Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Modrá smrt - windows XP

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Modrá smrt - windows XP

#1 Příspěvek od s-o-k-o-l »

Dobrý den, mám tu takový větší zádrhel. Při spouštění PC se nepravidelně objevuje modrá smrt. Počítač naběhne a pak spadne tak 2x a po 3 restartu zas běží normálně. Vyfotil sem obrazovku modré smrti a udělal sem log. Snad mi pomůžete tento problém vyřešit.

Přikládám obrázky modré smrti: http://img718.imageshack.us/i/fotografie0004d.jpg/
http://img822.imageshack.us/i/fotografie0003k.jpg/



Logfile of random's system information tool 1.07 (written by random/random)
Run by sokol at 2010-06-19 15:50:15
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 73 GB (73%) free of 100 GB
Total RAM: 2046 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:50:23, on 19.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS\AI Booster\OverClk.exe
C:\Program Files\ASUS\AI Nap\AiNap.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ASUS\AI Gear\GearHelp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
D:\Steam\Steam.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wuauclt.exe
D:\ICQ7.1\ICQ.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\sokol\Dokumenty\Downloads\RSIT.exe
C:\Documents and Settings\sokol\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\sokol\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\sokol.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.15\AsRunHelp.exe
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\AI Booster\OverClk.exe"
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Nap\AiNap.exe"
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Ai Gear Help] "C:\Program Files\ASUS\AI Gear\GearHelp.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Steam] "D:\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [BrowserChoice] "C:\WINDOWS\system32\browserchoice.exe" /run (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspe?sky Internet Security 2010\ie_banner_deny.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - D:\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - D:\ICQ7.1\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Sentinel HASP License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 11615 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-10-20 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-20 268816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-05-03 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-01-03 1019128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AsusStartupHelp"=C:\Program Files\ASUS\AASP\1.00.15\AsRunHelp.exe [2006-11-14 363008]
"Launch Ai Booster"=C:\Program Files\ASUS\AI Booster\OverClk.exe [2006-11-28 3714048]
"Ai Nap"=C:\Program Files\ASUS\AI Nap\AiNap.exe [2006-11-30 1419776]
"WinSys2"=C:\WINDOWS\system32\winsys2.exe [2007-10-30 208896]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Ai Gear Help"=C:\Program Files\ASUS\AI Gear\GearHelp.exe [2009-08-25 440832]
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe [2003-11-10 176128]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
"LXCYCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16 []
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"nwiz"=nwiz.exe /installquiet []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"SoundMax"=C:\Program Files\Analog Devices\SoundMAX\SMax4.exe [2006-07-13 729088]
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []
"NPSStartup"= []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=D:\Steam\Steam.exe [2010-05-23 1238352]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-12-23 143360]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]
"DAEMON Tools Lite"=D:\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
D:\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
D:\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
C:\Program Files\Lexmark 3400 Series\ezprint.exe [2007-06-25 82608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\sokol\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-05-24 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2003-10-23 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe [2003-06-25 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
D:\ICQ7.1\ICQ.exe [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcymon.exe]
C:\Program Files\Lexmark 3400 Series\lxcymon.exe [2007-06-25 291504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2009-10-20 219664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Opera\opera.exe"="D:\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\ICQ7.1\ICQ.exe"="D:\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"D:\ICQ7.1\aolload.exe"="D:\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"D:\Steam\SteamApps\common\call of duty modern warfare 2\iw4sp.exe"="D:\Steam\SteamApps\common\call of duty modern warfare 2\iw4sp.exe:*:Enabled:Call of Duty: Modern Warfare 2"
"D:\Steam\SteamApps\common\call of duty modern warfare 2\iw4mp.exe"="D:\Steam\SteamApps\common\call of duty modern warfare 2\iw4mp.exe:*:Enabled:Call of Duty: Modern Warfare 2 - Multiplayer"
"D:\THQ\Company of Heroes\RelicCOH.exe"="D:\THQ\Company of Heroes\RelicCOH.exe:*:Enabled:Company of Heroes - Opposing Fronts"
"D:\THQ\Company of Heroes\RelicDownloader\RelicDownloader.exe"="D:\THQ\Company of Heroes\RelicDownloader\RelicDownloader.exe:*:Enabled:Relic Downloader"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\lxcycoms.exe"="C:\WINDOWS\system32\lxcycoms.exe:*:Enabled:3400 Series Server"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"D:\HLSW\hlsw.exe"="D:\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\ICQ7.1\ICQ.exe"="D:\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"D:\ICQ7.1\aolload.exe"="D:\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-06-19 15:50:16 ----D---- C:\Program Files\trend micro
2010-06-19 15:50:15 ----D---- C:\rsit
2010-06-18 18:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-06-18 18:34:16 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-06-18 18:32:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-06-18 14:41:20 ----D---- C:\WINDOWS\Prefetch
2010-06-18 12:15:33 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-06-18 12:06:44 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-06-17 16:36:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\PC Suite
2010-06-17 16:36:39 ----D---- C:\Documents and Settings\sokol\Data aplikací\PC Suite
2010-06-17 16:34:00 ----A---- C:\WINDOWS\system32\nmwcdcls.dll
2010-06-17 16:33:18 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
2010-06-17 16:33:05 ----A---- C:\WINDOWS\system32\FsUsbExService.Exe
2010-06-17 16:33:05 ----A---- C:\WINDOWS\system32\FsUsbExDevice.Dll
2010-06-17 16:32:11 ----D---- C:\Documents and Settings\sokol\Data aplikací\Samsung
2010-06-17 16:32:02 ----D---- C:\Program Files\MarkAny
2010-06-17 16:32:00 ----D---- C:\Program Files\PC Connectivity Solution
2010-06-17 16:31:06 ----D---- C:\Program Files\Samsung
2010-06-16 21:38:51 ----SHD---- C:\found.000
2010-06-16 15:22:14 ----A---- C:\WINDOWS\003117_.tmp
2010-06-14 00:36:29 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-14 00:36:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-06-14 00:36:21 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-06-14 00:36:16 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-06-14 00:36:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-06-14 00:36:06 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-06-14 00:36:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-06-14 00:35:54 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-06-14 00:35:47 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-06-14 00:35:40 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-06-14 00:35:30 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-06-14 00:35:25 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-06-14 00:35:20 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-06-14 00:35:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-06-14 00:35:09 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-06-14 00:35:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-06-14 00:34:59 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-06-14 00:34:54 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-06-14 00:34:50 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-06-14 00:34:45 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-06-14 00:34:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-06-14 00:34:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-06-14 00:34:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-06-14 00:34:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-06-14 00:34:08 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-06-14 00:34:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-06-14 00:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-06-14 00:33:46 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-06-14 00:33:40 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-06-14 00:33:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-06-14 00:33:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-06-14 00:33:24 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-06-14 00:33:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-06-14 00:33:13 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2010-06-14 00:33:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-06-14 00:33:04 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-06-14 00:32:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-14 00:32:54 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-06-14 00:32:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-06-14 00:32:41 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-06-14 00:32:35 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-06-14 00:32:30 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-06-14 00:32:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-06-14 00:32:13 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-06-14 00:32:08 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-06-14 00:32:03 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-06-14 00:31:56 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-14 00:31:52 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-06-14 00:31:36 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-06-14 00:31:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-06-14 00:31:26 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-14 00:31:22 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-06-14 00:31:16 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-06-14 00:31:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-06-14 00:31:00 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2010-06-14 00:30:48 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-06-14 00:30:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-06-14 00:30:37 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-06-13 23:24:32 ----HDC---- C:\WINDOWS\$NtUninstallKB926239$
2010-06-13 23:24:11 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-06-13 23:24:08 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2010-06-13 12:33:23 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-06-13 12:32:34 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-06-13 12:17:13 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-06-13 12:17:13 ----A---- C:\WINDOWS\system32\irclass.dll
2010-06-13 12:16:58 ----RA---- C:\WINDOWS\SET72.tmp
2010-06-13 12:16:50 ----RA---- C:\WINDOWS\SET47.tmp
2010-06-13 12:16:48 ----RA---- C:\WINDOWS\SET3B.tmp
2010-06-13 12:16:46 ----RA---- C:\WINDOWS\SET38.tmp
2010-06-13 11:44:01 ----RA---- C:\WINDOWS\SETDD.tmp
2010-06-13 11:43:52 ----RA---- C:\WINDOWS\SETB2.tmp
2010-06-13 11:43:49 ----RA---- C:\WINDOWS\SETA6.tmp
2010-06-13 11:43:47 ----RA---- C:\WINDOWS\SETA3.tmp
2010-06-12 19:46:33 ----D---- C:\Documents and Settings\sokol\Data aplikací\HLSW
2010-06-11 16:14:49 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-06-11 16:14:47 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2010-06-11 16:14:38 ----A---- C:\WINDOWS\game.ini
2010-06-11 16:05:04 ----D---- C:\Program Files\Activision
2010-06-09 19:51:07 ----SHD---- C:\RECYCLER
2010-06-09 19:41:01 ----A---- C:\WINDOWS\system32\dopdfmn6.dll
2010-06-09 19:41:01 ----A---- C:\WINDOWS\system32\dopdfmi6.dll
2010-06-09 10:24:53 ----SD---- C:\ComboFix
2010-06-09 10:18:06 ----A---- C:\ComboFix.txt
2010-06-07 07:28:51 ----D---- C:\spoolerlogs
2010-06-02 15:39:29 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-06-02 15:39:02 ----D---- C:\Documents and Settings\sokol\Data aplikací\DAEMON Tools Lite
2010-06-02 15:38:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2010-06-02 15:28:49 ----RHD---- C:\Documents and Settings\sokol\Data aplikací\SecuROM
2010-06-02 14:04:46 ----D---- C:\Program Files\lx_cats
2010-06-02 14:04:29 ----A---- C:\WINDOWS\system32\lxcyvs.dll
2010-06-02 14:04:28 ----A---- C:\WINDOWS\system32\lxcycoin.dll
2010-06-02 14:04:21 ----A---- C:\WINDOWS\system32\wiafbdrv.dll
2010-06-02 14:04:19 ----A---- C:\WINDOWS\system32\lxcydrs.dll
2010-06-02 14:04:19 ----A---- C:\WINDOWS\system32\lxcycnv4.dll
2010-06-02 14:04:19 ----A---- C:\WINDOWS\system32\lxcycaps.dll
2010-06-02 14:04:12 ----D---- C:\Program Files\Lexmark 3400 Series
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyutil.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyusb1.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyserv.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyprox.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcypplc.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcypmui.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcylmpm.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyjswr.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyinst.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyinpa.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyiesc.dll
2010-06-02 14:04:05 ----A---- C:\WINDOWS\system32\lxcyhcp.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcyinsr.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcyinsb.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcyins.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcyih.exe
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcyhbn3.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcygf.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycur.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycub.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycu.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycoms.exe
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycomm.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycomc.dll
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycfg.exe
2010-06-02 14:04:04 ----A---- C:\WINDOWS\system32\lxcycfg.dll
2010-06-02 14:02:41 ----D---- C:\drivers
2010-06-01 11:39:51 ----D---- C:\Program Files\Kaspersky Lab
2010-06-01 11:39:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab
2010-06-01 11:34:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2010-05-31 19:31:03 ----D---- C:\Documents and Settings\sokol\Data aplikací\TS3Client
2010-05-31 19:17:25 ----D---- C:\Documents and Settings\sokol\Data aplikací\skypePM
2010-05-31 19:17:07 ----D---- C:\Documents and Settings\sokol\Data aplikací\Skype
2010-05-31 19:16:48 ----D---- C:\Program Files\Common Files\Skype
2010-05-31 19:16:45 ----RD---- C:\Program Files\Skype
2010-05-31 19:16:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-05-30 19:59:24 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-29 16:19:05 ----A---- C:\WINDOWS\zip.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\SWSC.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\SWREG.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\sed.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\PEV.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\NIRCMD.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\MBR.exe
2010-05-29 16:19:05 ----A---- C:\WINDOWS\grep.exe
2010-05-29 16:19:01 ----D---- C:\WINDOWS\ERDNT
2010-05-29 16:18:28 ----D---- C:\Qoobox
2010-05-28 09:34:27 ----D---- C:\Documents and Settings\sokol\Data aplikací\Ahead
2010-05-28 09:30:43 ----D---- C:\Program Files\Nero
2010-05-28 09:30:43 ----D---- C:\Program Files\Common Files\Ahead
2010-05-28 09:30:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-05-27 20:40:04 ----D---- C:\Program Files\Common Files\Aladdin Shared
2010-05-27 20:40:03 ----A---- C:\WINDOWS\system32\hasplms.exe
2010-05-27 19:45:43 ----A---- C:\WINDOWS\ConverterCore.INI
2010-05-27 19:44:05 ----D---- C:\Documents and Settings\sokol\Data aplikací\SolidDocuments
2010-05-27 19:43:46 ----A---- C:\WINDOWS\system32\solidlocalui.dll
2010-05-27 19:43:46 ----A---- C:\WINDOWS\system32\solidlocalmon.dll
2010-05-27 19:42:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\SolidDocuments
2010-05-27 15:14:42 ----D---- C:\WINDOWS\pss
2010-05-25 20:32:17 ----D---- C:\Program Files\Common Files\Freedom Scientific
2010-05-25 20:22:01 ----D---- C:\Program Files\Common Files\soft602
2010-05-25 20:22:01 ----D---- C:\Documents and Settings\sokol\Data aplikací\602XML
2010-05-25 20:21:15 ----D---- C:\Program Files\Software602
2010-05-25 13:09:21 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-05-25 13:05:54 ----A---- C:\WINDOWS\system32\msonpmon.dll
2010-05-25 13:05:25 ----D---- C:\Program Files\Microsoft Works
2010-05-25 13:05:22 ----D---- C:\Program Files\MSBuild
2010-05-25 13:05:13 ----D---- C:\Program Files\Microsoft Visual Studio
2010-05-25 13:05:13 ----D---- C:\Program Files\Common Files\DESIGNER
2010-05-25 13:03:24 ----HD---- C:\WINDOWS\ShellNew
2010-05-25 13:02:52 ----RD---- C:\MSOCache
2010-05-24 20:32:16 ----D---- C:\Program Files\MSXML 4.0
2010-05-24 19:59:11 ----D---- C:\Program Files\Microsoft Office
2010-05-24 19:59:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-05-24 19:52:04 ----RA---- C:\WINDOWS\system32\hpvaut32.dll
2010-05-24 19:52:04 ----A---- C:\WINDOWS\system32\msxml4a.dll
2010-05-24 19:52:03 ----RA---- C:\WINDOWS\system32\hpvcr70.dll
2010-05-24 19:52:03 ----RA---- C:\WINDOWS\system32\hpvcp70.dll
2010-05-24 14:54:36 ----D---- C:\Program Files\HP
2010-05-24 14:54:36 ----D---- C:\Program Files\Hewlett-Packard
2010-05-24 14:54:15 ----A---- C:\WINDOWS\hpdj3600.ini
2010-05-24 00:33:49 ----D---- C:\Documents and Settings\sokol\Data aplikací\Media Player Classic
2010-05-23 20:02:54 ----D---- C:\Documents and Settings\sokol\Data aplikací\WinRAR
2010-05-23 20:02:23 ----D---- C:\Program Files\WinRAR
2010-05-23 14:35:54 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2010-05-23 14:35:54 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2010-05-23 14:35:54 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-05-23 14:35:53 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-05-23 14:35:53 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2010-05-23 14:35:53 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2010-05-23 14:35:53 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-05-23 14:35:53 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-05-23 14:35:53 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-05-23 14:35:52 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2010-05-23 14:35:52 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-05-23 14:35:52 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2010-05-23 14:35:52 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-05-23 14:35:52 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-05-23 14:35:52 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2010-05-23 14:35:52 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-05-23 14:35:51 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2010-05-23 14:35:50 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2010-05-23 14:35:50 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-05-23 14:35:50 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2010-05-23 14:35:50 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-05-23 14:35:50 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-05-23 14:35:50 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-05-23 14:35:50 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-05-23 14:35:49 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-05-23 14:35:48 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2010-05-23 14:35:48 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2010-05-23 14:35:48 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2010-05-23 14:35:48 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2010-05-23 14:35:48 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2010-05-23 14:35:48 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-05-23 14:35:47 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-05-23 14:35:46 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-05-23 14:35:46 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-05-23 14:35:45 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-05-23 14:35:45 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2010-05-23 14:35:45 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2010-05-23 14:35:44 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2010-05-23 14:35:44 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2010-05-23 14:35:44 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2010-05-23 14:35:44 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2010-05-23 14:35:44 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2010-05-23 14:35:44 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-05-23 14:35:44 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-05-23 14:35:43 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2010-05-23 14:35:43 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2010-05-23 14:35:43 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-05-23 14:35:43 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2010-05-23 14:35:42 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-05-23 14:35:42 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2010-05-23 14:35:42 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2010-05-23 14:35:41 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2010-05-23 14:34:43 ----D---- C:\WINDOWS\Logs
2010-05-23 13:49:14 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-05-23 13:49:13 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-05-23 13:49:12 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-05-23 13:49:12 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-05-23 13:45:46 ----SHD---- C:\WINDOWS\ftpcache
2010-05-23 12:52:20 ----D---- C:\Documents and Settings\sokol\Data aplikací\ICQ
2010-05-23 11:26:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-05-23 11:26:19 ----D---- C:\Program Files\Common Files\Java
2010-05-23 11:26:14 ----A---- C:\WINDOWS\system32\javaws.exe
2010-05-23 11:26:14 ----A---- C:\WINDOWS\system32\javaw.exe
2010-05-23 11:26:14 ----A---- C:\WINDOWS\system32\java.exe
2010-05-23 11:26:14 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-05-23 11:16:37 ----D---- C:\WINDOWS\Minidump
2010-05-22 18:25:44 ----D---- C:\Program Files\Common Files\Real
2010-05-22 18:25:43 ----D---- C:\Program Files\Real
2010-05-22 18:25:43 ----D---- C:\Documents and Settings\sokol\Data aplikací\Real
2010-05-22 18:25:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-05-22 18:23:08 ----D---- C:\Program Files\Java
2010-05-22 18:22:59 ----D---- C:\Documents and Settings\sokol\Data aplikací\Sun
2010-05-22 18:20:22 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-22 18:20:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-05-22 18:17:00 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-05-22 18:17:00 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-05-22 18:17:00 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-05-22 18:16:57 ----A---- C:\WINDOWS\system32\unrar.dll
2010-05-22 18:16:55 ----A---- C:\WINDOWS\avisplitter.ini
2010-05-22 18:16:45 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-05-22 18:16:44 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-05-22 18:16:44 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-05-22 18:16:41 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2010-05-22 18:16:41 ----A---- C:\WINDOWS\system32\dpl100.dll
2010-05-22 18:16:35 ----A---- C:\WINDOWS\system32\divx.dll
2010-05-22 18:16:32 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-05-22 18:16:32 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-05-22 18:16:31 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-05-22 16:00:14 ----D---- C:\Program Files\Windows Media Connect 2
2010-05-22 16:00:09 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-05-22 15:59:51 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-22 15:59:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 15:55:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-05-22 15:34:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2010-05-22 15:34:04 ----A---- C:\WINDOWS\system32\OpenCL.dll
2010-05-22 15:34:04 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2010-05-22 15:34:04 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2010-05-22 15:34:03 ----A---- C:\WINDOWS\system32\nvcuda.dll
2010-05-22 15:34:03 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2010-05-22 15:33:56 ----D---- C:\NVIDIA
2010-05-22 15:22:21 ----D---- C:\Documents and Settings\sokol\Data aplikací\Macromedia
2010-05-22 15:22:21 ----D---- C:\Documents and Settings\sokol\Data aplikací\Adobe
2010-05-22 15:22:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-05-22 15:22:07 ----D---- C:\Program Files\Common Files\Adobe
2010-05-22 15:15:45 ----D---- C:\Documents and Settings\sokol\Data aplikací\Mozilla
2010-05-22 15:14:55 ----D---- C:\WINDOWS\ie8updates
2010-05-22 15:14:48 ----D---- C:\WINDOWS\WBEM
2010-05-22 15:14:34 ----HDC---- C:\WINDOWS\ie8
2010-05-22 15:14:11 ----D---- C:\Documents and Settings\sokol\Data aplikací\Opera
2010-05-22 15:14:06 ----D---- C:\Program Files\Opera
2010-05-22 14:37:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-05-22 14:34:05 ----D---- C:\WINDOWS\system32\cs-cz
2010-05-22 14:34:04 ----D---- C:\WINDOWS\system32\cs
2010-05-22 14:34:04 ----D---- C:\WINDOWS\l2schemas
2010-05-22 14:34:03 ----D---- C:\WINDOWS\system32\bits
2010-05-22 14:25:27 ----D---- C:\WINDOWS\network diagnostic
2010-05-22 14:23:12 ----D---- C:\WINDOWS\EHome
2010-05-22 14:19:59 ----D---- C:\Documents and Settings\sokol\Data aplikací\ESET
2010-05-22 14:18:32 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2010-05-22 14:18:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2010-05-22 14:18:24 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2010-05-22 14:18:20 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2010-05-22 14:18:16 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2010-05-22 14:18:07 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2010-05-22 14:17:29 ----HDC---- C:\WINDOWS\$NtUninstallKB971468_0$
2010-05-22 14:17:24 ----HDC---- C:\WINDOWS\$NtUninstallKB979683_0$
2010-05-22 14:17:13 ----HDC---- C:\WINDOWS\$NtUninstallKB980232_0$
2010-05-22 14:17:10 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2010-05-22 14:17:02 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2010-05-22 14:16:57 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2010-05-22 14:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2010-05-22 14:16:49 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-22 14:16:45 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2010-05-22 14:15:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2010-05-22 14:15:39 ----HDC---- C:\WINDOWS\$NtUninstallKB978037_0$
2010-05-22 14:15:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975713_0$
2010-05-22 14:15:32 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2010-05-22 14:15:29 ----HDC---- C:\WINDOWS\$NtUninstallKB978338_0$
2010-05-22 14:15:26 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2010-05-22 14:15:23 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2010-05-22 14:15:20 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2010-05-22 14:15:13 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2010-05-22 14:15:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2010-05-22 14:15:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2010-05-22 14:15:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975561_0$
2010-05-22 14:14:57 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2010-05-22 14:14:54 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2010-05-22 14:14:49 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2010-05-22 14:14:46 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2010-05-22 14:14:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975560_0$
2010-05-22 14:14:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2010-05-22 14:14:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2010-05-22 14:14:30 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2010-05-22 14:14:24 ----HDC---- C:\WINDOWS\$NtUninstallKB980182_0$
2010-05-22 14:14:21 ----HDC---- C:\WINDOWS\$NtUninstallKB978601_0$
2010-05-22 14:14:18 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2010-05-22 14:14:11 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2010-05-22 14:14:06 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2010-05-22 14:14:01 ----HDC---- C:\WINDOWS\$NtUninstallKB977914_0$
2010-05-22 14:13:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2010-05-22 14:13:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-05-22 14:13:51 ----HDC---- C:\WINDOWS\$NtUninstallKB978542_0$
2010-05-22 14:13:48 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2010-05-22 14:13:46 ----HDC---- C:\WINDOWS\$NtUninstallKB979309_0$
2010-05-22 14:13:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978706_0$
2010-05-22 14:13:41 ----D---- C:\WINDOWS\ServicePackFiles
2010-05-22 14:13:39 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2010-05-22 14:13:37 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2010-05-22 14:13:34 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2010-05-22 14:13:32 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2010-05-22 14:13:29 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2010-05-22 14:13:24 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2010-05-22 14:13:15 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2010-05-22 14:13:11 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2010-05-22 14:13:08 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2010-05-22 14:13:05 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2010-05-22 14:13:00 ----HDC---- C:\WINDOWS\$NtUninstallKB969947_0$
2010-05-22 14:12:51 ----A---- C:\WINDOWS\system32\wpa.bak
2010-05-22 14:00:29 ----A---- C:\WINDOWS\system32\browserchoice.exe
2010-05-22 14:00:06 ----A---- C:\WINDOWS\system32\tzchange.exe
2010-05-22 13:50:15 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-05-22 13:50:08 ----D---- C:\WINDOWS\system32\PreInstall
2010-05-22 13:50:06 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-05-22 13:50:06 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-22 13:01:53 ----A---- C:\WINDOWS\system32\h323log.txt
2010-05-22 12:56:36 ----A---- C:\WINDOWS\msicpl.ini
2010-05-22 12:54:03 ----D---- C:\WINDOWS\nview
2010-05-22 12:54:02 ----RA---- C:\WINDOWS\system32\smdll.dll
2010-05-22 12:54:02 ----RA---- C:\WINDOWS\system32\MadCHook.dll
2010-05-22 12:54:02 ----A---- C:\WINDOWS\system32\nvudisp.exe
2010-05-22 12:54:01 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-05-22 12:54:01 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2010-05-22 12:54:00 ----RA---- C:\WINDOWS\system32\WinSys2.exe
2010-05-22 12:54:00 ----RA---- C:\WINDOWS\system32\sw24.exe
2010-05-22 12:54:00 ----RA---- C:\WINDOWS\system32\sw20.exe
2010-05-22 12:54:00 ----RA---- C:\WINDOWS\system32\HookShield.dll
2010-05-22 12:54:00 ----RA---- C:\WINDOWS\system32\HookMAp.dll
2010-05-22 12:54:00 ----RA---- C:\WINDOWS\system32\Auxiliary.dll
2010-05-22 12:54:00 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-05-22 12:53:59 ----RA---- C:\WINDOWS\system32\msicpl.dll
2010-05-22 12:45:05 ----A---- C:\WINDOWS\imsins.BAK
2010-05-22 12:45:03 ----SHD---- C:\WINDOWS\Installer
2010-05-22 12:45:03 ----D---- C:\Program Files\Common Files\ODBC
2010-05-22 12:45:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-22 12:45:03 ----A---- C:\WINDOWS\ODBCINST.INI
2010-05-22 12:45:01 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-05-22 12:44:58 ----RD---- C:\Program Files
2010-05-22 12:44:58 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:44:58 ----D---- C:\Program Files\Common Files
2010-05-22 12:44:47 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-05-22 12:44:47 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-05-22 12:44:45 ----A---- C:\WINDOWS\system32\CONFIG.TMP
2010-05-22 12:44:43 ----A---- C:\WINDOWS\system32\storprop.dll
2010-05-22 12:44:38 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2010-05-22 12:42:58 ----RA---- C:\WINDOWS\SET8.tmp
2010-05-22 12:42:56 ----RA---- C:\WINDOWS\SET4.tmp
2010-05-22 12:42:55 ----RA---- C:\WINDOWS\SET3.tmp
2010-05-22 12:42:51 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-22 12:42:51 ----D---- C:\WINDOWS\system32\CatRoot
2010-05-22 12:42:45 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-05-22 12:42:17 ----A---- C:\WINDOWS\setuplog.txt
2010-05-22 12:42:15 ----D---- C:\Documents and Settings
2010-05-22 12:42:14 ----SHD---- C:\System Volume Information
2010-05-22 12:41:18 ----SH---- C:\boot.ini
2010-05-22 12:37:17 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-22 12:37:17 ----RSD---- C:\WINDOWS\Fonts
2010-05-22 12:37:17 ----RD---- C:\WINDOWS\Web
2010-05-22 12:37:17 ----HD---- C:\WINDOWS\inf
2010-05-22 12:37:17 ----D---- C:\WINDOWS\WinSxS
2010-05-22 12:37:17 ----D---- C:\WINDOWS\twain_32
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Temp
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\wins
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\wbem
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\usmt
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\spool
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\ShellExt
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\Setup
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\ras
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\oobe
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\npp
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\mui
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\inetsrv
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\IME
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\icsxml
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\ias
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\export
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\drivers
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\dhcp
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\config
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\3com_dmi
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\3076
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\2052
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1054
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1042
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1041
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1037
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1033
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1031
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1029
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1028
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32\1025
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system32
2010-05-22 12:37:17 ----D---- C:\WINDOWS\system
2010-05-22 12:37:17 ----D---- C:\WINDOWS\security
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Resources
2010-05-22 12:37:17 ----D---- C:\WINDOWS\repair
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Provisioning
2010-05-22 12:37:17 ----D---- C:\WINDOWS\pchealth
2010-05-22 12:37:17 ----D---- C:\WINDOWS\PeerNet
2010-05-22 12:37:17 ----D---- C:\WINDOWS\mui
2010-05-22 12:37:17 ----D---- C:\WINDOWS\msapps
2010-05-22 12:37:17 ----D---- C:\WINDOWS\msagent
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Media
2010-05-22 12:37:17 ----D---- C:\WINDOWS\java
2010-05-22 12:37:17 ----D---- C:\WINDOWS\ime

Pokračování logu:

s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Re: Modrá smrt - windows XP

#2 Příspěvek od s-o-k-o-l »

pokračování logu:

2010-05-22 12:37:17 ----D---- C:\WINDOWS\Help
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Driver Cache
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Debug
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Cursors
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Connection Wizard
2010-05-22 12:37:17 ----D---- C:\WINDOWS\Config
2010-05-22 12:37:17 ----D---- C:\WINDOWS\AppPatch
2010-05-22 12:37:17 ----D---- C:\WINDOWS\addins
2010-05-22 12:37:17 ----D---- C:\WINDOWS
2010-05-22 12:29:27 ----A---- C:\WINDOWS\system32\MSVCRTD.DLL
2010-05-22 12:29:27 ----A---- C:\WINDOWS\system32\mfc42d.dll
2010-05-22 12:29:26 ----A---- C:\WINDOWS\system32\AsIO.dll
2010-05-22 12:29:24 ----D---- C:\Program Files\ASUS
2010-05-22 12:28:19 ----A---- C:\WINDOWS\system32\PostProc.dll
2010-05-22 12:28:19 ----A---- C:\WINDOWS\system32\a3d.dll
2010-05-22 12:28:18 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-05-22 12:28:11 ----A---- C:\WINDOWS\system32\wdmioctl.dll
2010-05-22 12:28:11 ----A---- C:\WINDOWS\system32\SMMedia.dll
2010-05-22 12:28:09 ----D---- C:\Program Files\Analog Devices
2010-05-22 12:28:09 ----A---- C:\WINDOWS\system32\DSndUp.exe
2010-05-22 12:28:09 ----A---- C:\WINDOWS\system32\CleanUp.exe
2010-05-22 12:27:39 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-05-22 12:26:57 ----D---- C:\Program Files\DIFX
2010-05-22 12:26:55 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-22 12:24:22 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-22 12:24:01 ----D---- C:\Program Files\NVIDIA Corporation
2010-05-22 12:23:49 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-05-22 12:23:07 ----A---- C:\WINDOWS\system32\CapabilityTable.exe
2010-05-22 12:22:59 ----A---- C:\WINDOWS\system32\nvuide.exe
2010-05-22 12:22:59 ----A---- C:\WINDOWS\system32\NVCOI.DLL
2010-05-22 12:22:59 ----A---- C:\WINDOWS\system32\idecoiins.dll
2010-05-22 12:22:58 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-05-22 12:22:58 ----A---- C:\WINDOWS\system32\idecoi.dll
2010-05-22 12:22:45 ----A---- C:\WINDOWS\system32\fdco1ins.dll
2010-05-22 12:22:45 ----A---- C:\WINDOWS\system32\fdco1.dll
2010-05-22 12:22:44 ----A---- C:\WINDOWS\system32\nvunrm.exe
2010-05-22 12:22:43 ----A---- C:\WINDOWS\system32\nvconrm.dll
2010-05-22 12:22:43 ----A---- C:\WINDOWS\system32\bdco1ins.dll
2010-05-22 12:22:43 ----A---- C:\WINDOWS\system32\bdco1.dll
2010-05-22 12:22:31 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2010-05-22 12:22:23 ----D---- C:\Program Files\Common Files\InstallShield
2010-05-22 12:22:21 ----RA---- C:\WINDOWS\system32\raidmgmt.ini
2010-05-22 12:22:21 ----RA---- C:\WINDOWS\system32\AsusSetup.ini
2010-05-22 12:22:20 ----RA---- C:\WINDOWS\system32\AsusSetup.exe
2010-05-22 12:22:20 ----A---- C:\WINDOWS\AS_Debug.txt
2010-05-22 12:22:10 ----A---- C:\WINDOWS\Ascd_tmp.ini
2010-05-22 11:08:51 ----D---- C:\Documents and Settings\sokol\Data aplikací\Identities
2010-05-22 11:08:50 ----HD---- C:\Program Files\Uninstall Information
2010-05-22 11:08:36 ----SD---- C:\Documents and Settings\sokol\Data aplikací\Microsoft
2010-05-22 11:08:36 ----ASH---- C:\Documents and Settings\sokol\Data aplikací\desktop.ini
2010-05-22 11:07:49 ----D---- C:\WINDOWS\SoftwareDistribution
2010-05-22 11:07:47 ----SD---- C:\WINDOWS\system32\Microsoft
2010-05-22 11:07:47 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-22 11:05:34 ----D---- C:\WINDOWS\system32\xircom
2010-05-22 11:05:34 ----D---- C:\Program Files\xerox
2010-05-22 11:05:34 ----D---- C:\Program Files\microsoft frontpage
2010-05-22 11:05:23 ----A---- C:\WINDOWS\control.ini
2010-05-22 11:05:23 ----A---- C:\AUTOEXEC.BAT
2010-05-22 11:05:17 ----A---- C:\WINDOWS\OEWABLog.txt
2010-05-22 11:05:14 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-05-22 11:04:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-05-22 11:04:45 ----RD---- C:\WINDOWS\Offline Web Pages
2010-05-22 11:04:42 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-05-22 11:04:39 ----HD---- C:\Program Files\WindowsUpdate
2010-05-22 11:04:37 ----D---- C:\Program Files\Online Services
2010-05-22 11:04:28 ----D---- C:\WINDOWS\system32\DirectX
2010-05-22 11:04:16 ----A---- C:\WINDOWS\system32\atrace.dll
2010-05-22 11:04:14 ----A---- C:\WINDOWS\system32\desktop.ini
2010-05-22 11:04:14 ----A---- C:\WINDOWS\desktop.ini
2010-05-22 11:04:09 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-05-22 11:04:08 ----D---- C:\Program Files\Common Files\Services
2010-05-22 11:04:08 ----A---- C:\WINDOWS\system32\acctres.dll
2010-05-22 11:04:06 ----SD---- C:\WINDOWS\Tasks
2010-05-22 11:04:06 ----D---- C:\Program Files\Common Files\MSSoap
2010-05-22 11:04:06 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-05-22 11:04:03 ----D---- C:\WINDOWS\system32\Macromed
2010-05-22 11:04:03 ----D---- C:\WINDOWS\srchasst
2010-05-22 11:04:01 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-05-22 11:04:01 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-05-22 11:04:01 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-05-22 11:04:01 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-05-22 11:04:01 ----A---- C:\WINDOWS\system32\wuaueng.dll.wusetup.143875.bak
2010-05-22 11:04:01 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\wups.dll
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-05-22 11:04:00 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-05-22 11:03:58 ----D---- C:\Program Files\Movie Maker
2010-05-22 11:03:55 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-05-22 11:03:55 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-05-22 11:03:55 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-05-22 11:03:55 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-05-22 11:03:53 ----D---- C:\WINDOWS\system32\Restore
2010-05-22 11:03:53 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-05-22 11:03:53 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-05-22 11:03:53 ----A---- C:\WINDOWS\system32\fltmc.exe
2010-05-22 11:03:53 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-05-22 11:03:52 ----A---- C:\WINDOWS\system32\srclient.dll
2010-05-22 11:03:52 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-05-22 11:03:52 ----A---- C:\WINDOWS\system32\msconf.dll
2010-05-22 11:03:52 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-05-22 11:03:52 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-05-22 11:03:52 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-05-22 11:03:52 ----A---- C:\WINDOWS\system32\ils.dll
2010-05-22 11:03:50 ----D---- C:\Program Files\NetMeeting
2010-05-22 11:03:50 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-05-22 11:03:50 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-05-22 11:03:49 ----A---- C:\WINDOWS\system32\inetres.dll
2010-05-22 11:03:49 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-05-22 11:03:48 ----D---- C:\Program Files\Outlook Express
2010-05-22 11:03:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-05-22 11:03:48 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-05-22 11:03:48 ----A---- C:\WINDOWS\system32\mstask.dll
2010-05-22 11:03:47 ----A---- C:\WINDOWS\system32\isign32.dll
2010-05-22 11:03:47 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-05-22 11:03:47 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-05-22 11:03:47 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-05-22 11:03:44 ----D---- C:\Program Files\Common Files\System
2010-05-22 11:03:43 ----D---- C:\Program Files\Internet Explorer
2010-05-22 11:03:34 ----D---- C:\Program Files\ComPlus Applications
2010-05-22 11:03:32 ----A---- C:\WINDOWS\vbaddin.ini
2010-05-22 11:03:32 ----A---- C:\WINDOWS\vb.ini
2010-05-22 11:03:29 ----D---- C:\WINDOWS\Registration
2010-05-22 11:03:12 ----D---- C:\Program Files\Windows Media Player
2010-05-22 11:03:09 ----D---- C:\Program Files\Messenger
2010-05-22 11:03:06 ----D---- C:\Program Files\MSN Gaming Zone
2010-05-22 11:03:06 ----A---- C:\WINDOWS\system32\write.exe
2010-05-22 11:03:01 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-05-22 11:03:01 ----A---- C:\WINDOWS\system32\hticons.dll
2010-05-22 11:03:01 ----A---- C:\WINDOWS\system32\avwav.dll
2010-05-22 11:03:01 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-05-22 11:03:01 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-05-22 11:03:00 ----A---- C:\WINDOWS\system32\winchat.exe
2010-05-22 11:02:56 ----A---- C:\WINDOWS\system32\winmine.exe
2010-05-22 11:02:56 ----A---- C:\WINDOWS\system32\sol.exe
2010-05-22 11:02:56 ----A---- C:\WINDOWS\system32\charmap.exe
2010-05-22 11:02:56 ----A---- C:\WINDOWS\system32\getuname.dll
2010-05-22 11:02:56 ----A---- C:\WINDOWS\system32\calc.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\tskill.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\tscon.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\shadow.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\reset.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\regini.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\msg.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\logoff.exe
2010-05-22 11:02:55 ----A---- C:\WINDOWS\system32\freecell.exe
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-05-22 11:02:54 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-05-22 11:02:53 ----A---- C:\WINDOWS\system32\stclient.dll
2010-05-22 11:02:53 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-05-22 11:02:51 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-05-22 11:02:50 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-05-22 11:02:50 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-05-22 11:02:50 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-05-22 11:02:49 ----D---- C:\Program Files\Windows NT
2010-05-22 11:02:49 ----A---- C:\WINDOWS\system32\spider.exe
2010-05-22 11:02:49 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-05-22 11:02:49 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-05-22 11:02:49 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-05-22 11:02:48 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-05-22 11:02:47 ----D---- C:\WINDOWS\system32\MsDtc
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-05-22 11:02:47 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-05-22 11:02:46 ----D---- C:\WINDOWS\system32\Com
2010-05-22 11:02:46 ----A---- C:\WINDOWS\system32\colbact.dll
2010-05-22 11:02:46 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-05-22 11:02:46 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-05-22 11:02:46 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-05-22 11:02:46 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-05-22 11:02:45 ----A---- C:\WINDOWS\system32\comuid.dll
2010-05-22 11:02:45 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-05-22 11:02:45 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-05-22 11:02:42 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-05-22 11:02:42 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-05-22 11:02:42 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-05-22 11:02:42 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2010-06-13 12:32:19 ----A---- C:\WINDOWS\win.ini
2010-06-13 12:17:19 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2009-08-04 11296]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 kl1;Kl1; \??\C:\WINDOWS\system32\drivers\kl1.sys []
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2010-06-11 315408]
R1 NVTCP;NVIDIA TCP/IP Protocol Driver; C:\WINDOWS\System32\DRIVERS\NVTcp.sys [2006-09-11 110592]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
R2 aksfridge;Sentinel HASP Fridge; C:\WINDOWS\system32\DRIVERS\aksfridge.sys [2009-12-17 356864]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-04 10232128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-09-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-09-11 19968]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
R3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 akshasp;SafeNet Inc. HASP Key; C:\WINDOWS\system32\DRIVERS\akshasp.sys [2009-12-17 238208]
S3 akshhl;SafeNet Inc. Sentinel HASP Key; C:\WINDOWS\system32\DRIVERS\akshhl.sys [2009-12-17 46336]
S3 aksusb;SafeNet Inc. USB Key; C:\WINDOWS\system32\DRIVERS\aksusb.sys [2009-12-17 16384]
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2009-09-14 32272]
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2006-09-11 172032]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-04-13 20543]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 hasplms;Sentinel HASP License Manager; C:\WINDOWS\system32\hasplms.exe [2009-12-17 3750400]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-12 153376]
R2 lxcy_device;lxcy_device; C:\WINDOWS\system32\lxcycoms.exe [2007-06-20 537264]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2006-09-11 135227]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-09-11 65599]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-06-11 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-06-19 219128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2006-12-23 262144]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Modrá smrt - windows XP

#3 Příspěvek od Roli »

Zdravím, nejdříve odstraníme nepořádek a pak se podíváme na tu modrou smrt.

Tohle fixni v HJT :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe


HJT najdeš zde :

C:\Program Files\trend micro\sokol.exe

Fix znamená že spustíš HJT Obrázek

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Ovládací panely >> Přidat nebo odebrat odinstaluj ICQ6Toolbar


Tohle :

C:\WINDOWS\system32\winsys2.exe

otestuj na VIRUSTOTAL

(po načtení stránky klikni na tlačítko Procházet, najdi cestu k výše zmíněnému souboru a klikni na tlačítko Odeslat soubor

trvá to okolo deseti minut pak mi sem zkopíruj link, to je ten řádek nahoře v prohlížeči)
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Re: Modrá smrt - windows XP

#4 Příspěvek od s-o-k-o-l »


Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Modrá smrt - windows XP

#5 Příspěvek od Roli »

Stáhni a spusť OTMoveIt

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe       

:files 
C:\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\Documents and Settings\sokol\Data aplikací\ESET

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci zkopírovat obsah logu uloženého na C:\_OTMoveIt\MovedFiles\



Návod na analýzu BSOD (modrá smrt)

Stáhni a nainstaluj Debugging Tools For Windows .

Přes Start >> Všechny programy vyhledej program s jménem WinDbg ve složce Debugging Tools for Window a spusť.

První co budeš muset nastavit je cesta k symbolům. Klikni na File -> Symbol File Path a zde nastav http://msdl.microsoft.com/download/symbols

Nyní můžeš začít analyzovat BSOD.

Klikni na File -> Open Crash Dump a najdi složku C:\Windows\Minidump.

Ve složce Minidumps se nacházejí soubory Minixxxxxx-xx.dmp (xxxxxx-xx je datum a pořadové číslo).

Pokud je složka prázdná neměl jsi ještě žádnou BSOD nebo jsi jí vymazal.

Jakmile soubor otevřeš začnou se načítat symboly a po chvilce můžeš zadávat přikazy do přikazového řádku, kde stačí napsat !analyze -v

nebo kliknout myší na příkaz.

Nejdůležitější parametry, které tě mohou zajímat jsou :

PROCESS_NAME (jméno procesu, který způsobil chybu),

IMAGE_NAME

MODULE_NAME

(tyto tři hodnoty mi sem nakopíruj)

Vypadá to asi TAKHLE
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Re: Modrá smrt - windows XP

#6 Příspěvek od s-o-k-o-l »

OTMoveIt

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\*.tmp not found.
C:\WINDOWS\System32\CONFIG.TMP moved successfully.
C:\WINDOWS\System32\SET4BE.tmp moved successfully.
C:\WINDOWS\System32\SET4C2.tmp moved successfully.
C:\WINDOWS\System32\SET4CA.tmp moved successfully.
C:\WINDOWS\System32\SET51A.tmp moved successfully.
C:\WINDOWS\System32\SETA5F.tmp moved successfully.
C:\WINDOWS\002582_.tmp moved successfully.
C:\WINDOWS\003117_.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET38.tmp moved successfully.
C:\WINDOWS\SET3B.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET47.tmp moved successfully.
C:\WINDOWS\SET72.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\SETA3.tmp moved successfully.
C:\WINDOWS\SETA6.tmp moved successfully.
C:\WINDOWS\SETB2.tmp moved successfully.
C:\WINDOWS\SETDD.tmp moved successfully.
C:\Documents and Settings\sokol\Data aplikací\ESET\ESET Smart Security folder moved successfully.
C:\Documents and Settings\sokol\Data aplikací\ESET folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: sokol
->Temp folder emptied: 11797044 bytes
->Temporary Internet Files folder emptied: 1906212 bytes
->Java cache emptied: 10680993 bytes
->FireFox cache emptied: 43901678 bytes
->Google Chrome cache emptied: 442430346 bytes
->Flash cache emptied: 41850 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 382540 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 371746960 bytes

Total Files Cleaned = 842,00 mb


OTM by OldTimer - Version 3.1.12.2 log created on 06202010_142409

Files moved on Reboot...
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.

Registry entries deleted on Reboot...

s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Re: Modrá smrt - windows XP

#7 Příspěvek od s-o-k-o-l »

dbg (19.06.2010)


Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Minidump\Mini061910-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt
Built by: 2600.xpsp_sp3_gdr.100216-1514
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Sat Jun 19 13:27:00.937 2010 (GMT+2)
System Uptime: 0 days 0:02:25.664
Loading Kernel Symbols
...............................................................
.............................................................
Loading User Symbols
Loading unloaded module list
...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007E, {c0000005, b3ffbc29, b84fbca4, b84fb9a0}

Probably caused by : netbt.sys ( netbt!NTExecuteWorker+18 )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: b3ffbc29, The address that the exception occurred at
Arg3: b84fbca4, Exception Record Address
Arg4: b84fb9a0, Context Record Address

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Instrukce na adrese 0x%08lx odkazovala na adresu pam

FAULTING_IP:
netbt!NTExecuteWorker+18
b3ffbc29 8b4620 mov eax,dword ptr [esi+20h]

EXCEPTION_RECORD: b84fbca4 -- (.exr 0xffffffffb84fbca4)
Cannot read Exception record @ b84fbca4

CONTEXT: b84fb9a0 -- (.cxr 0xffffffffb84fb9a0)
Unable to read context, Win32 error 0n30

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x7E

EXCEPTION_STR: 0x0

LAST_CONTROL_TRANSFER: from 80538789 to b3ffbc29

STACK_TEXT:
b84fbd7c 80538789 88d616f8 00000000 8a5b78b8 netbt!NTExecuteWorker+0x18
b84fbdac 805cff62 88d616f8 00000000 00000000 nt!ExpWorkerThread+0xef
b84fbddc 8054611e 8053869a 00000001 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


FOLLOWUP_IP:
netbt!NTExecuteWorker+18
b3ffbc29 8b4620 mov eax,dword ptr [esi+20h]

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: netbt!NTExecuteWorker+18

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: netbt

IMAGE_NAME: netbt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 48025d1b

STACK_COMMAND: .cxr 0xffffffffb84fb9a0 ; kb

FAILURE_BUCKET_ID: 0x7E_netbt!NTExecuteWorker+18

BUCKET_ID: 0x7E_netbt!NTExecuteWorker+18

Followup: MachineOwner
---------

dbg (12-06-2010)




Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Minidump\Mini061210-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 2600.xpsp_sp3_gdr.100216-1514
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Sat Jun 12 10:32:36.250 2010 (GMT+2)
System Uptime: 0 days 0:05:51.970
Loading Kernel Symbols
...............................................................
...............................................................
Loading User Symbols
Loading unloaded module list
..............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 10000050, {ebc00008, 0, 805058fe, 2}


Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MiFreeWsle+54 )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ebc00008, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 805058fe, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000002, (reserved)

Debugging Details:
------------------


Could not read faulting driver name

READ_ADDRESS: ebc00008

FAULTING_IP:
nt!MiFreeWsle+54
805058fe 83780801 cmp dword ptr [eax+8],1

MM_INTERNAL_CODE: 2

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: jqs.exe

LAST_CONTROL_TRANSFER: from 805059c8 to 805058fe

STACK_TEXT:
b3461b04 805059c8 00000090 c0883cfc c000e000 nt!MiFreeWsle+0x54
b3461b34 8064c9cb 0000007d 887666b8 00000002 nt!MiTrimWorkingSet+0x7c
b3461b64 805cbb2e 00000159 c0883000 00000000 nt!MmAdjustWorkingSetSizeEx+0x21b
b3461c18 805ce1b3 ffffffff 00000001 00bafd38 nt!PspSetQuotaLimits+0x202
b3461d4c 8054163c ffffffff 00000001 00bafd38 nt!NtSetInformationProcess+0x36f
b3461d4c 7c90e514 ffffffff 00000001 00bafd38 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
00bafd58 00000000 00000000 00000000 00000000 0x7c90e514


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!MiFreeWsle+54
805058fe 83780801 cmp dword ptr [eax+8],1

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!MiFreeWsle+54

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP: 4b7a9cac

IMAGE_NAME: memory_corruption

FAILURE_BUCKET_ID: 0x50_nt!MiFreeWsle+54

BUCKET_ID: 0x50_nt!MiFreeWsle+54

Followup: MachineOwner
---------

s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Re: Modrá smrt - windows XP

#8 Příspěvek od s-o-k-o-l »

06-09-2010


SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: Ntfs!NtfsLookupHashEntry+42

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME: Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 48025be5

STACK_COMMAND: .cxr 0xffffffffb366c244 ; kb

FAILURE_BUCKET_ID: 0x24_Ntfs!NtfsLookupHashEntry+42

BUCKET_ID: 0x24_Ntfs!NtfsLookupHashEntry+42

Followup: MachineOwner
---------


***************************************************************************


06-09-2010 (podruhé)

Debugging Details:
------------------


BUGCHECK_STR: 0x4E_8f

PFN_PAGE_SINGLE_BIT_ERROR: Bugcheck args 2 and 3 differ by a bit, its hardware error.

MEMORY_CORRUPTOR: ONE_BIT

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

PROCESS_NAME: System

LAST_CONTROL_TRANSFER: from 8051cbd0 to 804f9f43

STACK_TEXT:
b84c37f8 8051cbd0 0000004e 0000008f 0000d102 nt!KeBugCheckEx+0x1b
b84c3840 80698b94 89db9788 00000000 00000044 nt!MmZeroPageThread+0x250
b84c3dac 805cff62 80087000 00000000 00000000 nt!Phase1Initialization+0x1288
b84c3ddc 8054611e 8069790c 80087000 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


STACK_COMMAND: kb

FOLLOWUP_NAME: memory_corruption

MODULE_NAME: memory_corruption

IMAGE_NAME: memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP: 0

FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT

BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT

Followup: memory_corruption
---------


6-9-2010

PROCESS_NAME: steam.exe

SYMBOL_NAME: Ntfs!NtfsLookupHashEntry+42
IMAGE_NAME: Ntfs.sys
MODULE_NAME: Ntfs

Ještě jen tak uvažuju, nebude lepší spíš udělat formát celýho počítače když nato tak koukám

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Modrá smrt - windows XP

#9 Příspěvek od Roli »

No není toho zrovna málo.


Nejdříve stáhni HD Tune a otestuj HDD.

Benchmark - Test disku Klikni na tlačítko Start a vyčkej dokud se nezaplní celý graf. Poté se dozvíš přenosovou rychlost a přístupový čas pevného disku.

Info Přesná kapacita, souborový systém, podporované funkce, verze firmware, sériové číslo a typ zapojení disků.

Health - Kondice Seznam důležitých parametrů a jejich hodnoty. Ideální je mít všude OK.

Když je nějaká položka žlutá pravděpodobně brzy změní status na failed. Když je červená má status failed, to by znamenalo výměnu disku.

Error Scan - Hledání chyb Klikni na tlačítko Start a program prozkoumá disk zda na něm nejsou vadné bloky.

Pokud na konci testu jsou všechny zelené, je vše v pořádku. Když je byť jeden z nich červený, doporučuji zazálohovat data a počítat s výměnou disku.

Teplota Teploměr nahoře a číslo vedle něj znázorňují teplotu disku. Normální hodnota je pod 50°C. Teplota ale nesmí přesáhnout 60°C, program upozorní když dosáhne hranice 55°C.


Pak dej vědět jak to dopadlo.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Re: Modrá smrt - windows XP

#10 Příspěvek od s-o-k-o-l »

zatim posílam obrázky 3/4, ještě se dělá poslední test s těma čtverečkama zelenýma, ale vypadá to, že skončí dobře, kdyby ne, ještě dopíšu, zatim přikládam ostatní 3, (jdu do práce, takže ať aspoň něco sem hodim). Jinak díky moc za dosavadní pomoc.

http://img37.imageshack.us/i/222rx.jpg/
http://img685.imageshack.us/i/111utb.jpg/

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Modrá smrt - windows XP

#11 Příspěvek od Roli »

Zatím to vypadá dobře, ještě počkáme na ten poslední test.

Kdyby i ten byl OK zkusil bych opravu systému.

V Bios Setup do kterého se dostaneš při restartu mačkáním klávesy :

* DEL
* F2
* F1
* F10

záleží na PC, ale vždy je to na monitoru napsáno,

otevři nabídku ADVANCED BIOS FEATURES a vyhledej Boot Devices 0 až 4 nebo Boot Sequence.

Na první místo nastav CD-ROM,

na druhé pevný disk HDD, u obou položek bývá napsán i výrobce.

Stisknutím Save většinou je to F10 a potvrzením Entrem uložíš nastavení,

pak ještě stisknutím Save and Exit se dostaneš z Biosu a můžeš začít s opravou.

Vlož instalační CD do mechaniky, nech nabootovat,

chvíli počkej zobrazí se první obrazovka kde klávesou Enter potvrdíš spuštění instalace Windows,

v další obrazovce klávesou F8 potvrdíš licenční ujednání,

v další obrazovce pak klávesou R zvol Opravit stávající instalaci Windows

podrobný postup ZDE

Tímto postupem nepřijdeš o žádná data.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

s-o-k-o-l
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 08 úno 2010 14:35

Re: Modrá smrt - windows

#12 Příspěvek od s-o-k-o-l »

poslední test dopadl dobře, což sem šťastnej, že nemam nic s HD. Provedu opravu teda. Díky ti moc za předešlé analýzy, nebylo toho zrovínka málo. Ještě jednou díky.

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Modrá smrt - windows XP

#13 Příspěvek od Roli »

Zatím není zač a pak dej vědět jak to dopadlo.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět