Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Nejdou spustit .exe Win32:Rootkit-gen

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
radval
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 30 bře 2010 12:14

Re: Nejdou spustit .exe Win32:Rootkit-gen

#31 Příspěvek od radval »

Caroprd111 píše:Poprosím o nový log z RSIT.
Je tady divné trvalo mu to jen pár sekund....

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-04-02 10:21:09
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (23%) free of 8 GB
Total RAM: 247 MB (9% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:21:25, on 2.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
D:\OFFICE 2003\OFFICE11\EXCEL.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\SIM\sim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\INSTALACE pod XP\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: setup_9.0.0.722_29.03.2010_09-02.lnk = C:\Documents and Settings\Administrator\Plocha\Virus Removal Tool\setup_9.0.0.722_29.03.2010_09-02\startup.exe
O4 - Startup: _uninst_setup_9.0.0.722_04.12.2009_23-36.exe.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\_uninst_setup_9.0.0.722_04.12.2009_23-36.exe.bat
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

--
End of file - 4462 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
C:\WINDOWS\tasks\Uniblue SpyEraser.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-11-04 54248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E5A1691B-D188-4419-AD02-90002030B8EE}]
FlashFXP Helper for Internet Explorer - C:\PROGRA~1\FlashFXP\IEFlash.dll [2006-03-31 191096]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2002-10-15 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2002-10-15 114688]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
setup_9.0.0.722_29.03.2010_09-02.lnk - C:\Documents and Settings\Administrator\Plocha\Virus Removal Tool\setup_9.0.0.722_29.03.2010_09-02\startup.exe
_uninst_setup_9.0.0.722_04.12.2009_23-36.exe.lnk - C:\Documents and Settings\Administrator\Local Settings\Temp\_uninst_setup_9.0.0.722_04.12.2009_23-36.exe.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2002-10-15 315392]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\wincmd\WINCMD32.EXE"="D:\wincmd\WINCMD32.EXE:*:Enabled:Windows Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\SIM\sim.exe"="C:\Program Files\SIM\sim.exe:*:Enabled:sim"
"C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe"="C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe:*:Disabled:Sentinel Protection Server"
"C:\Program Files\Sony Ericsson\Update Service Pro\USP.exe"="C:\Program Files\Sony Ericsson\Update Service Pro\USP.exe:*:Enabled:Update Service Pro"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-04-02 09:48:40 ----SHD---- C:\RECYCLER
2010-04-02 09:08:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-04-02 09:07:55 ----D---- C:\Program Files\Adobe
2010-04-01 14:16:45 ----A---- C:\ComboFix.txt
2010-03-31 16:28:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980182$
2010-03-30 14:23:41 ----A---- C:\Boot.bak
2010-03-30 14:23:35 ----RASHD---- C:\cmdcons
2010-03-30 14:22:01 ----A---- C:\WINDOWS\PEV.exe
2010-03-30 14:22:01 ----A---- C:\WINDOWS\NIRCMD.exe
2010-03-30 14:22:01 ----A---- C:\WINDOWS\MBR.exe
2010-03-30 14:22:00 ----A---- C:\WINDOWS\zip.exe
2010-03-30 14:22:00 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-03-30 14:22:00 ----A---- C:\WINDOWS\SWSC.exe
2010-03-30 14:22:00 ----A---- C:\WINDOWS\SWREG.exe
2010-03-30 14:22:00 ----A---- C:\WINDOWS\sed.exe
2010-03-30 14:22:00 ----A---- C:\WINDOWS\grep.exe
2010-03-30 14:21:46 ----D---- C:\WINDOWS\ERDNT
2010-03-30 14:21:27 ----D---- C:\Qoobox
2010-03-30 13:51:02 ----D---- C:\Program Files\trend micro
2010-03-30 13:50:59 ----D---- C:\rsit
2010-03-30 13:10:57 ----D---- C:\Program Files\HJT
2010-03-30 10:52:15 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
2010-03-30 10:51:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-30 10:51:56 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-29 15:35:04 ----D---- C:\Program Files\Trell
2010-03-25 12:27:01 ----D---- C:\Program Files\Sony Ericsson
2010-03-24 15:24:23 ----D---- C:\Program Files\Common Files\SafeNet Sentinel
2010-03-24 15:24:22 ----D---- C:\Program Files\SafeNet Sentinel
2010-03-24 12:17:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-03-24 11:30:29 ----A---- C:\rollback.ini
2010-03-24 11:14:19 ----D---- C:\Program Files\Common Files\ParetoLogic
2010-03-11 17:29:10 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$

======List of files/folders modified in the last 1 months======

2010-04-02 09:51:12 ----D---- C:\WINDOWS\Temp
2010-04-02 09:48:41 ----D---- C:\WINDOWS\Minidump
2010-04-02 09:48:41 ----D---- C:\WINDOWS\Debug
2010-04-02 09:48:41 ----D---- C:\WINDOWS
2010-04-02 09:19:55 ----D---- C:\Documents and Settings\Administrator\Data aplikací\sim
2010-04-02 09:08:34 ----SHD---- C:\WINDOWS\Installer
2010-04-02 09:07:55 ----RD---- C:\Program Files
2010-04-02 09:02:55 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-02 09:00:04 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-04-01 14:36:22 ----D---- C:\WINDOWS\system32\drivers
2010-04-01 14:36:21 ----HD---- C:\WINDOWS\inf
2010-04-01 14:11:36 ----A---- C:\WINDOWS\system.ini
2010-04-01 14:04:53 ----D---- C:\WINDOWS\system32
2010-04-01 14:04:53 ----D---- C:\WINDOWS\AppPatch
2010-04-01 14:04:48 ----D---- C:\Program Files\Common Files
2010-04-01 12:59:41 ----D---- C:\Program Files\Mozilla Firefox
2010-03-31 16:29:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-31 13:40:56 ----D---- C:\Program Files\FlashFXP
2010-03-31 08:31:12 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-30 14:37:16 ----SD---- C:\WINDOWS\Tasks
2010-03-30 14:23:42 ----RASH---- C:\boot.ini
2010-03-30 14:22:00 ----SHD---- C:\System Volume Information
2010-03-30 14:22:00 ----D---- C:\WINDOWS\system32\Restore
2010-03-30 14:21:46 ----D---- C:\WINDOWS\Prefetch
2010-03-30 13:11:05 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-03-29 08:30:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-26 10:36:24 ----D---- C:\WINDOWS\Registration
2010-03-25 12:53:15 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-24 17:24:51 ----D---- C:\WINDOWS\system32\config
2010-03-24 15:48:04 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-24 12:17:14 ----D---- C:\WINDOWS\WinSxS
2010-03-11 17:29:13 ----D---- C:\Program Files\Movie Maker
2010-03-10 06:43:10 ----A---- C:\WINDOWS\system32\shdocvw.dll
2010-03-10 06:43:04 ----A---- C:\WINDOWS\system32\browseui.dll
2010-03-09 13:24:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-03-08 11:29:18 ----D---- C:\Program Files\ScreenshotCaptor

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2002-10-16 91678]
R1 69560261;69560261; C:\WINDOWS\system32\DRIVERS\69560261.sys [2009-09-25 128016]
R1 91531021;91531021; C:\WINDOWS\system32\DRIVERS\91531021.sys [2009-09-25 128016]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-03-09 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 setup_9.0.0.722_29.03.2010_09-02drv;setup_9.0.0.722_29.03.2010_09-02drv; C:\WINDOWS\system32\DRIVERS\9153102.sys [2009-10-09 315408]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-03-09 100432]
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2005-03-02 90168]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2002-10-16 71514]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-03-09 23376]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2002-02-25 139776]
R3 FTDIBUS;STUMOBIL USB Unibox Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2004-02-04 24177]
R3 FTSER2K;STUMOBIL USB Unibox Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2004-02-04 57372]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2002-10-16 79323]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-03-24 27632]
R3 STAC97;Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\STAC97.sys [2002-08-12 179664]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSMARTPrj;USB Smart device driver; C:\WINDOWS\System32\Drivers\UsbSmart.sys [2005-09-15 7680]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys []
S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys []
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2009-06-19 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2009-06-19 25512]
S3 ntportio;ntportio; \??\D:\ODBLOK SE\SEMC_Tool_v87\ntportio.sys []
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-18 5888]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 utm5nda4;AVZ Kernel Driver; \??\C:\WINDOWS\system32\Drivers\utm5nda4.sys []
S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 SentinelProtectionServer;Sentinel Protection Server; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [2005-03-02 193592]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Nejdou spustit .exe Win32:Rootkit-gen

#32 Příspěvek od Caroprd111 »

Obrázek Tohle otestujte na http://www.virustotal.com/cs/
C:\WINDOWS\system32\DRIVERS\69560261.sys

(Soubor nehledejte, jenom vložíte tučně označenou cestu, v případě hlášky "Soubor již byl testován" dejte otestovat znovu. Výsledek analýzy sem v podobě odkazu vložte.)


Obrázek Odinstalujte Uniblue.


Obrázek Odinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter


Obrázek Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe
  • Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
  • Po použití program vymažte. Pozor,antiviry ho mohou falešně označit za vir.


Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky stiskem "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít


Obrázek V logu nevidím firewall, doinstalujte :!: Přehled: http://www.viry.cz/forum/viewtopic.php?f=41&t=6523
Obrázek

radval
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 30 bře 2010 12:14

Re: Nejdou spustit .exe Win32:Rootkit-gen

#33 Příspěvek od radval »

[quote="Caroprd111"]Obrázek Tohle otestujte na http://www.virustotal.com/cs/
C:\WINDOWS\system32\DRIVERS\69560261.sys

(Soubor nehledejte, jenom vložíte tučně označenou cestu, v případě hlášky "Soubor již byl testován" dejte otestovat znovu. Výsledek analýzy sem v podobě odkazu vložte.)


Takže zatím výsledek z Virus Total :

http://www.virustotal.com/cs/analisis/1 ... 1270197388

Zbytek jdu na to....

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Nejdou spustit .exe Win32:Rootkit-gen

#34 Příspěvek od Caroprd111 »

OK :)
Obrázek

radval
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 30 bře 2010 12:14

Re: Nejdou spustit .exe Win32:Rootkit-gen

#35 Příspěvek od radval »

Caroprd111 píše:OK :)
Takže vyčištěno T-Cleaner , OTC i CCleaner, ninstaloval jsem Zone Alarm, po restartu a instalaci toho firewallu mi zmizla ikona Avastu.

Nový log z RSIT: Divné je že ta složka UNIBLUE ( naplánované úkoly) tam zůstala i když jsem je odinstaloval a to Adobe Acrobat ukazuje nějaký klíč v registru pod ActiveX a nejde pořád spustit.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-04-02 11:38:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (27%) free of 8 GB
Total RAM: 247 MB (6% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:08, on 2.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\OFFICE 2003\OFFICE11\EXCEL.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\INSTALACE pod XP\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: _uninst_setup_9.0.0.722_04.12.2009_23-36.exe.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\_uninst_setup_9.0.0.722_04.12.2009_23-36.exe.bat
O4 - Startup: _uninst_setup_9.0.0.722_29.03.2010_09-02.exe.lnk = C:\Documents and Settings\Administrator\Local Settings\temp\_uninst_setup_9.0.0.722_29.03.2010_09-02.exe.bat
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 4651 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
C:\WINDOWS\tasks\Uniblue SpyEraser.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-11-04 54248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E5A1691B-D188-4419-AD02-90002030B8EE}]
FlashFXP Helper for Internet Explorer - C:\PROGRA~1\FlashFXP\IEFlash.dll [2006-03-31 191096]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2002-10-15 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2002-10-15 114688]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-11-22 1037192]

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
_uninst_setup_9.0.0.722_04.12.2009_23-36.exe.lnk - C:\Documents and Settings\Administrator\Local Settings\Temp\_uninst_setup_9.0.0.722_04.12.2009_23-36.exe.bat
_uninst_setup_9.0.0.722_29.03.2010_09-02.exe.lnk - C:\Documents and Settings\Administrator\Local Settings\temp\_uninst_setup_9.0.0.722_29.03.2010_09-02.exe.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2002-10-15 315392]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\wincmd\WINCMD32.EXE"="D:\wincmd\WINCMD32.EXE:*:Enabled:Windows Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\SIM\sim.exe"="C:\Program Files\SIM\sim.exe:*:Enabled:sim"
"C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe"="C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe:*:Disabled:Sentinel Protection Server"
"C:\Program Files\Sony Ericsson\Update Service Pro\USP.exe"="C:\Program Files\Sony Ericsson\Update Service Pro\USP.exe:*:Enabled:Update Service Pro"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-04-02 11:38:16 ----D---- C:\Program Files\trend micro
2010-04-02 11:38:12 ----D---- C:\rsit
2010-04-02 11:08:29 ----A---- C:\WINDOWS\system32\vsregexp.dll
2010-04-02 11:08:24 ----A---- C:\WINDOWS\system32\zlcommdb.dll
2010-04-02 11:08:24 ----A---- C:\WINDOWS\system32\zlcomm.dll
2010-04-02 11:08:01 ----A---- C:\WINDOWS\system32\vswmi.dll
2010-04-02 11:07:55 ----A---- C:\WINDOWS\system32\zpeng25.dll
2010-04-02 11:07:54 ----A---- C:\WINDOWS\system32\vsxml.dll
2010-04-02 11:07:53 ----D---- C:\WINDOWS\system32\ZoneLabs
2010-04-02 11:07:53 ----A---- C:\WINDOWS\system32\vspubapi.dll
2010-04-02 11:07:53 ----A---- C:\WINDOWS\system32\vsmonapi.dll
2010-04-02 11:07:46 ----D---- C:\Program Files\Zone Labs
2010-04-02 11:07:11 ----D---- C:\WINDOWS\Internet Logs
2010-04-02 11:07:10 ----A---- C:\WINDOWS\system32\vsutil.dll
2010-04-02 11:07:10 ----A---- C:\WINDOWS\system32\vsinit.dll
2010-04-02 11:07:10 ----A---- C:\WINDOWS\system32\vsdata.dll
2010-04-02 09:48:40 ----SHD---- C:\RECYCLER
2010-04-02 09:08:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-04-02 09:07:55 ----D---- C:\Program Files\Adobe
2010-03-31 16:28:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980182$
2010-03-30 14:23:41 ----A---- C:\Boot.bak
2010-03-30 14:23:35 ----RASHD---- C:\cmdcons
2010-03-30 13:10:57 ----D---- C:\Program Files\HJT
2010-03-30 10:52:15 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
2010-03-30 10:51:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-30 10:51:56 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-29 15:35:04 ----D---- C:\Program Files\Trell
2010-03-25 12:27:01 ----D---- C:\Program Files\Sony Ericsson
2010-03-24 15:24:23 ----D---- C:\Program Files\Common Files\SafeNet Sentinel
2010-03-24 15:24:22 ----D---- C:\Program Files\SafeNet Sentinel
2010-03-24 12:17:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-03-24 11:30:29 ----A---- C:\rollback.ini
2010-03-24 11:14:19 ----D---- C:\Program Files\Common Files\ParetoLogic
2010-03-11 17:29:10 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$

======List of files/folders modified in the last 1 months======

2010-04-02 11:39:09 ----D---- C:\WINDOWS\Prefetch
2010-04-02 11:38:16 ----RD---- C:\Program Files
2010-04-02 11:34:35 ----D---- C:\WINDOWS\Temp
2010-04-02 11:11:39 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-02 11:10:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-02 11:08:33 ----D---- C:\WINDOWS\system32
2010-04-02 11:07:11 ----D---- C:\WINDOWS
2010-04-02 11:01:26 ----D---- C:\WINDOWS\system32\drivers
2010-04-02 10:55:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\sim
2010-04-02 10:43:25 ----SHD---- C:\System Volume Information
2010-04-02 10:43:25 ----D---- C:\WINDOWS\system32\Restore
2010-04-02 10:40:14 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Uniblue
2010-04-02 09:48:41 ----D---- C:\WINDOWS\Minidump
2010-04-02 09:48:41 ----D---- C:\WINDOWS\Debug
2010-04-02 09:08:34 ----SHD---- C:\WINDOWS\Installer
2010-04-01 14:36:21 ----HD---- C:\WINDOWS\inf
2010-04-01 14:11:36 ----A---- C:\WINDOWS\system.ini
2010-04-01 14:04:53 ----D---- C:\WINDOWS\AppPatch
2010-04-01 14:04:48 ----D---- C:\Program Files\Common Files
2010-04-01 12:59:41 ----D---- C:\Program Files\Mozilla Firefox
2010-03-31 16:29:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-31 13:40:56 ----D---- C:\Program Files\FlashFXP
2010-03-31 08:31:12 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-30 14:37:16 ----SD---- C:\WINDOWS\Tasks
2010-03-30 14:23:42 ----RASH---- C:\boot.ini
2010-03-30 13:11:05 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-03-29 08:30:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-26 10:36:24 ----D---- C:\WINDOWS\Registration
2010-03-25 12:53:15 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-24 17:24:51 ----D---- C:\WINDOWS\system32\config
2010-03-24 15:48:04 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-24 12:17:14 ----D---- C:\WINDOWS\WinSxS
2010-03-11 17:29:13 ----D---- C:\Program Files\Movie Maker
2010-03-10 06:43:10 ----A---- C:\WINDOWS\system32\shdocvw.dll
2010-03-10 06:43:04 ----A---- C:\WINDOWS\system32\browseui.dll
2010-03-09 13:24:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-03-08 11:29:18 ----D---- C:\Program Files\ScreenshotCaptor

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2002-10-16 91678]
R1 69560261;69560261; C:\WINDOWS\system32\DRIVERS\69560261.sys [2009-09-25 128016]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-03-09 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-11-22 486280]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-03-09 100432]
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2005-03-02 90168]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2002-10-16 71514]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-03-09 23376]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2002-02-25 139776]
R3 FTDIBUS;STUMOBIL USB Unibox Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2004-02-04 24177]
R3 FTSER2K;STUMOBIL USB Unibox Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2004-02-04 57372]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2002-10-16 79323]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-03-24 27632]
R3 STAC97;Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\STAC97.sys [2002-08-12 179664]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSMARTPrj;USB Smart device driver; C:\WINDOWS\System32\Drivers\UsbSmart.sys [2005-09-15 7680]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys []
S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys []
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2009-06-19 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2009-06-19 25512]
S3 ntportio;ntportio; \??\D:\ODBLOK SE\SEMC_Tool_v87\ntportio.sys []
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-18 5888]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 utm5nda4;AVZ Kernel Driver; \??\C:\WINDOWS\system32\Drivers\utm5nda4.sys []
S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 SentinelProtectionServer;Sentinel Protection Server; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [2005-03-02 193592]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-11-22 2384240]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Nejdou spustit .exe Win32:Rootkit-gen

#36 Příspěvek od Caroprd111 »

Avast přeinstalujte. Jinak je to v pořádku. :)
Obrázek

radval
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 30 bře 2010 12:14

Re: Nejdou spustit .exe Win32:Rootkit-gen

#37 Příspěvek od radval »

Caroprd111 píše:Avast přeinstalujte. Jinak je to v pořádku. :)
HUH, takový kouř ten systém teda ještě nedostal :)

Díky tomu čištění se mi poddařilo nainstalovat Acrobat 9, ta verze 6.0 ani po čištění nefungovala a teď ta 9.3 jde , vypadá to OK, moc děkuji za strávený čas .....jen aby to fungování nebylo tím, že tam není ten Avast, který kolikrát dělá podobnou neplechu....mám ho instalovat, když je v compu ten firewall ? Divím se že XP neřvou, že není nainstalovaný antivir :o

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Nejdou spustit .exe Win32:Rootkit-gen

#38 Příspěvek od Caroprd111 »

Pokud jste nainstaloval jen firewall, tak Avast nainstalujte.
Obrázek

radval
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 30 bře 2010 12:14

Re: Nejdou spustit .exe Win32:Rootkit-gen

#39 Příspěvek od radval »

Caroprd111 píše:Pokud jste nainstaloval jen firewall, tak Avast nainstalujte.
Nemusel jsem ten Avast instalovat, stačilo ho spustit (zůstal nainstalován). Teď už funguje (pouze webový štít mám vypnutý) jinak bych nic nestáhl...

Takže díky moc...snad se v útery neozvu že je to zpět, tfuj tfuj tfuj....

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Nejdou spustit .exe Win32:Rootkit-gen

#40 Příspěvek od Caroprd111 »

Nemáte zač :)
Obrázek

Odpovědět