HJT - modra obrazovka Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Mefisto
Level 3
Level 3
Příspěvky: 410
Registrován: duben 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Mefisto » 14 bře 2012 20:57

20:53:00.0500 2740 TDSS rootkit removing tool 2.7.20.0 Mar 9 2012 17:10:43
20:53:00.0609 2740 ============================================================
20:53:00.0609 2740 Current date / time: 2012/03/14 20:53:00.0609
20:53:00.0609 2740 SystemInfo:
20:53:00.0609 2740
20:53:00.0609 2740 OS Version: 5.1.2600 ServicePack: 3.0
20:53:00.0609 2740 Product type: Workstation
20:53:00.0609 2740 ComputerName: JENIK
20:53:00.0609 2740 UserName: Honzik
20:53:00.0609 2740 Windows directory: C:\WINDOWS
20:53:00.0609 2740 System windows directory: C:\WINDOWS
20:53:00.0609 2740 Processor architecture: Intel x86
20:53:00.0609 2740 Number of processors: 2
20:53:00.0609 2740 Page size: 0x1000
20:53:00.0609 2740 Boot type: Normal boot
20:53:00.0609 2740 ============================================================
20:53:02.0171 2740 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
20:53:02.0171 2740 \Device\Harddisk0\DR0:
20:53:02.0171 2740 MBR used
20:53:02.0171 2740 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2542D682
20:53:02.0203 2740 Initialize success
20:53:02.0203 2740 ============================================================
20:53:39.0890 0780 ============================================================
20:53:39.0890 0780 Scan started
20:53:39.0890 0780 Mode: Manual;
20:53:39.0890 0780 ============================================================
20:53:40.0531 0780 Aavmker4 - ok
20:53:40.0562 0780 Abiosdsk - ok
20:53:40.0578 0780 abp480n5 - ok
20:53:40.0625 0780 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:53:40.0625 0780 ACPI - ok
20:53:40.0640 0780 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
20:53:40.0640 0780 ACPIEC - ok
20:53:40.0656 0780 adpu160m - ok
20:53:40.0703 0780 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
20:53:40.0703 0780 aec - ok
20:53:40.0750 0780 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
20:53:40.0750 0780 AFD - ok
20:53:40.0781 0780 Aha154x - ok
20:53:40.0812 0780 aic78u2 - ok
20:53:40.0828 0780 aic78xx - ok
20:53:40.0843 0780 AliIde - ok
20:53:40.0921 0780 Ambfilt (267fc636801edc5ab28e14036349e3be) C:\WINDOWS\system32\drivers\Ambfilt.sys
20:53:40.0968 0780 Ambfilt - ok
20:53:41.0015 0780 AmdK8 (22ad3ec1f0486c863d70cdd50b97761b) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
20:53:41.0015 0780 AmdK8 - ok
20:53:41.0031 0780 amsint - ok
20:53:41.0078 0780 AppleCharger (e592751036c1d0a74ec3e57302a03745) C:\WINDOWS\system32\DRIVERS\AppleCharger.sys
20:53:41.0078 0780 AppleCharger - ok
20:53:41.0156 0780 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
20:53:41.0156 0780 Arp1394 - ok
20:53:41.0171 0780 asc - ok
20:53:41.0187 0780 asc3350p - ok
20:53:41.0218 0780 asc3550 - ok
20:53:41.0281 0780 ASFWHide - ok
20:53:41.0328 0780 aswMon2 - ok
20:53:41.0343 0780 AswRdr - ok
20:53:41.0390 0780 aswTdi - ok
20:53:41.0453 0780 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:53:41.0453 0780 AsyncMac - ok
20:53:41.0515 0780 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
20:53:41.0515 0780 atapi - ok
20:53:41.0546 0780 Atdisk - ok
20:53:41.0796 0780 ati2mtag (c832bf76f003999d2e91e5115583c69e) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
20:53:41.0828 0780 ati2mtag - ok
20:53:41.0875 0780 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\WINDOWS\system32\DRIVERS\atksgt.sys
20:53:41.0875 0780 atksgt - ok
20:53:41.0968 0780 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:53:41.0968 0780 Atmarpc - ok
20:53:42.0031 0780 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
20:53:42.0031 0780 audstub - ok
20:53:42.0109 0780 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
20:53:42.0109 0780 Beep - ok
20:53:42.0156 0780 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
20:53:42.0156 0780 BthEnum - ok
20:53:42.0171 0780 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
20:53:42.0187 0780 BTHMODEM - ok
20:53:42.0203 0780 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
20:53:42.0203 0780 BthPan - ok
20:53:42.0265 0780 BTHPORT (f338662a6c1fc11dd9508f6dff2c06a2) C:\WINDOWS\system32\Drivers\BTHport.sys
20:53:42.0265 0780 BTHPORT - ok
20:53:42.0281 0780 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
20:53:42.0281 0780 BTHUSB - ok
20:53:42.0281 0780 catchme - ok
20:53:42.0343 0780 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
20:53:42.0343 0780 cbidf2k - ok
20:53:42.0375 0780 cd20xrnt - ok
20:53:42.0437 0780 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
20:53:42.0437 0780 Cdaudio - ok
20:53:42.0500 0780 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
20:53:42.0500 0780 Cdfs - ok
20:53:42.0531 0780 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:53:42.0531 0780 Cdrom - ok
20:53:42.0531 0780 Changer - ok
20:53:42.0546 0780 CmdIde - ok
20:53:42.0562 0780 Cpqarray - ok
20:53:42.0562 0780 dac2w2k - ok
20:53:42.0578 0780 dac960nt - ok
20:53:42.0578 0780 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
20:53:42.0578 0780 Disk - ok
20:53:42.0625 0780 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
20:53:42.0687 0780 dmboot - ok
20:53:42.0703 0780 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
20:53:42.0703 0780 dmio - ok
20:53:42.0734 0780 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
20:53:42.0734 0780 dmload - ok
20:53:42.0750 0780 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
20:53:42.0750 0780 DMusic - ok
20:53:42.0765 0780 dpti2o - ok
20:53:42.0812 0780 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
20:53:42.0812 0780 drmkaud - ok
20:53:42.0890 0780 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
20:53:42.0890 0780 Fastfat - ok
20:53:42.0921 0780 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
20:53:42.0921 0780 Fdc - ok
20:53:42.0937 0780 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
20:53:42.0937 0780 Fips - ok
20:53:42.0937 0780 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
20:53:42.0937 0780 Flpydisk - ok
20:53:43.0015 0780 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
20:53:43.0015 0780 FltMgr - ok
20:53:43.0062 0780 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:53:43.0062 0780 Fs_Rec - ok
20:53:43.0109 0780 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:53:43.0125 0780 Ftdisk - ok
20:53:43.0140 0780 gdrv - ok
20:53:43.0156 0780 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:53:43.0156 0780 Gpc - ok
20:53:43.0218 0780 GVTDrv (689a8eef2a2d62b28a0a578a6196531c) C:\WINDOWS\system32\Drivers\GVTDrv.sys
20:53:43.0218 0780 GVTDrv - ok
20:53:43.0265 0780 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys
20:53:43.0265 0780 hamachi - ok
20:53:43.0312 0780 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:53:43.0312 0780 HDAudBus - ok
20:53:43.0343 0780 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:53:43.0343 0780 hidusb - ok
20:53:43.0359 0780 hpn - ok
20:53:43.0468 0780 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
20:53:43.0468 0780 HTTP - ok
20:53:43.0500 0780 hwdatacard - ok
20:53:43.0562 0780 i2omgmt - ok
20:53:43.0625 0780 i2omp - ok
20:53:43.0687 0780 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:53:43.0687 0780 i8042prt - ok
20:53:43.0718 0780 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
20:53:43.0718 0780 Imapi - ok
20:53:43.0750 0780 ini910u - ok
20:53:44.0000 0780 IntcAzAudAddService (8f45830f12a210fc581ae2bbc7e03925) C:\WINDOWS\system32\drivers\RtkHDAud.sys
20:53:44.0031 0780 IntcAzAudAddService - ok
20:53:44.0078 0780 IntelIde - ok
20:53:44.0140 0780 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:53:44.0140 0780 intelppm - ok
20:53:44.0171 0780 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
20:53:44.0171 0780 Ip6Fw - ok
20:53:44.0218 0780 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:53:44.0218 0780 IpFilterDriver - ok
20:53:44.0250 0780 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:53:44.0265 0780 IpInIp - ok
20:53:44.0296 0780 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:53:44.0296 0780 IpNat - ok
20:53:44.0328 0780 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:53:44.0328 0780 IPSec - ok
20:53:44.0359 0780 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
20:53:44.0359 0780 IRENUM - ok
20:53:44.0406 0780 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:53:44.0406 0780 isapnp - ok
20:53:44.0500 0780 ISODrive (bf71a06ff065e3fd7e32ea67dca34885) C:\Program Files\UltraISO\drivers\ISODrive.sys
20:53:44.0500 0780 ISODrive - ok
20:53:44.0562 0780 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:53:44.0562 0780 Kbdclass - ok
20:53:44.0625 0780 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:53:44.0625 0780 kbdhid - ok
20:53:44.0656 0780 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
20:53:44.0656 0780 kmixer - ok
20:53:44.0703 0780 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
20:53:44.0703 0780 KSecDD - ok
20:53:44.0750 0780 L8042mou (d6fc755ff505d99e6cc73e83492310df) C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
20:53:44.0750 0780 L8042mou - ok
20:53:44.0812 0780 LBeepKE (be2dc24d403643a2d1d98f33c7087b38) C:\WINDOWS\system32\Drivers\LBeepKE.sys
20:53:44.0812 0780 LBeepKE - ok
20:53:44.0828 0780 lbrtfdc - ok
20:53:44.0875 0780 LHidFilt (24e0ddb99aeccf86bb37702611761459) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
20:53:44.0875 0780 LHidFilt - ok
20:53:44.0906 0780 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
20:53:44.0906 0780 lirsgt - ok
20:53:44.0921 0780 LMouFilt (d58b330d318361a66a9fe60d7c9b4951) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
20:53:44.0921 0780 LMouFilt - ok
20:53:44.0968 0780 LMouKE (c149bdad13194df16ea33f9f601ed7bf) C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
20:53:44.0968 0780 LMouKE - ok
20:53:44.0968 0780 LUsbFilt (144011d14bd35f4e36136ae057b1aadd) C:\WINDOWS\system32\Drivers\LUsbFilt.Sys
20:53:44.0968 0780 LUsbFilt - ok
20:53:45.0015 0780 mbmiodrvr (290fb01f7f51eff0960599404a09f8d6) C:\WINDOWS\system32\mbmiodrvr.sys
20:53:45.0015 0780 mbmiodrvr - ok
20:53:45.0093 0780 MEI (cfcb18986426a2d8e66f1992636221d0) C:\WINDOWS\system32\DRIVERS\HECI.sys
20:53:45.0093 0780 MEI - ok
20:53:45.0140 0780 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
20:53:45.0140 0780 mnmdd - ok
20:53:45.0187 0780 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
20:53:45.0187 0780 Modem - ok
20:53:45.0265 0780 Monfilt (c7d9f9717916b34c1b00dd4834af485c) C:\WINDOWS\system32\drivers\Monfilt.sys
20:53:45.0312 0780 Monfilt - ok
20:53:45.0328 0780 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:53:45.0328 0780 Mouclass - ok
20:53:45.0375 0780 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:53:45.0375 0780 mouhid - ok
20:53:45.0421 0780 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
20:53:45.0421 0780 MountMgr - ok
20:53:45.0437 0780 mraid35x - ok
20:53:45.0468 0780 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:53:45.0468 0780 MRxDAV - ok
20:53:45.0546 0780 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:53:45.0546 0780 MRxSmb - ok
20:53:45.0609 0780 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
20:53:45.0609 0780 Msfs - ok
20:53:45.0640 0780 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:53:45.0640 0780 MSKSSRV - ok
20:53:45.0656 0780 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:53:45.0656 0780 MSPCLOCK - ok
20:53:45.0687 0780 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
20:53:45.0687 0780 MSPQM - ok
20:53:45.0765 0780 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:53:45.0781 0780 mssmbios - ok
20:53:45.0812 0780 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
20:53:45.0812 0780 Mup - ok
20:53:45.0890 0780 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
20:53:45.0890 0780 NDIS - ok
20:53:45.0953 0780 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:53:45.0953 0780 NdisTapi - ok
20:53:45.0984 0780 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:53:45.0984 0780 Ndisuio - ok
20:53:46.0015 0780 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:53:46.0015 0780 NdisWan - ok
20:53:46.0078 0780 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
20:53:46.0078 0780 NDProxy - ok
20:53:46.0109 0780 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
20:53:46.0109 0780 NetBIOS - ok
20:53:46.0140 0780 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
20:53:46.0140 0780 NetBT - ok
20:53:46.0171 0780 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
20:53:46.0171 0780 NIC1394 - ok
20:53:46.0234 0780 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\WINDOWS\system32\drivers\ccdcmb.sys
20:53:46.0250 0780 nmwcd - ok
20:53:46.0265 0780 nmwcdc (2914ceb789964141ac6e22c6bc980c42) C:\WINDOWS\system32\drivers\ccdcmbo.sys
20:53:46.0265 0780 nmwcdc - ok
20:53:46.0312 0780 nmwcdnsu (28d40797bcb050321fa6674b08a620c0) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
20:53:46.0312 0780 nmwcdnsu - ok
20:53:46.0343 0780 nmwcdnsuc (7804e9747bc27eddc6a8382bbf35cf25) C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
20:53:46.0343 0780 nmwcdnsuc - ok
20:53:46.0406 0780 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
20:53:46.0406 0780 Npfs - ok
20:53:46.0453 0780 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
20:53:46.0453 0780 Ntfs - ok
20:53:46.0500 0780 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
20:53:46.0500 0780 Null - ok
20:53:46.0640 0780 nv (59e5d945934ec2e7eaa22af81813dabf) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:53:46.0734 0780 nv - ok
20:53:46.0781 0780 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:53:46.0781 0780 NwlnkFlt - ok
20:53:46.0796 0780 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:53:46.0796 0780 NwlnkFwd - ok
20:53:46.0828 0780 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
20:53:46.0828 0780 ohci1394 - ok
20:53:46.0843 0780 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
20:53:46.0859 0780 Parport - ok
20:53:46.0875 0780 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
20:53:46.0875 0780 PartMgr - ok
20:53:46.0921 0780 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
20:53:46.0921 0780 ParVdm - ok
20:53:46.0984 0780 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
20:53:46.0984 0780 pccsmcfd - ok
20:53:47.0031 0780 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
20:53:47.0046 0780 PCI - ok
20:53:47.0062 0780 PCIDump - ok
20:53:47.0062 0780 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
20:53:47.0062 0780 PCIIde - ok
20:53:47.0171 0780 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
20:53:47.0171 0780 Pcmcia - ok
20:53:47.0218 0780 PDCOMP - ok
20:53:47.0218 0780 PDFRAME - ok
20:53:47.0281 0780 PDRELI - ok
20:53:47.0296 0780 PDRFRAME - ok
20:53:47.0359 0780 perc2 - ok
20:53:47.0406 0780 perc2hib - ok
20:53:47.0468 0780 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:53:47.0468 0780 PptpMiniport - ok
20:53:47.0500 0780 Processor (7eb15dce4ec3a0220bd796a15c18186e) C:\WINDOWS\system32\DRIVERS\processr.sys
20:53:47.0500 0780 Processor - ok
20:53:47.0546 0780 prodrv06 (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys
20:53:47.0546 0780 prodrv06 - ok
20:53:47.0593 0780 prohlp02 (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys
20:53:47.0593 0780 prohlp02 - ok
20:53:47.0625 0780 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
20:53:47.0625 0780 prosync1 - ok
20:53:47.0625 0780 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
20:53:47.0625 0780 PSched - ok
20:53:47.0656 0780 psdrv02 (453697810a576c04e48b70e84f500313) C:\WINDOWS\system32\drivers\psdrv02.sys
20:53:47.0656 0780 psdrv02 - ok
20:53:47.0703 0780 pssync05 (a03a57d7e681a712f5500a8fe8ccf83b) C:\WINDOWS\system32\drivers\pssync05.sys
20:53:47.0703 0780 pssync05 - ok
20:53:47.0765 0780 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:53:47.0765 0780 Ptilink - ok
20:53:47.0812 0780 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
20:53:47.0812 0780 PxHelp20 - ok
20:53:47.0843 0780 ql1080 - ok
20:53:47.0843 0780 Ql10wnt - ok
20:53:47.0890 0780 ql12160 - ok
20:53:47.0953 0780 ql1240 - ok
20:53:47.0968 0780 ql1280 - ok
20:53:48.0015 0780 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:53:48.0015 0780 RasAcd - ok
20:53:48.0078 0780 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:53:48.0078 0780 Rasl2tp - ok
20:53:48.0093 0780 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:53:48.0093 0780 RasPppoe - ok
20:53:48.0125 0780 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
20:53:48.0125 0780 Raspti - ok
20:53:48.0156 0780 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:53:48.0156 0780 Rdbss - ok
20:53:48.0234 0780 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:53:48.0234 0780 RDPCDD - ok
20:53:48.0296 0780 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
20:53:48.0296 0780 RDPWD - ok
20:53:48.0359 0780 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
20:53:48.0359 0780 redbook - ok
20:53:48.0406 0780 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
20:53:48.0421 0780 RFCOMM - ok
20:53:48.0468 0780 RTL8023xp (a8dd3687627737b0f4e34c300c121dfb) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
20:53:48.0468 0780 RTL8023xp - ok
20:53:48.0531 0780 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
20:53:48.0531 0780 rtl8139 - ok
20:53:48.0578 0780 RTLE8023xp (6fd9c99f0b8617122ae27392ab1b3059) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
20:53:48.0578 0780 RTLE8023xp - ok
20:53:48.0640 0780 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:53:48.0640 0780 Secdrv - ok
20:53:48.0671 0780 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
20:53:48.0671 0780 serenum - ok
20:53:48.0703 0780 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
20:53:48.0703 0780 Serial - ok
20:53:48.0781 0780 sfdrv01 (58235f4483b63ff33b0fc41c1cd624c5) C:\WINDOWS\system32\drivers\sfdrv01.sys
20:53:48.0781 0780 sfdrv01 - ok
20:53:48.0812 0780 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
20:53:48.0812 0780 sfhlp01 - ok
20:53:48.0828 0780 sfhlp02 (e58bfc561f3d1d9c79b61a151c208c78) C:\WINDOWS\system32\drivers\sfhlp02.sys
20:53:48.0828 0780 sfhlp02 - ok
20:53:48.0906 0780 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
20:53:48.0906 0780 Sfloppy - ok
20:53:48.0953 0780 sfsync02 (798d918d8f20380008277ce3ce5319d1) C:\WINDOWS\system32\drivers\sfsync02.sys
20:53:48.0953 0780 sfsync02 - ok
20:53:49.0031 0780 sfsync04 (8451848f85453c24a8f91ac8d9dfa77f) C:\WINDOWS\system32\drivers\sfsync04.sys
20:53:49.0031 0780 sfsync04 - ok
20:53:49.0062 0780 Simbad - ok
20:53:49.0140 0780 smserial (3eac7455b7352cf5cda6e0772f6bd5b1) C:\WINDOWS\system32\DRIVERS\smserial.sys
20:53:49.0187 0780 smserial - ok
20:53:49.0218 0780 Sparrow - ok
20:53:49.0265 0780 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
20:53:49.0265 0780 splitter - ok
20:53:49.0328 0780 sptd (4e3c4ffcb2c95c2ec1fa04a6f4531533) C:\WINDOWS\system32\Drivers\sptd.sys
20:53:49.0328 0780 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 4e3c4ffcb2c95c2ec1fa04a6f4531533
20:53:49.0328 0780 sptd ( LockedFile.Multi.Generic ) - warning
20:53:49.0328 0780 sptd - detected LockedFile.Multi.Generic (1)
20:53:49.0375 0780 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
20:53:49.0375 0780 sr - ok
20:53:49.0453 0780 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
20:53:49.0453 0780 Srv - ok
20:53:49.0500 0780 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
20:53:49.0500 0780 swenum - ok
20:53:49.0531 0780 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
20:53:49.0531 0780 swmidi - ok
20:53:49.0562 0780 symc810 - ok
20:53:49.0625 0780 symc8xx - ok
20:53:49.0671 0780 sym_hi - ok
20:53:49.0734 0780 sym_u3 - ok
20:53:49.0812 0780 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
20:53:49.0812 0780 sysaudio - ok
20:53:49.0875 0780 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:53:49.0875 0780 Tcpip - ok
20:53:49.0890 0780 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
20:53:49.0890 0780 TDPIPE - ok
20:53:49.0937 0780 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
20:53:49.0937 0780 TDTCP - ok
20:53:49.0953 0780 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
20:53:49.0953 0780 TermDD - ok
20:53:49.0984 0780 TosIde - ok
20:53:50.0046 0780 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
20:53:50.0046 0780 Udfs - ok
20:53:50.0046 0780 ultra - ok
20:53:50.0125 0780 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
20:53:50.0125 0780 Update - ok
20:53:50.0171 0780 upperdev (e526a166e6acafd0a9b3841d3941669e) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
20:53:50.0171 0780 upperdev - ok
20:53:50.0187 0780 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:53:50.0187 0780 usbccgp - ok
20:53:50.0250 0780 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:53:50.0250 0780 usbehci - ok
20:53:50.0281 0780 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:53:50.0281 0780 usbhub - ok
20:53:50.0328 0780 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
20:53:50.0328 0780 usbohci - ok
20:53:50.0375 0780 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
20:53:50.0375 0780 usbprint - ok
20:53:50.0406 0780 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:53:50.0406 0780 usbscan - ok
20:53:50.0421 0780 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys
20:53:50.0421 0780 usbser - ok
20:53:50.0468 0780 UsbserFilt (6f3e3c6811b930d2414552a2e4a40f36) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
20:53:50.0468 0780 UsbserFilt - ok
20:53:50.0500 0780 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:53:50.0500 0780 usbstor - ok
20:53:50.0531 0780 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
20:53:50.0531 0780 VgaSave - ok
20:53:50.0562 0780 ViaIde - ok
20:53:50.0609 0780 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
20:53:50.0609 0780 VolSnap - ok
20:53:50.0640 0780 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:53:50.0640 0780 Wanarp - ok
20:53:50.0703 0780 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
20:53:50.0703 0780 Wdf01000 - ok
20:53:50.0750 0780 WDICA - ok
20:53:50.0796 0780 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
20:53:50.0812 0780 wdmaud - ok
20:53:50.0921 0780 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
20:53:50.0921 0780 WpdUsb - ok
20:53:50.0968 0780 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:53:50.0968 0780 WS2IFSL - ok
20:53:51.0046 0780 WudfPf (eaa6324f51214d2f6718977ec9ce0def) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:53:51.0046 0780 WudfPf - ok
20:53:51.0078 0780 WudfRd (f91ff1e51fca30b3c3981db7d5924252) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:53:51.0078 0780 WudfRd - ok
20:53:51.0125 0780 MBR (0x1B8) (3dfbd33517922022aab2367021b4bbec) \Device\Harddisk0\DR0
20:53:51.0140 0780 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected
20:53:51.0140 0780 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a (0)
20:53:51.0140 0780 Boot (0x1200) (ea8aabe853dec96d8d545d22a5a9ff1c) \Device\Harddisk0\DR0\Partition0
20:53:51.0140 0780 \Device\Harddisk0\DR0\Partition0 - ok
20:53:51.0140 0780 ============================================================
20:53:51.0140 0780 Scan finished
20:53:51.0140 0780 ============================================================
20:53:51.0156 3772 Detected object count: 2
20:53:51.0156 3772 Actual detected object count: 2
20:54:09.0296 3772 sptd ( LockedFile.Multi.Generic ) - skipped by user
20:54:09.0296 3772 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
20:54:09.0562 3772 \Device\Harddisk0\DR0\# - copied to quarantine
20:54:09.0578 3772 \Device\Harddisk0\DR0 - copied to quarantine
20:54:09.0578 3772 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - will be cured on reboot
20:54:09.0578 3772 \Device\Harddisk0\DR0 - ok
20:54:09.0578 3772 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - User select action: Cure
20:54:17.0781 3232 Deinitialize success

Reklama
Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Žbeky » 14 bře 2012 21:51

Snad je ten šmejd pryč

Stáhni si MBR Rootkit Detektor
- ulož si ho přímo na disk C a spusť ho
- za chvíli se ti vytvoří jeho log (mbr.log) vlož sem celý jeho obsah.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
Mefisto
Level 3
Level 3
Příspěvky: 410
Registrován: duben 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Mefisto » 14 bře 2012 22:22

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3320820AS rev.3.AAC -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK













a co to teda bylo? a můžu teď znova nainstalovat avast?

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Žbeky » 14 bře 2012 22:33

Byl tam i rootkit
20:53:51.0140 0780 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected
20:53:51.0140 0780 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a (0)

Smaž C:\avast! sandbox

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

vyčisti systém CCleanerem

a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj AVG , Avast,Avira či Microsoft Security Essentials následně T-Cleaner smaž a zapni si AVG , Avast, Avira či Microsoft Security Essentials

+ Nový log z HJT

Jak se chová PC? Zkus znova ten avast
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
Mefisto
Level 3
Level 3
Příspěvky: 410
Registrován: duben 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Mefisto » 14 bře 2012 22:44

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:43:08, on 14.3.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe
C:\Program Files\Nokia\Nokia Software Updater 3\nsu3ui_agent.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\GamePark2\gpcl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [DivX Download Manager] "C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe" start
O4 - HKLM\..\Run: [NSU_agent] "C:\Program Files\Nokia\Nokia Software Updater 3\nsu3ui_agent.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IMSS] "C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: GamePark klient 2.lnk = C:\Program Files\GamePark2\gpcl.exe
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{48C3E7D4-42F5-491A-9FF0-BDC622AFD4C2}: NameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{645A233A-9386-4466-8F2B-A73774C6CB09}: NameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{B24B0124-61EE-4332-84B3-732C45BE057C}: NameServer = 8.8.8.8
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

--
End of file - 8067 bytes






pc se chová normálně a v pořádku, stejně tak i předtim až na ty pády, teď už tu končím tak uvidíme zítra,
zatím vám děkuji za pomoc

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod jaro3 » 14 bře 2012 23:23

Dej vědět , myslím , že nákazy jsou už pryč..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Mefisto
Level 3
Level 3
Příspěvky: 410
Registrován: duben 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Mefisto » 15 bře 2012 15:00

tak to tu zatím nebudu dávat jako vyřešené kdyby se objevil další pád a děkuji moc

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod jaro3 » 15 bře 2012 16:00

Nemáš zač!

Pak napiš.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Mefisto
Level 3
Level 3
Příspěvky: 410
Registrován: duben 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Mefisto » 15 bře 2012 18:34

vypadá to že co se týče pádů tak vyřešeno, je tu ale nový problém ale ne tak závažný, jedna ze stránek se mi zobrazuje takhle(obrázek v příloze)
a chvíli se mi tak ukazoval i pc-help, tam ale pomohlo aktualizovat .. to u eurofotbalu nepomáhá, a je to takhle od těch včerejších čistek co jsem prováděl
Přílohy
eurofotbal.JPG

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod jaro3 » 15 bře 2012 20:10

CCleaner---zkontroluj zatržení cookies ve všech prohlížečích a pak vyčisti.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Mefisto
Level 3
Level 3
Příspěvky: 410
Registrován: duben 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod Mefisto » 15 bře 2012 20:19

nepomohlo to, zkusil jsem i stáhnout nejnovější verzi ccleaneru a taky nic

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - modra obrazovka

Příspěvekod jaro3 » 15 bře 2012 20:21

měl si všude zaškrtlý cookies?

Jak tio vypadá na jiných stránkách?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 84 hostů