kontrola logu-modra smrt Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

mishel275
Level 1.5
Level 1.5
Příspěvky: 145
Registrován: květen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod mishel275 » 23 led 2011 20:25

no tak spravilo to to iste, vybehla ta hlaska....odklikol som ju OK, a potom som len tak stalcil este raz RunFix -> program sa normalne rozbehol(nechapem), Pc sa restartovalo a tu je log:
All processes killed
Error: Unable to interpret <O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.> in the current context!
Error: Unable to interpret <O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.> in the current context!
Error: Unable to interpret <O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [KiesTrayAgent] File not found> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [Nektra OEAPI] File not found> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [OEXPRESS] File not found> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found> in the current context!
Error: Unable to interpret <O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found> in the current context!
Error: Unable to interpret <O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found> in the current context!
Error: Unable to interpret <O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.> in the current context!
Error: Unable to interpret <O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.> in the current context!
Error: Unable to interpret <[2011/01/16 09:58:39 | 000,607,634 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat> in the current context!
Error: Unable to interpret <[2011/01/16 09:58:39 | 000,103,754 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat> in the current context!
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
C:\Windows\SysNative\drivers\etc\tmvsthfud.bin moved successfully.
C:\Windows\SysNative\drivers\etc\tmvsthfss.bin moved successfully.
C:\ProgramData\ezsidmv.dat moved successfully.
C:\ProgramData\FullRemove.exe moved successfully.
C:\Windows\SysWow64\cis-2.4.dll moved successfully.
C:\Windows\SysWow64\issacapi_bs-2.3.dll moved successfully.
C:\Windows\SysWow64\issacapi_pe-2.3.dll moved successfully.
C:\Windows\SysWow64\issacapi_se-2.3.dll moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\promotion folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\mozilla-profile\updates\0 folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\mozilla-profile\updates folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\mozilla-profile\extensions folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\mozilla-profile\Cache folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\mozilla-profile folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\certificate folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\res\html folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\res folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\plugins folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\modules folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\greprefs folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\defaults\pref folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\defaults folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\components folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner\chrome folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser\xulrunner folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\browser folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire\.AppSpecialShare folder moved successfully.
C:\Users\Michal\AppData\Roaming\LimeWire folder moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Michal
->Temp folder emptied: 8320607 bytes
->Temporary Internet Files folder emptied: 3852313 bytes
->Java cache emptied: 546358 bytes
->FireFox cache emptied: 103370087 bytes
->Flash cache emptied: 15745745 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4261150 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67803 bytes
RecycleBin emptied: 444737738 bytes

Total Files Cleaned = 554,00 mb


OTL by OldTimer - Version 3.2.20.4 log created on 01232011_202039

Files\Folders moved on Reboot...
C:\Users\Michal\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod jaro3 » 23 led 2011 20:43

Co jsi odinstaloval:
Trend Micro\Internet Security
Avira\AntiVir Desktop
??

Jak to je s modrou smrtí?

Postni mi někam ten zararovaný soubor v minidump.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mishel275
Level 1.5
Level 1.5
Příspěvky: 145
Registrován: květen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod mishel275 » 23 led 2011 20:59

Nechal som si Aviru.....
No ta modra smrt sa mi 2 krat tusim zjavila, ako som pisal predtym proste znicoho nic.
Chcel som ti to uploadnut na upnito.sk len mi to nejde mam poziadat o povolenie spravcu....pritom som jediny user na pc.....neviem ako mam poziadat
Ten subor nieje zararovany ma priponu .dmp

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod jaro3 » 23 led 2011 22:32

dej ho do složky s názvem minidump , zararuj a postni na:
http://data7.edisk.cz/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mishel275
Level 1.5
Level 1.5
Příspěvky: 145
Registrován: květen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod mishel275 » 23 led 2011 22:45

skopiroval som si to na plochu...zararoval a .rar subor som dal do zlozky minudump...:D inak to neslo
tu je http://www.edisk.cz/stahni/85478/012011 ... .61KB.html

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod jaro3 » 24 led 2011 09:51

minidump-problém je tam jediný:
usbhub.sys

BUGCODE_USB_DRIVER


Používáš HUB na USB?

Udělej ještě jednou OTL , chtěl bych vidět , zda je ten druhý antivir (balík internet security) plně odinstalován..

Takto:
Stáhni si OTH
na svojí plochu( pokud používáš Firefox , pravým klikni na OTH link a vyber uložit jako (Save as..).

Stáhni si OTL
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).

Stáhni si soubor Scan.txt
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).

Poklepej na soubor OTH na ploše , po spuštění programu klikni na Kill All Processes.Poté klikni na Start OTL .Poklepej Do prázdného okna pod Vlastní skenování /opravy ( Custom Scans box). Objeví se zpráva: Kliknutím na OK vyberete cestu k souboru, kliknutím na Zrušit zrušíte výběr.
Klikni na OK. Objeví se okno průzkumníku , zde klikneš na plochu a najdeš na ní soubor Scan.txt .Klikni na Otevřít.
Poté klikni na Rychle prohledat (Quick Scan). Neměň žádná jiná nastavení . Sken může trvat dlouho.
Kdy sken skončí , objeví se na ploše dva logy:
OTL.Txt a Extras.Txt , jsou uloženy ve stejném místě jako OTL.
Zkopíruj sem prosím celý obsah obou logů.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mishel275
Level 1.5
Level 1.5
Příspěvky: 145
Registrován: květen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod mishel275 » 24 led 2011 10:17

Ak myslis, ze HUG pre USB je viac usb vstupov pripojenych cez 1 vstup tak to nepouzivam. ani som nikdy nepouzival. a ani, ked mi nabehla bluescreen tak som nic v usb nemal zapojene.
otl.txt:
OTL logfile created on: 24. 1. 2011 10:07:41 - Run 2
OTL by OldTimer - Version 3.2.20.5 Folder = C:\Users\Michal\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.7930.16406)
Locale: 0000041b | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 72,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 81,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 116,44 Gb Total Space | 54,26 Gb Free Space | 46,60% Space Free | Partition Type: NTFS
Drive D: | 329,79 Gb Total Space | 242,97 Gb Free Space | 73,67% Space Free | Partition Type: NTFS

Computer Name: MICHAL-PC | User Name: Michal | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Michal\Desktop\otl.exe (OldTimer Tools)
PRC - C:\Users\Michal\Desktop\OTH.scr (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\SysWOW64\dgdersvc.exe (Devguru Co., Ltd.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS)


========== Modules (SafeList) ==========

MOD - C:\Users\Michal\Desktop\otl.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
MOD - C:\Windows\SysWOW64\IconCodecService.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\normaliz.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (appdrvrem01) -- C:\Windows\SysNative\appdrvrem01.exe (Protection Technology)
SRV:64bit: - (AFBAgent) -- C:\Windows\SysNative\FBAgent.exe (ASUSTeK Computer Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (dgdersvc) -- C:\Windows\SysWOW64\dgdersvc.exe (Devguru Co., Ltd.)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (KiesAllShare) -- C:\Program Files (x86)\Samsung\Kies\WiselinkPro\WiselinkPro.exe ()
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (appdrv01) Application Driver (01) -- C:\Windows\SysNative\drivers\appdrv01.sys (Protection Technology)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (ssadmdfl) SAMSUNG Android USB Modem (Filter) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (dgderdrv) -- C:\Windows\SysNative\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV:64bit: - (TFsExDisk) -- C:\Windows\SysNative\drivers\TFsExDisk.sys (Teruten Inc)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel(R) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (L1C) NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller (NDIS 6.20) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (btusbflt) -- C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (lullaby) -- C:\Windows\SysNative\drivers\lullaby.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ATK64AMD.sys (ASUS)
DRV:64bit: - (KMWDFILTER) -- C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows (R) Codename Longhorn DDK provider)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (dgderdrv) -- C:\Windows\SysWOW64\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (TFsExDisk) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys (Teruten Inc)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.sk"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/20 07:58:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/17 08:16:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/12/17 08:16:41 | 000,000,000 | ---D | M]

[2010/10/13 18:55:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michal\AppData\Roaming\mozilla\Extensions
[2010/10/13 18:55:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michal\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2011/01/24 08:52:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michal\AppData\Roaming\mozilla\Firefox\Profiles\lj1uvxbd.default\extensions
[2010/10/17 08:50:42 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Michal\AppData\Roaming\mozilla\Firefox\Profiles\lj1uvxbd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/01/19 21:22:56 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Michal\AppData\Roaming\mozilla\Firefox\Profiles\lj1uvxbd.default\extensions\personas@christopher.beard
[2010/10/04 17:18:08 | 000,002,059 | ---- | M] () -- C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\lj1uvxbd.default\searchplugins\daemon-search.xml
[2010/12/29 11:33:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/10/02 11:59:55 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/29 11:33:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/09/14 22:57:55 | 000,001,583 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010/09/14 22:57:55 | 000,001,380 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\azet-sk.xml
[2010/09/14 22:57:55 | 000,001,479 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010/09/14 22:57:55 | 000,001,473 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010/09/14 22:57:55 | 000,001,104 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010/09/14 22:57:55 | 000,000,830 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\zoznam-sk.xml

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - D:\Translator 2010\WebIE.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - D:\Translator 2010\WebIE.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [Boingo Wi-Fi] C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [KiesTrayAgent] File not found
O4 - HKCU..\Run: [Nektra OEAPI] File not found
O4 - HKCU..\Run: [OEXPRESS] File not found
O4 - HKCU..\Run: [PPAP] C:\Program Files (x86)\Common Files\PPLiveNetwork\PPAP.exe (PPLive Corporation)
O4 - HKCU..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\syncables.exe (syncables, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: E&xportovať do programu Microsoft Excel - D:\Microsoft office\Office12\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - D:\Microsoft office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - D:\Translator 2010\WebIE.dll ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - D:\Translator 2010\WebIE.dll ()
O9 - Extra 'Tools' menuitem : &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - D:\Translator 2010\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - D:\Translator 2010\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - D:\Translator 2010\WebIE.dll ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} http://download.pplive.com/config/pplit ... nsetup.cab (PPLive Lite Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/01/24 10:01:31 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Users\Michal\Desktop\OTH.scr
[2011/01/24 08:01:28 | 000,000,000 | ---D | C] -- C:\Users\Michal\AppData\Local\Activision
[2011/01/23 19:13:05 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/01/23 16:36:07 | 000,603,136 | ---- | C] (OldTimer Tools) -- C:\Users\Michal\Desktop\OTL.exe
[2011/01/20 21:59:42 | 000,000,000 | ---D | C] -- C:\Users\Michal\AppData\Local\Cyberlink
[2011/01/20 20:55:39 | 000,000,000 | ---D | C] -- C:\Users\Michal\AppData\Roaming\Malwarebytes
[2011/01/20 20:55:35 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/01/20 20:55:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/20 20:55:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/01/20 20:55:31 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/01/20 20:55:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/01/20 20:54:19 | 000,000,000 | ---D | C] -- C:\Users\Michal\AppData\Local\Broadcom
[2011/01/20 20:27:17 | 000,000,000 | ---D | C] -- C:\Users\Michal\DoctorWeb
[2011/01/19 21:52:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011/01/19 21:52:48 | 000,000,000 | ---D | C] -- C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2010/12/29 11:33:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010/12/26 17:00:33 | 000,000,000 | ---D | C] -- C:\Users\Michal\Desktop\fotky-tematin
[2010/12/25 15:21:50 | 000,000,000 | R--D | C] -- C:\Users\Michal\Desktop\kontakty
[2010/12/25 11:57:41 | 000,159,208 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdm.sys
[2010/12/25 11:57:41 | 000,125,416 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadbus.sys
[2010/12/25 11:57:41 | 000,016,872 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdfl.sys
[2010/12/25 11:57:41 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwhnt.sys
[2010/12/25 11:57:41 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwh.sys
[2010/12/25 11:57:41 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcmnt.sys
[2010/12/25 11:57:41 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcm.sys
[2010/12/25 11:56:36 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\System32
[2010/12/25 11:48:07 | 000,000,000 | ---D | C] -- C:\Users\Michal\Documents\Samsung
[2010/12/25 11:48:06 | 000,000,000 | ---D | C] -- C:\Users\Michal\AppData\Roaming\PC Suite
[2010/12/25 11:48:06 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Suite
[2010/12/25 11:43:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2010/12/25 11:40:19 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2010/12/25 11:40:18 | 000,025,600 | ---- | C] (Nokia) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys
[2010/12/25 11:40:00 | 000,020,480 | ---- | C] (Teruten Inc) -- C:\Windows\SysWow64\FsExService64.Exe
[2010/12/25 11:40:00 | 000,016,392 | ---- | C] (Teruten Inc) -- C:\Windows\SysWow64\drivers\TFsExDisk.Sys
[2010/12/25 11:40:00 | 000,016,392 | ---- | C] (Teruten Inc) -- C:\Windows\SysNative\drivers\TFsExDisk.sys
[2010/12/25 11:38:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Connectivity Solution
[2010/12/25 11:36:57 | 000,000,000 | ---D | C] -- C:\Users\Michal\AppData\Roaming\Samsung
[2010/12/25 11:36:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2010/12/25 11:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2010/12/25 11:35:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung
[2010/12/25 11:35:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Samsung
[2010/12/25 10:45:23 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2008/08/12 05:45:20 | 000,155,648 | ---- | C] (ASUS) -- C:\Program Files (x86)\Common Files\MSIactionall.dll

========== Files - Modified Within 30 Days ==========

[2011/01/24 10:01:47 | 000,603,136 | ---- | M] (OldTimer Tools) -- C:\Users\Michal\Desktop\OTL.exe
[2011/01/24 10:01:32 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Users\Michal\Desktop\OTH.scr
[2011/01/24 09:12:52 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2011/01/24 08:04:06 | 000,111,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/01/24 08:01:25 | 000,000,136 | ---- | M] () -- C:\Users\Michal\Desktop\Call of Duty® World at War - odkaz.lnk
[2011/01/24 07:15:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/01/23 22:40:31 | 000,028,268 | ---- | M] () -- C:\Users\Michal\Desktop\012011-37050-01.rar
[2011/01/23 20:29:27 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/23 20:29:27 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/23 20:21:33 | 3055,706,112 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/20 20:55:35 | 000,001,129 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/20 07:43:45 | 000,362,968 | ---- | M] () -- C:\Users\Michal\Desktop\012011-37050-01.dmp
[2011/01/20 07:43:06 | 547,265,786 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/01/19 21:52:48 | 000,003,013 | ---- | M] () -- C:\Users\Michal\Desktop\HiJackThis.lnk
[2011/01/16 09:58:39 | 000,714,754 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/01/16 09:58:39 | 000,607,634 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/01/16 09:58:39 | 000,103,754 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/01/10 22:38:33 | 000,000,834 | ---- | M] () -- C:\Users\Michal\Desktop\Bluetooth.lnk
[2011/01/10 22:22:29 | 000,683,936 | ---- | M] () -- C:\Users\Michal\Desktop\peta.jpg
[2011/01/09 11:32:16 | 000,129,973 | ---- | M] () -- C:\Users\Michal\Desktop\ikona.png
[2011/01/09 11:27:16 | 000,001,498 | ---- | M] () -- C:\Users\Michal\Desktop\firefox - odkaz.lnk
[2010/12/31 12:45:52 | 000,002,515 | ---- | M] () -- C:\Users\Michal\Desktop\Skype.lnk
[2010/12/26 16:50:10 | 000,001,296 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2010/12/25 16:06:43 | 000,021,863 | ---- | M] () -- C:\Users\Michal\AppData\Roaming\Hodnoty oddelené čiarkou (systém Windows).ADR
[2010/12/25 15:47:57 | 000,010,100 | ---- | M] () -- C:\Users\Michal\Desktop\csv.csv
[2010/12/25 14:44:50 | 000,002,733 | ---- | M] () -- C:\Users\Michal\Desktop\Microsoft Office Outlook 2007.lnk
[2010/12/25 14:18:07 | 000,001,139 | ---- | M] () -- C:\Users\Michal\Documents\Alfa-Lofler.contact
[2010/12/25 12:37:24 | 000,090,002 | ---- | M] () -- C:\Users\Michal\Desktop\Whole Phonebook.vcf
[2010/12/25 12:08:16 | 000,096,560 | ---- | M] () -- C:\Users\Michal\Documents\Kontakty001.SPB
[2010/12/25 11:47:27 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/12/25 11:43:46 | 000,001,965 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2010/12/25 11:36:07 | 000,002,006 | ---- | M] () -- C:\aqua_bitmap.cpp
[2010/12/25 10:45:25 | 000,000,826 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk

========== Files Created - No Company Name ==========

[2011/01/24 09:12:52 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011/01/24 08:01:25 | 000,000,136 | ---- | C] () -- C:\Users\Michal\Desktop\Call of Duty® World at War - odkaz.lnk
[2011/01/23 22:40:24 | 000,028,268 | ---- | C] () -- C:\Users\Michal\Desktop\012011-37050-01.rar
[2011/01/23 20:52:28 | 000,362,968 | ---- | C] () -- C:\Users\Michal\Desktop\012011-37050-01.dmp
[2011/01/20 20:55:35 | 000,001,129 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/20 07:43:06 | 547,265,786 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/01/19 21:52:48 | 000,003,013 | ---- | C] () -- C:\Users\Michal\Desktop\HiJackThis.lnk
[2011/01/10 22:38:33 | 000,000,834 | ---- | C] () -- C:\Users\Michal\Desktop\Bluetooth.lnk
[2011/01/10 22:22:29 | 000,683,936 | ---- | C] () -- C:\Users\Michal\Desktop\peta.jpg
[2011/01/09 11:32:15 | 000,129,973 | ---- | C] () -- C:\Users\Michal\Desktop\ikona.png
[2011/01/09 11:27:16 | 000,001,498 | ---- | C] () -- C:\Users\Michal\Desktop\firefox - odkaz.lnk
[2010/12/31 12:45:52 | 000,002,515 | ---- | C] () -- C:\Users\Michal\Desktop\Skype.lnk
[2010/12/25 16:05:25 | 000,021,863 | ---- | C] () -- C:\Users\Michal\AppData\Roaming\Hodnoty oddelené čiarkou (systém Windows).ADR
[2010/12/25 15:50:23 | 000,010,100 | ---- | C] () -- C:\Users\Michal\Desktop\csv.csv
[2010/12/25 14:54:19 | 000,001,139 | ---- | C] () -- C:\Users\Michal\Documents\Alfa-Lofler.contact
[2010/12/25 14:44:50 | 000,002,733 | ---- | C] () -- C:\Users\Michal\Desktop\Microsoft Office Outlook 2007.lnk
[2010/12/25 12:38:25 | 000,090,002 | ---- | C] () -- C:\Users\Michal\Desktop\Whole Phonebook.vcf
[2010/12/25 12:08:16 | 000,096,560 | ---- | C] () -- C:\Users\Michal\Documents\Kontakty001.SPB
[2010/12/25 11:47:27 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/12/25 11:43:46 | 000,001,965 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2010/12/25 11:36:07 | 000,002,006 | ---- | C] () -- C:\aqua_bitmap.cpp
[2010/12/25 10:45:25 | 000,000,826 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2010/10/20 10:39:34 | 000,000,088 | -H-- | C] () -- C:\ProgramData\aspg.dat
[2010/10/01 15:57:42 | 003,056,520 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/01 07:59:18 | 000,002,455 | ---- | C] () -- C:\Windows\TRNCOM.INI
[2010/08/06 09:19:24 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\LogonStart.dll
[2010/08/06 08:36:07 | 000,000,105 | ---- | C] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/08/06 08:35:47 | 000,000,107 | ---- | C] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2010/08/06 08:34:49 | 000,000,105 | ---- | C] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2010/08/06 08:34:34 | 000,000,109 | ---- | C] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/08/06 08:33:27 | 000,000,106 | ---- | C] () -- C:\ProgramData\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}.log
[2010/08/06 08:30:20 | 000,000,110 | ---- | C] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/08/06 08:29:08 | 000,000,115 | ---- | C] () -- C:\ProgramData\{E3739848-5329-48E3-8D28-5BBD6E8BE384}.log
[2010/05/13 06:35:22 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\MAMACExtract.dll
[2010/04/30 17:42:23 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/04/30 17:42:23 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010/02/09 08:07:38 | 000,000,269 | ---- | C] () -- C:\Windows\OOBEPlayer.ini
[2009/07/29 06:20:40 | 000,000,010 | ---- | C] () -- C:\Windows\SysWow64\ABLKSR.ini
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/04/08 18:31:56 | 000,106,496 | ---- | C] () -- C:\Program Files (x86)\Common Files\CPInstallAction.dll
[2008/12/01 18:32:32 | 000,362,029 | ---- | C] () -- C:\Windows\SysWow64\sqlite3.dll
[2008/10/22 04:29:06 | 000,173,550 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2008/05/22 16:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files (x86)\Common Files\banner.jpg
[2007/06/12 17:34:50 | 000,035,822 | ---- | C] () -- C:\Program Files (x86)\Common Files\ASPG_icon.ico
[2006/05/19 20:39:57 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini

========== LOP Check ==========

[2010/09/30 11:37:09 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\Asus WebStorage
[2010/10/20 10:13:24 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/10/04 17:57:53 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
[2010/11/29 23:29:51 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\GetRightToGo
[2010/10/01 08:02:20 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\LangSoft
[2010/11/14 19:44:39 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\Leadertech
[2010/12/25 11:48:06 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\PC Suite
[2010/11/29 22:14:48 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\PPlive
[2010/12/25 11:36:57 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\Samsung
[2010/12/18 17:34:22 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\Smart PDF Converter Pro
[2011/01/24 10:04:21 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\SoftGrid Client
[2010/10/01 15:58:35 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\TP
[2010/11/15 13:31:21 | 000,000,000 | ---D | M] -- C:\Users\Michal\AppData\Roaming\uTorrent
[2011/01/23 20:22:11 | 000,011,080 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/15 12:11:59 | 000,000,054 | ---- | M] () -- C:\AdobeReader.log
[2010/12/25 11:36:07 | 000,002,006 | ---- | M] () -- C:\aqua_bitmap.cpp
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2009/07/29 07:03:37 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/08/06 09:35:21 | 000,015,953 | ---- | M] () -- C:\devlist.txt
[2010/08/06 09:35:20 | 000,000,009 | ---- | M] () -- C:\Finish.log
[2011/01/23 20:21:33 | 3055,706,112 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/06 09:24:28 | 000,456,650 | ---- | M] () -- C:\if.log
[2010/05/20 10:43:26 | 002,097,152 | -H-- | M] () -- C:\N61Jv.BIN
[2010/07/02 02:32:40 | 000,000,019 | ---- | M] () -- C:\N61Jv_WIN7.50
[2011/01/23 20:21:36 | 4074,278,912 | -HS- | M] () -- C:\pagefile.sys
[2010/08/05 20:59:26 | 000,000,233 | ---- | M] () -- C:\Pass.txt
[2009/12/04 14:31:57 | 000,000,005 | ---- | M] () -- C:\RECOVERY.DAT
[2010/08/06 09:05:47 | 000,003,122 | ---- | M] () -- C:\RHDSetup.log
[2010/08/06 09:19:12 | 000,000,168 | ---- | M] () -- C:\setup.log
[2006/05/13 17:22:24 | 000,000,005 | ---- | M] () -- C:\store.log
[2010/08/06 08:15:37 | 000,000,166 | ---- | M] () -- C:\SumHidd.txt
[2010/08/06 08:14:06 | 000,000,098 | ---- | M] () -- C:\SumOS.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWOW64\drivers\mbamswissarmy.sys

< End of report >

mishel275
Level 1.5
Level 1.5
Příspěvky: 145
Registrován: květen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod mishel275 » 24 led 2011 10:20

EXTRAS.TXT mi nevygenerovalo, ani nieje na ploche - tam kde je ulozene OTL

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod jaro3 » 24 led 2011 11:59

Ok..

Ak myslis, ze HUG pre USB je viac usb vstupov pripojenych cez 1 vstup tak to nepouzivam. ani som nikdy nepouzival. a ani, ked mi nabehla bluescreen tak som nic v usb nemal zapojene.--- ne , to je součást win7

problém možná bude , že tam není , nebo je poškozen..

Start-spustit-napiš: notepad ,do něho vlož tento celý text:

Kód: Vybrat vše

dir \usbhub.sys /a h /s > File.txt


uložit na plochu s názvem: find.bat (typ souboru- všechny soubory)
Najdi ho na ploše, poklepej na něj a počkej až se okno zavře a objeví se soubor.txt
Vlož sem potom celý text z tohoto souboru.

Soubor by se měl nacházet zde:
C:\Windows\System32\drivers

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\Users\Michal\Desktop\csv.csv
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Script udělám potom.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mishel275
Level 1.5
Level 1.5
Příspěvky: 145
Registrován: květen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod mishel275 » 24 led 2011 12:22

v C:\Windows\System32\drivers som nenasiel ziadny txt subor, vlastne len 1, ale ktory s tym asi nesuvisi. na plloche sa mi objavil File.txt - takze to je ono:
Volume in drive C is OS
Volume Serial Number is 56AB-0E98

Directory of C:\Windows\System32\drivers

14. 07. 2009 01:07 343˙040 usbhub.sys
1 File(s) 343˙040 bytes

Directory of C:\Windows\System32\DriverStore\FileRepository\usb.inf_amd64_neutral_e2b28ecac19a29af

14. 07. 2009 01:07 343˙040 usbhub.sys
1 File(s) 343˙040 bytes

Directory of C:\Windows\System32\DriverStore\FileRepository\usbport.inf_amd64_neutral_5a41ca742f7973cc

14. 07. 2009 01:07 343˙040 usbhub.sys
1 File(s) 343˙040 bytes

Directory of C:\Windows\winsxs\amd64_usb.inf_31bf3856ad364e35_6.1.7600.16385_none_26ed589d28235a16

14. 07. 2009 01:07 343˙040 usbhub.sys
1 File(s) 343˙040 bytes

Directory of C:\Windows\winsxs\amd64_usbport.inf_31bf3856ad364e35_6.1.7600.16385_none_19b7511a1d3ea7fd

14. 07. 2009 01:07 343˙040 usbhub.sys
1 File(s) 343˙040 bytes

poznamka: amd64 nejako nesuvisi s procesorom amd?....ked mam intel? (:D mozno to je pre teba smiesne, ale pre laika sa to zda divne)
a este nebude problem v tom, ked do vstupu usb 3.0 zapajam usb-ecko 2.0 (tiez mozno blba poznamka, ale kazdy napad mozme pomoct)

Virustotal mi nejde nacitat. ten subor csv.csv vznikol, ked som si kopiroval kontakty zo Sony Ericcsonu do Symbiantu. nejak sa mi to nedarilo a uz som skusal aj vselico v exceli- je to excel subor oddeleny ciarkami. neviem ci som to nerobil aj cez nejaky program, alebo len som to robil v exceli

UZ MI NACITALO VIRUSTOTAL: http://www.virustotal.com/file-scan/rep ... 1295868154

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod jaro3 » 24 led 2011 18:37

To je OK.

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
SRV:64bit: - (appdrvrem01) -- C:\Windows\SysNative\appdrvrem01.exe (Protection Technology)
[2010/10/04 17:18:08 | 000,002,059 | ---- | M] () -- C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\lj1uvxbd.default\searchplugins\daemon-search.xml
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKCU..\Run: [KiesTrayAgent] File not found
O4 - HKCU..\Run: [Nektra OEAPI] File not found
O4 - HKCU..\Run: [OEXPRESS] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

:Files
C:\Windows\SysWow64\System32
C:\Windows\SysNative\appdrvrem01.exe

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Poklepej znovu na ikonu OTL by OldTimer, pod Vlastní skenování/opravy (Custom Scans/Fixes) vlož následující text , zeleně zbarvený:

Kód: Vybrat vše

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT


Neměň nastavení, jen klikni na Prohledat (Run Scan), nech sken dokončit. Až se se objeví textový soubor , tak sem vlož prosím jeho celý obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mishel275
Level 1.5
Level 1.5
Příspěvky: 145
Registrován: květen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu-modra smrt

Příspěvekod mishel275 » 24 led 2011 20:15

Raz udavas ikonu OTL, raz OTL by OldTimer. Chcem sa uistit, ci to je to iste.......vdaka


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 119 hostů