Zdravím,
potřeboval bych pomoc s logem z GMER.
Symantek mi nasel Trojan.Mebroot .. po precteni fory jsem na nej pustil Dr.Web Curelt.
Nasel ho a pry odstranil .... Ale pak ho Symantec znovu nasel.
Pustil jsem tedy GMER a vkladam sem ten log co vyjel ( vubec se v nem nevyznam

)
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-05-04 07:10:25
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT E20770B8 ZwConnectPort
SSDT spfz.sys ZwCreateKey [0xB9EA80E0]
SSDT spfz.sys ZwEnumerateKey [0xB9EC6CA2]
SSDT spfz.sys ZwEnumerateValueKey [0xB9EC7030]
SSDT spfz.sys ZwOpenKey [0xB9EA80C0]
SSDT spfz.sys ZwQueryKey [0xB9EC7108]
SSDT spfz.sys ZwQueryValueKey [0xB9EC6F88]
SSDT spfz.sys ZwSetValueKey [0xB9EC719A]
SSDT \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys ZwUnloadKey [0x9BCB56D0]
INT 0x62 ? 89D63BF8
INT 0x63 ? 89BB4F00
INT 0x73 ? 89DCFBF8
INT 0x82 ? 89D63BF8
INT 0x83 ? 89DCFBF8
INT 0xB4 ? 89BB4F00
---- Kernel code sections - GMER 1.0.15 ----
? spfz.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload B8D578AC 5 Bytes JMP 89BB44E0
.text avrqnick.SYS B7C17384 1 Byte [20]
.text avrqnick.SYS B7C17384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text avrqnick.SYS B7C173AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text avrqnick.SYS B7C173C4 3 Bytes [00, 00, 00]
.text avrqnick.SYS B7C173C9 1 Byte [00]
.text ...
? C:\WINDOWS\system32\Drivers\uphcleanhlp.sys Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!??2@YAPAXI@Z 77C19CC5 5 Bytes JMP 0A93B250 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!??3@YAXPAX@Z 77C19CDD 5 Bytes JMP 0A93B2A0 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C19D9F 5 Bytes JMP 0A93B2C0 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_expand 77C19FE5 5 Bytes JMP 0A93B230 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_heapadd 77C1BC9F 5 Bytes JMP 0A93B310 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_heapchk 77C1BCB3 5 Bytes JMP 0A93B320 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_heapset + 1 77C1BD83 4 Bytes JMP 0A93B351 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_heapmin 77C1BD8C 5 Bytes JMP 0A93B420 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_heapused 77C1BE3A 5 Bytes JMP 0A93B3F0 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_heapwalk 77C1BE4D 5 Bytes JMP 0A93B360 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!_msize 77C1BF6C 5 Bytes JMP 0A93B180 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!calloc 77C1C0C3 5 Bytes JMP 0A93B110 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!free 77C1C21B 5 Bytes JMP 0A93B170 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!malloc 77C1C407 5 Bytes JMP 0A93B0D0 C:\WINDOWS\system32\SH33W32.dll
.text C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] msvcrt.dll!realloc 77C1C437 5 Bytes JMP 0A93B150 C:\WINDOWS\system32\SH33W32.dll
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EA9040] spfz.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EA913C] spfz.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EA90BE] spfz.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EA97FC] spfz.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EA96D2] spfz.sys
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\avrqnick.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EB9048] spfz.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LocalSize] [0A93C2E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [0A93A0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalHandle] [0A93C100] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LocalUnlock] [0A93C300] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LocalLock] [0A93C2A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LocalReAlloc] [0A93C2C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalAlloc] [0A93C0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalReAlloc] [0A93C140] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalFlags] [0A93C0C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalFree] [0A93C0E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LocalAlloc] [0A93C220] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LocalFree] [0A93C260] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalSize] [0A93C160] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalLock] [0A93C120] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GlobalUnlock] [0A93C180] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] [0A93B8C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\USER32.dll [ntdll.dll!RtlFreeHeap] [0A93BA00] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LocalReAlloc] [0A93C2C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GlobalLock] [0A93C120] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GlobalUnlock] [0A93C180] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [0A93A0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LocalFree] [0A93C260] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LocalAlloc] [0A93C220] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GlobalAlloc] [0A93C0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GlobalSize] [0A93C160] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GlobalFree] [0A93C0E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] [0A93B8C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] [0A93BA00] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LocalFree] [0A93C260] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LocalAlloc] [0A93C220] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LocalReAlloc] [0A93C2C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0A93A0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcessHeap] [0A93B830] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] [0A93BA00] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] [0A93B8C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] [0A93BA90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GlobalFree] [0A93C0E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcessHeap] [0A93B830] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] [0A93BA00] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] [0A93B8C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LocalFree] [0A93C260] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LocalAlloc] [0A93C220] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\Secur32.dll [ntdll.dll!RtlFreeHeap] [0A93BA00] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\Secur32.dll [ntdll.dll!RtlAllocateHeap] [0A93B8C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcessHeap] [0A93B830] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapDestroy] [0A93B9C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapCreate] [0A93B960] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapValidate] [0A93BB40] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapCompact] [0A93B930] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!HeapWalk] [0A93BB80] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!HeapCreate] [0A93B960] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcessHeap] [0A93B830] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!HeapDestroy] [0A93B9C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GlobalReAlloc] [0A93C140] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LocalSize] [0A93C2E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GlobalSize] [0A93C160] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GlobalAlloc] [0A93C0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GlobalLock] [0A93C120] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GlobalUnlock] [0A93C180] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GlobalFree] [0A93C0E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [0A93A0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LocalAlloc] [0A93C220] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LocalFree] [0A93C260] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LocalReAlloc] [0A93C2C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [0A93A010] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] [0A93BA00] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GlobalUnlock] [0A93C180] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GlobalFree] [0A93C0E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GlobalAlloc] [0A93C0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GlobalLock] [0A93C120] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0A93A010] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0A93A0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibraryAndExitThread] [0A93A230] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LocalSize] [0A93C2E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!HeapDestroy] [0A93B9C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!HeapCreate] [0A93B960] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LocalReAlloc] [0A93C2C0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LocalAlloc] [0A93C220] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LocalFree] [0A93C260] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0A939F10] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] [0A93A200] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [0A939F90] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] [0A93C180] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalLock] [0A93C120] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] [0A93B830] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!HeapValidate] [0A93BB40] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!HeapCompact] [0A93B930] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LocalAlloc] [0A93C220] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LocalFree] [0A93C260] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [0A93A0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibraryAndExitThread] [0A93A230] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [0A93A010] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalFree] [0A93C0E0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] [0A93C0A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalSize] [0A93C160] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalReAlloc] [0A93C140] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LocalUnlock] [0A93C300] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LocalLock] [0A93C2A0] C:\WINDOWS\system32\SH33W32.dll
IAT C:\Corel\Graphics8\Programs\MFIndexer.exe[1684] @ C:\WINDOWS\system32\ole32.dll [ntdll.dll!RtlFreeHeap] [0A93BA00] C:\WINDOWS\system32\SH33W32.dll
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 89DCE1F8
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fastfat \FatCdrom 88932500
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\NetBT \Device\NetBT_Tcpip_{49B7808E-C826-48B0-8DCD-17D32282BB6E} 897EF500
Device \Driver\usbohci \Device\USBPDO-0 89BA4500
Device \Driver\usbehci \Device\USBPDO-1 89B74500
Device \Driver\NetBT \Device\NetBT_Tcpip_{14217C79-DF98-4835-8813-19C59AF3B74E} 897EF500
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\nvata \Device\00000070 89DCF1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89D641F8
Device \Driver\nvata \Device\00000071 89DCF1F8
Device \Driver\sptd \Device\1378489512 spfz.sys
Device \Driver\Cdrom \Device\CdRom0 899CC1F8
Device \Driver\Cdrom \Device\CdRom1 899CC1F8
Device \Driver\Cdrom \Device\CdRom2 899CC1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 897EF500
Device \Driver\NetBT \Device\NetbiosSmb 897EF500
Device \Driver\PCI_PNP4512 \Device\0000004e spfz.sys
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbohci \Device\USBFDO-0 89BA4500
Device \Driver\usbehci \Device\USBFDO-1 89B74500
Device \Driver\nvatabus \Device\NvAta0 89D631F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 897EA500
Device \Driver\nvata \Device\NvAta1 89DCF1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 897EA500
Device \Driver\nvata \Device\NvAta2 89DCF1F8
Device \Driver\Ftdisk \Device\FtControl 89D641F8
Device \Driver\avrqnick \Device\Scsi\avrqnick1Port3Path0Target0Lun0 899831F8
Device \Driver\avrqnick \Device\Scsi\avrqnick1Port3Path0Target1Lun0 899831F8
Device \Driver\avrqnick \Device\Scsi\avrqnick1 899831F8
Device \FileSystem\Fastfat \Fat 88932500
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Cdfs \Cdfs 89873500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7C 0x72 0xEE 0x1A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x20 0x96 0xC8 0x12 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCF 0x29 0x34 0xD8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x57 0x58 0x7A 0x9D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x69 0x94 0x07 0x94 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xD6 0xA5 0xCE 0xC6 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x86 0x0D 0x49 0x2C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7C 0x72 0xEE 0x1A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x20 0x96 0xC8 0x12 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCF 0x29 0x34 0xD8 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x57 0x58 0x7A 0x9D ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 61: malicious code @ sector 0x1d1c06c0 size 0x1fd
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
---- EOF - GMER 1.0.15 ----
je to nejak dlouhe
Predem diky za radu