Stránka 1 z 1

Modrá smrt + zamrzání

Napsal: 22 lis 2010 12:38
od Castab
Dobrý den. Počítač mi už delší dobu zamrzá (např při přehrávání videí na internetu), ale dnes kolem 8:00 se počítač začal chovat divně. Prvně se sekl (nucený restart) a po 8-15min modrá smrt. Při tom jsem měl spuštěné aplikace Wow.exe (hra) a Chrome (wowhead.com), nevím jestli to s tím souvisí, alek když mam tuhle stránku zaplou i hru tak se mi hra seká. Jinak s tou hrou mam errory a ty jsem si vyhledal na internetu a zjistil jsem, že to může být právě funkcí alt + tab, nebo také, že je počítač zatížen, popřípadě ramky. Vím, že tohle asi není podstatné, ale radši to sem napíšu jestli to s tím nějak nesouvisí, ale taky je možnost, že počítač je napaden virem. Mockrát děkuji za váš vzácný čas, který obětujete mému problému. Předem moc děkuji :worship:.

// 12:57 Sám od sebe se mi restartoval PC, když jsem měl spuštěno Wow.exe (nic jiného). Po spuštění systému mi asi 30s nešli načítat stránky (webová stránka není dostupná).

Logfile of random's system information tool 1.08 (written by random/random)
Run by Kebaß at 2010-11-01 12:32:33
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 112 GB (74%) free of 153 GB
Total RAM: 1023 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:32:46, on 1.11.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Documents and Settings\Kebaß\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kebaß\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kebaß\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kebaß\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Kebaß.exe
C:\Documents and Settings\Kebaß\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 4917 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-09-27 1250696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2003-11-13 62464]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-16 86016]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
"MSConfig"=C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [2008-04-14 171008]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ekrn"=2
"JavaQuickStarterService"=2
"ServiceLayer"=3
"PLFlash DeviceIoControl Service"=2

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoRealMode"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Gamesy\World of Warcraft\WoW-3.2.0-enGB-downloader.exe"="C:\Gamesy\World of Warcraft\WoW-3.2.0-enGB-downloader.exe:*:Disabled:Blizzard Downloader"
"C:\Gamesy\World of Warcraft\Launcher.exe"="C:\Gamesy\World of Warcraft\Launcher.exe:*:Disabled:Blizzard Launcher"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-11-10 07:04:45 ----D---- C:\WINDOWS\Temp
2010-11-06 21:04:19 ----A---- C:\WINDOWS\system32\btw_ci.dll
2010-11-06 20:15:44 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Nokia
2010-11-06 20:15:41 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\PC Suite
2010-11-06 20:15:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\PC Suite
2010-11-06 20:13:44 ----D---- C:\Program Files\DIFX
2010-11-06 20:13:42 ----A---- C:\WINDOWS\system32\drivers\pccsmcfd.sys
2010-11-06 20:13:37 ----D---- C:\Program Files\PC Connectivity Solution
2010-11-06 20:13:32 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-11-06 20:13:30 ----D---- C:\Program Files\Nokia
2010-11-06 20:11:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\Installations
2010-11-06 20:05:32 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2010-11-06 20:04:35 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2010-11-01 12:31:10 ----D---- C:\WINDOWS\LastGood
2010-11-01 12:30:36 ----D---- C:\Program Files\ESET
2010-11-01 12:30:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-11-01 08:02:52 ----D---- C:\Program Files\CCleaner
2010-10-31 17:58:58 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\WeGame
2010-10-31 17:58:03 ----A---- C:\WINDOWS\system32\Ltkrn15u.dll
2010-10-31 17:58:03 ----A---- C:\WINDOWS\system32\Ltfil15u.dll
2010-10-31 17:58:03 ----A---- C:\WINDOWS\system32\Lfcmp15u.dll
2010-10-31 17:58:01 ----D---- C:\Program Files\WeGame
2010-10-28 17:54:55 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\skypePM
2010-10-28 17:52:22 ----D---- C:\Program Files\Common Files\Skype
2010-10-28 17:52:15 ----RD---- C:\Program Files\Skype
2010-10-28 17:52:14 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Skype
2010-10-28 17:52:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-10-28 10:17:09 ----D---- C:\Fraps
2010-10-28 10:01:40 ----A---- C:\WINDOWS\system32\javaws.exe
2010-10-28 10:01:40 ----A---- C:\WINDOWS\system32\javaw.exe
2010-10-28 10:01:40 ----A---- C:\WINDOWS\system32\java.exe
2010-10-27 18:23:37 ----SHD---- C:\RECYCLER
2010-10-27 18:19:43 ----A---- C:\ComboFix.txt
2010-10-27 18:13:23 ----A---- C:\WINDOWS\zip.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\SWSC.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\SWREG.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\sed.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\PEV.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\NIRCMD.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\MBR.exe
2010-10-27 18:13:23 ----A---- C:\WINDOWS\grep.exe
2010-10-27 18:12:24 ----D---- C:\WINDOWS\ERDNT
2010-10-27 18:12:21 ----D---- C:\Qoobox
2010-10-27 13:01:28 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-10-27 12:49:58 ----D---- C:\Program Files\Microsoft.NET
2010-10-27 12:48:53 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Windows Search
2010-10-27 12:48:08 ----D---- C:\WINDOWS\system32\GroupPolicy
2010-10-27 12:48:08 ----D---- C:\Program Files\Windows Desktop Search
2010-10-27 12:47:59 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-10-27 12:47:13 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2010-10-27 12:37:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Weskysoft
2010-10-22 21:55:49 ----D---- C:\WINDOWS\nview
2010-10-21 12:15:48 ----D---- C:\WINDOWS\Sun
2010-10-20 14:16:20 ----A---- C:\WINDOWS\unTMV.exe
2010-10-20 14:14:01 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\ODF
2010-10-20 14:13:46 ----D---- C:\Program Files\OD Fellowship
2010-10-14 06:08:04 ----A---- C:\WINDOWS\system32\Audio3D.dll
2010-10-14 06:08:04 ----A---- C:\WINDOWS\system32\a3d.dll
2010-10-14 06:08:03 ----A---- C:\WINDOWS\system32\drivers\ALCXSENS.SYS
2010-10-14 06:08:01 ----N---- C:\WINDOWS\alcupd.exe
2010-10-14 06:08:01 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-14 05:28:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-10-14 05:27:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-10-14 05:27:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-10-14 05:26:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-10-14 05:26:13 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-10-14 05:26:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-10-14 05:25:54 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-10-14 05:25:16 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-10-14 05:21:19 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-10-14 05:21:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-10-06 19:17:10 ----D---- C:\Program Files\Lavalys
2010-10-05 20:05:15 ----A---- C:\Boot.bak
2010-10-05 20:05:13 ----RASHD---- C:\cmdcons
2010-10-05 18:27:34 ----D---- C:\Program Files\Teamspeak2_RC2
2010-10-05 17:19:18 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\TS3Client
2010-10-05 15:36:38 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-10-05 06:13:34 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-10-04 19:37:07 ----N---- C:\WINDOWS\alcrmv.exe
2010-10-04 19:37:07 ----A---- C:\WINDOWS\system32\RTLCPAPI.dll
2010-10-04 19:37:07 ----A---- C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010-10-04 19:37:07 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-10-04 19:19:22 ----A---- C:\WINDOWS\NeroDigital.ini
2010-10-04 17:04:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
2010-10-04 06:51:48 ----D---- C:\WINDOWS\system32\Lang
2010-10-04 06:44:15 ----A---- C:\WINDOWS\system32\nvumpu.exe
2010-10-03 14:27:30 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2010-10-03 14:26:03 ----D---- C:\Program Files\MSBuild
2010-10-03 14:26:00 ----D---- C:\WINDOWS\system32\XPSViewer
2010-10-03 14:25:55 ----D---- C:\WINDOWS\system32\en-us
2010-10-03 14:25:55 ----D---- C:\Program Files\Reference Assemblies
2010-10-03 14:25:35 ----N---- C:\WINDOWS\system32\spmsg2.dll
2010-10-03 14:20:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-10-03 14:20:23 ----D---- C:\Program Files\Common Files\Java
2010-10-03 14:20:13 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-10-03 14:19:58 ----D---- C:\Program Files\Java
2010-10-03 14:19:45 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Sun
2010-10-03 14:13:20 ----D---- C:\WINDOWS\system32\appmgmt
2010-10-03 14:13:16 ----D---- C:\WINDOWS\SxsCaPendDel
2010-10-03 13:58:48 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-10-03 12:58:49 ----D---- C:\rsit
2010-10-03 10:09:47 ----D---- C:\Program Files\MSXML 4.0
2010-10-02 23:25:16 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2010-10-02 23:21:45 ----D---- C:\Program Files\Nero
2010-10-02 23:20:18 ----D---- C:\WINDOWS\RegisteredPackages
2010-10-02 23:19:33 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-10-02 23:19:31 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-10-02 22:29:56 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Malwarebytes
2010-10-02 22:29:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-10-02 22:29:44 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-10-02 14:24:05 ----D---- C:\WINDOWS\Minidump
2010-10-02 13:21:34 ----D---- C:\WINDOWS\pss
2010-10-02 13:06:36 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\AskToolbar
2010-10-02 12:32:04 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Nero
2010-10-02 12:31:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-10-02 12:31:01 ----D---- C:\Program Files\Common Files\Nero
2010-10-02 12:28:27 ----A---- C:\WINDOWS\system32\AdvrCntr4.dll
2010-10-02 00:55:26 ----D---- C:\Program Files\trend micro

======List of files/folders modified in the last 1 months======

2010-11-10 08:02:11 ----D---- C:\WINDOWS\Debug
2010-11-10 06:59:18 ----A---- C:\WINDOWS\system32\MRT.exe
2010-11-06 21:04:23 ----D---- C:\WINDOWS\system32
2010-11-06 20:13:33 ----D---- C:\WINDOWS\system32\CatRoot
2010-11-06 20:13:32 ----D---- C:\WINDOWS\Prefetch
2010-11-06 20:12:14 ----D---- C:\WINDOWS\WinSxS
2010-11-06 20:06:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-11-01 12:32:16 ----RASH---- C:\boot.ini
2010-11-01 12:32:16 ----A---- C:\WINDOWS\win.ini
2010-11-01 12:32:16 ----A---- C:\WINDOWS\system.ini
2010-11-01 12:32:07 ----RD---- C:\Program Files
2010-11-01 12:31:17 ----SHD---- C:\WINDOWS\Installer
2010-11-01 12:31:11 ----HD---- C:\WINDOWS\inf
2010-11-01 12:31:11 ----D---- C:\WINDOWS\system32\drivers
2010-11-01 12:31:10 ----AD---- C:\WINDOWS
2010-11-01 12:31:09 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-01 12:26:34 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-31 10:52:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-10-28 17:52:22 ----D---- C:\Program Files\Common Files
2010-10-28 10:22:43 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\teamspeak2
2010-10-28 03:00:46 ----D---- C:\WINDOWS\Microsoft.NET
2010-10-28 02:42:44 ----D---- C:\Program Files\WinRAR
2010-10-27 19:11:11 ----SHD---- C:\System Volume Information
2010-10-27 18:31:34 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-10-27 18:31:26 ----D---- C:\WINDOWS\system32\wbem
2010-10-27 18:31:26 ----D---- C:\WINDOWS\system32\cs-CZ
2010-10-27 18:17:57 ----D---- C:\WINDOWS\system32\drivers\etc
2010-10-27 18:16:14 ----D---- C:\WINDOWS\AppPatch
2010-10-27 13:03:56 ----D---- C:\WINDOWS\system32\config
2010-10-27 12:37:07 ----SD---- C:\WINDOWS\Tasks
2010-10-27 09:36:36 ----D---- C:\Documents and Settings
2010-10-22 21:55:52 ----D---- C:\WINDOWS\Help
2010-10-19 00:02:20 ----SD---- C:\Documents and Settings\Kebaß\Data aplikací\Microsoft
2010-10-14 06:08:20 ----D---- C:\WINDOWS\system
2010-10-14 06:07:59 ----D---- C:\Program Files\Common Files\InstallShield
2010-10-14 05:28:15 ----HD---- C:\WINDOWS\$hf_mig$
2010-10-14 05:24:26 ----D---- C:\Program Files\Internet Explorer
2010-10-06 19:15:52 ----D---- C:\WINDOWS\system32\Restore
2010-10-05 17:18:39 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-10-04 17:00:30 ----D---- C:\NVIDIA
2010-10-04 16:53:26 ----RSD---- C:\WINDOWS\Fonts
2010-10-03 14:38:09 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2010-10-02 23:21:42 ----D---- C:\WINDOWS\Cursors
2010-10-02 23:20:46 ----D---- C:\WINDOWS\security
2010-10-02 23:20:46 ----D---- C:\Program Files\Windows Media Player
2010-10-02 00:36:53 ----D---- C:\Gamesy

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BtHidBus;Bluetooth HID Bus Service; C:\WINDOWS\System32\Drivers\BtHidBus.sys [2008-07-31 20616]
R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-08-03 95896]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-11-13 391680]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-11-13 481596]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 NVENET;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2004-01-29 93764]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
S3 btkrnl;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\KEBA~1\LOCALS~1\Temp\catchme.sys []
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 IvtBtBUs;IVT Bluetooth Bus Service; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R4 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]

-----------------EOF-----------------

Re: Modrá smrt + zamrzání

Napsal: 22 lis 2010 15:18
od Rudy
Nic nebezpečného nevidím. Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.