Kontrola logu postup Rootkik
Napsal: 24 čer 2013 18:07
Dobrý den, prosím pěkně o kontrolu logu.
AVG antivir mi vyhledal rootkiky, který neumí odstranit. Jinak žádné problémy nejsou až na zpomalený start PC.
Děkuji
GMER 2.1.19163 - http://www.gmer.net
Rootkit quick scan 2013-06-23 18:06:12
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD600BB-00CAA1 rev.17.07W17 55,90GB
Running: gmer.exe; Driver: C:\DOCUME~1\sedlacek\LOCALS~1\Temp\pxtdapow.sys
---- Devices - GMER 2.1 ----
Device \Driver\atapi \Device\Ide\IdePort0 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target1Lun0 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target0Lun0 86AEC1F8
Device \FileSystem\Ntfs \Ntfs 86FD71F8
Device \FileSystem\Fastfat \Fat 86B511F8
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys
---- EOF - GMER 2.1 ----
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-23 21:02:14
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD600BB-00CAA1 rev.17.07W17 55,90GB
Running: gmer.exe; Driver: C:\DOCUME~1\sedlacek\LOCALS~1\Temp\pxtdapow.sys
---- System - GMER 2.1 ----
SSDT Lbd.sys ZwCreateKey [0xF75DE87E]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeKey [0xF784F5D0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeMultipleKeys [0xF784F700]
SSDT spxu.sys ZwOpenKey [0xF745B0C0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenProcess [0xF784F010]
SSDT spxu.sys ZwQueryKey [0xF747420A]
SSDT \??\C:\WINDOWS\system32\drivers\avgtpx86.sys ZwQueryValueKey [0xF766F1D6]
SSDT Lbd.sys ZwSetValueKey [0xF75DEBFE]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendProcess [0xF784F300]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendThread [0xF784F3E0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateProcess [0xF784F120]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateThread [0xF784F210]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwWriteVirtualMemory [0xF784F4D0]
INT 0x39 ? 86BB7F00
INT 0x39 ? 86FDBBF8
INT 0x3B ? 86BB7F00
INT 0x3B ? 86BB7F00
INT 0x3B ? 86BB7F00
INT 0x3E ? 86FD8BF8
INT 0x3F ? 86FD8BF8
---- Kernel code sections - GMER 2.1 ----
? spxu.sys Systém nemůže nalézt uvedený soubor. !
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF653F000, 0x2C3BC6, 0xE8000020]
---- Devices - GMER 2.1 ----
Device \FileSystem\Ntfs \Ntfs 86FD71F8
Device \FileSystem\Fastfat \FatCdrom 86B511F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{99045E80-A4BE-4EFE-9FF3-5D425F602DE1} 86C8C500
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys
Device \Driver\usbohci \Device\USBPDO-0 86B451F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86F6A1F8
Device \Driver\dmio \Device\DmControl\DmConfig 86F6A1F8
Device \Driver\dmio \Device\DmControl\DmPnP 86F6A1F8
Device \Driver\dmio \Device\DmControl\DmInfo 86F6A1F8
Device \Driver\usbohci \Device\USBPDO-1 86B451F8
Device \Driver\usbehci \Device\USBPDO-2 86B2E1F8
Device \Driver\usbuhci \Device\USBPDO-3 86B061F8
Device \Driver\usbuhci \Device\USBPDO-4 86B061F8
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 86FD91F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86FD91F8
Device \Driver\Cdrom \Device\CdRom0 86D5D1F8
Device \Driver\atapi \Device\Ide\IdePort0 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 86D5D1F8
Device \Driver\Cdrom \Device\CdRom2 86D5D1F8
Device \Driver\Cdrom \Device\CdRom3 86D5D1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 86C8C500
Device \Driver\sptd \Device\4172899952 spxu.sys
Device \Driver\NetBT \Device\NetbiosSmb 86C8C500
Device \Driver\PCI_PNP8368 \Device\0000005c spxu.sys
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys
Device \Driver\usbohci \Device\USBFDO-0 86B451F8
Device \Driver\usbohci \Device\USBFDO-1 86B451F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8668E500
Device \Driver\usbehci \Device\USBFDO-2 86B2E1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8668E500
Device \Driver\usbuhci \Device\USBFDO-3 86B061F8
Device \Driver\usbuhci \Device\USBFDO-4 86B061F8
Device \Driver\Ftdisk \Device\FtControl 86FD91F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target1Lun0 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target0Lun0 86AEC1F8
Device \FileSystem\Fastfat \Fat 86B511F8
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys
Device \FileSystem\Cdfs \Cdfs 86B62500
---- Trace I/O - GMER 2.1 ----
Trace ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spxu.sys >>UNKNOWN [0x86f8a938]<< 86f8a938
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86ea3ab8] 86ea3ab8
Trace 3 CLASSPNP.SYS[f75cefd7] -> nt!IofCallDriver -> \Device\00000074[0x86fcc338] 86fcc338
Trace 5 ACPI.sys[f741a620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x86f41d98] 86f41d98
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x78 0xEB 0x6F 0x79 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE3 0x19 0xC5 0xF7 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF0 0x63 0x63 0x94 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xE5 0x64 0x0B 0x13 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x02 0xB7 0xEC 0x50 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x02 0xB7 0xEC 0x50 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x78 0xEB 0x6F 0x79 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE3 0x19 0xC5 0xF7 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF0 0x63 0x63 0x94 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xE5 0x64 0x0B 0x13 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x02 0xB7 0xEC 0x50 ...
---- EOF - GMER 2.1 ----
Process:
System Idle Process
System
C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\AVG SafeGuard toolbar\vprot.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\smss.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Documents and Settings\sedlacek\Plocha\IceSword122en\IceSword.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG2013\avgfws.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\alg.exe
Kernel Module:
\WINDOWS\system32\ntoskrnl.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
spxu.sys
\WINDOWS\System32\Drivers\WMILIB.SYS
\WINDOWS\System32\Drivers\SCSIPORT.SYS
ACPI.sys
pci.sys
ohci1394.sys
\WINDOWS\system32\DRIVERS\1394BUS.SYS
isapnp.sys
intelide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
dmload.sys
dmio.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
Lbd.sys
PxHelp20.sys
KSecDD.sys
WudfPf.sys
Ntfs.sys
NDIS.sys
Mup.sys
avgrkx86.sys
avglogx.sys
avgmfx86.sys
avgidshx.sys
agp440.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\RTL8139.SYS
\SystemRoot\system32\DRIVERS\nic1394.sys
\SystemRoot\system32\drivers\wfeaglxt.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\BdaSup.SYS
\SystemRoot\system32\drivers\emu10k1m.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\sfmanm.sys
\SystemRoot\system32\drivers\ctlfacem.sys
\SystemRoot\system32\DRIVERS\ctljystk.sys
\SystemRoot\system32\DRIVERS\gameenum.sys
\SystemRoot\system32\DRIVERS\usbohci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\system32\drivers\Afc.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\System32\Drivers\a8zhrd5b.SYS
\SystemRoot\system32\DRIVERS\fdc.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\avgfwdx.sys
\SystemRoot\system32\DRIVERS\safetica.sys
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\flpydisk.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\??\C:\WINDOWS\system32\drivers\avgtpx86.sys
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\system32\DRIVERS\avgtdix.sys
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\System32\Drivers\StarOpen.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\arp1394.sys
\SystemRoot\system32\DRIVERS\avgldx86.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\avgidsshimx.sys
\SystemRoot\system32\DRIVERS\avgidsdriverx.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\Fastfat.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\atiok3x2.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\AegisP.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\System32\Drivers\ParVdm.SYS
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\HTTP.sys
\??\C:\DOCUME~1\sedlacek\LOCALS~1\Temp\pxtdapow.sys
\SystemRoot\System32\Drivers\IsDrv122.sys
\??\C:\WINDOWS\system32\Drivers\RKREVEAL150.SYS
\SystemRoot\system32\drivers\kmixer.sys
\WINDOWS\system32\ntdll.dll
\Program Files\DAEMON Tools Lite\Engine.dll
C:\WINDOWS\System32\Drivers\sptd.sys
06/23/13 21:27:21 [Info]: BlackLight Engine 2.2.1092 initialized
06/23/13 21:27:21 [Info]: OS: 5.1 build 2600 (Service Pack 3)
06/23/13 21:27:21 [Note]: 7019 4
06/23/13 21:27:21 [Note]: 7005 0
06/23/13 21:27:25 [Note]: 7006 0
06/23/13 21:27:25 [Note]: 7011 500
06/23/13 21:27:25 [Note]: 7035 0
06/23/13 21:27:25 [Note]: 7026 0
06/23/13 21:27:25 [Note]: 7026 0
06/23/13 21:27:28 [Note]: FSRAW library version 1.7.1024
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:37:31 [Note]: 7007 0
RootkikReval
HKU\S-1-5-21-1960408961-1580818891-1060284298-1003\Software\Adobe\MediaBrowser\MRU\illustrator\ApplicationPath 10.6.2012 20:01 91 bytes Data mismatch between Windows API and raw hive data.
HKLM\SECURITY\Policy\Secrets\SAC* 3.12.2008 21:14 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 3.12.2008 21:14 0 bytes Key name contains embedded nulls (*)
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 16.10.2012 16:26 0 bytes Access is denied.
C:\Documents and Settings\All Users\Data aplikací\AVG2013\log\avgfw8db.log 24.6.2013 18:23 252 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\075884af680ff6dc__exp__1372090868 23.6.2013 18:21 1.26 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\075884af680ff6dc__exp__1372177398 24.6.2013 18:23 1.26 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\49fbbc5a8678d502__exp__1372090868 23.6.2013 18:21 661 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\49fbbc5a8678d502__exp__1372177398 24.6.2013 18:23 661 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\56c7c753f2f71f3e__exp__1372090867 23.6.2013 18:21 11.14 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\56c7c753f2f71f3e__exp__1372177397 24.6.2013 18:23 11.14 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\5c54eb1a1655b076__exp__1372090868 23.6.2013 18:21 1.61 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\5c54eb1a1655b076__exp__1372177398 24.6.2013 18:23 1.61 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\613e8ce7ab7106af__exp__1372090868 23.6.2013 18:21 1.05 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\613e8ce7ab7106af__exp__1372177398 24.6.2013 18:23 1.05 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\691f14230153a9e1__exp__1372090869 23.6.2013 18:21 668 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\691f14230153a9e1__exp__1372177399 24.6.2013 18:23 668 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\7614bd6cfa99e546__exp__1372090869 23.6.2013 18:21 663 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\7614bd6cfa99e546__exp__1372177398 24.6.2013 18:23 663 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\881b3593316772f0__exp__1372090868 23.6.2013 18:21 586 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\881b3593316772f0__exp__1372177398 24.6.2013 18:23 586 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c4e10d1be905349b__exp__1372090868 23.6.2013 18:21 627 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c4e10d1be905349b__exp__1372177398 24.6.2013 18:23 627 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c8a51ba84752784f__exp__1372090868 23.6.2013 18:21 5.92 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c8a51ba84752784f__exp__1372177398 24.6.2013 18:23 5.92 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\f2cda51fd108941f__exp__1372090868 23.6.2013 18:21 366 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\f2cda51fd108941f__exp__1372177398 24.6.2013 18:23 366 bytes Hidden from Windows API.
C:\System Volume Information\_restore{FD147038-28E7-4033-A3B2-20EA6BEC61C4}\RP886\A0166633.cfg 23.6.2013 21:13 182.50 KB Hidden from Windows API.
C:\System Volume Information\_restore{FD147038-28E7-4033-A3B2-20EA6BEC61C4}\RP886\A0166634.ini 23.6.2013 17:21 306 bytes Hidden from Windows API.
C:\WINDOWS\Temp\avg-02e41f20-d96c-400e-b0f1-8211637fbc77.tmp 24.6.2013 17:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\Temp\avg-5b11bd5b-7188-4c48-b6a4-db2cce95c72b.tmp 24.6.2013 18:23 0 bytes Hidden from Windows API.
C:\WINDOWS\Temp\avg-9b45e263-c229-4e6f-bd0c-dd4f53b1207d.tmp 24.6.2013 18:23 0 bytes Hidden from Windows API.
AVG antivir mi vyhledal rootkiky, který neumí odstranit. Jinak žádné problémy nejsou až na zpomalený start PC.
Děkuji
GMER 2.1.19163 - http://www.gmer.net
Rootkit quick scan 2013-06-23 18:06:12
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD600BB-00CAA1 rev.17.07W17 55,90GB
Running: gmer.exe; Driver: C:\DOCUME~1\sedlacek\LOCALS~1\Temp\pxtdapow.sys
---- Devices - GMER 2.1 ----
Device \Driver\atapi \Device\Ide\IdePort0 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target1Lun0 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target0Lun0 86AEC1F8
Device \FileSystem\Ntfs \Ntfs 86FD71F8
Device \FileSystem\Fastfat \Fat 86B511F8
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys
---- EOF - GMER 2.1 ----
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-23 21:02:14
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 WDC_WD600BB-00CAA1 rev.17.07W17 55,90GB
Running: gmer.exe; Driver: C:\DOCUME~1\sedlacek\LOCALS~1\Temp\pxtdapow.sys
---- System - GMER 2.1 ----
SSDT Lbd.sys ZwCreateKey [0xF75DE87E]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeKey [0xF784F5D0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeMultipleKeys [0xF784F700]
SSDT spxu.sys ZwOpenKey [0xF745B0C0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenProcess [0xF784F010]
SSDT spxu.sys ZwQueryKey [0xF747420A]
SSDT \??\C:\WINDOWS\system32\drivers\avgtpx86.sys ZwQueryValueKey [0xF766F1D6]
SSDT Lbd.sys ZwSetValueKey [0xF75DEBFE]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendProcess [0xF784F300]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendThread [0xF784F3E0]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateProcess [0xF784F120]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateThread [0xF784F210]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwWriteVirtualMemory [0xF784F4D0]
INT 0x39 ? 86BB7F00
INT 0x39 ? 86FDBBF8
INT 0x3B ? 86BB7F00
INT 0x3B ? 86BB7F00
INT 0x3B ? 86BB7F00
INT 0x3E ? 86FD8BF8
INT 0x3F ? 86FD8BF8
---- Kernel code sections - GMER 2.1 ----
? spxu.sys Systém nemůže nalézt uvedený soubor. !
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF653F000, 0x2C3BC6, 0xE8000020]
---- Devices - GMER 2.1 ----
Device \FileSystem\Ntfs \Ntfs 86FD71F8
Device \FileSystem\Fastfat \FatCdrom 86B511F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{99045E80-A4BE-4EFE-9FF3-5D425F602DE1} 86C8C500
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys
Device \Driver\usbohci \Device\USBPDO-0 86B451F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86F6A1F8
Device \Driver\dmio \Device\DmControl\DmConfig 86F6A1F8
Device \Driver\dmio \Device\DmControl\DmPnP 86F6A1F8
Device \Driver\dmio \Device\DmControl\DmInfo 86F6A1F8
Device \Driver\usbohci \Device\USBPDO-1 86B451F8
Device \Driver\usbehci \Device\USBPDO-2 86B2E1F8
Device \Driver\usbuhci \Device\USBPDO-3 86B061F8
Device \Driver\usbuhci \Device\USBPDO-4 86B061F8
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 86FD91F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86FD91F8
Device \Driver\Cdrom \Device\CdRom0 86D5D1F8
Device \Driver\atapi \Device\Ide\IdePort0 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 [F73AFB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 86D5D1F8
Device \Driver\Cdrom \Device\CdRom2 86D5D1F8
Device \Driver\Cdrom \Device\CdRom3 86D5D1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 86C8C500
Device \Driver\sptd \Device\4172899952 spxu.sys
Device \Driver\NetBT \Device\NetbiosSmb 86C8C500
Device \Driver\PCI_PNP8368 \Device\0000005c spxu.sys
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys
Device \Driver\usbohci \Device\USBFDO-0 86B451F8
Device \Driver\usbohci \Device\USBFDO-1 86B451F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8668E500
Device \Driver\usbehci \Device\USBFDO-2 86B2E1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8668E500
Device \Driver\usbuhci \Device\USBFDO-3 86B061F8
Device \Driver\usbuhci \Device\USBFDO-4 86B061F8
Device \Driver\Ftdisk \Device\FtControl 86FD91F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target1Lun0 86AEC1F8
Device \Driver\a8zhrd5b \Device\Scsi\a8zhrd5b1Port2Path0Target0Lun0 86AEC1F8
Device \FileSystem\Fastfat \Fat 86B511F8
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys
Device \FileSystem\Cdfs \Cdfs 86B62500
---- Trace I/O - GMER 2.1 ----
Trace ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spxu.sys >>UNKNOWN [0x86f8a938]<< 86f8a938
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86ea3ab8] 86ea3ab8
Trace 3 CLASSPNP.SYS[f75cefd7] -> nt!IofCallDriver -> \Device\00000074[0x86fcc338] 86fcc338
Trace 5 ACPI.sys[f741a620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x86f41d98] 86f41d98
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x78 0xEB 0x6F 0x79 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE3 0x19 0xC5 0xF7 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF0 0x63 0x63 0x94 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xE5 0x64 0x0B 0x13 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x02 0xB7 0xEC 0x50 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x02 0xB7 0xEC 0x50 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x78 0xEB 0x6F 0x79 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE3 0x19 0xC5 0xF7 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF0 0x63 0x63 0x94 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xE5 0x64 0x0B 0x13 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x02 0xB7 0xEC 0x50 ...
---- EOF - GMER 2.1 ----
Process:
System Idle Process
System
C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\AVG SafeGuard toolbar\vprot.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\smss.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Documents and Settings\sedlacek\Plocha\IceSword122en\IceSword.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG2013\avgfws.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\alg.exe
Kernel Module:
\WINDOWS\system32\ntoskrnl.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
spxu.sys
\WINDOWS\System32\Drivers\WMILIB.SYS
\WINDOWS\System32\Drivers\SCSIPORT.SYS
ACPI.sys
pci.sys
ohci1394.sys
\WINDOWS\system32\DRIVERS\1394BUS.SYS
isapnp.sys
intelide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
dmload.sys
dmio.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
Lbd.sys
PxHelp20.sys
KSecDD.sys
WudfPf.sys
Ntfs.sys
NDIS.sys
Mup.sys
avgrkx86.sys
avglogx.sys
avgmfx86.sys
avgidshx.sys
agp440.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\RTL8139.SYS
\SystemRoot\system32\DRIVERS\nic1394.sys
\SystemRoot\system32\drivers\wfeaglxt.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\BdaSup.SYS
\SystemRoot\system32\drivers\emu10k1m.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\sfmanm.sys
\SystemRoot\system32\drivers\ctlfacem.sys
\SystemRoot\system32\DRIVERS\ctljystk.sys
\SystemRoot\system32\DRIVERS\gameenum.sys
\SystemRoot\system32\DRIVERS\usbohci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\system32\drivers\Afc.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\System32\Drivers\a8zhrd5b.SYS
\SystemRoot\system32\DRIVERS\fdc.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\avgfwdx.sys
\SystemRoot\system32\DRIVERS\safetica.sys
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\flpydisk.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\??\C:\WINDOWS\system32\drivers\avgtpx86.sys
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\system32\DRIVERS\avgtdix.sys
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\System32\Drivers\StarOpen.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\arp1394.sys
\SystemRoot\system32\DRIVERS\avgldx86.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\avgidsshimx.sys
\SystemRoot\system32\DRIVERS\avgidsdriverx.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\Fastfat.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\atiok3x2.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\AegisP.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\System32\Drivers\ParVdm.SYS
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\HTTP.sys
\??\C:\DOCUME~1\sedlacek\LOCALS~1\Temp\pxtdapow.sys
\SystemRoot\System32\Drivers\IsDrv122.sys
\??\C:\WINDOWS\system32\Drivers\RKREVEAL150.SYS
\SystemRoot\system32\drivers\kmixer.sys
\WINDOWS\system32\ntdll.dll
\Program Files\DAEMON Tools Lite\Engine.dll
C:\WINDOWS\System32\Drivers\sptd.sys
06/23/13 21:27:21 [Info]: BlackLight Engine 2.2.1092 initialized
06/23/13 21:27:21 [Info]: OS: 5.1 build 2600 (Service Pack 3)
06/23/13 21:27:21 [Note]: 7019 4
06/23/13 21:27:21 [Note]: 7005 0
06/23/13 21:27:25 [Note]: 7006 0
06/23/13 21:27:25 [Note]: 7011 500
06/23/13 21:27:25 [Note]: 7035 0
06/23/13 21:27:25 [Note]: 7026 0
06/23/13 21:27:25 [Note]: 7026 0
06/23/13 21:27:28 [Note]: FSRAW library version 1.7.1024
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:34:10 [Note]: 2000 1012
06/23/13 21:37:31 [Note]: 7007 0
RootkikReval
HKU\S-1-5-21-1960408961-1580818891-1060284298-1003\Software\Adobe\MediaBrowser\MRU\illustrator\ApplicationPath 10.6.2012 20:01 91 bytes Data mismatch between Windows API and raw hive data.
HKLM\SECURITY\Policy\Secrets\SAC* 3.12.2008 21:14 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 3.12.2008 21:14 0 bytes Key name contains embedded nulls (*)
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 16.10.2012 16:26 0 bytes Access is denied.
C:\Documents and Settings\All Users\Data aplikací\AVG2013\log\avgfw8db.log 24.6.2013 18:23 252 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\075884af680ff6dc__exp__1372090868 23.6.2013 18:21 1.26 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\075884af680ff6dc__exp__1372177398 24.6.2013 18:23 1.26 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\49fbbc5a8678d502__exp__1372090868 23.6.2013 18:21 661 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\49fbbc5a8678d502__exp__1372177398 24.6.2013 18:23 661 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\56c7c753f2f71f3e__exp__1372090867 23.6.2013 18:21 11.14 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\56c7c753f2f71f3e__exp__1372177397 24.6.2013 18:23 11.14 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\5c54eb1a1655b076__exp__1372090868 23.6.2013 18:21 1.61 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\5c54eb1a1655b076__exp__1372177398 24.6.2013 18:23 1.61 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\613e8ce7ab7106af__exp__1372090868 23.6.2013 18:21 1.05 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\613e8ce7ab7106af__exp__1372177398 24.6.2013 18:23 1.05 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\691f14230153a9e1__exp__1372090869 23.6.2013 18:21 668 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\691f14230153a9e1__exp__1372177399 24.6.2013 18:23 668 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\7614bd6cfa99e546__exp__1372090869 23.6.2013 18:21 663 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\7614bd6cfa99e546__exp__1372177398 24.6.2013 18:23 663 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\881b3593316772f0__exp__1372090868 23.6.2013 18:21 586 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\881b3593316772f0__exp__1372177398 24.6.2013 18:23 586 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c4e10d1be905349b__exp__1372090868 23.6.2013 18:21 627 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c4e10d1be905349b__exp__1372177398 24.6.2013 18:23 627 bytes Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c8a51ba84752784f__exp__1372090868 23.6.2013 18:21 5.92 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\c8a51ba84752784f__exp__1372177398 24.6.2013 18:23 5.92 KB Hidden from Windows API.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\f2cda51fd108941f__exp__1372090868 23.6.2013 18:21 366 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\sedlacek\Data aplikací\AVG SafeGuard toolbar\cache\f2cda51fd108941f__exp__1372177398 24.6.2013 18:23 366 bytes Hidden from Windows API.
C:\System Volume Information\_restore{FD147038-28E7-4033-A3B2-20EA6BEC61C4}\RP886\A0166633.cfg 23.6.2013 21:13 182.50 KB Hidden from Windows API.
C:\System Volume Information\_restore{FD147038-28E7-4033-A3B2-20EA6BEC61C4}\RP886\A0166634.ini 23.6.2013 17:21 306 bytes Hidden from Windows API.
C:\WINDOWS\Temp\avg-02e41f20-d96c-400e-b0f1-8211637fbc77.tmp 24.6.2013 17:24 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\Temp\avg-5b11bd5b-7188-4c48-b6a4-db2cce95c72b.tmp 24.6.2013 18:23 0 bytes Hidden from Windows API.
C:\WINDOWS\Temp\avg-9b45e263-c229-4e6f-bd0c-dd4f53b1207d.tmp 24.6.2013 18:23 0 bytes Hidden from Windows API.