Právě je 25 kvě 2013 23:56

Všechny časy jsou v UTC + 1 hodina


Pravidla fóra


Pokud chcete pomoc, vložte log z RSIT dle tohoto návodu

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.



Odeslat nové téma Odpovědět na téma  [ Příspěvků: 14 ] 
Autor Zpráva
 Předmět příspěvku: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 10:57 
Offline
Vzorný návštěvník
Vzorný návštěvník

Registrován: 02 srp 2006 20:32
Příspěvky: 49
Tato "modrá smrt" se mi objevuje už asi 2 týdny. Dnes se mi navíc nechce spustit Eset smart, respektive se spustí, ale hlásí, že nenašel virový skener. Díky za pomoc.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:57:11, on 5.7.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
F:\CdiskNemazat\Program Files\PeerGuardian2\pg2.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\system32\cidaemon.exe
F:\CdiskNemazat\Program Files\Maxthon\Maxthon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: :-)mojelogo SMS ToolBar - {CFBC2741-0C1F-11D6-9224-004F490BED09} - F:\CdiskNemazat\Program Files\SMS toolbar\SMS ToolBar\smsbar.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] F:\CdiskNemazat\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1123561945-1844823847-682003330-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'eMule_Secure')
O4 - HKUS\S-1-5-21-1123561945-1844823847-682003330-1004\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (User 'eMule_Secure')
O4 - HKUS\S-1-5-21-1123561945-1844823847-682003330-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: &Stáhnout všechno FlashGetem - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Přizpůsobit Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: RF Nástrojová lišta - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Uložit formuláře - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Vyplnit formulář - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Vyplnit formulář - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Vyplnit formulář - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Uložit - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Uložit formuláře - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF Nástrojová lišta - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{7D372C08-FCA4-41CB-9229-D0A26DDBDAA9}: NameServer = 217.168.208.20,217.168.208.21
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 8250 bytes

_________________
Obrázek


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 11:21 
Offline
Rádce
Rádce
Uživatelský avatar

Registrován: 13 úno 2007 14:20
Příspěvky: 13488
Ahoj,

zkus sem hodit log utlity kterou najdes na edisku http://www.edisk.cz/stahni/12823/sreng9 ... .99KB.html rozbalte, zmente cas systemu v try liste o mesic nazpet, nyni dany program spuste - odklepnete pripadna hlaseni a udelejte:

- zvolte "zvol Smart Scan", nechte nastaveni tak jak je
- zvolte "Verify the digital signature of process modules"
- klik na "Scan"
- klik na Save Reports, ulozte log na plochu a cely obsah logu zkopirujte sem

_________________
?


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 11:32 
Offline
Vzorný návštěvník
Vzorný návštěvník

Registrován: 02 srp 2006 20:32
Příspěvky: 49
Bohužel se mi objeví toto:

Tento soubor již neexistuje z následujích důvodů:

soubor byl smazán majitelem
vypršela doba, po kterou může být soubor nahrán
soubor byl v rozporu s podmínkami užití podmínkami užití.

_________________
Obrázek


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 11:48 
Offline
Rádce
Rádce
Uživatelský avatar

Registrován: 13 úno 2007 14:20
Příspěvky: 13488
promin - nez jsem ti postl odkaz, jeste jsem ho kontroloval.

zde novy http://www.edisk.cz/stahni/42523/utilit ... .99KB.html

_________________
?


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 11:58 
Offline
Vzorný návštěvník
Vzorný návštěvník

Registrován: 02 srp 2006 20:32
Příspěvky: 49
Kód:

2008-06-05,12:56:28

System Repair Engineer 2.6.8.980
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <PeerGuardian><F:\CdiskNemazat\Program Files\PeerGuardian2\pg2.exe>  [Methlabs]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <CTStartup><C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run>  [Creative Technology Ltd.]
    <LVCOMSX><C:\WINDOWS\system32\LVCOMSX.EXE>  [Logitech Inc.]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  []
    <SpywareTerminator><"C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe">  [Crawler.com]
    <egui><"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice>  [(Verified)"ESET, spol. s r.o."]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <Adresář 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path]
    <IFEO[Your Image File Name Here without a path]><ntsd -d>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <CamWizard><; C:\Program Files\Common Files\Logitech\QCDRV\BIN\CamWizrd.exe>  [Logitech Inc.]
    <Jet Detection><; C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe>  []
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <RaidTool><; C:\Program Files\VIA\RAID\raid_tool.exe>  [VIA Technologies]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]

==================================
Startup Folders
[APC UPS Status]
  <C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\APC UPS Status.lnk --> C:\PROGRA~1\APC\APCPOW~1\Display.exe [American Power Conversion Corporation]><N>

==================================
Services
[APC UPS Service / APC UPS Service][Running/Auto Start]
  <C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe><American Power Conversion Corporation>
[Eset HTTP Server / EhttpSrv][Stopped/Manual Start]
  <"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
  <"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"><ESET>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[NMIndexingService / NMIndexingService][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe"><Nero AG>
[NVIDIA Display Driver Service / NVSvc][Stopped/Disabled]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Cyberlink RichVideo Service(CRVS) / RichVideo][Running/Auto Start]
  <"C:\Program Files\CyberLink\Shared files\RichVideo.exe"><>
[Spyware Terminator Realtime Shield Service / sp_rssrv][Running/Auto Start]
  <"C:\Program Files\Spyware Terminator\sp_rsser.exe"><Crawler.com>

==================================
Drivers
[BrPar / BrPar][Running/Auto Start]
  <\SystemRoot\System32\drivers\BrPar.sys><Brother Industries Ltd.>
[CO_Mon / CO_Mon][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\Drivers\CO_Mon.sys><N/A>
[Creative AC3 Software Decoder / ctac32k][Running/Manual Start]
  <System32\drivers\ctac32k.sys><Creative Technology Ltd>
[Creative Proxy Driver / ctprxy2k][Running/Manual Start]
  <System32\drivers\ctprxy2k.sys><Creative Technology Ltd>
[Creative SoundFont Management Device Driver / ctsfm2k][Running/Manual Start]
  <System32\drivers\ctsfm2k.sys><Creative Technology Ltd>
[Cisco Systems VPN Adapter / CVirtA][Stopped/Manual Start]
  <system32\DRIVERS\CVirtA.sys><Cisco Systems, Inc.>
[eamon / eamon][Running/Auto Start]
  <system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
  <system32\DRIVERS\easdrv.sys><ESET>
[ElbyCDFL / ElbyCDFL][Running/Manual Start]
  <System32\Drivers\ElbyCDFL.sys><SlySoft, Inc.>
[ElbyCDIO Driver / ElbyCDIO][Running/Auto Start]
  <System32\Drivers\ElbyCDIO.sys><Elaborate Bytes AG>
[ElbyDelay / ElbyDelay][Running/Manual Start]
  <System32\Drivers\ElbyDelay.sys><Elaborate Bytes AG>
[Creative EMU10K1/EMU10K2 Audio Driver (WDM) / emu10kx][Running/Manual Start]
  <system32\drivers\e10kx2k.sys><Creative Technology Ltd>
[E-mu Plug-in Architecture Driver / emupia][Running/Manual Start]
  <System32\drivers\emupia2k.sys><Creative Technology Ltd>
[epfw / epfw][Running/Auto Start]
  <system32\DRIVERS\epfw.sys><ESET>
[Eset Personal Firewall / Epfwndis][Running/Manual Start]
  <system32\DRIVERS\Epfwndis.sys><ESET>
[epfwtdi / epfwtdi][Running/System Start]
  <system32\DRIVERS\epfwtdi.sys><ESET>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[SEMC USB Flash Driver Filter / ggflt][Stopped/Manual Start]
  <system32\DRIVERS\ggflt.sys><Sony Ericsson Mobile Communications>
[SEMC USB Flash Driver / ggsemc][Stopped/Manual Start]
  <system32\DRIVERS\ggsemc.sys><Sony Ericsson Mobile Communications>
[Sony Ericsson 750 driver (WDM) / k750bus][Stopped/Manual Start]
  <system32\DRIVERS\k750bus.sys><MCCI>
[Sony Ericsson 750 USB WMC Modem Filter / k750mdfl][Stopped/Manual Start]
  <system32\DRIVERS\k750mdfl.sys><MCCI>
[Sony Ericsson 750 USB WMC Modem Drivers / k750mdm][Stopped/Manual Start]
  <system32\DRIVERS\k750mdm.sys><MCCI>
[Sony Ericsson 750 USB WMC Device Management Drivers / k750mgmt][Stopped/Manual Start]
  <system32\DRIVERS\k750mgmt.sys><MCCI>
[Sony Ericsson 750 USB WMC OBEX Interface Drivers / k750obex][Stopped/Manual Start]
  <system32\DRIVERS\k750obex.sys><MCCI>
[Logitech USB Monitor Filter / LVUSBSta][Running/Manual Start]
  <system32\drivers\lvusbsta.sys><Logitech Inc.>
[Pinnacle Marvin Bus / MarvinBus][Running/Manual Start]
  <system32\DRIVERS\MarvinBus.sys><Pinnacle Systems GmbH>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Creative OS Services Driver / ossrv][Running/Manual Start]
  <system32\drivers\ctoss2k.sys><Creative Technology Ltd.>
[PCLEPCI / PCLEPCI][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\pclepci.sys><Pinnacle Systems GmbH>
[VSO Software pcouffin / Pcouffin][Running/Manual Start]
  <System32\Drivers\Pcouffin.sys><VSO Software>
[Volume Adapter / pepifilter][Stopped/Manual Start]
  <system32\DRIVERS\lv302af.sys><Logitech Inc.>
[Padus ASPI Shell / pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[PfModNT / PfModNT][Running/Auto Start]
  <\??\C:\WINDOWS\system32\PfModNT.sys><Creative Technology Ltd.>
[QuickCam IM(PID_08A0) / PID_08A0][Running/Manual Start]
  <system32\DRIVERS\LV302AV.SYS><Logitech Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[Prolific Serial port driver / Ser2pl][Stopped/Manual Start]
  <system32\DRIVERS\ser2pl.sys><Prolific Technology Inc.>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Spyware Terminator Driver 2 / sp_rsdrv2][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys><>
[VPN Anonymizer Adapter / tap0901_2gm][Stopped/Manual Start]
  <system32\DRIVERS\tap0901_2gm.sys><The OpenVPN Project>
[viamraid / viamraid][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[viasraid / viasraid][Running/Boot Start]
  <\SystemRoot\system32\drivers\viasraid.sys><VIA Technologies inc,.ltd>
[Wdf01000 / Wdf01000][Stopped/Manual Start]
  <system32\DRIVERS\Wdf01000.sys><Microsoft Corporation>
[{95808DC4-FA4A-4c74-92FE-5B863F82066B} / {95808DC4-FA4A-4c74-92FE-5B863F82066B}][Running/Auto Start]
  <\??\C:\Program Files\CyberLink\PowerDVD\000.fcl><Cyberlink Corp.>
[pgfilter / pgfilter][Running/Manual Start]
  <\??\F:\CdiskNemazat\Program Files\PeerGuardian2\pgfilter.sys><N/A>

==================================
Browser Add-ons
[Podpora odkazu pro Adobe PDF Reader]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[WebTransBHO Class]
  {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} <C:\WINDOWS\WebIE.dll, >
[RealPlayer Download and Record Plugin for Internet Explorer]
  {3049C3E9-B461-4BC5-8870-4C09146192CA} <C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll, RealPlayer>
[]
  {724d43a9-0d85-11d4-9908-00400523e39a} <C:\Program Files\Siber Systems\AI RoboForm\roboform.dll, Siber Systems>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_03]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[Vyplnit formulář]
  {320AF880-6646-11D3-ABEE-C5DBF3571F46} <, N/A>
[Uložit]
  {320AF880-6646-11D3-ABEE-C5DBF3571F49} <, N/A>
[RoboForm]
  {724d43aa-0d85-11d4-9908-00400523e39a} <, N/A>
[ToolBarButton Class]
  {7E6A20FB-153F-402c-A84B-1A64E1955D3D} <C:\WINDOWS\WebIE.dll, >
[MenuItem4 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748449} <C:\WINDOWS\WebIE.dll, >
[MenuItem4 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748450} <C:\WINDOWS\WebIE.dll, >
[MenuItem2 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748451} <C:\WINDOWS\WebIE.dll, >
[MenuItem1 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748452} <C:\WINDOWS\WebIE.dll, >
[:-)mojelogo SMS ToolBar]
  {CFBC2741-0C1F-11D6-9224-004F490BED09} <F:\CdiskNemazat\Program Files\SMS toolbar\SMS ToolBar\smsbar.dll, Axima spol. s r.o., www.axima-brno.cz>
[&RoboForm]
  {724d43a0-0d85-11d4-9908-00400523e39a} <C:\Program Files\Siber Systems\AI RoboForm\roboform.dll, Siber Systems>
[WebTranslator]
  {BFC32E1D-EE75-4A48-BC60-104E11EE2431} <C:\WINDOWS\WebIE.dll, >
[FlashGet]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <F:\CdiskNemazat\Program Files\QuickTime Alternative\QTSystem\QTPlugin.ocx, Apple Computer, Inc.>
[Podpora odkazu pro Adobe PDF Reader]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[InformationCardSigninHelper Class]
  {19916E01-B44E-4E31-94A4-4696DF46157B} <C:\WINDOWS\system32\icardie.dll, Microsoft Corporation>
[Shockwave ActiveX Control]
  {233C1507-6A77-46A4-9443-F871F945D258} <C:\WINDOWS\system32\Macromed\Director\SwDir.dll, Adobe Systems, Inc.>
[XML DOM Document]
  {2933BF90-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XSL Template]
  {2933BF94-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[WebTransBHO Class]
  {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} <C:\WINDOWS\WebIE.dll, >
[RealPlayer Download and Record Plugin for Internet Explorer]
  {3049C3E9-B461-4BC5-8870-4C09146192CA} <C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll, RealPlayer>
[HtmlDlgSafeHelper Class]
  {3050F819-98B5-11CF-BB82-00AA00BDCE0B} <C:\WINDOWS\system32\mshtmled.dll, Microsoft Corporation>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[XML Schema Cache]
  {373984C9-B845-449B-91E7-45AC83036ADE} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[QuickTime Object]
  {4063BE15-3B08-470D-A0D5-B37161CFFD69} <F:\CdiskNemazat\Program Files\QuickTime Alternative\QTSystem\QTPlugin.ocx, Apple Computer, Inc.>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Microsoft Shell UI Helper]
  {64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[&RoboForm]
  {724D43A0-0D85-11D4-9908-00400523E39A} <C:\Program Files\Siber Systems\AI RoboForm\roboform.dll, Siber Systems>
[]
  {724D43A9-0D85-11D4-9908-00400523E39A} <C:\Program Files\Siber Systems\AI RoboForm\roboform.dll, Siber Systems>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[ToolBarButton Class]
  {7E6A20FB-153F-402C-A84B-1A64E1955D3D} <C:\WINDOWS\WebIE.dll, >
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[XML DOM Document 4.0]
  {88D969C0-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[Free Threaded XML DOM Document 4.0]
  {88D969C1-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XML Schema Cache 4.0]
  {88D969C2-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XSL Template 4.0]
  {88D969C3-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XML Data Source Object 4.0]
  {88D969C4-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XML HTTP 4.0]
  {88D969C5-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XML DOM Document 6.0]
  {88D96A05-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, Microsoft Corporation>
[Free Threaded XML DOM Document 6.0]
  {88D96A06-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, Microsoft Corporation>
[XML Schema Cache 6.0]
  {88D96A07-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, Microsoft Corporation>
[XSL Template 6.0]
  {88D96A08-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, Microsoft Corporation>
[XML HTTP 6.0]
  {88D96A0A-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, Microsoft Corporation>
[Java Plug-in 1.6.0_03]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[WebTranslator]
  {BFC32E1D-EE75-4A48-BC60-104E11EE2431} <C:\WINDOWS\WebIE.dll, >
[Adobe PDF Reader]
  {CA8A9780-280D-11CF-A24D-444553540000} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll, Adobe Systems, Inc.>
[Java Plug-in 1.6.0_03]
  {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[MenuItem3 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748449} <C:\WINDOWS\WebIE.dll, >
[MenuItem4 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748450} <C:\WINDOWS\WebIE.dll, >
[MenuItem2 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748451} <C:\WINDOWS\WebIE.dll, >
[MenuItem1 Class]
  {CC963627-B1DC-40E0-B52A-CF21EE748452} <C:\WINDOWS\WebIE.dll, >
[:-)mojelogo SMS ToolBar]
  {CFBC2741-0C1F-11D6-9224-004F490BED09} <F:\CdiskNemazat\Program Files\SMS toolbar\SMS ToolBar\smsbar.dll, Axima spol. s r.o., www.axima-brno.cz>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
[FlashGet]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[Scripting.Dictionary]
  {EE09B103-97E0-11CF-978F-00A02463E06F} <C:\WINDOWS\system32\SCRRUN.DLL, Microsoft Corporation>
[XML DOM Document 3.0]
  {F5078F32-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[Free Threaded XML DOM Document 3.0]
  {F5078F33-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML Schema Cache 3.0]
  {F5078F34-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML HTTP 3.0]
  {F5078F35-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XSL Template 3.0]
  {F5078F36-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML Data Source Object 3.0]
  {F5078F39-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[Free Threaded XML DOM Document]
  {F6D90F12-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML Data Source Object]
  {F6D90F14-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[&Stáhnout všechno FlashGetem]
  <C:\PROGRA~1\FlashGet\jc_all.htm, N/A>
[E&xportovat do aplikace Microsoft Office Excel]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[Přizpůsobit Menu]
  <file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html, N/A>
[RF Nástrojová lišta]
  <file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html, N/A>
[Uložit formuláře]
  <file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html, N/A>
[Vyplnit formulář]
  <file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html, N/A>

==================================
Running Processes
[PID: 872 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1040 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1064 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1112 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1124 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1272 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1340 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1500 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1948 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 140 / gorman][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\BROWSEUI.dll]  [Společnost Microsoft, 6.00.2900.3020 (xpsp.061023-0222)]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 8.0.0.0]
[PID: 348 / gorman][C:\WINDOWS\system32\LVCOMSX.EXE]  [Logitech Inc., 8.4.1.1092]
    [C:\WINDOWS\system32\lvmaenum.dll]  [Logitech Inc., 8.4.1.1092]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
[PID: 372 / gorman][C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe]  [Crawler.com, 2.2.1.347]
[PID: 384 / gorman][C:\Program Files\ESET\ESET Smart Security\egui.exe]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiScan.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll]  [ESET, 3.0.667 ]
[PID: 428 / gorman][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 440 / SYSTEM][C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\drvutil.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\UpsDevice.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\pdcdll.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\UpsControl.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\res.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
[PID: 464 / gorman][F:\CdiskNemazat\Program Files\PeerGuardian2\pg2.exe]  [Methlabs, 1, 0, 6, 4]
[PID: 600 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 644 / SYSTEM][C:\WINDOWS\system32\cisvc.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 676 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\ekrn.exe]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\updater.dll]  [ESET, 3.0.667 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll]  [ESET, 3.0.667 ]
[PID: 548 / gorman][C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\UpsControl.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\UpsDevice.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\pdcdll.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
    [C:\Program Files\APC\APC PowerChute Personal Edition\res.dll]  [American Power Conversion Corporation, 2, 0, 0, 0]
[PID: 876 / SYSTEM][C:\Program Files\CyberLink\Shared files\RichVideo.exe]  [, 1.1.0808  ]
[PID: 1720 / SYSTEM][C:\Program Files\Spyware Terminator\sp_rsser.exe]  [Crawler.com, 2.2.1.365]
[PID: 1880 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1900 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1528 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 204 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3240 / SYSTEM][C:\WINDOWS\system32\cidaemon.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Adobe\Reader 8.0\Reader\bibutils.dll]  [Adobe Systems Incorporated, 1.1.01]
    [C:\Program Files\Adobe\Reader 8.0\Reader\jp2klib.dll]  [Adobe systems Incorporated, 44.0.219.0]
    [C:\Program Files\Adobe\Reader 8.0\Reader\adobexmp.dll]  [, 4.0-c316]
[PID: 2908 / gorman][F:\CdiskNemazat\Program Files\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 6, 3, 80]
    [F:\CdiskNemazat\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [C:\WINDOWS\system32\browseui.dll]  [Společnost Microsoft, 6.00.2900.3020 (xpsp.061023-0222)]
    [F:\CdiskNemazat\Program Files\SMS toolbar\SMS ToolBar\smsbar.dll]  [Axima spol. s r.o., www.axima-brno.cz, 4.3.3.5]
    [C:\Program Files\Siber Systems\AI RoboForm\roboform.dll]  [Siber Systems, 6-6-6]
    [F:\CdiskNemazat\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
[PID: 540 / gorman][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\BROWSEUI.dll]  [Společnost Microsoft, 6.00.2900.3020 (xpsp.061023-0222)]
    [F:\CdiskNemazat\Program Files\SMS toolbar\SMS ToolBar\smsbar.dll]  [Axima spol. s r.o., www.axima-brno.cz, 4.3.3.5]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 8.0.0.2006102200]
    [C:\WINDOWS\WebIE.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Siber Systems\AI RoboForm\roboform.dll]  [Siber Systems, 6-6-6]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 8.0.0.0]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.11.6218]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [F:\CdiskNemazat\Program Files\rar\rarext.dll]  [N/A, ]
    [F:\CdiskNemazat\Program Files\rar\rarlng.dll]  [N/A, ]
    [C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrgui.dll]  [Sony Ericsson Mobile Communications AB, 1, 3, 11, 0]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.6030.0]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrguil.dll]  [Sony Ericsson Mobile Communications AB, 1, 3, 4, 0]
    [C:\PROGRA~1\SPYWAR~1\sptcontmenu.dll]  [Crawler.com, 1.1.0.15]
    [C:\Program Files\ESET\ESET Smart Security\shellExt.dll]  [ESET, 3.0.667 ]
[PID: 1184 / gorman][F:\a data\Downloads\software\disk\edisk\SREngLdr.EXE]  [Smallfrogs Studio, 2.6.8.980]
[PID: 1856 / gorman][F:\a data\Downloads\software\disk\edisk\SRE44cc070b.EXE]  [Smallfrogs Studio, 2.6.8.980]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   Error. []
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1 localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 348, C:\WINDOWS\SYSTEM32\LVCOMSX.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 440, C:\PROGRAM FILES\APC\APC POWERCHUTE PERSONAL EDITION\MAINSERV.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 548, C:\PROGRAM FILES\APC\APC POWERCHUTE PERSONAL EDITION\APCSYSTRAY.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1720, C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2908, F:\CDISKNEMAZAT\PROGRAM FILES\MAXTHON\MAXTHON.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1184, F:\A DATA\DOWNLOADS\SOFTWARE\DISK\EDISK\SRENGLDR.EXE]

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================



_________________
Obrázek


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 12:26 
Offline
Rádce
Rádce
Uživatelský avatar

Registrován: 13 úno 2007 14:20
Příspěvky: 13488
V logu nic nebezpecneho neni primo videt (pokud sem prehledl prosim o napsani od vsimavejsich oci).

:arrow: Otestuj na http://www.virustotal.com soubor C:\WINDOWS\system32\Drivers\CO_Mon.sys vysledek mi nahlas.

:arrow: predpokladaz, ze mas naistalovan winrar jen pod jinou cestou viz F:\CdiskNemazat\Program Files\rar\rarext.dll Pokud ne, informuj.

:arrow: Jeste jsi stahni ComboFix s nasledujici adresy http://download.bleepingcomputer.com/sUBs/ComboFix.exe , uloz na plochu, spust, pak pokracuj dle instrukci. Log v podobe textoveho souboru se ti otevre sam, pripade potizi ho najdes na C:\ComboFix.txt - jeho obsah mi sem zkopci.

:arrow: stahni mbr z http://www2.gmer.net/mbr/mbr.exe , spust ho, log s nazvem mbr.txt v miste spusteni programu mi opet zkopiruj

:arrow: Nepamatujes jsi, jest-li jsi pred chybovou hlaskou neco instaloval, ci menil nejak konfiguraci PC?

_________________
?


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 12:45 
Offline
Vzorný návštěvník
Vzorný návštěvník

Registrován: 02 srp 2006 20:32
Příspěvky: 49
Antivirus Verze Poslední aktualizace Výsledek
AhnLab-V3 2008.7.4.1 2008.07.05 -
AntiVir 7.8.0.64 2008.07.04 -
Authentium 5.1.0.4 2008.07.04 -
Avast 4.8.1195.0 2008.07.04 -
AVG 7.5.0.516 2008.07.04 -
BitDefender 7.2 2008.07.05 -
CAT-QuickHeal 9.50 2008.07.04 -
ClamAV 0.93.1 2008.07.04 -
DrWeb 4.44.0.09170 2008.07.05 -
eSafe 7.0.17.0 2008.07.03 -
eTrust-Vet 31.6.5929 2008.07.05 -
Ewido 4.0 2008.07.05 -
F-Prot 4.4.4.56 2008.07.04 -
F-Secure 7.60.13501.0 2008.07.03 Suspicious:W32/DNSChanger!Gemini
Fortinet 3.14.0.0 2008.07.04 -
GData 2.0.7306.1023 2008.07.05 -
Ikarus T3.1.1.26.0 2008.07.05 -
Kaspersky 7.0.0.125 2008.07.05 -
McAfee 5332 2008.07.04 -
Microsoft 1.3704 2008.07.05 -
NOD32v2 3244 2008.07.05 -
Norman 5.80.02 2008.07.04 -
Panda 9.0.0.4 2008.07.05 -
Prevx1 V2 2008.07.05 -
Rising 20.51.42.00 2008.07.04 -
Sophos 4.31.0 2008.07.05 -
Sunbelt 3.1.1509.1 2008.07.04 -
Symantec 10 2008.07.05 -
TheHacker 6.2.96.371 2008.07.04 -
TrendMicro 8.700.0.1004 2008.07.05 -
VBA32 3.12.6.8 2008.07.04 -
VirusBuster 4.5.11.0 2008.07.04 -
Webwasher-Gateway 6.6.2 2008.07.05 -


Winrar je pouze na tom F disku


ComboFix 08-07-04.5 - gorman 2008-07-05 13:38:32.3 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.232 [GMT 2:00]
Running from: C:\Documents and Settings\gorman\Plocha\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\gorman\Data aplikací\inst.exe
C:\Documents and Settings\gorman\Oblíbené položky\Online Security Test.url
C:\WINDOWS\msvrc20.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 )))))))))))))))))))))))))))))))
.

2008-07-01 22:46 . 2008-07-01 22:46 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-01 22:46 . 2008-07-01 22:46 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-05 12:30 . 2008-06-05 12:30 <DIR> d-------- C:\Program Files\Edisk

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-05 09:44 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\SiteAdvisor
2008-07-05 09:05 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-07-04 12:21 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2008-07-03 20:39 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2008-06-27 18:47 --------- d-----w C:\Documents and Settings\gorman\Data aplikací\Skype
2008-06-27 14:04 --------- d-----w C:\Documents and Settings\gorman\Data aplikací\skypePM
2008-06-27 12:27 --------- d-----w C:\Documents and Settings\gorman\Data aplikací\MxBoost
2008-06-26 05:42 --------- d-----w C:\Program Files\Spyware Terminator
2008-06-15 14:28 --------- d-----w C:\Program Files\iTV
2008-06-14 18:00 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 16:56 71,688 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-06-10 16:56 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-06-10 16:56 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-06-10 16:48 53,256 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-06-10 16:47 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-06-05 10:58 --------- d-----w C:\Documents and Settings\gorman\Data aplikací\Spyware Terminator
2008-06-02 18:06 --------- d-----w C:\Documents and Settings\gorman\Data aplikací\uTorrent
2008-05-16 17:42 --------- d-----w C:\Program Files\Torrent Master
2008-05-08 14:21 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:16 1,290,240 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2007-11-19 20:46 32 ----a-w C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
2007-05-05 21:53 4,608 ----a-w C:\Program Files\cesta.cdx
2007-05-05 21:53 1,773 ----a-w C:\Program Files\cesta.dbf
2007-04-25 19:11 47,360 ----a-w C:\Documents and Settings\gorman\Data aplikací\pcouffin.sys
2006-11-02 09:40 680 ----a-w C:\Program Files\ukoly.dbf
2006-11-02 09:40 512 ----a-w C:\Program Files\ukoly.fpt
2006-11-02 09:40 4,608 ----a-w C:\Program Files\ukoly.cdx
2003-10-11 08:23 575 ----a-w C:\Program Files\udaje2.dbf
2007-01-10 16:52 56 --sh--r C:\WINDOWS\system32\D2FE506499.sys
2008-03-23 16:01 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

------- Sigcheck -------

2006-04-20 14:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-04 00:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-12-04 22:05 359808 b4e29943b4b04bd5e7381546848e6669 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-10-30 19:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 19:20 360064 8283a4d489b207991efdc8328733d0bc C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 16:49 15360]
"PeerGuardian"="F:\CdiskNemazat\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 19:40 1421824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTStartup"="C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" [2001-09-15 03:10 28672]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43 8466432]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-06-10 18:52 1447168]
"nwiz"="nwiz.exe" [2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 16:49 15360]

C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe [2006-10-23 20:21:51 221247]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"msacm.ac3filter"= ac3filter.acm

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"eMuleAutoStart"=F:\a data\eMule\emule.exe -AutoStart
"AWMON"="F:\CdiskNemazat\Program Files\Ad-Aware SE Professional\Ad-Watch.exe"
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 viasraid;viasraid;C:\WINDOWS\system32\drivers\viasraid.sys [2003-06-12 20:31]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-05-08 16:21]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 17:51]
R3 emu10kx;Creative EMU10K1/EMU10K2 Audio Driver (WDM);C:\WINDOWS\system32\drivers\e10kx2k.sys [2001-10-02 17:06]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 00:04]
S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-01-24 23:34]
S3 tap0901_2gm;VPN Anonymizer Adapter;C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 17:21]

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-05 13:40:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run???h??????s?????\?w? ?w???????w???w4???????.??w4???????4???TA?s4????????&7???6~??6~????????\???\???????????U?6~??6~\???\???????0?_??????C@?\???\??????s????\??????s\????&7?A??s?&7??C@?x???`|?w\?????@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
Completion time: 2008-07-05 13:41:42
ComboFix-quarantined-files.txt 2008-07-05 11:41:16

Adresářů: 15, Volných bajtů: 486,699,008
Adresářů: 18, Volných bajtů: 488,046,592

127 --- E O F --- 2008-06-20 17:32:04




Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK



Jediný co mě napadá, že jsem stahoval aktualizaci ESS 3.0.667

_________________
Obrázek


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 13:06 
Offline
Rádce
Rádce
Uživatelský avatar

Registrován: 13 úno 2007 14:20
Příspěvky: 13488
At vyloucime z 90 procent infekci malwarem

:arrow: pouzij SDFix navod zde: viewtopic.php?f=15&t=40395 , opet log najdes Report.txt

:arrow: Sken pomoci AVP Tool navod zde: viewtopic.php?f=29&t=58179 , log uprav cituji

Kód:
Pokud jste skenovali počítač s AVPTool poprvé, bude log dlouhý. Otevřete ho v Poznámkovém bloku a hned na jeho začátku označte myší celý odstavec začínající nadpisem Detected, stiskněte pravé tlačítko myši a vyberte Kopírovat. Tento odstavec, který informuje o souborech, které byly detekovány a na kterých byla provedena akce, vložte do svého threadu na forum.
vloz

_________________
?


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 13:24 
Offline
Vzorný návštěvník
Vzorný návštěvník

Registrován: 02 srp 2006 20:32
Příspěvky: 49
System Report
*************

Run on so 05.07.2008 at 14:20

Microsoft Windows XP [Verze 5.1.2600]

Current user is an administrator

Running Processes:

\SystemRoot\System32\smss.exe [872]
\??\C:\WINDOWS\system32\csrss.exe [1040]
\??\C:\WINDOWS\system32\winlogon.exe [1064]
C:\WINDOWS\system32\services.exe [1112]
C:\WINDOWS\system32\lsass.exe [1124]
C:\WINDOWS\system32\svchost.exe [1272]
C:\WINDOWS\system32\svchost.exe [1340]
C:\WINDOWS\System32\svchost.exe [1500]
C:\WINDOWS\system32\spoolsv.exe [1948]
C:\WINDOWS\system32\LVCOMSX.EXE [348]
C:\Program Files\ESET\ESET Smart Security\egui.exe [384]
C:\WINDOWS\system32\ctfmon.exe [428]
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe [440]
F:\CdiskNemazat\Program Files\PeerGuardian2\pg2.exe [464]
C:\WINDOWS\system32\svchost.exe [600]
C:\WINDOWS\system32\cisvc.exe [644]
C:\Program Files\ESET\ESET Smart Security\ekrn.exe [676]
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe [548]
C:\Program Files\CyberLink\Shared files\RichVideo.exe [876]
C:\Program Files\Spyware Terminator\sp_rsser.exe [1720]
C:\WINDOWS\system32\svchost.exe [1880]
C:\WINDOWS\system32\wdfmgr.exe [1900]
C:\WINDOWS\system32\svchost.exe [1528]
C:\WINDOWS\System32\alg.exe [204]
C:\WINDOWS\system32\cidaemon.exe [3240]
F:\CdiskNemazat\Program Files\Maxthon\Maxthon.exe [2908]
C:\WINDOWS\explorer.exe [2104]
C:\WINDOWS\explorer.exe [4032]
C:\WINDOWS\system32\wscntfy.exe [240]


Drivers - Running:

ACPI
AFD
AmdK7
Arp1394
atapi
audstub
Beep
BrPar
BthEnum
BTHMODEM
BthPan
BTHUSB
Cdrom
Compbatt
ctac32k
ctprxy2k
ctsfm2k
Disk
dmio
dmload
eamon
easdrv
ElbyCDFL
ElbyCDIO
ElbyDelay
emu10kx
emupia
epfw
Epfwndis
epfwtdi
Fastfat
Fdc
FETNDIS
Fips
Flpydisk
FltMgr
Ftdisk
gameenum
Gpc
HidBth
hidusb
HTTP
i8042prt
Imapi
IpFilterDriver
IpNat
IPSec
isapnp
Kbdclass
kbdhid
KSecDD
LVUSBSta
MarvinBus
mnmdd
Modem
Mouclass
mouhid
MountMgr
MRxSmb
Msfs
mssmbios
ms_mpu401
Mup
NDIS
NdisTapi
Ndisuio
NdisWan
NDProxy
NetBIOS
NetBT
NIC1394
Npfs
Ntfs
Null
nv
ohci1394
ossrv
Parport
PartMgr
ParVdm
PCI
PCLEPCI
Pcouffin
pfc
PfModNT
PID_08A0
PptpMiniport
PQNTDrv
PSched
Ptilink
RasAcd
Rasl2tp
RasPppoe
Raspti
Rdbss
RDPCDD
rdpdr
redbook
RFCOMM
serenum
Serial
sp_rsdrv2
sr
Srv
swenum
sysaudio
Tcpip
TermDD
uagp35
Udfs
Update
usbaudio
usbccgp
usbehci
usbhub
usbuhci
VgaSave
ViaIde
viamraid
viasraid
VolSnap
Wanarp
wdmaud
{95808DC4-FA4A-4c74-92FE-5B863F82066B}
pgfilter


Drivers - Stopped:

Abiosdsk
abp480n5
ACPIEC
Ad-Watch
adpu160m
aec
Aha154x
aic78u2
aic78xx
AliIde
amsint
asc
asc3350p
asc3550
AsyncMac
Atdisk
Atmarpc
BlueletAudio
BlueletSCOAudio
BT
Btcsrusb
BTHidEnum
BTHidMgr
BTHPORT
cbidf2k
CCDECODE
cd20xrnt
Cdaudio
Cdfs
Changer
CmdIde
CO_Mon
Cpqarray
CVirtA
dac960nt
dmboot
DMusic
dpti2o
drmkaud
ggflt
ggsemc
HidBatt
hpn
i2omgmt
i2omp
ini910u
IntelIde
Ip6Fw
IpInIp
IRENUM
k750bus
k750mdfl
k750mdm
k750mgmt
k750obex
kmixer
lbrtfdc
mraid35x
MRxDAV
MSKSSRV
MSPCLOCK
MSPQM
MSTEE
NABTSFEC
NdisIP
NwlnkFlt
NwlnkFwd
PCIDump
PCIIde
Pcmcia
PDCOMP
PDFRAME
PDRELI
PDRFRAME
pepifilter
perc2
perc2hib
ProtoWall
ql1080
Ql10wnt
ql12160
ql1240
ql1280
RDPWD
ROOTMODEM
Secdrv
Ser2pl
Sfloppy
Simbad
SLIP
SONYPVU1
Sparrow
splitter
streamip
swmidi
symc810
symc8xx
sym_hi
sym_u3
tap0901_2gm
TDPIPE
TDTCP
TosIde
ultra
usbprint
usbscan
USBSTOR
VComm
VcommMgr
VHidMinidrv
vsdatant
Wdf01000
WDICA
WSTCODEC


Services - Running:

ALG
APC
AudioSrv
BITS
Browser
BthServ
CiSvc
CryptSvc
DcomLaunch
Dhcp
dmserver
ekrn
ERSvc
Eventlog
EventSystem
FastUserSwitchingCompatibility
helpsvc
HidServ
lanmanserver
lanmanworkstation
Netman
Nla
PlugPlay
ProtectedStorage
RasMan
RichVideo
RpcSs
SamSs
Schedule
seclogon
SENS
SharedAccess
ShellHWDetection
Spooler
sp_rssrv
srservice
SSDPSRV
stisvc
TapiSrv
TermService
Themes
UMWdf
W32Time
winmgmt
wscsvc
wuauserv
WZCSVC


Services - Stopped:

Alerter
AppMgmt
aspnet_state
ClipSrv
clr_optimization_v2.0.50727_32
COMSysApp
dmadmin
Dnscache
EhttpSrv
HTTPFilter
IDriverT
ImapiService
LmHosts
Messenger
mnmsrvc
MSDTC
MSIServer
NetDDE
NetDDEdsdm
Netlogon
NMIndexingService
NtLmSsp
NtmsSvc
NVSvc
ose
PolicyAgent
RasAuto
RDSessMgr
RemoteAccess
RemoteRegistry
RpcLocator
RSVP
SCardSvr
SwPrv
SysmonLog
TlntSvr
TrkWks
upnphost
UPS
VSS
WebClient
WmdmPmSN
Wmi
WmiApSrv
xmlprov


Files Created/Modified - 60 Days:


C:\

11 May 2008 22.22.48 211 A.SH. "C:\boot.ini"
5 Jul 2008 13.41.44 8 482 A.... "C:\ComboFix.txt"
5 Jul 2008 11.38.10 536 391 680 A.SH. "C:\hiberfil.sys"
5 Jul 2008 11.38.10 805 306 368 A.SH. "C:\pagefile.sys"


C:\WINDOWS\

5 Jul 2008 11.38.16 2 048 A.S.. "C:\WINDOWS\bootstat.dat"
8 May 2008 9.43.10 423 A.... "C:\WINDOWS\BRWMARK.INI"
5 Jul 2008 13.44.10 1 774 A.... "C:\WINDOWS\MAILTRAN.INI"
1 Jul 2008 22.46.58 1 409 A.... "C:\WINDOWS\QTFont.for"
1 Jul 2008 22.46.58 54 156 A..H. "C:\WINDOWS\QTFont.qfn"
4 Jul 2008 23.00.36 32 550 ..... "C:\WINDOWS\SchedLgU.Txt"
5 Jul 2008 13.40.38 277 A.... "C:\WINDOWS\system.ini"
29 Jun 2008 23.02.12 636 A.... "C:\WINDOWS\wcx_ftp.ini"
4 Jun 2008 17.21.18 2 130 A.... "C:\WINDOWS\WDICT32.INI"
5 Jul 2008 11.38.42 159 ..... "C:\WINDOWS\wiadebug.log"
5 Jul 2008 11.38.42 48 ..... "C:\WINDOWS\wiaservc.log"
29 Jun 2008 23.02.58 3 521 A.... "C:\WINDOWS\WINCMD.INI"
5 Jul 2008 14.06.42 1 653 632 A.... "C:\WINDOWS\WindowsUpdate.log"
14 Jun 2008 13.22.38 4 477 A.... "C:\WINDOWS\WTRAN32.INI"
14 Jun 2008 13.22.38 0 A.... "C:\WINDOWS\XXLGSC"
11 Jun 2008 23.00.38 6 823 936 A.... "C:\WINDOWS\$NtUninstallKB950760$\reg00001"
5 Jul 2008 11.38.16 0 ..... "C:\WINDOWS\Debug\PASSWD.LOG"
16 Jun 2008 19.23.00 926 A.... "C:\WINDOWS\inf\branches.inf"
11 May 2008 15.11.20 4 100 A.... "C:\WINDOWS\inf\branches.PNF"
11 May 2008 15.11.20 1 446 896 A.... "C:\WINDOWS\inf\INFCACHE.1"
10 Jun 2008 18.47.34 3 421 A.... "C:\WINDOWS\inf\oem21.inf"
20 Jun 2008 22.26.00 7 362 A.... "C:\WINDOWS\inf\oem21.PNF"
10 Jun 2008 18.47.34 1 461 A.... "C:\WINDOWS\inf\oem22.inf"
20 Jun 2008 22.26.00 5 306 A.... "C:\WINDOWS\inf\oem22.PNF"
4 Jul 2008 23.00.56 23 196 A.... "C:\WINDOWS\system32\BMXBkpCtrlState-{00000000-00000000-00000009-00001102-00000004-00531102}.rfx"
4 Jul 2008 23.00.56 23 196 A.... "C:\WINDOWS\system32\BMXCtrlState-{00000000-00000000-00000009-00001102-00000004-00531102}.rfx"
4 Jul 2008 23.00.56 18 560 A.... "C:\WINDOWS\system32\BMXState-{00000000-00000000-00000009-00001102-00000004-00531102}.rfx"
4 Jul 2008 23.00.56 18 560 A.... "C:\WINDOWS\system32\BMXStateBkp-{00000000-00000000-00000009-00001102-00000004-00531102}.rfx"
4 Jul 2008 23.00.56 24 A.... "C:\WINDOWS\system32\DVCState-{00000000-00000000-00000009-00001102-00000004-00531102}.dat"
4 Jul 2008 23.00.56 24 A.... "C:\WINDOWS\system32\DVCStateBkp-{00000000-00000000-00000009-00001102-00000004-00531102}.dat"
30 May 2008 1.35.12 17 486 968 A.... "C:\WINDOWS\system32\MRT.exe"
5 Jul 2008 11.42.44 70 376 A.... "C:\WINDOWS\system32\perfc005.dat"
5 Jul 2008 11.42.44 59 780 A.... "C:\WINDOWS\system32\perfc009.dat"
5 Jul 2008 11.42.44 394 788 A.... "C:\WINDOWS\system32\perfh005.dat"
5 Jul 2008 11.42.44 397 560 A.... "C:\WINDOWS\system32\perfh009.dat"
5 Jul 2008 11.42.44 934 310 A.... "C:\WINDOWS\system32\PerfStringBackup.INI"
7 May 2008 7.16.22 1 290 240 A.... "C:\WINDOWS\system32\quartz.dll"
4 Jul 2008 23.00.56 1 072 A.... "C:\WINDOWS\system32\settings.sfm"
4 Jul 2008 23.00.56 1 072 A.... "C:\WINDOWS\system32\settingsbkup.sfm"
5 Jul 2008 11.01.34 2 228 A.... "C:\WINDOWS\system32\wpa.dbl"
5 Jul 2008 11.38.18 6 A..H. "C:\WINDOWS\Tasks\SA.DAT"
5 Jul 2008 14.19.48 7 586 A.... "C:\WINDOWS\TEMP\scsB53.tmp"
27 May 2008 21.45.02 12 816 A.... "C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.inf"
27 May 2008 21.44.52 370 A.... "C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.txt"
20 Jun 2008 19.32.04 14 244 A.... "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.inf"
20 Jun 2008 19.31.58 607 A.... "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.txt"
11 Jun 2008 23.00.40 12 181 A.... "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.inf"
11 Jun 2008 23.00.38 122 A.... "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.txt"
11 Jun 2008 23.00.54 13 697 A.... "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.inf"
11 Jun 2008 23.00.48 478 A.... "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.txt"
11 Jun 2008 23.00.28 13 847 A.... "C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.inf"
11 Jun 2008 23.00.20 534 A.... "C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.txt"
11 Jun 2008 23.01.04 13 688 A.... "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.inf"
11 Jun 2008 23.01.00 470 A.... "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.txt"
15 May 2008 22.27.40 19 210 A.... "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.inf"
15 May 2008 22.27.30 4 362 A.... "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.txt"
5 Jul 2008 14.18.02 13 398 A.... "C:\WINDOWS\Debug\UserMode\userenv.log"
14 Jun 2008 20.00.16 272 128 ..... "C:\WINDOWS\Driver Cache\i386\bthport.sys"
5 Jul 2008 13.38.20 1 155 072 A.... "C:\WINDOWS\erdnt\Hiv-backup\default"
5 Jul 2008 13.38.22 673 A.... "C:\WINDOWS\erdnt\Hiv-backup\ERDNT.CON"
5 Jul 2008 13.38.22 1 504 A.... "C:\WINDOWS\erdnt\Hiv-backup\ERDNT.INF"
5 Jul 2008 13.38.20 24 576 A.... "C:\WINDOWS\erdnt\Hiv-backup\SAM"
5 Jul 2008 13.38.12 45 056 A.... "C:\WINDOWS\erdnt\Hiv-backup\SECURITY"
5 Jul 2008 13.38.20 33 722 368 A.... "C:\WINDOWS\erdnt\Hiv-backup\software"
5 Jul 2008 13.38.20 4 829 184 A.... "C:\WINDOWS\erdnt\Hiv-backup\system"
11 Jun 2008 23.04.38 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00002"
11 Jun 2008 23.04.38 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00003"
11 Jun 2008 23.04.40 6 823 936 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00004"
11 Jun 2008 23.04.40 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00005"
11 Jun 2008 23.04.40 12 288 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00006"
11 Jun 2008 23.04.40 12 288 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00007"
11 Jun 2008 23.04.40 12 288 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00008"
11 Jun 2008 23.04.40 12 288 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00009"
11 Jun 2008 23.04.40 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00010"
11 Jun 2008 23.04.40 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00011"
11 Jun 2008 23.04.40 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00012"
11 Jun 2008 23.04.40 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00013"
11 Jun 2008 23.04.40 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00014"
11 Jun 2008 23.04.40 8 192 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00015"
11 Jun 2008 23.04.40 12 288 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\reg00016"
14 Jun 2008 20.00.16 272 128 ..... "C:\WINDOWS\system32\dllcache\bthport.sys"
7 May 2008 7.16.22 1 290 240 ..... "C:\WINDOWS\system32\dllcache\quartz.dll"
8 May 2008 14.28.50 202 752 ..... "C:\WINDOWS\system32\dllcache\rmcast.sys"
14 Jun 2008 20.00.16 272 128 ..... "C:\WINDOWS\system32\drivers\bthport.sys"
10 Jun 2008 18.47.42 39 944 A.... "C:\WINDOWS\system32\drivers\eamon.sys"
10 Jun 2008 18.48.38 53 256 A.... "C:\WINDOWS\system32\drivers\easdrv.sys"
10 Jun 2008 18.56.04 71 688 A.... "C:\WINDOWS\system32\drivers\epfw.sys"
10 Jun 2008 18.56.08 30 728 A.... "C:\WINDOWS\system32\drivers\epfwndis.sys"
10 Jun 2008 18.56.08 54 280 A.... "C:\WINDOWS\system32\drivers\epfwtdi.sys"
8 May 2008 14.28.50 202 752 ..... "C:\WINDOWS\system32\drivers\rmcast.sys"
8 May 2008 16.21.44 141 312 A.... "C:\WINDOWS\system32\drivers\sp_rsdrv2.sys"
8 May 2008 14.14.52 203 008 A.... "C:\WINDOWS\$hf_mig$\KB950762\SP2QFE\rmcast.sys"
8 May 2008 16.02.52 203 136 A.... "C:\WINDOWS\$hf_mig$\KB950762\SP3GDR\rmcast.sys"
8 May 2008 15.58.18 203 136 A.... "C:\WINDOWS\$hf_mig$\KB950762\SP3QFE\rmcast.sys"
8 May 2008 22.08.30 926 A.... "C:\WINDOWS\$hf_mig$\KB950762\update\branches.inf"
8 May 2008 23.25.28 12 431 A.... "C:\WINDOWS\$hf_mig$\KB950762\update\KB950762.CAT"
9 May 2008 0.12.28 386 A.... "C:\WINDOWS\$hf_mig$\KB950762\update\update.ver"
8 May 2008 23.27.54 23 087 A.... "C:\WINDOWS\$hf_mig$\KB950762\update\update_SP2QFE.inf"
8 May 2008 23.49.12 25 455 A.... "C:\WINDOWS\$hf_mig$\KB950762\update\update_SP3GDR.inf"
8 May 2008 23.26.44 25 455 A.... "C:\WINDOWS\$hf_mig$\KB950762\update\update_SP3QFE.inf"
20 May 2008 11.48.36 705 A.... "C:\WINDOWS\$hf_mig$\KB950759-IE7\update\branches.inf"
20 May 2008 14.56.46 32 215 A.... "C:\WINDOWS\$hf_mig$\KB950759-IE7\update\KB950759-IE7.CAT"
20 May 2008 20.24.10 5 960 A.... "C:\WINDOWS\$hf_mig$\KB950759-IE7\update\update.ver"
20 May 2008 11.48.36 500 A.... "C:\WINDOWS\$hf_mig$\KB950759-IE7\update\updatebr.inf"
20 May 2008 13.12.18 123 881 A.... "C:\WINDOWS\$hf_mig$\KB950759-IE7\update\update_SP2QFE.inf"
14 Jun 2008 20.05.50 272 128 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys"
14 Jun 2008 19.35.32 272 128 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys"
14 Jun 2008 19.40.30 272 128 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys"
16 Jun 2008 19.23.00 926 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\branches.inf"
16 Jun 2008 20.15.36 12 431 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\KB951376-v2.CAT"
16 Jun 2008 22.25.46 390 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.ver"
16 Jun 2008 19.23.00 681 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\updatebr.inf"
16 Jun 2008 20.00.46 23 667 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update_SP2QFE.inf"
16 Jun 2008 20.21.58 26 035 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update_SP3GDR.inf"
16 Jun 2008 19.59.46 26 035 A.... "C:\WINDOWS\$hf_mig$\KB951376-v2\update\update_SP3QFE.inf"
7 May 2008 7.03.14 1 290 752 A.... "C:\WINDOWS\$hf_mig$\KB951698\SP2QFE\quartz.dll"
7 May 2008 7.12.00 1 290 752 A.... "C:\WINDOWS\$hf_mig$\KB951698\SP3GDR\quartz.dll"
7 May 2008 7.05.02 1 290 752 A.... "C:\WINDOWS\$hf_mig$\KB951698\SP3QFE\quartz.dll"
7 May 2008 7.19.32 926 A.... "C:\WINDOWS\$hf_mig$\KB951698\update\branches.inf"
7 May 2008 8.02.52 12 431 A.... "C:\WINDOWS\$hf_mig$\KB951698\update\KB951698.CAT"
7 May 2008 8.10.50 390 A.... "C:\WINDOWS\$hf_mig$\KB951698\update\update.ver"
7 May 2008 7.19.32 678 A.... "C:\WINDOWS\$hf_mig$\KB951698\update\updatebr.inf"
7 May 2008 7.36.00 23 072 A.... "C:\WINDOWS\$hf_mig$\KB951698\update\update_SP2QFE.inf"
7 May 2008 8.09.40 25 440 A.... "C:\WINDOWS\$hf_mig$\KB951698\update\update_SP3GDR.inf"
7 May 2008 7.36.22 25 440 A.... "C:\WINDOWS\$hf_mig$\KB951698\update\update_SP3QFE.inf"
11 Jun 2008 23.05.06 25 024 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.inf"
11 Jun 2008 23.04.40 7 811 A.... "C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.txt"
8 May 2008 23.25.28 12 431 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB950762.cat"
20 May 2008 14.56.46 32 215 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB950759-IE7.cat"
16 Jun 2008 20.15.36 12 431 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB951376-v2.cat"
7 May 2008 8.02.52 12 431 ..S.. "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB951698.cat"
20 Jun 2008 22.26.02 8 A.... "C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TimeStamp"
4 Jun 2008 17.35.14 17 532 A.... "C:\WINDOWS\system32\Macromed\Flash\install.log"
4 Jun 2008 17.35.14 74 649 A.... "C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe"
5 Jul 2008 13.38.20 1 114 112 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT"
5 Jul 2008 13.38.20 8 192 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat"
5 Jul 2008 13.38.22 11 546 624 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT"
5 Jul 2008 13.38.22 323 584 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat"
5 Jul 2008 13.38.22 1 114 112 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT"
5 Jul 2008 13.38.22 8 192 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat"
5 Jul 2008 13.38.22 274 432 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000007\NTUSER.DAT"
5 Jul 2008 13.38.22 679 936 A.... "C:\WINDOWS\erdnt\Hiv-backup\Users\00000008\NTUSER.DAT"


C:\Program Files\

14 Jun 2008 18.39.48 334 336 A.... "C:\Program Files\iTV\iTV.exe"
29 May 2008 22.32.44 17 408 A.... "C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll"
29 May 2008 22.32.46 185 856 A.... "C:\Program Files\Mozilla Firefox\crashreporter.exe"
29 May 2008 22.32.46 307 712 A.... "C:\Program Files\Mozilla Firefox\firefox.exe"
29 May 2008 16.24.14 233 472 A.... "C:\Program Files\Mozilla Firefox\freebl3.dll"
29 May 2008 22.32.46 695 808 A.... "C:\Program Files\Mozilla Firefox\js3250.dll"
29 May 2008 22.32.46 710 144 A.... "C:\Program Files\Mozilla Firefox\mozcrt19.dll"
29 May 2008 22.32.46 198 144 A.... "C:\Program Files\Mozilla Firefox\nspr4.dll"
29 May 2008 22.32.46 697 856 A.... "C:\Program Files\Mozilla Firefox\nss3.dll"
29 May 2008 22.32.46 304 640 A.... "C:\Program Files\Mozilla Firefox\nssckbi.dll"
29 May 2008 22.32.46 103 936 A.... "C:\Program Files\Mozilla Firefox\nssdbm3.dll"
29 May 2008 22.32.46 87 552 A.... "C:\Program Files\Mozilla Firefox\nssutil3.dll"
29 May 2008 22.32.46 20 480 A.... "C:\Program Files\Mozilla Firefox\plc4.dll"
29 May 2008 22.32.46 17 408 A.... "C:\Program Files\Mozilla Firefox\plds4.dll"
29 May 2008 22.32.46 103 936 A.... "C:\Program Files\Mozilla Firefox\smime3.dll"
29 May 2008 16.24.14 151 552 A.... "C:\Program Files\Mozilla Firefox\softokn3.dll"
29 May 2008 22.32.46 414 208 A.... "C:\Program Files\Mozilla Firefox\sqlite3.dll"
29 May 2008 22.32.46 136 704 A.... "C:\Program Files\Mozilla Firefox\ssl3.dll"
29 May 2008 22.32.46 241 664 A.... "C:\Program Files\Mozilla Firefox\updater.exe"
29 May 2008 22.32.46 17 920 A.... "C:\Program Files\Mozilla Firefox\xpcom.dll"
29 May 2008 22.32.46 9 715 200 A.... "C:\Program Files\Mozilla Firefox\xul.dll"
8 May 2008 16.21.44 1 817 600 A.... "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe"
8 May 2008 16.21.44 606 720 A.... "C:\Program Files\Spyware Terminator\sp_rsser.exe"
16 May 2008 19.42.40 1 349 A.... "C:\Program Files\Torrent Master\wyrazy.dat"
4 Jul 2008 23.00.38 14 140 A.... "C:\Program Files\APC\APC PowerChute Personal Edition\eventlog.dat"
10 Jun 2008 18.47.46 66 816 A.... "C:\Program Files\ESET\ESET Smart Security\callmsi.exe"
10 Jun 2008 18.49.20 230 656 A.... "C:\Program Files\ESET\ESET Smart Security\ecls.exe"
10 Jun 2008 18.48.46 17 152 A.... "C:\Program Files\ESET\ESET Smart Security\eclsLang.dll"
10 Jun 2008 18.50.00 39 680 A.... "C:\Program Files\ESET\ESET Smart Security\ecmd.exe"
10 Jun 2008 18.52.30 1 447 168 A.... "C:\Program Files\ESET\ESET Smart Security\egui.exe"
10 Jun 2008 18.48.30 103 680 A.... "C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll"
10 Jun 2008 18.47.54 13 056 A.... "C:\Program Files\ESET\ESET Smart Security\eguiAmonLang.dll"
10 Jun 2008 18.51.32 107 776 A.... "C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll"
10 Jun 2008 18.50.10 13 568 A.... "C:\Program Files\ESET\ESET Smart Security\eguiEmonLang.dll"
10 Jun 2008 18.55.50 771 328 A.... "C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll"
10 Jun 2008 18.54.42 169 216 A.... "C:\Program Files\ESET\ESET Smart Security\eguiEpfwLang.dll"
10 Jun 2008 18.51.44 132 352 A.... "C:\Program Files\ESET\ESET Smart Security\eguiLang.dll"
10 Jun 2008 19.02.16 91 392 A.... "C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll"
10 Jun 2008 18.59.40 10 496 A.... "C:\Program Files\ESET\ESET Smart Security\eguiMailPluginsLang.dll"
10 Jun 2008 18.52.24 251 136 A.... "C:\Program Files\ESET\ESET Smart Security\eguiProduct.dll"
10 Jun 2008 18.56.32 275 712 A.... "C:\Program Files\ESET\ESET Smart Security\eguiScan.dll"
10 Jun 2008 18.52.36 22 784 A.... "C:\Program Files\ESET\ESET Smart Security\eguiScanLang.dll"
10 Jun 2008 18.59.08 152 832 A.... "C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll"
10 Jun 2008 18.56.52 17 664 A.... "C:\Program Files\ESET\ESET Smart Security\eguiSmonLang.dll"
10 Jun 2008 19.04.42 226 560 A.... "C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll"
10 Jun 2008 19.03.20 37 632 A.... "C:\Program Files\ESET\ESET Smart Security\eguiUpdateLang.dll"
10 Jun 2008 18.59.18 19 200 A.... "C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"
10 Jun 2008 18.53.54 468 224 A.... "C:\Program Files\ESET\ESET Smart Security\ekrn.exe"
10 Jun 2008 18.48.32 136 448 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll"
10 Jun 2008 18.51.34 103 680 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll"
10 Jun 2008 18.55.52 259 328 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll"
10 Jun 2008 18.54.44 17 664 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnEpfwLang.dll"
10 Jun 2008 18.53.16 24 832 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnLang.dll"
10 Jun 2008 19.02.16 103 680 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll"
10 Jun 2008 18.59.42 9 984 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnMailPluginsLang.dll"
10 Jun 2008 18.56.32 156 928 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll"
10 Jun 2008 18.53.58 9 472 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnScanLang.dll"
10 Jun 2008 18.59.10 189 696 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll"
10 Jun 2008 18.59.10 2 172 248 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnSmonEngine.dll"
10 Jun 2008 18.56.54 11 008 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnSmonLang.dll"
10 Jun 2008 19.04.44 132 352 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll"
10 Jun 2008 19.03.22 38 144 A.... "C:\Program Files\ESET\ESET Smart Security\ekrnUpdateLang.dll"
20 Jun 2008 22.24.32 49 503 A.... "C:\Program Files\ESET\ESET Smart Security\em000_32.dat"
3 Jul 2008 15.30.08 310 126 A.... "C:\Program Files\ESET\ESET Smart Security\em001_32.dat"
5 Jul 2008 12.03.06 9 680 104 A.... "C:\Program Files\ESET\ESET Smart Security\em002_32.dat"
20 Jun 2008 22.25.06 220 145 A.... "C:\Program Files\ESET\ESET Smart Security\em003_32.dat"
20 Jun 2008 22.25.08 431 515 A.... "C:\Program Files\ESET\ESET Smart Security\em004_32.dat"
30 Jun 2008 15.58.00 43 055 A.... "C:\Program Files\ESET\ESET Smart Security\em005_32.dat"
20 Jun 2008 22.25.10 10 232 A.... "C:\Program Files\ESET\ESET Smart Security\em006_32.dat"
20 Jun 2008 22.25.10 158 036 A.... "C:\Program Files\ESET\ESET Smart Security\em008_32.dat"
20 Jun 2008 22.35.54 669 939 A.... "C:\Program Files\ESET\ESET Smart Security\em010_32.dat"
20 Jun 2008 22.25.24 990 A.... "C:\Program Files\ESET\ESET Smart Security\em012_32.dat"
10 Jun 2008 18.59.44 14 080 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOutlookLang.dll"
10 Jun 2008 18.50.12 17 664 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOutlookEmonLang.dll"
10 Jun 2008 19.02.18 10 496 A.... "C:\Program Files\ESET\ESET Smart Security\eplgHooks.dll"
10 Jun 2008 19.02.20 247 040 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOE.dll"
10 Jun 2008 18.59.12 345 344 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOESmon.dll"
10 Jun 2008 18.51.36 185 600 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOEEmon.dll"
10 Jun 2008 18.56.56 23 296 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOESmonLang.dll"
10 Jun 2008 18.59.44 14 080 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOELang.dll"
10 Jun 2008 18.59.14 374 016 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOutlookSmon.dll"
10 Jun 2008 19.02.26 263 424 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOutlook.dll"
10 Jun 2008 18.51.36 161 024 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOutlookEmon.dll"
10 Jun 2008 18.56.58 16 640 A.... "C:\Program Files\ESET\ESET Smart Security\eplgOutlookSmonLang.dll"
10 Jun 2008 18.59.20 75 008 A.... "C:\Program Files\ESET\ESET Smart Security\http_dll.dll"
5 Jul 2008 13.37.56 183 A.... "C:\Program Files\ESET\ESET Smart Security\mod_comp.dat"
10 Jun 2008 19.03.12 169 216 A.... "C:\Program Files\ESET\ESET Smart Security\shellExt.dll"
10 Jun 2008 19.02.34 28 416 A.... "C:\Program Files\ESET\ESET Smart Security\ShellExtLang.dll"
10 Jun 2008 19.04.46 173 312 A.... "C:\Program Files\ESET\ESET Smart Security\updater.dll"
29 May 2008 22.32.46 23 040 A.... "C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll"
29 May 2008 22.32.46 134 144 A.... "C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll"
29 May 2008 22.32.46 65 536 A.... "C:\Program Files\Mozilla Firefox\plugins\npnul32.dll"
29 May 2008 16.24.14 117 A.... "C:\Program Files\Mozilla Firefox\res\hiddenWindow.html"
29 May 2008 22.32.44 508 040 A.... "C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
30 May 2008 15.54.14 21 718 312 A...R "C:\Program Files\Skype\Phone\Skype.exe"
30 May 2008 15.54.16 3 279 816 A...R "C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll"
30 May 2008 15.54.16 76 744 A...R "C:\Program Files\Skype\Plugin Manager\skypePM.exe"
7 Jun 2008 21.01.30 14 336 A.... "C:\Program Files\SopCast\adv\sopadver.dat"
10 Jun 2008 18.47.42 39 944 A.... "C:\Program Files\ESET\ESET Smart Security\Drivers\eamon\eamon.sys"
10 Jun 2008 18.48.38 53 256 A.... "C:\Program Files\ESET\ESET Smart Security\Drivers\easdrv\easdrv.sys"
10 Jun 2008 18.56.04 71 688 A.... "C:\Program Files\ESET\ESET Smart Security\Drivers\epfw\epfw.sys"
10 Jun 2008 18.56.08 30 728 A.... "C:\Program Files\ESET\ESET Smart Security\Drivers\epfwndis\epfwndis.sys"
10 Jun 2008 18.56.08 54 280 A.... "C:\Program Files\ESET\ESET Smart Security\Drivers\epfwtdi\epfwtdi.sys"


Files with hidden attributes:

Wed 10 Jan 2007 56 ..SHR --- "C:\WINDOWS\system32\D2FE506499.sys"
Sun 23 Mar 2008 12,208 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 4 Oct 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 2 Nov 2003 2,104 A..H. --- "C:\Program Files\Common Files\ACD Systems\registrace.reg"
Wed 16 Apr 2008 1,123,880 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\44e979936d19a4e833746e7d6f8e194d\BITE65.tmp"
Thu 4 Oct 2007 4,348 ...H. --- "C:\Documents and Settings\gorman\Dokumenty\Hudba\Z lohov nˇ licence\drmv1key.bak"
Fri 5 Oct 2007 20 A..H. --- "C:\Documents and Settings\gorman\Dokumenty\Hudba\Z lohov nˇ licence\drmv1lic.bak"
Thu 4 Oct 2007 400 A.SH. --- "C:\Documents and Settings\gorman\Dokumenty\Hudba\Z lohov nˇ licence\drmv2key.bak"


Program Folders:

C:\Program Files\

AC
AC3Filter
ACD Systems
Adobe
Alwil Software
APC
AV Vcs 6.0 DIAMOND
Avi2Dvd
AviSynth 2.5
Bluetack
Brother
Brownie
Common Files
ComPlus Applications
Creative
CyberLink
DIFX
DivX
DVD Shrink
Edisk
ESET
EsetOnlineScanner
ffdshow
FlashGet
GoldWave
Google
Haali
IGC
InstallShield Installation Information
Internet Explorer
IObit
iTV
Java
JLC's Software
JlgSolera
Kaspersky Lab
Kerio
Lavalys
legis
Media Player Classic
Messenger
microsoft frontpage
Microsoft Office
Movie Maker
Mozilla Firefox
Mozilla Thunderbird
MSN Gaming Zone
MSXML 4.0
MSXML 6.0
Nero
NetMeeting
Online Services
OO Software
Outlook Express
ParallelGraphics
PowerQuest
Raketu
Real
Real Alternative
Room Arranger
Siber Systems
SiteAdvisor
Skype
Smart Projects
SmartSound Software
Sony Ericsson
SopCast
Spyware Terminator
Terasoft
Torrent Master
Trend Micro
TVPlayerClassic
TVUPlayer
Uninstall Information
URUSoft
uTorrent
VIA
VoipBuster.com
VSO
Webteh
WinAVIVideoConverter
Windows Media Components
Windows Media Player
Windows NT
WindowsUpdate
xerox
Yamicsoft

C:\Program Files\Common Files\

ACD Systems
Adobe
Ahead
DESIGNER
InstallShield
Java
Logitech
Microsoft Shared
MSSoap
ODBC
ParallelGraphics
Real
Services
Skype
SpeechEngines
System
SystemRequirementsLab
Teleca Shared
Ulead Systems
xing shared


Add/Remove Programs:

:-)mojelogo SMS ToolBar v4.3.1.1
AC3Filter (remove only)
Ad-Aware SE Professional
Adobe Flash Player ActiveX
Adobe Shockwave Player
AI RoboForm (All Users)
AV Voice Changer Software DIAMOND 6.0
AviSynth 2.5
BSPlayer
BS.Player PRO
CCleaner (remove only)
CloneCD
CloneDVD2
Domácí učitel angličtiny 1 (odstranění)
Domácí učitel angličtiny 2 (odstranění)
DVD Shrink 3.2
eMule
ESET Online Scanner
EVEREST Ultimate Edition v4.20
ffdshow [rev 735] [2007-01-02]
GoldWave v5.13
Haali Media Splitter
Hide IP Platinum 3.21
HijackThis 2.0.2
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
VIA Platform Device Manager
SmartSound Quicktracks Plugin
PowerDVD
PowerQuest PartitionMagic 8.0
IsoBuster 1.9
JLC's Internet TV
Oprava Hotfix systému Windows XP číslo KB873339
Oprava Hotfix systému Windows XP číslo KB885835
Oprava Hotfix systému Windows XP číslo KB885836
Oprava Hotfix systému Windows XP číslo KB886185
Oprava Hotfix systému Windows XP číslo KB887472
Oprava Hotfix systému Windows XP číslo KB888302
Aktualizace zabezpečení systému Windows XP (KB890046)
Oprava Hotfix systému Windows XP číslo KB890859
Oprava Hotfix systému Windows XP číslo KB891781
Aktualizace zabezpečení systému Windows XP (KB893756)
Windows Installer 3.1 (KB893803)
Aktualizace systému Windows XP (KB894391)
Aktualizace zabezpečení systému Windows XP (KB896358)
Aktualizace zabezpečení systému Windows XP (KB896423)
Aktualizace zabezpečení systému Windows XP (KB896424)
Aktualizace zabezpečení systému Windows XP (KB896428)
Aktualizace systému Windows XP (KB898461)
Aktualizace zabezpečení systému Windows XP (KB899587)
Aktualizace zabezpečení systému Windows XP (KB899589)
Aktualizace zabezpečení systému Windows XP (KB899591)
Aktualizace systému Windows XP (KB900485)
Aktualizace zabezpečení systému Windows XP (KB900725)
Aktualizace zabezpečení systému Windows XP (KB901017)
Aktualizace zabezpečení systému Windows XP (KB901214)
Aktualizace zabezpečení systému Windows XP (KB902400)
Aktualizace zabezpečení systému Windows XP (KB904706)
Aktualizace systému Windows XP (KB904942)
Aktualizace zabezpečení systému Windows XP (KB905414)
Aktualizace zabezpečení systému Windows XP (KB905749)
Aktualizace zabezpečení systému Windows XP (KB908519)
Aktualizace systému Windows XP (KB908531)
Aktualizace systému Windows XP (KB910437)
Aktualizace systému Windows XP (KB911280)
Aktualizace zabezpečení systému Windows XP (KB911562)
Aktualizace zabezpečení aplikace Windows Media Player (KB911564)
Aktualizace zabezpečení systému Windows XP (KB911567)
Aktualizace zabezpečení systému Windows XP (KB911927)
Aktualizace zabezpečení systému Windows XP (KB912919)
Aktualizace zabezpečení systému Windows XP (KB913433)
Aktualizace zabezpečení systému Windows XP (KB913580)
Aktualizace zabezpečení systému Windows XP (KB914388)
Aktualizace zabezpečení systému Windows XP (KB914389)
Oprava Hotfix systému Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Aktualizace systému Windows XP (KB916595)
Aktualizace zabezpečení systému Windows XP (KB917344)
Aktualizace zabezpečení systému Windows XP (KB917422)
Aktualizace zabezpečení aplikace Windows Media Player 10 (KB917734)
Aktualizace zabezpečení aplikace Windows Media Player 9 (KB917734)
Aktualizace zabezpečení systému Windows XP (KB917953)
Aktualizace zabezpečení systému Windows XP (KB918118)
Aktualizace zabezpečení systému Windows XP (KB918439)
Aktualizace zabezpečení systému Windows XP (KB918899)
Aktualizace zabezpečení systému Windows XP (KB919007)
Aktualizace zabezpečení systému Windows XP (KB920213)
Aktualizace zabezpečení systému Windows XP (KB920214)
Aktualizace zabezpečení systému Windows XP (KB920670)
Aktualizace zabezpečení systému Windows XP (KB920683)
Aktualizace zabezpečení systému Windows XP (KB920685)
Aktualizace systému Windows XP (KB920872)
Aktualizace zabezpečení systému Windows XP (KB921398)
Aktualizace zabezpečení systému Windows XP (KB921503)
Aktualizace zabezpečení systému Windows XP (KB921883)
Aktualizace systému Windows XP (KB922582)
Aktualizace zabezpečení systému Windows XP (KB922616)
Aktualizace zabezpečení systému Windows XP (KB922760)
Aktualizace zabezpečení systému Windows XP (KB922819)
Aktualizace zabezpečení systému Windows XP (KB923191)
Aktualizace zabezpečení systému Windows XP (KB923414)
Aktualizace zabezpečení produktu Windows XP (KB923689)
Aktualizace zabezpečení systému Windows XP (KB923694)
Aktualizace zabezpečení systému Windows XP (KB923980)
Aktualizace zabezpečení systému Windows XP (KB924191)
Aktualizace zabezpečení systému Windows XP (KB924270)
Aktualizace zabezpečení systému Windows XP (KB924496)
Aktualizace zabezpečení systému Windows XP (KB924667)
Aktualizace zabezpečení aplikace Windows Media Player 6.4 (KB925398)
Aktualizace zabezpečení systému Windows XP (KB925454)
Aktualizace zabezpečení systému Windows XP (KB925486)
Aktualizace zabezpečení systému Windows XP (KB925902)
Aktualizace zabezpečení systému Windows XP (KB926255)
Aktualizace zabezpečení systému Windows XP (KB926436)
Aktualizace zabezpečení systému Windows XP (KB927779)
Aktualizace zabezpečení systému Windows XP (KB927802)
Aktualizace systému Windows XP (KB927891)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB928090)
Aktualizace zabezpečení systému Windows XP (KB928255)
Aktualizace zabezpečení systému Windows XP (KB928843)
Aktualizace systému Windows XP (KB929338)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB929969)
Aktualizace zabezpečení systému Windows XP (KB930178)
Aktualizace systému Windows XP (KB930916)
Aktualizace zabezpečení systému Windows XP (KB931261)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB931768)
Aktualizace zabezpečení systému Windows XP (KB931784)
Aktualizace systému Windows XP (KB931836)
Aktualizace zabezpečení systému Windows XP (KB932168)
Aktualizace systému Windows XP (KB932823-v3)
Aktualizace systému Windows XP (KB933360)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB933566)
Aktualizace zabezpečení systému Windows XP (KB933729)
Aktualizace zabezpečení systému Windows XP (KB935839)
Aktualizace zabezpečení systému Windows XP (KB935840)
Aktualizace zabezpečení systému Windows XP (KB936021)
Aktualizace zabezpečení aplikace Windows Media Player 10 (KB936782)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB937143)
Aktualizace zabezpečení systému Windows XP (KB937894)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB938127)
Aktualizace systému Windows XP (KB938828)
Aktualizace zabezpečení systému Windows XP (KB938829)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB939653)
Aktualizace zabezpečení systému Windows XP (KB941568)
Aktualizace zabezpečení produktu Windows XP (KB941569)
Aktualizace zabezpečení systému Windows XP (KB941644)
Aktualizace zabezpečení systému Windows XP (KB941693)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB942615)
Aktualizace systému Windows XP (KB942763)
Aktualizace zabezpečení systému Windows XP (KB943055)
Aktualizace zabezpečení systému Windows XP (KB943460)
Aktualizace zabezpečení systému Windows XP (KB943485)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB944533)
Aktualizace zabezpečení systému Windows XP (KB944653)
Aktualizace zabezpečení systému Windows XP (KB945553)
Aktualizace zabezpečení systému Windows XP (KB946026)
Oprava Hotfix systému Windows Internet Explorer 7 (KB947864)
Aktualizace zabezpečení systému Windows XP (KB948590)
Aktualizace zabezpečení systému Windows XP (KB948881)
Aktualizace zabezpečení systému Windows XP (KB950749)
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB950759)
Aktualizace zabezpečení systému Windows XP (KB950760)
Aktualizace zabezpečení systému Windows XP (KB950762)
Aktualizace zabezpečení systému Windows XP (KB951376)
Aktualizace zabezpečení systému Windows XP (KB951376-v2)
Aktualizace zabezpečení systému Windows XP (KB951698)
Kubik SMS DreamCom 5.65
Maxthon Browser (remove only)
Maxthon2 Browser (remove only)
MOBILedit! 2.8
Mozilla Firefox (3.0)
Mozilla Thunderbird (2.0.0.14)
Microsoft National Language Support Downlevel APIs
NVIDIA Drivers
PC Translator
PeerGuardian 2.0
##CAMERADRIVERNAME##
QuickTime Alternative 1.76
Real Alternative 1.51
RealPlayer
Room Arranger
ShowIP v1.5.3
SopCast 2.0.4
Sound Blaster Audigy
Spyware Terminator
SpywareBlaster 4.1
Subtitle Workshop 2.51
System Requirements Lab
Torrent Master v. 1.4
Total Commander (Remove or Repair)
TVUPlayer 2.3.4.1
Update Service
VideoLAN VLC media player 0.8.6f
VoipBuster
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Windows Media Format Runtime
Windows Media Player 10
WinRAR archiver
MSXML 6.0 Parser (KB933579)
Google Earth
Platform
Rhapsody Player Engine
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 3
MSXML 4.0 SP2 (KB927978)
SmartSound Quicktracks Plugin
ESET Smart Security
neroxml
APC PowerChute Personal Edition
Skype™ 3.8
PowerDVD
PartitionMagic
Sony Ericsson PC Suite
Microsoft Office Professional Edition 2003
Microsoft Office FrontPage 2003
Brother HL-2030
Adobe Reader 8 - Czech
Spelling Dictionaries Support For Adobe Reader 8
ACDSee 9 Photo Manager
Microsoft .NET Framework 2.0 Service Pack 1
Free DWG Viewer 6.0
ConvertXtoDVD 2.1.18.242
MSXML 4.0 SP2 (KB936181)
Nero 7 Premium
Moorhuhn 3 DL
µTorrent


Run Values:

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"CTStartup"="C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE /run"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"egui"="\"C:\\Program Files\\ESET\\ESET Smart Security\\egui.exe\" /hide /waitservice"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"PeerGuardian"="F:\\CdiskNemazat\\Program Files\\PeerGuardian2\\pg2.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce\CTStartup]
"CTStartup"="\"C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE\" /play"


Bot Check:

SERVICE_NAME: wscsvc
DISPLAY_NAME : Centrum zabezpe
START_TYPE : 2 AUTO_START

SERVICE_NAME: sharedaccess
DISPLAY_NAME : Internet Connection Sharing
START_TYPE : 2 AUTO_START

SERVICE_NAME: wuauserv
DISPLAY_NAME : Automatické aktualizace
START_TYPE : 2 AUTO_START

SERVICE_NAME: srservice
DISPLAY_NAME : Slu
START_TYPE : 2 AUTO_START

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"EnableDCOM"="Y"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"restrictanonymous"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"AUOptions"=dword:00000002

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"WaitToKillServiceTimeout"="20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"SFCDisable"=dword:00000000
"Shell"="Explorer.exe"
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions]



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters]
"TransportBindName"="\\Device\\"


ShellExecuteHooks:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""



Environment:


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\environment
ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe
Path REG_EXPAND_SZ %systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\Common Files\Ulead Systems\MPEG
windir REG_EXPAND_SZ %SystemRoot%
OS REG_SZ Windows_NT
PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
TEMP REG_EXPAND_SZ %SystemRoot%\TEMP
TMP REG_EXPAND_SZ %SystemRoot%\TEMP
DEFAULT_CA_NR REG_SZ CA6

SecurityProviders:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders
SecurityProviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Authentication Packages:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0


Subsystem Startup:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems]
"Windows"="%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16"


Midi Drivers:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midi"="wdmaud.drv"
"midi1"="wdmaud.drv"
"midi2"="wdmaud.drv"
"midi3"="wdmaud.drv"
"midi4"="wdmaud.drv"


Non-Default IFEO Debugger:


Non-Default Installed Components:


Non-Default Safeboot Minimal:


File Associations:


[HKEY_CLASSES_ROOT\batfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\cmdfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\comfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\htafile\shell\open\command]
@="C:\\WINDOWS\\system32\\mshta.exe \"%1\" %*"

[HKEY_CLASSES_ROOT\http\shell\open\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" -nohome"

[HKEY_CLASSES_ROOT\htmlfile\shell\open\command]
@="\"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE\" -nohome"

[HKEY_CLASSES_ROOT\regedit\shell\open\command]
@="regedit.exe %1"

[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\""

[HKEY_CLASSES_ROOT\scrfile\shell\open\command]
@="\"%1\" /S"

[HKEY_CLASSES_ROOT\txtfile\shell\open\command]
@="%SystemRoot%\system32\NOTEPAD.EXE %1"


Finished!

AVP sem náhodím večer... zatím dík

_________________
Obrázek


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 13:31 
Offline
Rádce
Rádce
Uživatelský avatar

Registrován: 13 úno 2007 14:20
Příspěvky: 13488
Oki, ja dote doby dostuduji logy, jestli tam neco neni zalezleho :)

_________________
?


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 18:53 
Offline
Vzorný návštěvník
Vzorný návštěvník

Registrován: 02 srp 2006 20:32
Příspěvky: 49
Ještě zajímavost, jak nešel naběhnout ESS, tak po stažení nových vir. definicí naběhnul úplně OK

Tady je ten log
Detected
--------
Status Object
------ ------
deleted: Trojan program Trojan-Downloader.Win32.Agent.tmo File: C:\Program Files\iTV\iTV.exe
deleted: riskware not-a-virus:NetTool.Win32.Portscan.c File: F:\a data\Downloads\software\ProtoBlock\BLMInstall277.exe//file31//UPX
deleted: Trojan program Trojan-Downloader.Win32.Delf.hky
deleted: Trojan program Trojan.Win32.Delf.cmx
deleted: Trojan program Trojan-Downloader.Win32.Delf.jtp
deleted: Trojan program Backdoor.Win32.Hupigon.cdnk

_________________
Obrázek


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 19:11 
Offline
Rádce
Rádce
Uživatelský avatar

Registrován: 13 úno 2007 14:20
Příspěvky: 13488
Pokud by chybova hlaska v modre obrazovky objevila znovu, doporucji udelat hw testy, tj na disk, na RAm atd. V logach zadne viry nevidim

Start - spustit - do pole nakopiruj ComboFix/u - odentruj.

Co se tyce ESS asi chyba esetu.

_________________
?


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 19:13 
Offline
Vzorný návštěvník
Vzorný návštěvník

Registrován: 02 srp 2006 20:32
Příspěvky: 49
Moc díky :) :D :)

_________________
Obrázek


Nahoru
 Profil  
 
 Předmět příspěvku: Re: PAGE_FAULT_IN_NONPAGE_AREA
PříspěvekNapsal: 05 črc 2008 19:15 
Offline
Rádce
Rádce
Uživatelský avatar

Registrován: 13 úno 2007 14:20
Příspěvky: 13488
Rado se stalo :-)

_________________
?


Nahoru
 Profil  
 
Zobrazit příspěvky za předchozí:  Seřadit podle  
Odeslat nové téma Odpovědět na téma  [ Příspěvků: 14 ] 

Všechny časy jsou v UTC + 1 hodina


Kdo je online

Uživatelé procházející toto fórum: Google [Bot] a 2 návštevníků


Nemůžete zakládat nová témata v tomto fóru
Nemůžete odpovídat v tomto fóru
Nemůžete upravovat své příspěvky v tomto fóru
Nemůžete mazat své příspěvky v tomto fóru
Nemůžete přikládat soubory v tomto fóru

Hledat:
Přejít na:  
POWERED_BY
Český překlad – phpBB.cz