Omlouvám se za spoždění a přerušení komunikace. On mi navíc klekl ventilátorek od chipsetu a až do ted jsem byl bez PC a tudíž offline.A to byla asi i jedna s příčin zatuhávání PC.
Jinak vše jsem provedl dle popisu.A v nouzáku se mi podařilo i rozjet ten ComboFix.
Zde jsou logy:
5:57:35:328 3592 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
15:57:35:328 3592 ================================================================================
15:57:35:328 3592 SystemInfo:
15:57:35:328 3592 OS Version: 5.1.2600 ServicePack: 3.0
15:57:35:328 3592 Product type: Workstation
15:57:35:328 3592 ComputerName: 4500717F2B5C41C
15:57:35:328 3592 UserName: Administrator
15:57:35:328 3592 Windows directory: C:\WINDOWS
15:57:35:328 3592 Processor architecture: Intel x86
15:57:35:328 3592 Number of processors: 1
15:57:35:328 3592 Page size: 0x1000
15:57:35:328 3592 Boot type: Normal boot
15:57:35:328 3592 ================================================================================
15:57:35:328 3592 UnloadDriverW: NtUnloadDriver error 2
15:57:35:328 3592 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
15:57:35:343 3592 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
15:57:35:343 3592 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
15:57:35:343 3592 wfopen_ex: Trying to KLMD file open
15:57:35:343 3592 wfopen_ex: File opened ok (Flags 2)
15:57:35:343 3592 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
15:57:35:343 3592 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
15:57:35:343 3592 wfopen_ex: Trying to KLMD file open
15:57:35:343 3592 wfopen_ex: File opened ok (Flags 2)
15:57:35:343 3592 Initialize success
15:57:35:343 3592
15:57:35:343 3592 Scanning Services ...
15:57:35:375 3592 Raw services enum returned 376 services
15:57:35:390 3592
15:57:35:390 3592 Scanning Kernel memory ...
15:57:35:390 3592 Devices to scan: 2
15:57:35:390 3592
15:57:35:390 3592 Driver Name: Disk
15:57:35:390 3592 IRP_MJ_CREATE : F75E2BB0
15:57:35:390 3592 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
15:57:35:390 3592 IRP_MJ_CLOSE : F75E2BB0
15:57:35:390 3592 IRP_MJ_READ : F75DCD1F
15:57:35:390 3592 IRP_MJ_WRITE : F75DCD1F
15:57:35:390 3592 IRP_MJ_QUERY_INFORMATION : 804F355A
15:57:35:390 3592 IRP_MJ_SET_INFORMATION : 804F355A
15:57:35:390 3592 IRP_MJ_QUERY_EA : 804F355A
15:57:35:390 3592 IRP_MJ_SET_EA : 804F355A
15:57:35:390 3592 IRP_MJ_FLUSH_BUFFERS : F75DD2E2
15:57:35:390 3592 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
15:57:35:390 3592 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
15:57:35:390 3592 IRP_MJ_DIRECTORY_CONTROL : 804F355A
15:57:35:390 3592 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
15:57:35:390 3592 IRP_MJ_DEVICE_CONTROL : F75DD3BB
15:57:35:390 3592 IRP_MJ_INTERNAL_DEVICE_CONTROL : F75E0F28
15:57:35:390 3592 IRP_MJ_SHUTDOWN : F75DD2E2
15:57:35:390 3592 IRP_MJ_LOCK_CONTROL : 804F355A
15:57:35:390 3592 IRP_MJ_CLEANUP : 804F355A
15:57:35:390 3592 IRP_MJ_CREATE_MAILSLOT : 804F355A
15:57:35:390 3592 IRP_MJ_QUERY_SECURITY : 804F355A
15:57:35:390 3592 IRP_MJ_SET_SECURITY : 804F355A
15:57:35:390 3592 IRP_MJ_POWER : F75DEC82
15:57:35:390 3592 IRP_MJ_SYSTEM_CONTROL : F75E399E
15:57:35:390 3592 IRP_MJ_DEVICE_CHANGE : 804F355A
15:57:35:390 3592 IRP_MJ_QUERY_QUOTA : 804F355A
15:57:35:390 3592 IRP_MJ_SET_QUOTA : 804F355A
15:57:35:406 3592 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
15:57:35:406 3592
15:57:35:406 3592 Driver Name: nvatabus
15:57:35:406 3592 IRP_MJ_CREATE : 8787E660
15:57:35:406 3592 IRP_MJ_CREATE_NAMED_PIPE : 8787E660
15:57:35:406 3592 IRP_MJ_CLOSE : 8787E660
15:57:35:406 3592 IRP_MJ_READ : 8787E660
15:57:35:406 3592 IRP_MJ_WRITE : 8787E660
15:57:35:406 3592 IRP_MJ_QUERY_INFORMATION : 8787E660
15:57:35:406 3592 IRP_MJ_SET_INFORMATION : 8787E660
15:57:35:406 3592 IRP_MJ_QUERY_EA : 8787E660
15:57:35:406 3592 IRP_MJ_SET_EA : 8787E660
15:57:35:406 3592 IRP_MJ_FLUSH_BUFFERS : 8787E660
15:57:35:406 3592 IRP_MJ_QUERY_VOLUME_INFORMATION : 8787E660
15:57:35:406 3592 IRP_MJ_SET_VOLUME_INFORMATION : 8787E660
15:57:35:406 3592 IRP_MJ_DIRECTORY_CONTROL : 8787E660
15:57:35:406 3592 IRP_MJ_FILE_SYSTEM_CONTROL : 8787E660
15:57:35:406 3592 IRP_MJ_DEVICE_CONTROL : 8787E660
15:57:35:406 3592 IRP_MJ_INTERNAL_DEVICE_CONTROL : 8787E660
15:57:35:406 3592 IRP_MJ_SHUTDOWN : 8787E660
15:57:35:406 3592 IRP_MJ_LOCK_CONTROL : 8787E660
15:57:35:406 3592 IRP_MJ_CLEANUP : 8787E660
15:57:35:406 3592 IRP_MJ_CREATE_MAILSLOT : 8787E660
15:57:35:406 3592 IRP_MJ_QUERY_SECURITY : 8787E660
15:57:35:406 3592 IRP_MJ_SET_SECURITY : 8787E660
15:57:35:406 3592 IRP_MJ_POWER : 8787E660
15:57:35:406 3592 IRP_MJ_SYSTEM_CONTROL : 8787E660
15:57:35:406 3592 IRP_MJ_DEVICE_CHANGE : 8787E660
15:57:35:406 3592 IRP_MJ_QUERY_QUOTA : 8787E660
15:57:35:406 3592 IRP_MJ_SET_QUOTA : 8787E660
15:57:35:468 3592 C:\WINDOWS\system32\DRIVERS\nvatabus.sys - Verdict: 1
15:57:35:468 3592
15:57:35:468 3592 Completed
15:57:35:468 3592
15:57:35:468 3592 Results:
15:57:35:468 3592 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
15:57:35:468 3592 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
15:57:35:468 3592 File objects infected / cured / cured on reboot: 0 / 0 / 0
15:57:35:468 3592
15:57:35:468 3592 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
15:57:35:468 3592 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
15:57:35:468 3592 KLMD(ARK) unloaded successfully
a log.č.2:
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
Error: No service named S3 VBoxNetFlt was found to stop!
Service\Driver key S3 VBoxNetFlt not found.
Service sfrem02 stopped successfully!
Service sfrem02 deleted successfully!
Error: No service named FrontLine Drivers Auto Removal (v2) was found to stop!
Service\Driver key FrontLine Drivers Auto Removal (v2) not found.
Error: No service named VBoxNetFlt Service was found to stop!
Service\Driver key VBoxNetFlt Service not found.
========== REGISTRY ==========
========== FILES ==========
c:\windows\system32\sys_drv.dat moved successfully.
c:\windows\system32\sys_drv_2.dat moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 178000 bytes
->Temporary Internet Files folder emptied: 64042 bytes
->Java cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 1790 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41044 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 155648 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 23948 bytes
Total Files Cleaned = 1,00 mb
OTM by OldTimer - Version 3.1.10.1 log created on 04142010_160150
A log CF:
ComboFix 10-04-09.01 - Administrator 14.04.2010 18:21:34.25.1 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.809 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
FILE ::
"c:\windows\system32\sys_drv.dat"
"c:\windows\system32\sys_drv_2.dat"
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-14 do 2010-04-14 )))))))))))))))))))))))))))))))
.
2010-04-14 14:01 . 2010-04-14 14:01 -------- d-----w- C:\_OTM
2010-04-02 13:34 . 2010-04-02 13:34 -------- d-----w- c:\windows\system32\wbem\Repository
2010-04-02 11:36 . 2010-04-05 08:27 -------- d-----w- C:\Paradise
2010-03-28 13:03 . 2010-03-28 13:11 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-15 18:21 . 2010-03-15 18:21 -------- d-----w- c:\program files\Lamer
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-14 15:44 . 2008-12-18 15:07 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-04-02 12:44 . 2010-02-22 10:29 -------- d-----w- c:\program files\Ubisoft
2010-04-01 16:33 . 2010-02-13 20:09 -------- d-----w- c:\program files\TopCD
2010-03-30 14:44 . 2009-08-27 11:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-29 22:46 . 2009-08-27 11:16 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 22:45 . 2009-08-27 11:16 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-28 19:03 . 2009-12-28 08:27 -------- d-----w- c:\program files\MotoGP2
2010-03-28 13:11 . 2009-08-05 17:50 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-03-28 13:11 . 2009-08-05 17:50 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-03-28 12:42 . 2008-12-21 08:19 -------- d-----w- c:\program files\Activision
2010-03-28 06:49 . 2001-09-20 12:00 97578 ----a-w- c:\windows\system32\perfc005.dat
2010-03-28 06:49 . 2001-09-20 12:00 466408 ----a-w- c:\windows\system32\perfh005.dat
2010-03-27 17:25 . 2008-12-18 14:11 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-26 11:14 . 2009-09-06 17:42 -------- d-----w- c:\program files\Opera
2010-03-14 16:54 . 2010-03-09 10:54 -------- d-----w- c:\program files\Crashday
2010-03-11 12:36 . 2004-08-17 13:49 832512 ------w- c:\windows\system32\wininet.dll
2010-03-11 12:36 . 2004-08-17 13:49 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:36 . 2004-08-17 13:49 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 13:50 . 2009-09-10 09:18 -------- d-----w- c:\program files\uTorrent
2010-03-09 11:42 . 2008-12-18 16:22 -------- d-----w- c:\program files\Google
2010-03-09 11:13 . 2010-03-09 10:59 -------- d-----w- c:\program files\JoWooD
2010-03-09 11:01 . 2010-03-09 11:01 -------- d-----w- c:\program files\ZOO Digital Publishing
2010-03-09 10:46 . 2010-02-03 14:20 -------- d-----w- c:\program files\Electronic Arts
2010-03-08 11:18 . 2010-01-30 18:24 -------- d-----w- c:\program files\ATI
2010-03-08 07:44 . 2010-02-04 19:21 -------- d-----w- c:\program files\MagicISO
2010-03-07 06:40 . 2008-12-18 15:44 -------- d-----w- c:\program files\VS Revo Group
2010-03-06 11:52 . 2010-03-06 11:33 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-06 11:52 . 2010-03-06 11:52 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-06 11:52 . 2010-03-06 11:33 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-06 11:52 . 2010-03-06 11:33 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-03-06 11:52 . 2010-03-06 11:33 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-03-06 11:52 . 2010-03-06 11:33 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-03-06 11:52 . 2010-03-06 11:33 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-06 11:52 . 2010-03-06 11:33 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-03-06 11:33 . 2010-03-06 11:33 -------- d-----w- c:\program files\AVG
2010-03-04 12:15 . 2010-03-04 12:15 -------- d-----w- c:\program files\THQ
2010-02-28 07:48 . 2010-02-28 07:48 -------- d-----w- c:\program files\Empire Interactive
2010-02-21 19:48 . 2009-09-10 09:58 -------- d-----w- c:\program files\IObit
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-18 16:35 . 2010-02-18 13:42 45056 ----a-w- c:\windows\NCUNINST.EXE
2010-02-18 13:42 . 2010-02-18 13:42 -------- d-----w- c:\program files\Common Files\SWF Studio
2010-02-14 17:19 . 2009-01-05 16:30 -------- d-----w- c:\program files\The Learning Company
2010-02-04 09:01 . 2010-02-13 20:09 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-02-04 09:01 . 2010-02-13 20:09 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-02-04 09:01 . 2010-02-13 20:09 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-02-04 09:01 . 2010-02-13 20:09 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-02-03 04:52 . 2008-08-21 04:52 4605952 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-02-03 04:12 . 2010-01-30 18:03 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-02-03 04:12 . 2010-01-30 18:03 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-02-03 04:10 . 2010-01-30 18:03 3633152 ----a-w- c:\windows\system32\aticaldd.dll
2010-02-03 04:07 . 2010-01-30 18:24 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-02-03 04:02 . 2010-01-30 18:03 14188544 ----a-w- c:\windows\system32\atioglxx.dll
2010-02-03 03:50 . 2010-01-30 18:03 3566048 ----a-w- c:\windows\system32\ati3duag.dll
2010-02-03 03:40 . 2010-01-30 18:24 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-02-03 03:39 . 2010-01-30 18:03 301568 ----a-w- c:\windows\system32\ati2dvag.dll
2010-02-03 03:35 . 2010-01-30 18:03 2176640 ----a-w- c:\windows\system32\ativvaxx.dll
2010-02-03 03:34 . 2010-01-30 18:24 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-02-03 03:34 . 2010-01-30 18:24 3 ----a-w- c:\windows\system32\ativva5x.dat
2010-02-03 03:32 . 2010-01-30 18:03 397312 ----a-w- c:\windows\system32\atiok3x2.dll
2010-02-03 03:23 . 2009-12-21 18:58 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-02-03 03:23 . 2010-01-30 18:03 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-02-03 03:23 . 2010-01-30 18:03 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-02-03 03:23 . 2009-12-21 18:58 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-02-03 03:22 . 2010-01-30 18:03 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-02-03 03:21 . 2009-12-21 18:58 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-02-03 03:19 . 2010-01-30 18:03 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-02-03 03:19 . 2010-03-08 11:18 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-02-03 03:18 . 2010-01-30 18:03 65024 ----a-w- c:\windows\system32\atimpc32.dll
2010-02-03 03:18 . 2010-01-30 18:03 65024 ----a-w- c:\windows\system32\amdpcom32.dll
2010-02-03 03:17 . 2010-01-30 18:03 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-02-03 03:15 . 2010-01-30 18:03 565248 ----a-w- c:\windows\system32\atikvmag.dll
2010-02-03 03:12 . 2010-01-30 18:03 180224 ----a-w- c:\windows\system32\atiadlxx.dll
2010-02-03 03:12 . 2010-01-30 18:03 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-02-03 03:06 . 2010-01-30 18:03 638976 ----a-w- c:\windows\system32\ati2cqag.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-06 11:52 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [6.3.2010 13:33 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [6.3.2010 13:33 52872]
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [5.2.2009 19:18 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [5.2.2009 19:18 5248]
R0 sfdrv02;FrontLine Environment Driver (v2);c:\windows\system32\drivers\sfdrv02.sys [11.9.2006 13:57 67960]
R0 sfsync05;FrontLine Synchronization Driver (v5);c:\windows\system32\drivers\sfsync05.sys [11.8.2006 18:09 59776]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [8.9.2009 22:25 95592]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6.3.2010 13:33 216200]
S1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6.3.2010 13:33 242696]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [6.3.2010 13:52 916760]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [6.3.2010 13:52 308064]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [6.3.2010 13:52 2325816]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [6.3.2010 13:52 5888008]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [6.3.2010 13:33 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [6.3.2010 13:33 30104]
S3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [6.3.2010 13:33 122376]
S3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [6.3.2010 13:33 30216]
S3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [6.3.2010 13:33 26120]
S3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [7.11.2007 20:15 12928]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [14.9.2009 16:04 91856]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.12.2008 23:28 691696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
------- Doplňkový sken -------
.
uDefault_Search_URL =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
TCP: {5D3D3CCE-D4C6-45B6-A85C-952672CC26EB} = 10.0.0.1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-14 18:28
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x87B15C40]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7633f28
\Driver\ACPI -> ACPI.sys @ 0xf7580cb8
\Driver\atapi -> atapi.sys @ 0xf74ed852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
user & kernel MBR OK
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(276)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
- - - - - - - > 'explorer.exe'(1420)
c:\progra~1\WINDOW~2\wmpband.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
.
**************************************************************************
.
Celkový čas: 2010-04-14 18:33:21 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-04-14 16:33
ComboFix2.txt 2010-04-09 11:29
Před spuštěním: Volných bajtů: 35 391 680 512
Po spuštění: Volných bajtů: 35 344 113 664
Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - DA6F2E4A11AFAB9874A0DB9BAEE0FFB8