.0937 2664 redbook - ok
07:33:25.0953 2664 RemoteAccess (127c26b5371651043450e52542099aba) D:\WINDOWS\System32\mprdim.dll
07:33:26.0406 2664 RemoteAccess - ok
07:33:26.0453 2664 RpcLocator (718b3bdc0bc3c2f7d065a53d26202af9) D:\WINDOWS\system32\locator.exe
07:33:26.0718 2664 RpcLocator - ok
07:33:26.0796 2664 RpcSs (be27674d1cbc3214aec84b4336a38bbf) D:\WINDOWS\system32\rpcss.dll
07:33:26.0843 2664 RpcSs - ok
07:33:26.0890 2664 RSVP (09ab2e71e58b078038e3bfdba7ffc984) D:\WINDOWS\system32\rsvp.exe
07:33:27.0203 2664 RSVP - ok
07:33:27.0265 2664 RT73 (c7bcf9808e2a1b4cabe16ff7fbce5fab) D:\WINDOWS\system32\DRIVERS\rt73.sys
07:33:27.0359 2664 RT73 - ok
07:33:27.0375 2664 SamSs (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
07:33:27.0703 2664 SamSs - ok
07:33:27.0750 2664 SCardSvr (410046e401eb11e1e6749e9deea41d4a) D:\WINDOWS\System32\SCardSvr.exe
07:33:28.0109 2664 SCardSvr - ok
07:33:28.0140 2664 Schedule (3ff232a7731621b8902d81d42418c93c) D:\WINDOWS\system32\schedsvc.dll
07:33:28.0437 2664 Schedule - ok
07:33:28.0484 2664 Secdrv (90a3935d05b494a5a39d37e71f09a677) D:\WINDOWS\system32\DRIVERS\secdrv.sys
07:33:28.0593 2664 Secdrv - ok
07:33:28.0625 2664 seclogon (477e2c3cc5e4a0d635bcb0ea8dcac3c6) D:\WINDOWS\System32\seclogon.dll
07:33:29.0031 2664 seclogon - ok
07:33:29.0062 2664 SENS (a530b75c10c23c9ab28fdb6ce719e21f) D:\WINDOWS\system32\sens.dll
07:33:29.0359 2664 SENS - ok
07:33:29.0390 2664 serenum (0f29512ccd6bead730039fb4bd2c85ce) D:\WINDOWS\system32\DRIVERS\serenum.sys
07:33:29.0687 2664 serenum - ok
07:33:29.0718 2664 Serial (b842729337c9b921615c40d3c1a1af96) D:\WINDOWS\system32\DRIVERS\serial.sys
07:33:30.0000 2664 Serial - ok
07:33:30.0062 2664 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) D:\WINDOWS\system32\drivers\Sfloppy.sys
07:33:30.0437 2664 Sfloppy - ok
07:33:30.0500 2664 SharedAccess (f58faca9621d2db01bd0927d9a0a208e) D:\WINDOWS\System32\ipnathlp.dll
07:33:30.0796 2664 SharedAccess - ok
07:33:30.0843 2664 ShellHWDetection (ee9a2b9ea968a792a053c9d1a86bf870) D:\WINDOWS\System32\shsvcs.dll
07:33:30.0875 2664 ShellHWDetection - ok
07:33:30.0890 2664 Simbad - ok
07:33:30.0937 2664 SISNIC (3fbb6ef8b5a71a2fa11f5f461bb73219) D:\WINDOWS\system32\DRIVERS\sisnic.sys
07:33:31.0281 2664 SISNIC - ok
07:33:31.0312 2664 Sparrow - ok
07:33:31.0343 2664 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) D:\WINDOWS\system32\drivers\splitter.sys
07:33:31.0625 2664 splitter - ok
07:33:31.0671 2664 Spooler (60784f891563fb1b767f70117fc2428f) D:\WINDOWS\system32\spoolsv.exe
07:33:31.0703 2664 Spooler - ok
07:33:31.0781 2664 sptd (bd66bf74d06624f3abf15dd990888c54) D:\WINDOWS\system32\Drivers\sptd.sys
07:33:31.0781 2664 Suspicious file (NoAccess): D:\WINDOWS\system32\Drivers\sptd.sys. md5: bd66bf74d06624f3abf15dd990888c54
07:33:31.0796 2664 sptd ( LockedFile.Multi.Generic ) - warning
07:33:31.0796 2664 sptd - detected LockedFile.Multi.Generic (1)
07:33:31.0843 2664 sr (94610c8653635e4459316a0050d55ce7) D:\WINDOWS\system32\DRIVERS\sr.sys
07:33:31.0937 2664 sr - ok
07:33:32.0000 2664 srservice (35b91147124f64ac8081a2edb9ea4dee) D:\WINDOWS\system32\srsvc.dll
07:33:32.0109 2664 srservice - ok
07:33:32.0171 2664 Srv (47ddfc2f003f7f9f0592c6874962a2e7) D:\WINDOWS\system32\DRIVERS\srv.sys
07:33:32.0234 2664 Srv - ok
07:33:32.0281 2664 SSDPSRV (becd5271dc4e3b7c3d035f790fcbc1e5) D:\WINDOWS\System32\ssdpsrv.dll
07:33:32.0406 2664 SSDPSRV - ok
07:33:32.0468 2664 stisvc (c1cdd9275f6a115bb0ae1d55d8d27ba6) D:\WINDOWS\system32\wiaservc.dll
07:33:32.0859 2664 stisvc - ok
07:33:32.0890 2664 swenum (3941d127aef12e93addf6fe6ee027e0f) D:\WINDOWS\system32\DRIVERS\swenum.sys
07:33:33.0140 2664 swenum - ok
07:33:33.0171 2664 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) D:\WINDOWS\system32\drivers\swmidi.sys
07:33:33.0468 2664 swmidi - ok
07:33:33.0484 2664 SwPrv - ok
07:33:33.0531 2664 symc810 - ok
07:33:33.0546 2664 symc8xx - ok
07:33:33.0578 2664 sym_hi - ok
07:33:33.0609 2664 sym_u3 - ok
07:33:33.0656 2664 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) D:\WINDOWS\system32\drivers\sysaudio.sys
07:33:33.0937 2664 sysaudio - ok
07:33:33.0984 2664 SysmonLog (ce06f01b88ace199a1bf460cac29c110) D:\WINDOWS\system32\smlogsvc.exe
07:33:34.0265 2664 SysmonLog - ok
07:33:34.0296 2664 TapiSrv (c2546cd7a398476f9df5614b2ae160e8) D:\WINDOWS\System32\tapisrv.dll
07:33:34.0625 2664 TapiSrv - ok
07:33:34.0703 2664 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) D:\WINDOWS\system32\DRIVERS\tcpip.sys
07:33:34.0765 2664 Tcpip - ok
07:33:34.0812 2664 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) D:\WINDOWS\system32\DRIVERS\tcpip6.sys
07:33:34.0875 2664 Tcpip6 - ok
07:33:34.0921 2664 TDPIPE (6471a66807f5e104e4885f5b67349397) D:\WINDOWS\system32\drivers\TDPIPE.sys
07:33:35.0234 2664 TDPIPE - ok
07:33:35.0250 2664 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) D:\WINDOWS\system32\drivers\TDTCP.sys
07:33:35.0515 2664 TDTCP - ok
07:33:35.0562 2664 TermDD (88155247177638048422893737429d9e) D:\WINDOWS\system32\DRIVERS\termdd.sys
07:33:35.0937 2664 TermDD - ok
07:33:36.0000 2664 TermService (a75dd6fc3dbee4fff5ebc9f2c28bb66e) D:\WINDOWS\System32\termsrv.dll
07:33:36.0312 2664 TermService - ok
07:33:36.0359 2664 Themes (ee9a2b9ea968a792a053c9d1a86bf870) D:\WINDOWS\System32\shsvcs.dll
07:33:36.0390 2664 Themes - ok
07:33:36.0421 2664 tnndsbir (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\tnndsbir.sys
07:33:36.0500 2664 tnndsbir - ok
07:33:36.0531 2664 TosIde - ok
07:33:36.0578 2664 TrkWks (38853304ccb938d30e0c4cde8d2c2a8a) D:\WINDOWS\system32\trkwks.dll
07:33:36.0984 2664 TrkWks - ok
07:33:37.0031 2664 tunmp (8f861eda21c05857eb8197300a92501c) D:\WINDOWS\system32\DRIVERS\tunmp.sys
07:33:37.0296 2664 tunmp - ok
07:33:37.0328 2664 uagp35 (d85938f272d1bcf3db3a31fc0a048928) D:\WINDOWS\system32\DRIVERS\uagp35.sys
07:33:37.0687 2664 uagp35 - ok
07:33:37.0718 2664 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) D:\WINDOWS\system32\drivers\Udfs.sys
07:33:38.0031 2664 Udfs - ok
07:33:38.0046 2664 ultra - ok
07:33:38.0125 2664 Update (402ddc88356b1bac0ee3dd1580c76a31) D:\WINDOWS\system32\DRIVERS\update.sys
07:33:38.0375 2664 Update - ok
07:33:38.0437 2664 upnphost (651bd90dcee5b7bdc74a2eb7c9266f9e) D:\WINDOWS\System32\upnphost.dll
07:33:38.0546 2664 upnphost - ok
07:33:38.0578 2664 UPS (20a0f6a11959e92908717d09e87d670d) D:\WINDOWS\System32\ups.exe
07:33:38.0890 2664 UPS - ok
07:33:38.0937 2664 urhbyldj (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\urhbyldj.sys
07:33:39.0000 2664 urhbyldj - ok
07:33:39.0046 2664 usbccgp (173f317ce0db8e21322e71b7e60a27e8) D:\WINDOWS\system32\DRIVERS\usbccgp.sys
07:33:39.0375 2664 usbccgp - ok
07:33:39.0406 2664 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) D:\WINDOWS\system32\DRIVERS\usbehci.sys
07:33:39.0734 2664 usbehci - ok
07:33:39.0765 2664 usbhub (1ab3cdde553b6e064d2e754efe20285c) D:\WINDOWS\system32\DRIVERS\usbhub.sys
07:33:40.0062 2664 usbhub - ok
07:33:40.0093 2664 usbohci (0daecce65366ea32b162f85f07c6753b) D:\WINDOWS\system32\DRIVERS\usbohci.sys
07:33:40.0359 2664 usbohci - ok
07:33:40.0421 2664 usbprint (a717c8721046828520c9edf31288fc00) D:\WINDOWS\system32\DRIVERS\usbprint.sys
07:33:40.0734 2664 usbprint - ok
07:33:40.0765 2664 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) D:\WINDOWS\system32\DRIVERS\usbscan.sys
07:33:41.0015 2664 usbscan - ok
07:33:41.0062 2664 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
07:33:41.0359 2664 USBSTOR - ok
07:33:41.0390 2664 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) D:\WINDOWS\System32\drivers\vga.sys
07:33:41.0734 2664 VgaSave - ok
07:33:41.0750 2664 ViaIde - ok
07:33:41.0796 2664 VolSnap (28a4b296b47782173c346e376cb374d1) D:\WINDOWS\system32\drivers\VolSnap.sys
07:33:42.0140 2664 VolSnap - ok
07:33:42.0218 2664 VSS (d6ba1a63d9e00933f1cd2a885573afb2) D:\WINDOWS\System32\vssvc.exe
07:33:42.0328 2664 VSS - ok
07:33:42.0359 2664 W32Time (fa4e1cdba256787f2149f4aad07bc91f) D:\WINDOWS\system32\w32time.dll
07:33:42.0609 2664 W32Time - ok
07:33:42.0671 2664 Wanarp (e20b95baedb550f32dd489265c1da1f6) D:\WINDOWS\system32\DRIVERS\wanarp.sys
07:33:43.0000 2664 Wanarp - ok
07:33:43.0031 2664 WDICA - ok
07:33:43.0078 2664 wdmaud (6768acf64b18196494413695f0c3a00f) D:\WINDOWS\system32\drivers\wdmaud.sys
07:33:43.0343 2664 wdmaud - ok
07:33:43.0390 2664 WebClient (47ae51048a82dfa1cd6b51d369f7e169) D:\WINDOWS\System32\webclnt.dll
07:33:43.0671 2664 WebClient - ok
07:33:43.0765 2664 winmgmt (e488332126e3b1182d2b8a0c35408ec6) D:\WINDOWS\system32\wbem\WMIsvc.dll
07:33:44.0062 2664 winmgmt - ok
07:33:44.0187 2664 WinRM (4d34cedd74bdbf2b6a935eae3bf80543) D:\WINDOWS\system32\WsmSvc.dll
07:33:44.0359 2664 WinRM - ok
07:33:44.0406 2664 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) D:\WINDOWS\system32\MsPMSNSv.dll
07:33:44.0484 2664 WmdmPmSN - ok
07:33:44.0546 2664 WmiApSrv (23f6f03272f7e5679f1f050aed5acee6) D:\WINDOWS\system32\wbem\wmiapsrv.exe
07:33:44.0859 2664 WmiApSrv - ok
07:33:45.0015 2664 WMPNetworkSvc (3739866d20abd42f26a7b85f9e2560af) D:\Program Files\Windows Media Player\WMPNetwk.exe
07:33:45.0125 2664 WMPNetworkSvc - ok
07:33:45.0187 2664 wscsvc (4c86d5faf78194995af9cc1075f65dd3) D:\WINDOWS\system32\wscsvc.dll
07:33:45.0500 2664 wscsvc - ok
07:33:45.0546 2664 wuauserv (c1364564800ee9784192145324a23308) D:\WINDOWS\system32\wuauserv.dll
07:33:45.0875 2664 wuauserv - ok
07:33:45.0921 2664 WudfPf (f15feafffbb3644ccc80c5da584e6311) D:\WINDOWS\system32\DRIVERS\WudfPf.sys
07:33:45.0968 2664 WudfPf - ok
07:33:45.0984 2664 WudfRd (28b524262bce6de1f7ef9f510ba3985b) D:\WINDOWS\system32\DRIVERS\wudfrd.sys
07:33:46.0031 2664 WudfRd - ok
07:33:46.0078 2664 WudfSvc (05231c04253c5bc30b26cbaae680ed89) D:\WINDOWS\System32\WUDFSvc.dll
07:33:46.0125 2664 WudfSvc - ok
07:33:46.0203 2664 WZCSVC (a27d4ba7264c0bf52f32d10405bea1d4) D:\WINDOWS\System32\wzcsvc.dll
07:33:46.0609 2664 WZCSVC - ok
07:33:46.0625 2664 xcpip - ok
07:33:46.0671 2664 xefsflhx (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\xefsflhx.sys
07:33:46.0750 2664 xefsflhx - ok
07:33:46.0781 2664 xmlprov (eaa4bb9edb3fb10cf8979fe65e63658f) D:\WINDOWS\System32\xmlprov.dll
07:33:47.0093 2664 xmlprov - ok
07:33:47.0125 2664 xpsec - ok
07:33:47.0218 2664 MBR (0x1B8) (0e1d60863e74698b6255deeb65261da6) \Device\Harddisk0\DR0
07:33:47.0218 2664 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - infected
07:33:47.0218 2664 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Sinowal.b (0)
07:33:47.0312 2664 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk1\DR1
07:33:47.0421 2664 \Device\Harddisk1\DR1 - ok
07:33:47.0437 2664 Boot (0x1200) (25b7d8f78bef80b5be7b3cadabf84bbd) \Device\Harddisk0\DR0\Partition0
07:33:47.0437 2664 \Device\Harddisk0\DR0\Partition0 - ok
07:33:47.0453 2664 Boot (0x1200) (9bb6c29286ecd27996a136c2fb4a55be) \Device\Harddisk1\DR1\Partition0
07:33:47.0453 2664 \Device\Harddisk1\DR1\Partition0 - ok
07:33:47.0468 2664 ============================================================
07:33:47.0468 2664 Scan finished
07:33:47.0468 2664 ============================================================
07:33:47.0609 0636 Detected object count: 8
07:33:47.0609 0636 Actual detected object count: 8
07:35:07.0015 0636 AegisP ( UnsignedFile.Multi.Generic ) - skipped by user
07:35:07.0015 0636 AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:35:07.0015 0636 ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user
07:35:07.0015 0636 ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:35:07.0015 0636 dtscsi ( LockedFile.Multi.Generic ) - skipped by user
07:35:07.0015 0636 dtscsi ( LockedFile.Multi.Generic ) - User select action: Skip
07:35:07.0015 0636 MREMP50 ( UnsignedFile.Multi.Generic ) - skipped by user
07:35:07.0015 0636 MREMP50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:35:07.0015 0636 MRESP50 ( UnsignedFile.Multi.Generic ) - skipped by user
07:35:07.0015 0636 MRESP50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:35:07.0015 0636 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
07:35:07.0015 0636 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
07:35:07.0031 0636 sptd ( LockedFile.Multi.Generic ) - skipped by user
07:35:07.0031 0636 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
07:35:07.0031 0636 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - skipped by user
07:35:07.0031 0636 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - User select action: Skip

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 07:49
od vyosek
:arrow: No jo, je tam :boxed:

:arrow: Spustte znovu TDSSKiller, nechte probehnout sken ale u polozky \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) zvolte moznost cure

:arrow: Bude zrejme potreba restart, log pak sem

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 08:07
od jaroslav.24
Hotovo. Snad je pryč.


08:59:56.0906 2348 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
08:59:56.0984 2348 ============================================================
08:59:56.0984 2348 Current date / time: 2012/08/02 08:59:56.0984
08:59:56.0984 2348 SystemInfo:
08:59:56.0984 2348
08:59:56.0984 2348 OS Version: 5.1.2600 ServicePack: 3.0
08:59:56.0984 2348 Product type: Workstation
08:59:56.0984 2348 ComputerName: JARDA
08:59:56.0984 2348 UserName: Kryton
08:59:56.0984 2348 Windows directory: D:\WINDOWS
08:59:56.0984 2348 System windows directory: D:\WINDOWS
08:59:56.0984 2348 Processor architecture: Intel x86
08:59:56.0984 2348 Number of processors: 1
08:59:56.0984 2348 Page size: 0x1000
08:59:56.0984 2348 Boot type: Normal boot
08:59:56.0984 2348 ============================================================
08:59:58.0515 2348 Drive \Device\Harddisk0\DR0 - Size: 0x4A94F0000 (18.65 Gb), SectorSize: 0x200, Cylinders: 0x982, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
08:59:58.0531 2348 Drive \Device\Harddisk1\DR1 - Size: 0x25432CDE00 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
08:59:58.0531 2348 ============================================================
08:59:58.0531 2348 \Device\Harddisk0\DR0:
08:59:58.0531 2348 MBR partitions:
08:59:58.0531 2348 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2546802
08:59:58.0531 2348 \Device\Harddisk1\DR1:
08:59:58.0531 2348 MBR partitions:
08:59:58.0531 2348 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1
08:59:58.0531 2348 ============================================================
08:59:58.0531 2348 C: <-> \Device\Harddisk0\DR0\Partition0
08:59:58.0562 2348 D: <-> \Device\Harddisk1\DR1\Partition0
08:59:58.0562 2348 ============================================================
08:59:58.0562 2348 Initialize success
08:59:58.0562 2348 ============================================================
09:00:19.0703 1844 ============================================================
09:00:19.0703 1844 Scan started
09:00:19.0703 1844 Mode: Manual; SigCheck; TDLFS;
09:00:19.0703 1844 ============================================================
09:00:20.0031 1844 6to4 (d76e9f5a991458a9f7e28395479b3150) D:\WINDOWS\System32\6to4svc.dll
09:00:20.0250 1844 6to4 - ok
09:00:20.0296 1844 Abiosdsk - ok
09:00:20.0312 1844 abp480n5 - ok
09:00:20.0375 1844 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) D:\WINDOWS\system32\DRIVERS\ACPI.sys
09:00:20.0593 1844 ACPI - ok
09:00:20.0640 1844 ACPIEC (afdff022a01f0b11c776f0860c3b282f) D:\WINDOWS\system32\drivers\ACPIEC.sys
09:00:20.0921 1844 ACPIEC - ok
09:00:20.0953 1844 adpu160m - ok
09:00:20.0984 1844 aec (8bed39e3c35d6a489438b8141717a557) D:\WINDOWS\system32\drivers\aec.sys
09:00:21.0296 1844 aec - ok
09:00:21.0328 1844 AegisP (023867b6606fbabcdd52e089c4a507da) D:\WINDOWS\system32\DRIVERS\AegisP.sys
09:00:21.0343 1844 AegisP ( UnsignedFile.Multi.Generic ) - warning
09:00:21.0343 1844 AegisP - detected UnsignedFile.Multi.Generic (1)
09:00:21.0406 1844 AFD (1e44bc1e83d8fd2305f8d452db109cf9) D:\WINDOWS\System32\drivers\afd.sys
09:00:21.0453 1844 AFD - ok
09:00:21.0468 1844 Aha154x - ok
09:00:21.0484 1844 aic78u2 - ok
09:00:21.0500 1844 aic78xx - ok
09:00:21.0531 1844 Alerter (e0a6fa244b8624d78fe5ff6f56a33bae) D:\WINDOWS\system32\alrsvc.dll
09:00:21.0843 1844 Alerter - ok
09:00:21.0875 1844 ALG (88842de939a827577bf24243699ac80a) D:\WINDOWS\System32\alg.exe
09:00:21.0968 1844 ALG - ok
09:00:22.0000 1844 AliIde - ok
09:00:22.0062 1844 AmdK7 (3980814f8027d27ea003e2e3d9d4f604) D:\WINDOWS\system32\DRIVERS\amdk7.sys
09:00:22.0343 1844 AmdK7 - ok
09:00:22.0375 1844 amsint - ok
09:00:22.0390 1844 AppMgmt - ok
09:00:22.0421 1844 asc - ok
09:00:22.0437 1844 asc3350p - ok
09:00:22.0468 1844 asc3550 - ok
09:00:22.0578 1844 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
09:00:22.0593 1844 aspnet_state - ok
09:00:22.0625 1844 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) D:\WINDOWS\system32\DRIVERS\asyncmac.sys
09:00:22.0937 1844 AsyncMac - ok
09:00:22.0984 1844 atapi (9f3a2f5aa6875c72bf062c712cfa2674) D:\WINDOWS\system32\DRIVERS\atapi.sys
09:00:23.0281 1844 atapi - ok
09:00:23.0312 1844 Atdisk - ok
09:00:23.0390 1844 Ati HotKey Poller (c27a0a876e7277428ab894cd58600686) D:\WINDOWS\system32\Ati2evxx.exe
09:00:23.0484 1844 Ati HotKey Poller - ok
09:00:23.0562 1844 ATI Smart (bfbe2f559eba2aaff58235760fc1ecba) D:\WINDOWS\system32\ati2sgag.exe
09:00:23.0609 1844 ATI Smart ( UnsignedFile.Multi.Generic ) - warning
09:00:23.0609 1844 ATI Smart - detected UnsignedFile.Multi.Generic (1)
09:00:23.0781 1844 ati2mtag (633d22a45283762dc05989751cc1397c) D:\WINDOWS\system32\DRIVERS\ati2mtag.sys
09:00:23.0937 1844 ati2mtag - ok
09:00:24.0046 1844 Atmarpc (9916c1225104ba14794209cfa8012159) D:\WINDOWS\system32\DRIVERS\atmarpc.sys
09:00:24.0328 1844 Atmarpc - ok
09:00:24.0359 1844 AudioSrv (de31b88962a8645dba5a37b993e7b0f1) D:\WINDOWS\System32\audiosrv.dll
09:00:24.0734 1844 AudioSrv - ok
09:00:24.0765 1844 audstub (d9f724aa26c010a217c97606b160ed68) D:\WINDOWS\system32\DRIVERS\audstub.sys
09:00:25.0125 1844 audstub - ok
09:00:25.0156 1844 Beep (da1f27d85e0d1525f6621372e7b685e9) D:\WINDOWS\system32\drivers\Beep.sys
09:00:25.0531 1844 Beep - ok
09:00:25.0593 1844 BITS (19395d092fd85ddc2d9c7729cf5a2ac8) D:\WINDOWS\system32\qmgr.dll
09:00:25.0984 1844 BITS - ok
09:00:26.0031 1844 Browser (249276d3ef1e74b992299cb96099e4d7) D:\WINDOWS\System32\browser.dll
09:00:26.0390 1844 Browser - ok
09:00:26.0421 1844 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) D:\WINDOWS\system32\drivers\cbidf2k.sys
09:00:26.0750 1844 cbidf2k - ok
09:00:26.0781 1844 cd20xrnt - ok
09:00:26.0812 1844 Cdaudio (c1b486a7658353d33a10cc15211a873b) D:\WINDOWS\system32\drivers\Cdaudio.sys
09:00:27.0203 1844 Cdaudio - ok
09:00:27.0234 1844 Cdfs (c885b02847f5d2fd45a24e219ed93b32) D:\WINDOWS\system32\drivers\Cdfs.sys
09:00:27.0625 1844 Cdfs - ok
09:00:27.0656 1844 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) D:\WINDOWS\system32\DRIVERS\cdrom.sys
09:00:28.0015 1844 Cdrom - ok
09:00:28.0062 1844 cebdpdcw (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\cebdpdcw.sys
09:00:28.0093 1844 cebdpdcw - ok
09:00:28.0109 1844 Changer - ok
09:00:28.0140 1844 CiSvc (e390dc1d7c461d7d56ec53402f329928) D:\WINDOWS\system32\cisvc.exe
09:00:28.0515 1844 CiSvc - ok
09:00:28.0562 1844 ClipSrv (064507a8dfa8c5c7e2ffddd3e6f424fa) D:\WINDOWS\system32\clipsrv.exe
09:00:28.0937 1844 ClipSrv - ok
09:00:29.0015 1844 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
09:00:29.0031 1844 clr_optimization_v2.0.50727_32 - ok
09:00:29.0062 1844 CmdIde - ok
09:00:29.0140 1844 cmpci (e5842ccf0953d3d46d5e26427b67e901) D:\WINDOWS\system32\drivers\cmaudio.sys
09:00:29.0218 1844 cmpci - ok
09:00:29.0250 1844 COMSysApp - ok
09:00:29.0281 1844 Cpqarray - ok
09:00:29.0328 1844 CryptSvc (f3ab0933cbd166d271992f411c27ccaf) D:\WINDOWS\System32\cryptsvc.dll
09:00:29.0687 1844 CryptSvc - ok
09:00:29.0703 1844 dac2w2k - ok
09:00:29.0718 1844 dac960nt - ok
09:00:29.0796 1844 DcomLaunch (be27674d1cbc3214aec84b4336a38bbf) D:\WINDOWS\system32\rpcss.dll
09:00:29.0843 1844 DcomLaunch - ok
09:00:29.0906 1844 Dhcp (8c9a53e285ac5e6704844d0459ec85be) D:\WINDOWS\System32\dhcpcsvc.dll
09:00:30.0250 1844 Dhcp - ok
09:00:30.0265 1844 Disk (044452051f3e02e7963599fc8f4f3e25) D:\WINDOWS\system32\DRIVERS\disk.sys
09:00:30.0687 1844 Disk - ok
09:00:30.0703 1844 dmadmin - ok
09:00:30.0812 1844 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) D:\WINDOWS\system32\drivers\dmboot.sys
09:00:31.0187 1844 dmboot - ok
09:00:31.0218 1844 dmio (fff1720af51171f32f1ead5cf71f2810) D:\WINDOWS\system32\drivers\dmio.sys
09:00:31.0578 1844 dmio - ok
09:00:31.0609 1844 dmload (e9317282a63ca4d188c0df5e09c6ac5f) D:\WINDOWS\system32\drivers\dmload.sys
09:00:31.0984 1844 dmload - ok
09:00:32.0015 1844 dmserver (2bfefe9e865655a76982f050450b9591) D:\WINDOWS\System32\dmserver.dll
09:00:32.0406 1844 dmserver - ok
09:00:32.0437 1844 DMusic (8a208dfcf89792a484e76c40e5f50b45) D:\WINDOWS\system32\drivers\DMusic.sys
09:00:32.0796 1844 DMusic - ok
09:00:32.0828 1844 Dnscache (dfaa406bf19f4ee806a6f8d4342137f7) D:\WINDOWS\System32\dnsrslvr.dll
09:00:32.0859 1844 Dnscache - ok
09:00:32.0906 1844 Dot3svc (4a3e2bd20157a0946751229e92eb8621) D:\WINDOWS\System32\dot3svc.dll
09:00:33.0203 1844 Dot3svc - ok
09:00:33.0234 1844 dpti2o - ok
09:00:33.0265 1844 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) D:\WINDOWS\system32\drivers\drmkaud.sys
09:00:33.0609 1844 drmkaud - ok
09:00:33.0656 1844 dtscsi (6461e57bb51a848aae26f52427b7cf9e) D:\WINDOWS\System32\Drivers\dtscsi.sys
09:00:33.0656 1844 Suspicious file (NoAccess): D:\WINDOWS\System32\Drivers\dtscsi.sys. md5: 6461e57bb51a848aae26f52427b7cf9e
09:00:33.0656 1844 dtscsi ( LockedFile.Multi.Generic ) - warning
09:00:33.0656 1844 dtscsi - detected LockedFile.Multi.Generic (1)
09:00:33.0703 1844 dyntnyii (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\dyntnyii.sys
09:00:33.0781 1844 dyntnyii - ok
09:00:33.0796 1844 EapHost (0887d9c2be8d940778cad1e3b85f2a41) D:\WINDOWS\System32\eapsvc.dll
09:00:34.0171 1844 EapHost - ok
09:00:34.0203 1844 ERSvc (a2a4912798f2be706abadd3d30800d16) D:\WINDOWS\System32\ersvc.dll
09:00:34.0593 1844 ERSvc - ok
09:00:34.0640 1844 Eventlog (9ef697af07bb8dd82c3b02ca953a95b7) D:\WINDOWS\system32\services.exe
09:00:34.0671 1844 Eventlog - ok
09:00:34.0734 1844 EventSystem (a371f11ef07653591c8de26afb13ce7f) D:\WINDOWS\system32\es.dll
09:00:34.0765 1844 EventSystem - ok
09:00:34.0796 1844 Fastfat (38d332a6d56af32635675f132548343e) D:\WINDOWS\system32\drivers\Fastfat.sys
09:00:35.0125 1844 Fastfat - ok
09:00:35.0171 1844 FastUserSwitchingCompatibility (ee9a2b9ea968a792a053c9d1a86bf870) D:\WINDOWS\System32\shsvcs.dll
09:00:35.0203 1844 FastUserSwitchingCompatibility - ok
09:00:35.0265 1844 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) D:\WINDOWS\system32\DRIVERS\fdc.sys
09:00:35.0625 1844 Fdc - ok
09:00:35.0671 1844 Fips (ac366695a0796560aa37215ad5762aaf) D:\WINDOWS\system32\drivers\Fips.sys
09:00:36.0078 1844 Fips - ok
09:00:36.0109 1844 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) D:\WINDOWS\system32\DRIVERS\flpydisk.sys
09:00:36.0421 1844 Flpydisk - ok
09:00:36.0468 1844 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) D:\WINDOWS\system32\drivers\fltmgr.sys
09:00:36.0875 1844 FltMgr - ok
09:00:36.0937 1844 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
09:00:36.0953 1844 FontCache3.0.0.0 - ok
09:00:36.0984 1844 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) D:\WINDOWS\system32\drivers\Fs_Rec.sys
09:00:37.0312 1844 Fs_Rec - ok
09:00:37.0343 1844 Ftdisk (4e664d8541db4a66b73a24257e322e1f) D:\WINDOWS\system32\DRIVERS\ftdisk.sys
09:00:37.0734 1844 Ftdisk - ok
09:00:37.0765 1844 gameenum (065639773d8b03f33577f6cdaea21063) D:\WINDOWS\system32\DRIVERS\gameenum.sys
09:00:38.0156 1844 gameenum - ok
09:00:38.0171 1844 gda2amy7.sys - ok
09:00:38.0218 1844 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) D:\WINDOWS\system32\DRIVERS\msgpc.sys
09:00:38.0593 1844 Gpc - ok
09:00:38.0703 1844 gupdate (f02a533f517eb38333cb12a9e8963773) D:\Program Files\Google\Update\GoogleUpdate.exe
09:00:38.0734 1844 gupdate - ok
09:00:38.0734 1844 gupdatem (f02a533f517eb38333cb12a9e8963773) D:\Program Files\Google\Update\GoogleUpdate.exe
09:00:38.0765 1844 gupdatem - ok
09:00:38.0828 1844 helpsvc (fcfe31fb75f8a6295b6b0af87a626282) D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
09:00:39.0234 1844 helpsvc - ok
09:00:39.0265 1844 HidServ - ok
09:00:39.0312 1844 hkmsvc (7a6b320928f86bc851530d63c82965d9) D:\WINDOWS\System32\kmsvc.dll
09:00:39.0687 1844 hkmsvc - ok
09:00:39.0703 1844 hpn - ok
09:00:39.0750 1844 HPZid412 (5faba4775d4c61e55ec669d643ffc71f) D:\WINDOWS\system32\DRIVERS\HPZid412.sys
09:00:39.0812 1844 HPZid412 - ok
09:00:39.0843 1844 HPZipr12 (a3c43980ee1f1beac778b44ea65dbdd4) D:\WINDOWS\system32\DRIVERS\HPZipr12.sys
09:00:39.0875 1844 HPZipr12 - ok
09:00:39.0906 1844 HPZius12 (2906949bd4e206f2bb0dd1896ce9f66f) D:\WINDOWS\system32\DRIVERS\HPZius12.sys
09:00:39.0953 1844 HPZius12 - ok
09:00:40.0000 1844 HTTP (f80a415ef82cd06ffaf0d971528ead38) D:\WINDOWS\system32\Drivers\HTTP.sys
09:00:40.0046 1844 HTTP - ok
09:00:40.0093 1844 HTTPFilter (58fe2f2da3bc5573f4a35b3760d3125f) D:\WINDOWS\System32\w3ssl.dll
09:00:40.0453 1844 HTTPFilter - ok
09:00:40.0468 1844 i2omgmt - ok
09:00:40.0484 1844 i2omp - ok
09:00:40.0531 1844 i8042prt (c528e27945367191e7bae364930b6932) D:\WINDOWS\system32\DRIVERS\i8042prt.sys
09:00:40.0906 1844 i8042prt - ok
09:00:41.0015 1844 idsvc (c01ac32dc5c03076cfb852cb5da5229c) d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
09:00:41.0109 1844 idsvc - ok
09:00:41.0140 1844 Imapi (083a052659f5310dd8b6a6cb05edcf8e) D:\WINDOWS\system32\DRIVERS\imapi.sys
09:00:41.0484 1844 Imapi - ok
09:00:41.0546 1844 ImapiService (f7b93aafad33b2320954c17e26c8d361) D:\WINDOWS\system32\imapi.exe
09:00:41.0859 1844 ImapiService - ok
09:00:41.0890 1844 ini910u - ok
09:00:41.0921 1844 IntelIde - ok
09:00:41.0953 1844 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) D:\WINDOWS\system32\drivers\ip6fw.sys
09:00:42.0328 1844 Ip6Fw - ok
09:00:42.0375 1844 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) D:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
09:00:42.0718 1844 IpFilterDriver - ok
09:00:42.0765 1844 IpInIp (b87ab476dcf76e72010632b5550955f5) D:\WINDOWS\system32\DRIVERS\ipinip.sys
09:00:43.0140 1844 IpInIp - ok
09:00:43.0171 1844 IpNat (cc748ea12c6effde940ee98098bf96bb) D:\WINDOWS\system32\DRIVERS\ipnat.sys
09:00:43.0484 1844 IpNat - ok
09:00:43.0515 1844 IPSec (23c74d75e36e7158768dd63d92789a91) D:\WINDOWS\system32\DRIVERS\ipsec.sys
09:00:43.0937 1844 IPSec - ok
09:00:43.0968 1844 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) D:\WINDOWS\system32\DRIVERS\irenum.sys
09:00:44.0062 1844 IRENUM - ok
09:00:44.0109 1844 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) D:\WINDOWS\system32\DRIVERS\isapnp.sys
09:00:44.0390 1844 isapnp - ok
09:00:44.0437 1844 jlojyjbp (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\jlojyjbp.sys
09:00:44.0500 1844 jlojyjbp - ok
09:00:44.0515 1844 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) D:\WINDOWS\system32\DRIVERS\kbdclass.sys
09:00:44.0906 1844 Kbdclass - ok
09:00:44.0968 1844 kmixer (692bcf44383d056aed41b045a323d378) D:\WINDOWS\system32\drivers\kmixer.sys
09:00:45.0281 1844 kmixer - ok
09:00:45.0343 1844 KSecDD (b467646c54cc746128904e1654c750c1) D:\WINDOWS\system32\drivers\KSecDD.sys
09:00:45.0375 1844 KSecDD - ok
09:00:45.0437 1844 lanmanserver (3428e8f86f8add36b42fb23542c7b3e4) D:\WINDOWS\System32\srvsvc.dll
09:00:45.0468 1844 lanmanserver - ok
09:00:45.0500 1844 lanmanworkstation (936c1d110232d23b621cb0196e4f80f0) D:\WINDOWS\System32\wkssvc.dll
09:00:45.0546 1844 lanmanworkstation - ok
09:00:45.0562 1844 lbrtfdc - ok
09:00:45.0625 1844 LmHosts (0ab159f536e3e8f7f07113702a07cca5) D:\WINDOWS\System32\lmhsvc.dll
09:00:46.0046 1844 LmHosts - ok
09:00:46.0093 1844 Messenger (221cd1c815b8a6b79389c3f5d1018de8) D:\WINDOWS\System32\msgsvc.dll
09:00:46.0437 1844 Messenger - ok
09:00:46.0468 1844 mhpylftc (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\mhpylftc.sys
09:00:46.0500 1844 mhpylftc - ok
09:00:46.0531 1844 miacbgzg (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\miacbgzg.sys
09:00:46.0593 1844 miacbgzg - ok
09:00:46.0640 1844 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) D:\WINDOWS\system32\drivers\mnmdd.sys
09:00:47.0000 1844 mnmdd - ok
09:00:47.0031 1844 mnmsrvc (9a57d046f88f4b69751b11fd40088a61) D:\WINDOWS\system32\mnmsrvc.exe
09:00:47.0437 1844 mnmsrvc - ok
09:00:47.0484 1844 Modem (44032b0c6d9954d3fd26438330b99ee7) D:\WINDOWS\system32\drivers\Modem.sys
09:00:47.0859 1844 Modem - ok
09:00:47.0890 1844 Mouclass (4cb582831dbde63ce43b45d771218374) D:\WINDOWS\system32\DRIVERS\mouclass.sys
09:00:48.0265 1844 Mouclass - ok
09:00:48.0296 1844 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) D:\WINDOWS\system32\drivers\MountMgr.sys
09:00:48.0640 1844 MountMgr - ok
09:00:48.0687 1844 MpFilter (d993bea500e7382dc4e760bf4f35efcb) D:\WINDOWS\system32\DRIVERS\MpFilter.sys
09:00:48.0734 1844 MpFilter - ok
09:00:48.0859 1844 MpKslba39dc34 (a69630d039c38018689190234f866d77) d:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E9ECE111-8918-42C5-9733-4E6F4B0C17B0}\MpKslba39dc34.sys
09:00:48.0890 1844 MpKslba39dc34 - ok
09:00:48.0906 1844 mraid35x - ok
09:00:49.0000 1844 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) D:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
09:00:49.0015 1844 MREMP50 ( UnsignedFile.Multi.Generic ) - warning
09:00:49.0015 1844 MREMP50 - detected UnsignedFile.Multi.Generic (1)
09:00:49.0031 1844 MREMP50a64 - ok
09:00:49.0046 1844 MREMPR5 - ok
09:00:49.0062 1844 MRENDIS5 - ok
09:00:49.0093 1844 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) D:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
09:00:49.0093 1844 MRESP50 ( UnsignedFile.Multi.Generic ) - warning
09:00:49.0093 1844 MRESP50 - detected UnsignedFile.Multi.Generic (1)
09:00:49.0109 1844 MRESP50a64 - ok
09:00:49.0156 1844 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) D:\WINDOWS\system32\DRIVERS\mrxdav.sys
09:00:49.0500 1844 MRxDAV - ok
09:00:49.0578 1844 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) D:\WINDOWS\system32\DRIVERS\mrxsmb.sys
09:00:49.0640 1844 MRxSmb - ok
09:00:49.0687 1844 MSDTC (6db4d1521caba9a5ffab54ade0ae867d) D:\WINDOWS\system32\msdtc.exe
09:00:50.0015 1844 MSDTC - ok
09:00:50.0046 1844 Msfs (c941ea2454ba8350021d774daf0f1027) D:\WINDOWS\system32\drivers\Msfs.sys
09:00:50.0484 1844 Msfs - ok
09:00:50.0515 1844 MSIServer - ok
09:00:50.0562 1844 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) D:\WINDOWS\system32\drivers\MSKSSRV.sys
09:00:50.0875 1844 MSKSSRV - ok
09:00:50.0937 1844 MsMpSvc (24516bf4e12a46cb67302e2cdcb8cddf) d:\Program Files\Microsoft Security Client\MsMpEng.exe
09:00:50.0953 1844 MsMpSvc - ok
09:00:50.0984 1844 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) D:\WINDOWS\system32\drivers\MSPCLOCK.sys
09:00:51.0359 1844 MSPCLOCK - ok
09:00:51.0390 1844 MSPQM (bad59648ba099da4a17680b39730cb3d) D:\WINDOWS\system32\drivers\MSPQM.sys
09:00:51.0765 1844 MSPQM - ok
09:00:51.0812 1844 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) D:\WINDOWS\system32\DRIVERS\mssmbios.sys
09:00:52.0156 1844 mssmbios - ok
09:00:52.0203 1844 Mup (de6a75f5c270e756c5508d94b6cf68f5) D:\WINDOWS\system32\drivers\Mup.sys
09:00:52.0234 1844 Mup - ok
09:00:52.0296 1844 napagent (6ea362e9db03d44f6b996f4d8be237e9) D:\WINDOWS\System32\qagentrt.dll
09:00:52.0656 1844 napagent - ok
09:00:52.0703 1844 NDIS (1df7f42665c94b825322fae71721130d) D:\WINDOWS\system32\drivers\NDIS.sys
09:00:53.0062 1844 NDIS - ok
09:00:53.0093 1844 NdisTapi (0109c4f3850dfbab279542515386ae22) D:\WINDOWS\system32\DRIVERS\ndistapi.sys
09:00:53.0125 1844 NdisTapi - ok
09:00:53.0156 1844 Ndisuio (f927a4434c5028758a842943ef1a3849) D:\WINDOWS\system32\DRIVERS\ndisuio.sys
09:00:53.0578 1844 Ndisuio - ok
09:00:53.0625 1844 NdisWan (edc1531a49c80614b2cfda43ca8659ab) D:\WINDOWS\system32\DRIVERS\ndiswan.sys
09:00:53.0953 1844 NdisWan - ok
09:00:53.0984 1844 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) D:\WINDOWS\system32\drivers\NDProxy.sys
09:00:54.0015 1844 NDProxy - ok
09:00:54.0046 1844 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) D:\WINDOWS\system32\DRIVERS\netbios.sys
09:00:54.0375 1844 NetBIOS - ok
09:00:54.0406 1844 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) D:\WINDOWS\system32\DRIVERS\netbt.sys
09:00:54.0750 1844 NetBT - ok
09:00:54.0796 1844 NetDDE (933de774986ec85e48210c44ab431de6) D:\WINDOWS\system32\netdde.exe
09:00:55.0171 1844 NetDDE - ok
09:00:55.0203 1844 NetDDEdsdm (933de774986ec85e48210c44ab431de6) D:\WINDOWS\system32\netdde.exe
09:00:55.0515 1844 NetDDEdsdm - ok
09:00:55.0546 1844 Netlogon (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
09:00:55.0937 1844 Netlogon - ok
09:00:55.0984 1844 Netman (72e1e9e2977be08bdeedb6d8fd9d4d40) D:\WINDOWS\System32\netman.dll
09:00:56.0343 1844 Netman - ok
09:00:56.0421 1844 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
09:00:56.0437 1844 NetTcpPortSharing - ok
09:00:56.0500 1844 Nla (39ee7c3bfbc64ba87cc8cf67386e814c) D:\WINDOWS\System32\mswsock.dll
09:00:56.0531 1844 Nla - ok
09:00:56.0562 1844 Npfs (3182d64ae053d6fb034f44b6def8034a) D:\WINDOWS\system32\drivers\Npfs.sys
09:00:56.0937 1844 Npfs - ok
09:00:57.0000 1844 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) D:\WINDOWS\system32\drivers\Ntfs.sys
09:00:57.0390 1844 Ntfs - ok
09:00:57.0406 1844 NtLmSsp (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
09:00:57.0765 1844 NtLmSsp - ok
09:00:57.0843 1844 NtmsSvc (023dd70573d644f3d9c8b1258a7bfd08) D:\WINDOWS\system32\ntmssvc.dll
09:00:58.0234 1844 NtmsSvc - ok
09:00:58.0265 1844 Null (73c1e1f395918bc2c6dd67af7591a3ad) D:\WINDOWS\system32\drivers\Null.sys
09:00:58.0671 1844 Null - ok
09:00:58.0703 1844 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) D:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
09:00:59.0062 1844 NwlnkFlt - ok
09:00:59.0093 1844 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) D:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
09:00:59.0515 1844 NwlnkFwd - ok
09:00:59.0578 1844 ose (7a56cf3e3f12e8af599963b16f50fb6a) D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
09:00:59.0609 1844 ose - ok
09:00:59.0656 1844 Parport (46f8db73b4a53e543f8e371dc7c75bae) D:\WINDOWS\system32\DRIVERS\parport.sys
09:00:59.0968 1844 Parport - ok
09:01:00.0000 1844 PartMgr (beb3ba25197665d82ec7065b724171c6) D:\WINDOWS\system32\drivers\PartMgr.sys
09:01:00.0312 1844 PartMgr - ok
09:01:00.0359 1844 ParVdm (1fae19d0457176318bba4a8795656ebc) D:\WINDOWS\system32\drivers\ParVdm.sys
09:01:00.0703 1844 ParVdm - ok
09:01:00.0750 1844 PCI (6ce351d149cb4befc702951e471e1730) D:\WINDOWS\system32\DRIVERS\pci.sys
09:01:01.0109 1844 PCI - ok
09:01:01.0140 1844 PCIDump - ok
09:01:01.0187 1844 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) D:\WINDOWS\system32\DRIVERS\pciide.sys
09:01:01.0500 1844 PCIIde - ok
09:01:01.0546 1844 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) D:\WINDOWS\system32\drivers\Pcmcia.sys
09:01:01.0875 1844 Pcmcia - ok
09:01:01.0906 1844 PDCOMP - ok
09:01:01.0921 1844 PDFRAME - ok
09:01:01.0937 1844 PDRELI - ok
09:01:01.0968 1844 PDRFRAME - ok
09:01:01.0984 1844 perc2 - ok
09:01:02.0000 1844 perc2hib - ok
09:01:02.0078 1844 PlugPlay (9ef697af07bb8dd82c3b02ca953a95b7) D:\WINDOWS\system32\services.exe
09:01:02.0109 1844 PlugPlay - ok
09:01:02.0156 1844 Pml Driver HPZ12 (901c43516504cbe582e4c4193e00876a) D:\WINDOWS\system32\HPZipm12.exe
09:01:02.0156 1844 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
09:01:02.0156 1844 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
09:01:02.0171 1844 PolicyAgent (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
09:01:02.0500 1844 PolicyAgent - ok
09:01:02.0546 1844 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) D:\WINDOWS\system32\DRIVERS\raspptp.sys
09:01:02.0953 1844 PptpMiniport - ok
09:01:02.0968 1844 ProtectedStorage (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
09:01:03.0281 1844 ProtectedStorage - ok
09:01:03.0312 1844 PSched (09298ec810b07e5d582cb3a3f9255424) D:\WINDOWS\system32\DRIVERS\psched.sys
09:01:03.0734 1844 PSched - ok
09:01:03.0765 1844 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) D:\WINDOWS\system32\DRIVERS\ptilink.sys
09:01:04.0109 1844 Ptilink - ok
09:01:04.0156 1844 PxHelp20 (d86b4a68565e444d76457f14172c875a) D:\WINDOWS\system32\Drivers\PxHelp20.sys
09:01:04.0218 1844 PxHelp20 - ok
09:01:04.0234 1844 ql1080 - ok
09:01:04.0265 1844 Ql10wnt - ok
09:01:04.0281 1844 ql12160 - ok
09:01:04.0312 1844 ql1240 - ok
09:01:04.0328 1844 ql1280 - ok
09:01:04.0359 1844 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) D:\WINDOWS\system32\DRIVERS\rasacd.sys
09:01:04.0781 1844 RasAcd - ok
09:01:04.0828 1844 RasAuto (2b5e44ea009f2f374b980e1e9a70635d) D:\WINDOWS\System32\rasauto.dll
09:01:05.0140 1844 RasAuto - ok
09:01:05.0171 1844 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) D:\WINDOWS\system32\DRIVERS\rasl2tp.sys
09:01:05.0500 1844 Rasl2tp - ok
09:01:05.0546 1844 RasMan (d57554c664b64604bd1ee13ea2c07e77) D:\WINDOWS\System32\rasmans.dll
09:01:05.0937 1844 RasMan - ok
09:01:05.0968 1844 RasPppoe (5bc962f2654137c9909c3d4603587dee) D:\WINDOWS\system32\DRIVERS\raspppoe.sys
09:01:06.0250 1844 RasPppoe - ok
09:01:06.0281 1844 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) D:\WINDOWS\system32\DRIVERS\raspti.sys
09:01:06.0656 1844 Raspti - ok
09:01:06.0703 1844 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) D:\WINDOWS\system32\DRIVERS\rdbss.sys
09:01:07.0031 1844 Rdbss - ok
09:01:07.0062 1844 RDPCDD (4912d5b403614ce99c28420f75353332) D:\WINDOWS\system32\DRIVERS\RDPCDD.sys
09:01:07.0437 1844 RDPCDD - ok
09:01:07.0515 1844 RDPWD (6589db6e5969f8eee594cf71171c5028) D:\WINDOWS\system32\drivers\RDPWD.sys
09:01:07.0531 1844 RDPWD - ok
09:01:07.0578 1844 RDSessMgr (c0d9d9711cb74ee9bc66353d8cbdab0e) D:\WINDOWS\system32\sessmgr.exe
09:01:07.0875 1844 RDSessMgr - ok
09:01:07.0921 1844 redbook (611bfd220305be3a85ae876ea47d4aa5) D:\WINDOWS\system32\DRIVERS\redbook.sys
09:01:08.0312 1844 redbook - ok
09:01:08.0343 1844 RemoteAccess (127c26b5371651043450e52542099aba) D:\WINDOWS\System32\mprdim.dll
09:01:08.0625 1844 RemoteAccess - ok
09:01:08.0687 1844 RpcLocator (718b3bdc0bc3c2f7d065a53d26202af9) D:\WINDOWS\system32\locator.exe
09:01:09.0046 1844 RpcLocator - ok
09:01:09.0109 1844 RpcSs (be27674d1cbc3214aec84b4336a38bbf) D:\WINDOWS\system32\rpcss.dll
09:01:09.0156 1844 RpcSs - ok
09:01:09.0203 1844 RSVP (09ab2e71e58b078038e3bfdba7ffc984) D:\WINDOWS\system32\rsvp.exe
09:01:09.0515 1844 RSVP - ok
09:01:09.0578 1844 RT73 (c7bcf9808e2a1b4cabe16ff7fbce5fab) D:\WINDOWS\system32\DRIVERS\rt73.sys
09:01:09.0625 1844 RT73 - ok
09:01:09.0656 1844 SamSs (ed0a176354487ceed65b80a7148ab739) D:\WINDOWS\system32\lsass.exe
09:01:10.0031 1844 SamSs - ok
09:01:10.0093 1844 SCardSvr (410046e401eb11e1e6749e9deea41d4a) D:\WINDOWS\System32\SCardSvr.exe
09:01:10.0390 1844 SCardSvr - ok
09:01:10.0437 1844 Schedule (3ff232a7731621b8902d81d42418c93c) D:\WINDOWS\system32\schedsvc.dll
09:01:10.0750 1844 Schedule - ok
09:01:10.0796 1844 Secdrv (90a3935d05b494a5a39d37e71f09a677) D:\WINDOWS\system32\DRIVERS\secdrv.sys
09:01:10.0890 1844 Secdrv - ok
09:01:10.0937 1844 seclogon (477e2c3cc5e4a0d635bcb0ea8dcac3c6) D:\WINDOWS\System32\seclogon.dll
09:01:11.0312 1844 seclogon - ok
09:01:11.0343 1844 SENS (a530b75c10c23c9ab28fdb6ce719e21f) D:\WINDOWS\system32\sens.dll
09:01:11.0656 1844 SENS - ok
09:01:11.0687 1844 serenum (0f29512ccd6bead730039fb4bd2c85ce) D:\WINDOWS\system32\DRIVERS\serenum.sys
09:01:12.0031 1844 serenum - ok
09:01:12.0078 1844 Serial (b842729337c9b921615c40d3c1a1af96) D:\WINDOWS\system32\DRIVERS\serial.sys
09:01:12.0359 1844 Serial - ok
09:01:12.0421 1844 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) D:\WINDOWS\system32\drivers\Sfloppy.sys
09:01:12.0812 1844 Sfloppy - ok
09:01:12.0859 1844 SharedAccess (f58faca9621d2db01bd0927d9a0a208e) D:\WINDOWS\System32\ipnathlp.dll
09:01:13.0187 1844 SharedAccess - ok
09:01:13.0234 1844 ShellHWDetection (ee9a2b9ea968a792a053c9d1a86bf870) D:\WINDOWS\System32\shsvcs.dll
09:01:13.0250 1844 ShellHWDetection - ok
09:01:13.0281 1844 Simbad - ok
09:01:13.0328 1844 SISNIC (3fbb6ef8b5a71a2fa11f5f461bb73219) D:\WINDOWS\system32\DRIVERS\sisnic.sys
09:01:13.0703 1844 SISNIC - ok
09:01:13.0718 1844 Sparrow - ok
09:01:13.0750 1844 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) D:\WINDOWS\system32\drivers\splitter.sys
09:01:14.0078 1844 splitter - ok
09:01:14.0125 1844 Spooler (60784f891563fb1b767f70117fc2428f) D:\WINDOWS\system32\spoolsv.exe
09:01:14.0140 1844 Spooler - ok
09:01:14.0250 1844 sptd (bd66bf74d06624f3abf15dd990888c54) D:\WINDOWS\system32\Drivers\sptd.sys
09:01:14.0250 1844 Suspicious file (NoAccess): D:\WINDOWS\system32\Drivers\sptd.sys. md5: bd66bf74d06624f3abf15dd990888c54
09:01:14.0250 1844 sptd ( LockedFile.Multi.Generic ) - warning
09:01:14.0250 1844 sptd - detected LockedFile.Multi.Generic (1)
09:01:14.0296 1844 sr (94610c8653635e4459316a0050d55ce7) D:\WINDOWS\system32\DRIVERS\sr.sys
09:01:14.0390 1844 sr - ok
09:01:14.0453 1844 srservice (35b91147124f64ac8081a2edb9ea4dee) D:\WINDOWS\system32\srsvc.dll
09:01:14.0546 1844 srservice - ok
09:01:14.0625 1844 Srv (47ddfc2f003f7f9f0592c6874962a2e7) D:\WINDOWS\system32\DRIVERS\srv.sys
09:01:14.0656 1844 Srv - ok
09:01:14.0703 1844 SSDPSRV (becd5271dc4e3b7c3d035f790fcbc1e5) D:\WINDOWS\System32\ssdpsrv.dll
09:01:14.0812 1844 SSDPSRV - ok
09:01:14.0890 1844 stisvc (c1cdd9275f6a115bb0ae1d55d8d27ba6) D:\WINDOWS\system32\wiaservc.dll
09:01:15.0093 1844 stisvc - ok
09:01:15.0125 1844 swenum (3941d127aef12e93addf6fe6ee027e0f) D:\WINDOWS\system32\DRIVERS\swenum.sys
09:01:15.0531 1844 swenum - ok
09:01:15.0578 1844 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) D:\WINDOWS\system32\drivers\swmidi.sys
09:01:15.0859 1844 swmidi - ok
09:01:15.0875 1844 SwPrv - ok
09:01:15.0921 1844 symc810 - ok
09:01:15.0937 1844 symc8xx - ok
09:01:15.0953 1844 sym_hi - ok
09:01:15.0984 1844 sym_u3 - ok
09:01:16.0015 1844 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) D:\WINDOWS\system32\drivers\sysaudio.sys
09:01:16.0375 1844 sysaudio - ok
09:01:16.0421 1844 SysmonLog (ce06f01b88ace199a1bf460cac29c110) D:\WINDOWS\system32\smlogsvc.exe
09:01:16.0718 1844 SysmonLog - ok
09:01:16.0765 1844 TapiSrv (c2546cd7a398476f9df5614b2ae160e8) D:\WINDOWS\System32\tapisrv.dll
09:01:17.0109 1844 TapiSrv - ok
09:01:17.0187 1844 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) D:\WINDOWS\system32\DRIVERS\tcpip.sys
09:01:17.0218 1844 Tcpip - ok
09:01:17.0281 1844 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) D:\WINDOWS\system32\DRIVERS\tcpip6.sys
09:01:17.0328 1844 Tcpip6 - ok
09:01:17.0390 1844 TDPIPE (6471a66807f5e104e4885f5b67349397) D:\WINDOWS\system32\drivers\TDPIPE.sys
09:01:17.0703 1844 TDPIPE - ok
09:01:17.0734 1844 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) D:\WINDOWS\system32\drivers\TDTCP.sys
09:01:18.0125 1844 TDTCP - ok
09:01:18.0171 1844 TermDD (88155247177638048422893737429d9e) D:\WINDOWS\system32\DRIVERS\termdd.sys
09:01:18.0453 1844 TermDD - ok
09:01:18.0515 1844 TermService (a75dd6fc3dbee4fff5ebc9f2c28bb66e) D:\WINDOWS\System32\termsrv.dll
09:01:18.0875 1844 TermService - ok
09:01:18.0921 1844 Themes (ee9a2b9ea968a792a053c9d1a86bf870) D:\WINDOWS\System32\shsvcs.dll
09:01:18.0953 1844 Themes - ok
09:01:19.0000 1844 tnndsbir (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\tnndsbir.sys
09:01:19.0015 1844 tnndsbir - ok
09:01:19.0046 1844 TosIde - ok
09:01:19.0078 1844 TrkWks (38853304ccb938d30e0c4cde8d2c2a8a) D:\WINDOWS\system32\trkwks.dll
09:01:19.0453 1844 TrkWks - ok
09:01:19.0500 1844 tunmp (8f861eda21c05857eb8197300a92501c) D:\WINDOWS\system32\DRIVERS\tunmp.sys
09:01:19.0828 1844 tunmp - ok
09:01:19.0859 1844 uagp35 (d85938f272d1bcf3db3a31fc0a048928) D:\WINDOWS\system32\DRIVERS\uagp35.sys
09:01:20.0234 1844 uagp35 - ok
09:01:20.0265 1844 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) D:\WINDOWS\system32\drivers\Udfs.sys
09:01:20.0562 1844 Udfs - ok
09:01:20.0593 1844 ultra - ok
09:01:20.0640 1844 Update (402ddc88356b1bac0ee3dd1580c76a31) D:\WINDOWS\system32\DRIVERS\update.sys
09:01:20.0968 1844 Update - ok
09:01:21.0031 1844 upnphost (651bd90dcee5b7bdc74a2eb7c9266f9e) D:\WINDOWS\System32\upnphost.dll
09:01:21.0156 1844 upnphost - ok
09:01:21.0171 1844 UPS (20a0f6a11959e92908717d09e87d670d) D:\WINDOWS\System32\ups.exe
09:01:21.0437 1844 UPS - ok
09:01:21.0484 1844 urhbyldj (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\urhbyldj.sys
09:01:21.0500 1844 urhbyldj - ok
09:01:21.0531 1844 usbccgp (173f317ce0db8e21322e71b7e60a27e8) D:\WINDOWS\system32\DRIVERS\usbccgp.sys
09:01:21.0921 1844 usbccgp - ok
09:01:21.0968 1844 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) D:\WINDOWS\system32\DRIVERS\usbehci.sys
09:01:22.0265 1844 usbehci - ok
09:01:22.0296 1844 usbhub (1ab3cdde553b6e064d2e754efe20285c) D:\WINDOWS\system32\DRIVERS\usbhub.sys
09:01:22.0687 1844 usbhub - ok
09:01:22.0734 1844 usbohci (0daecce65366ea32b162f85f07c6753b) D:\WINDOWS\system32\DRIVERS\usbohci.sys
09:01:23.0031 1844 usbohci - ok
09:01:23.0078 1844 usbprint (a717c8721046828520c9edf31288fc00) D:\WINDOWS\system32\DRIVERS\usbprint.sys
09:01:23.0390 1844 usbprint - ok
09:01:23.0421 1844 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) D:\WINDOWS\system32\DRIVERS\usbscan.sys
09:01:23.0718 1844 usbscan - ok
09:01:23.0765 1844 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:01:24.0125 1844 USBSTOR - ok
09:01:24.0156 1844 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) D:\WINDOWS\System32\drivers\vga.sys
09:01:24.0437 1844 VgaSave - ok
09:01:24.0453 1844 ViaIde - ok
09:01:24.0500 1844 VolSnap (28a4b296b47782173c346e376cb374d1) D:\WINDOWS\system32\drivers\VolSnap.sys
09:01:24.0812 1844 VolSnap - ok
09:01:24.0875 1844 VSS (d6ba1a63d9e00933f1cd2a885573afb2) D:\WINDOWS\System32\vssvc.exe
09:01:24.0968 1844 VSS - ok
09:01:25.0031 1844 W32Time (fa4e1cdba256787f2149f4aad07bc91f) D:\WINDOWS\system32\w32time.dll
09:01:25.0250 1844 W32Time - ok
09:01:25.0296 1844 Wanarp (e20b95baedb550f32dd489265c1da1f6) D:\WINDOWS\system32\DRIVERS\wanarp.sys
09:01:25.0703 1844 Wanarp - ok
09:01:25.0718 1844 WDICA - ok
09:01:25.0765 1844 wdmaud (6768acf64b18196494413695f0c3a00f) D:\WINDOWS\system32\drivers\wdmaud.sys
09:01:26.0093 1844 wdmaud - ok
09:01:26.0140 1844 WebClient (47ae51048a82dfa1cd6b51d369f7e169) D:\WINDOWS\System32\webclnt.dll
09:01:26.0468 1844 WebClient - ok
09:01:26.0562 1844 winmgmt (e488332126e3b1182d2b8a0c35408ec6) D:\WINDOWS\system32\wbem\WMIsvc.dll
09:01:26.0843 1844 winmgmt - ok
09:01:26.0953 1844 WinRM (4d34cedd74bdbf2b6a935eae3bf80543) D:\WINDOWS\system32\WsmSvc.dll
09:01:27.0078 1844 WinRM - ok
09:01:27.0140 1844 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) D:\WINDOWS\system32\MsPMSNSv.dll
09:01:27.0187 1844 WmdmPmSN - ok
09:01:27.0265 1844 WmiApSrv (23f6f03272f7e5679f1f050aed5acee6) D:\WINDOWS\system32\wbem\wmiapsrv.exe
09:01:27.0578 1844 WmiApSrv - ok
09:01:27.0703 1844 WMPNetworkSvc (3739866d20abd42f26a7b85f9e2560af) D:\Program Files\Windows Media Player\WMPNetwk.exe
09:01:27.0781 1844 WMPNetworkSvc - ok
09:01:27.0812 1844 wscsvc (4c86d5faf78194995af9cc1075f65dd3) D:\WINDOWS\system32\wscsvc.dll
09:01:28.0218 1844 wscsvc - ok
09:01:28.0250 1844 wuauserv (c1364564800ee9784192145324a23308) D:\WINDOWS\system32\wuauserv.dll
09:01:28.0531 1844 wuauserv - ok
09:01:28.0593 1844 WudfPf (f15feafffbb3644ccc80c5da584e6311) D:\WINDOWS\system32\DRIVERS\WudfPf.sys
09:01:28.0609 1844 WudfPf - ok
09:01:28.0656 1844 WudfRd (28b524262bce6de1f7ef9f510ba3985b) D:\WINDOWS\system32\DRIVERS\wudfrd.sys
09:01:28.0687 1844 WudfRd - ok
09:01:28.0734 1844 WudfSvc (05231c04253c5bc30b26cbaae680ed89) D:\WINDOWS\System32\WUDFSvc.dll
09:01:28.0765 1844 WudfSvc - ok
09:01:28.0843 1844 WZCSVC (a27d4ba7264c0bf52f32d10405bea1d4) D:\WINDOWS\System32\wzcsvc.dll
09:01:29.0218 1844 WZCSVC - ok
09:01:29.0234 1844 xcpip - ok
09:01:29.0281 1844 xefsflhx (dd0a8b0aa7791691ff597334708d9e8f) D:\WINDOWS\system32\drivers\xefsflhx.sys
09:01:29.0312 1844 xefsflhx - ok
09:01:29.0375 1844 xmlprov (eaa4bb9edb3fb10cf8979fe65e63658f) D:\WINDOWS\System32\xmlprov.dll
09:01:29.0687 1844 xmlprov - ok
09:01:29.0703 1844 xpsec - ok
09:01:29.0796 1844 MBR (0x1B8) (0e1d60863e74698b6255deeb65261da6) \Device\Harddisk0\DR0
09:01:29.0796 1844 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - infected
09:01:29.0796 1844 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Sinowal.b (0)
09:01:29.0890 1844 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk1\DR1
09:01:29.0984 1844 \Device\Harddisk1\DR1 - ok
09:01:30.0015 1844 Boot (0x1200) (25b7d8f78bef80b5be7b3cadabf84bbd) \Device\Harddisk0\DR0\Partition0
09:01:30.0031 1844 \Device\Harddisk0\DR0\Partition0 - ok
09:01:30.0046 1844 Boot (0x1200) (9bb6c29286ecd27996a136c2fb4a55be) \Device\Harddisk1\DR1\Partition0
09:01:30.0046 1844 \Device\Harddisk1\DR1\Partition0 - ok
09:01:30.0046 1844 ============================================================
09:01:30.0046 1844 Scan finished
09:01:30.0046 1844 ============================================================
09:01:30.0187 1856 Detected object count: 8
09:01:30.0187 1856 Actual detected object count: 8
09:02:29.0921 1856 AegisP ( UnsignedFile.Multi.Generic ) - skipped by user
09:02:29.0921 1856 AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:02:29.0921 1856 ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user
09:02:29.0921 1856 ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:02:29.0921 1856 dtscsi ( LockedFile.Multi.Generic ) - skipped by user
09:02:29.0921 1856 dtscsi ( LockedFile.Multi.Generic ) - User select action: Skip
09:02:29.0921 1856 MREMP50 ( UnsignedFile.Multi.Generic ) - skipped by user
09:02:29.0921 1856 MREMP50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:02:29.0921 1856 MRESP50 ( UnsignedFile.Multi.Generic ) - skipped by user
09:02:29.0921 1856 MRESP50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:02:29.0921 1856 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
09:02:29.0921 1856 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
09:02:29.0937 1856 sptd ( LockedFile.Multi.Generic ) - skipped by user
09:02:29.0937 1856 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
09:02:30.0453 1856 \Device\Harddisk0\DR0\# - copied to quarantine
09:02:30.0515 1856 \Device\Harddisk0\DR0 - copied to quarantine
09:02:30.0562 1856 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - will be cured on reboot
09:02:30.0578 1856 \Device\Harddisk0\DR0 - ok
09:02:30.0578 1856 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - User select action: Cure
09:02:58.0718 2472 Deinitialize success

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 09:49
od vyosek
:arrow: Sinowal je fuc, ale dalsi havet tam jeste je :boxed:

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 13:10
od jaroslav.24
A k čemu je tam ten antivir ??


ComboFix 12-07-31.03 - Kryton 02.08.2012 13:15:15.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.635 [GMT 2:00]
Spuštěný z: d:\documents and settings\Kryton\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\program files\VVSN
d:\program files\VVSN\vvsn.cfg
d:\windows\system32\URTTemp
d:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_xcpip
-------\Service_xpsec
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-02 do 2012-08-02 )))))))))))))))))))))))))))))))
.
.
2012-08-02 07:02 . 2012-08-02 07:02 -------- d-----w- D:\TDSSKiller_Quarantine
2012-08-02 04:31 . 2012-08-02 04:31 -------- d-----w- D:\rsit
2012-08-01 17:27 . 2012-06-29 08:44 6891424 ----a-w- d:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E9ECE111-8918-42C5-9733-4E6F4B0C17B0}\mpengine.dll
2012-07-31 17:24 . 2012-06-29 08:44 6891424 ----a-w- d:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-15 09:46 . 2012-07-15 09:46 -------- d-----w- d:\program files\Common Files\HP
2012-07-15 09:44 . 2012-07-15 09:44 -------- d-----w- d:\program files\Hewlett-Packard
2012-07-15 09:43 . 2012-07-15 09:43 -------- d-----w- d:\documents and settings\All Users\Data aplikací\Hewlett-Packard
2012-07-15 09:43 . 2012-07-15 09:43 45056 ----a-r- d:\documents and settings\Kryton\Data aplikací\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2012-07-15 09:36 . 2004-06-22 10:44 90112 ----a-w- d:\windows\system32\hpovst08.dll
2012-07-15 09:36 . 2004-06-22 10:44 581632 ----a-w- d:\windows\system32\hpotscl.dll
2012-07-15 09:36 . 2004-06-22 10:44 180315 ----a-w- d:\windows\system32\hpzsnt10.dll
2012-07-07 19:29 . 2012-07-07 19:29 151515 ----a-w- d:\windows\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2012-07-07 19:08 . 2012-07-07 19:08 -------- d-----w- d:\program files\Maxis
2012-07-06 14:01 . 2012-07-06 14:01 21361 ----a-w- d:\windows\system32\drivers\AegisP.sys
2012-07-06 14:00 . 2008-01-15 19:50 459520 ----a-w- d:\windows\system32\drivers\rt73.sys
2012-07-06 14:00 . 2005-11-30 09:33 2048 ----a-w- d:\windows\system32\rt73.bin
2012-07-06 14:00 . 2012-07-06 14:00 -------- d-----w- d:\program files\EDIMAX
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 11:36 . 2012-04-01 08:05 426184 ----a-w- d:\windows\system32\FlashPlayerApp.exe
2012-07-27 11:36 . 2012-01-30 20:13 70344 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:55 . 2006-03-02 12:00 1866112 ----a-w- d:\windows\system32\win32k.sys
2012-06-05 15:49 . 2007-05-15 14:43 1372672 ----a-w- d:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2006-03-02 12:00 1172480 ----a-w- d:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2006-03-02 12:00 152576 ----a-w- d:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-08-06 18:24 15384 ----a-w- d:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-08-06 18:24 22552 ----a-w- d:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2012-01-29 15:37 329240 ----a-w- d:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2012-01-29 15:37 219160 ----a-w- d:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2012-01-29 15:37 210968 ----a-w- d:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2012-01-29 15:37 53784 ----a-w- d:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2012-01-29 15:37 35864 ----a-w- d:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-08-06 18:24 45080 ----a-w- d:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 18:24 18456 ----a-w- d:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-08-06 18:24 15384 ----a-w- d:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2006-03-02 12:00 97304 ----a-w- d:\windows\system32\cdm.dll
2012-06-02 13:19 . 2012-01-29 15:37 577048 ----a-w- d:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2012-01-29 15:37 1933848 ----a-w- d:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2012-01-31 16:02 17648 ----a-w- d:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2012-01-31 16:02 275696 ----a-w- d:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2009-08-06 18:23 214256 ----a-w- d:\windows\system32\muweb.dll
2012-05-31 13:22 . 2006-03-02 12:00 602112 ----a-w- d:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2006-03-02 12:00 916992 ----a-w- d:\windows\system32\wininet.dll
2012-05-11 14:44 . 2006-03-02 12:00 43520 ----a-w- d:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2006-03-02 12:00 1469440 ----a-w- d:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-03-02 12:00 385024 ----a-w- d:\windows\system32\html.iec
2012-05-05 03:14 . 2006-03-02 12:00 2194816 ----a-w- d:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-17 15:45 2071296 ----a-w- d:\windows\system32\ntkrnlpa.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="d:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"C-Media Mixer"="Mixer.exe" [2002-10-15 1818624]
"ATICCC"="d:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"MSC"="d:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="d:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="d:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
d:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
HP Digital Imaging Monitor.lnk - d:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
Rychlé spuštění aplikace HP Image Zone.lnk - d:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\ICQ7.7\\ICQ.exe"=
"d:\\Program Files\\Diablo II\\Diablo II.exe"=
"d:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\Documents and Settings\\Kryton\\Plocha\\HRY\\DOTA\\Warcraft III\\w3l.exe"=
"d:\\Program Files\\Diablo II\\Game.exe"=
"d:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\HRY\\Lionheart\\Lionheart.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:Vzdálená správa systému Windows
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
.
R0 sptd;sptd;d:\windows\system32\drivers\sptd.sys [29.1.2012 20:39 664064]
S2 gupdate;Služba Google Update (gupdate);d:\program files\Google\Update\GoogleUpdate.exe [27.3.2012 20:10 136176]
S3 gda2amy7.sys;gda2amy7.sys;\??\d:\windows\system32\drivers\gda2amy7.sys --> d:\windows\system32\drivers\gda2amy7.sys [?]
S3 gupdatem;Služba Google Update (gupdatem);d:\program files\Google\Update\GoogleUpdate.exe [27.3.2012 20:10 136176]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-02 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2012-03-27 18:10]
.
2012-08-02 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2012-03-27 18:10]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz
TCP: DhcpNameServer = 109.238.32.52 8.8.8.8
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-02 13:23
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1644491937-1336601894-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1644491937-1336601894-682003330-1004\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-1644491937-1336601894-682003330-1004)
@Allowed: (Read) (S-1-5-21-1644491937-1336601894-682003330-1004)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\ACPI\PNP0F03\4&3a9a8c3e&0\LogConf]
@DACL=(02 0000)
"BasicConfigVector"=hex(a):48,00,00,00,0f,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,01,00,01,00,01,00,00,00,00,02,\
"BootConfig"=hex(8):01,00,00,00,0f,00,00,00,00,00,00,00,01,00,01,00,01,00,00,
00,02,01,01,00,0c,00,00,00,0c,00,00,00,ff,ff,ff,ff
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1300)
d:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2916)
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
d:\windows\system32\Ati2evxx.exe
d:\program files\Microsoft Security Client\MsMpEng.exe
d:\windows\system32\Ati2evxx.exe
d:\windows\system32\wscntfy.exe
d:\windows\Mixer.exe
d:\program files\ATI Technologies\ATI.ACE\CLI.EXE
d:\program files\HP\Digital Imaging\bin\hpqgalry.exe
d:\program files\ATI Technologies\ATI.ACE\cli.exe
d:\program files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Celkový čas: 2012-08-02 13:26:31 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-02 11:26
.
Před spuštěním: Volných bajtů: 101 355 855 872
Po spuštění: Volných bajtů: 101 298 835 456
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(1)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 41018A1AD3FD8362B0CCCEBFD450C241

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 14:04
od vyosek
:arrow: mbr rootkit kterym treba Sinowal je, se dostanou i pres AV ochranu. Dale jsou zdrojem cracky, pochybne stranky apod. Zadny bezp.SW Vas neochrani na 100 %

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"=-
    "Adobe ARM"=-
    "C-Media Mixer"=-
    "HP Software Update"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"=-
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5985:TCP"=-
    "3389:TCP"=-
    "65533:TCP"=-
    "52344:TCP"=-
    
    Collect::
    D:\WINDOWS\system32\drivers\urhbyldj.sys
    D:\WINDOWS\system32\drivers\gda2amy7.sys
    D:\WINDOWS\system32\drivers\xpsec.sys
    D:\WINDOWS\system32\drivers\xcpip.sys
    
    Driver::
    gupdate
    gupdatem
    urhbyldj
    gda2amy7.sys
    
    RegNull::
    [HKEY_USERS\S-1-5-21-1644491937-1336601894-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
    [HKEY_USERS\S-1-5-21-1644491937-1336601894-682003330-1004\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
    
    RegLock::
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\ACPI\PNP0F03\4&3a9a8c3e&0\LogConf]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 17:14
od jaroslav.24
Proběhlo to bez problémů


ComboFix 12-07-31.03 - Kryton 02.08.2012 18:02:15.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.673 [GMT 2:00]
Spuštěný z: d:\documents and settings\Kryton\Plocha\ComboFix.exe
Použité ovládací přepínače :: d:\documents and settings\Kryton\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"d:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"d:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GDA2AMY7.SYS
-------\Legacy_GUPDATE
-------\Service_gda2amy7.sys
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-02 do 2012-08-02 )))))))))))))))))))))))))))))))
.
.
2012-08-02 07:02 . 2012-08-02 07:02 -------- d-----w- D:\TDSSKiller_Quarantine
2012-08-02 04:31 . 2012-08-02 04:31 -------- d-----w- D:\rsit
2012-08-01 17:27 . 2012-06-29 08:44 6891424 ----a-w- d:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E9ECE111-8918-42C5-9733-4E6F4B0C17B0}\mpengine.dll
2012-07-31 17:24 . 2012-06-29 08:44 6891424 ----a-w- d:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-15 09:46 . 2012-07-15 09:46 -------- d-----w- d:\program files\Common Files\HP
2012-07-15 09:44 . 2012-07-15 09:44 -------- d-----w- d:\program files\Hewlett-Packard
2012-07-15 09:43 . 2012-07-15 09:43 -------- d-----w- d:\documents and settings\All Users\Data aplikací\Hewlett-Packard
2012-07-15 09:43 . 2012-07-15 09:43 45056 ----a-r- d:\documents and settings\Kryton\Data aplikací\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2012-07-15 09:36 . 2004-06-22 10:44 90112 ----a-w- d:\windows\system32\hpovst08.dll
2012-07-15 09:36 . 2004-06-22 10:44 581632 ----a-w- d:\windows\system32\hpotscl.dll
2012-07-15 09:36 . 2004-06-22 10:44 180315 ----a-w- d:\windows\system32\hpzsnt10.dll
2012-07-07 19:29 . 2012-07-07 19:29 151515 ----a-w- d:\windows\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2012-07-07 19:08 . 2012-07-07 19:08 -------- d-----w- d:\program files\Maxis
2012-07-06 14:01 . 2012-07-06 14:01 21361 ----a-w- d:\windows\system32\drivers\AegisP.sys
2012-07-06 14:00 . 2008-01-15 19:50 459520 ----a-w- d:\windows\system32\drivers\rt73.sys
2012-07-06 14:00 . 2005-11-30 09:33 2048 ----a-w- d:\windows\system32\rt73.bin
2012-07-06 14:00 . 2012-07-06 14:00 -------- d-----w- d:\program files\EDIMAX
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 11:36 . 2012-04-01 08:05 426184 ----a-w- d:\windows\system32\FlashPlayerApp.exe
2012-07-27 11:36 . 2012-01-30 20:13 70344 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:55 . 2006-03-02 12:00 1866112 ----a-w- d:\windows\system32\win32k.sys
2012-06-05 15:49 . 2007-05-15 14:43 1372672 ----a-w- d:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2006-03-02 12:00 1172480 ----a-w- d:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2006-03-02 12:00 152576 ----a-w- d:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-08-06 18:24 15384 ----a-w- d:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-08-06 18:24 22552 ----a-w- d:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2012-01-29 15:37 329240 ----a-w- d:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2012-01-29 15:37 219160 ----a-w- d:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2012-01-29 15:37 210968 ----a-w- d:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2012-01-29 15:37 53784 ----a-w- d:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2012-01-29 15:37 35864 ----a-w- d:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-08-06 18:24 45080 ----a-w- d:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 18:24 18456 ----a-w- d:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-08-06 18:24 15384 ----a-w- d:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2006-03-02 12:00 97304 ----a-w- d:\windows\system32\cdm.dll
2012-06-02 13:19 . 2012-01-29 15:37 577048 ----a-w- d:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2012-01-29 15:37 1933848 ----a-w- d:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2012-01-31 16:02 17648 ----a-w- d:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2012-01-31 16:02 275696 ----a-w- d:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2009-08-06 18:23 214256 ----a-w- d:\windows\system32\muweb.dll
2012-05-31 13:22 . 2006-03-02 12:00 602112 ----a-w- d:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2006-03-02 12:00 916992 ----a-w- d:\windows\system32\wininet.dll
2012-05-11 14:44 . 2006-03-02 12:00 43520 ----a-w- d:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2006-03-02 12:00 1469440 ----a-w- d:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-03-02 12:00 385024 ----a-w- d:\windows\system32\html.iec
2012-05-05 03:14 . 2006-03-02 12:00 2194816 ----a-w- d:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-17 15:45 2071296 ----a-w- d:\windows\system32\ntkrnlpa.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="d:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"MSC"="d:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"HP Component Manager"="d:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="d:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
d:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
HP Digital Imaging Monitor.lnk - d:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
Rychlé spuštění aplikace HP Image Zone.lnk - d:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\ICQ7.7\\ICQ.exe"=
"d:\\Program Files\\Diablo II\\Diablo II.exe"=
"d:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\Documents and Settings\\Kryton\\Plocha\\HRY\\DOTA\\Warcraft III\\w3l.exe"=
"d:\\Program Files\\Diablo II\\Game.exe"=
"d:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\HRY\\Lionheart\\Lionheart.exe"=
.
R0 sptd;sptd;d:\windows\system32\drivers\sptd.sys [29.1.2012 20:39 664064]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-02 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2012-03-27 18:10]
.
2012-08-02 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2012-03-27 18:10]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz
TCP: DhcpNameServer = 109.238.32.52 8.8.8.8
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-02 18:10
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1644491937-1336601894-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1644491937-1336601894-682003330-1004\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-1644491937-1336601894-682003330-1004)
@Allowed: (Read) (S-1-5-21-1644491937-1336601894-682003330-1004)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1056)
d:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2132)
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
d:\windows\system32\Ati2evxx.exe
d:\program files\Microsoft Security Client\MsMpEng.exe
d:\windows\system32\Ati2evxx.exe
d:\windows\system32\wscntfy.exe
d:\program files\ATI Technologies\ATI.ACE\CLI.EXE
d:\program files\HP\Digital Imaging\bin\hpqgalry.exe
d:\program files\ATI Technologies\ATI.ACE\cli.exe
d:\program files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Celkový čas: 2012-08-02 18:12:43 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-02 16:12
ComboFix2.txt 2012-08-02 11:26
.
Před spuštěním: Volných bajtů: 101 310 828 544
Po spuštění: Volných bajtů: 101 292 564 480
.
- - End Of File - - 09A9DAEC1E9BABB2441C0F83561CD039

Re: win32/sinoval.gen!y

Napsal: 02 srp 2012 21:44
od vyosek
:arrow: Nasledujici soubory otestujte na VirusTotalu https://www.virustotal.com/cs/
  • d:\windows\system32\drivers\AegisP.sys
    d:\windows\system32\drivers\rt73.sys
    d:\windows\system32\rt73.bin
  • Kliknete na Choose file
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Kliknete na Scan It
  • Pokud na Vas vyskoci obrazovka jako je nize, tak kliknete na ReAnalyse
    Obrázek
  • Vysledek analyzy sem vlozte (jako odkaz)

Re: win32/sinoval.gen!y

Napsal: 03 srp 2012 06:12
od jaroslav.24
Soubory jsem otestoval ,ale bohužel nevím jak mám udělat ten odkaz? Vůbec nevím o co jde.

Re: win32/sinoval.gen!y

Napsal: 03 srp 2012 06:30
od vyosek
:arrow: Nahore jak pisete adresu stranek, tak zkopirujte co to tam je

:arrow: Nebo jestli si pamatujete ci tam byl nejaky nalez = cerveny radek :?:

Re: win32/sinoval.gen!y

Napsal: 03 srp 2012 06:43
od jaroslav.24
Ne žádná červená ,žádný nález ,test byl bez nálezu.

Re: win32/sinoval.gen!y

Napsal: 03 srp 2012 06:46
od vyosek
:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :files
     d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte

Re: win32/sinoval.gen!y

Napsal: 03 srp 2012 06:54
od jaroslav.24
Promiň ,ale nejde to stáhnout. Odkaz nefunguje.