Stránka 1 z 1

Generic Host Process

Napsal: 05 čer 2011 08:46
od Shoily
Zdravím, předtím, než se začal s tímhle threadem, tak sem se snažil sám přijít na to co s tím je apod... ale bohužel sem na to velkej mamlas a jediné co se mi povedlo, najít nějaké patche ale ty nepomohly protože uz takové mám s SP 3...proto se obracím sem a doufám, že mi nějak pomůžete. Z ničeho nic mi včera naskočila tabulka, která obsahovala chybu s Generic host process a jeslti to mám odeslat jako chybu atd pro windows, poté chybě už mi nejel zvuk... Zkusil sem tu projet pár threadu a tak sem udělal scan s RSIT i HJT a tady mám to co mi vyjelo, sem z toho úplnej jelen, takže se prosím někdo inteligentní podívejte a řěkněte mi co mám dělat... ale prosím polopatě, děkuji :)

TOhle je z RSIT
-----------------

Logfile of random's system information tool 1.08 (written by random/random)
Run by Xtreme at 2011-06-05 09:37:41
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 30 GB (78%) free of 38 GB
Total RAM: 1023 MB (9% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:37:46, on 5.6.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
F:\Downloads\hijack analyza\hijackthis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
F:\Downloads\hijack analyza\RSIT.exe
C:\Program Files\trend micro\Xtreme.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [Steam] "F:\Games\Css\Steam.exe" -silent
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-602162358-839522115-1606980848-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 4934 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll [2011-04-11 767280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-04-07 13891176]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-02-24 1753192]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2011-03-17 74752]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-05-10 3459712]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"NPSStartup"= []
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-08-02 577536]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"Xvid"=C:\Program Files\Xvid\CheckUpdate.exe [2011-01-17 8192]
"Steam"=F:\Games\Css\Steam.exe -silent []
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"F:\Games\Css\Steam.exe"="F:\Games\Css\Steam.exe:*:Enabled:Steam"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"F:\Games\Steam\steamapps\COEN\counter-strike source\hl2.exe"="F:\Games\Steam\steamapps\COEN\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-06-05 09:37:42 ----D---- C:\Program Files\trend micro
2011-06-05 09:37:41 ----D---- C:\rsit
2011-06-05 09:09:58 ----A---- C:\WINDOWS\eSellerateEngine.dll
2011-06-05 09:09:57 ----D---- C:\Program Files\Svchost Fix Wizard
2011-06-05 09:09:57 ----A---- C:\WINDOWS\eSellerateControl350.dll
2011-06-04 21:40:05 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-06-04 21:39:49 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-06-04 21:39:39 ----D---- C:\Program Files\Realtek Sound Manager
2011-06-04 21:39:38 ----D---- C:\Program Files\AvRack
2011-06-04 21:39:37 ----A---- C:\WINDOWS\avrack.ini
2011-06-04 21:39:21 ----D---- C:\Program Files\Realtek AC97
2011-06-04 21:39:17 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-06-04 21:39:11 ----A---- C:\WINDOWS\soundman.exe
2011-06-04 21:39:08 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-06-04 21:39:03 ----A---- C:\WINDOWS\alcupd.exe
2011-06-04 21:39:03 ----A---- C:\WINDOWS\Alcrmv.exe
2011-05-30 16:36:52 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\OpenOffice.org
2011-05-30 16:32:20 ----D---- C:\Program Files\OpenOffice.org 3
2011-05-30 16:31:48 ----SHD---- C:\Config.Msi
2011-05-26 17:00:45 ----RD---- C:\Program Files\Skype
2011-05-26 17:00:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-05-26 16:59:37 ----D---- C:\WINDOWS\system32\appmgmt
2011-05-23 22:50:31 ----A---- C:\WINDOWS\RtlRack.ini
2011-05-23 15:03:20 ----D---- C:\Downloads
2011-05-23 11:29:16 ----A---- C:\WINDOWS\system32\nmwcdcls.dll
2011-05-23 11:29:10 ----A---- C:\WINDOWS\system32\drivers\pccsmcfd.sys
2011-05-23 11:28:40 ----A---- C:\WINDOWS\system32\drivers\ss_bwhnt.sys
2011-05-23 11:28:40 ----A---- C:\WINDOWS\system32\drivers\ss_bwh.sys
2011-05-23 11:28:40 ----A---- C:\WINDOWS\system32\drivers\ss_bbus.sys
2011-05-23 11:28:27 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
2011-05-23 11:28:24 ----D---- C:\Program Files\DIFX
2011-05-23 11:28:20 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-05-23 11:27:50 ----A---- C:\WINDOWS\system32\FsUsbExService.Exe
2011-05-23 11:27:50 ----A---- C:\WINDOWS\system32\FsUsbExDisk.Sys
2011-05-23 11:27:50 ----A---- C:\WINDOWS\system32\FsUsbExDevice.Dll
2011-05-23 11:27:15 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\Samsung
2011-05-23 11:26:28 ----D---- C:\Program Files\MarkAny
2011-05-23 11:26:25 ----D---- C:\Program Files\PC Connectivity Solution
2011-05-23 11:24:35 ----D---- C:\Program Files\Samsung
2011-05-21 09:12:03 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\BitComet
2011-05-21 09:12:02 ----D---- C:\Program Files\BitComet
2011-05-20 02:19:47 ----D---- C:\Program Files\Matroska Pack
2011-05-19 19:19:08 ----D---- C:\Program Files\Common Files\Adobe
2011-05-19 19:19:08 ----D---- C:\Program Files\Adobe
2011-05-19 19:14:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-05-19 16:01:07 ----D---- C:\Program Files\Teamspeak2_RC2
2011-05-19 15:48:46 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-05-19 15:48:46 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-05-19 15:48:44 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-05-19 15:48:43 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-05-19 15:48:43 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-05-19 15:48:42 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-05-19 15:48:42 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-05-19 15:48:41 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-05-19 15:48:23 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-05-19 15:48:10 ----D---- C:\Program Files\AVAST Software
2011-05-19 15:48:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-05-18 23:31:04 ----D---- C:\Program Files\K-Lite Codec Pack
2011-05-18 23:16:02 ----A---- C:\WINDOWS\iun6002.exe
2011-05-18 23:15:54 ----D---- C:\WINDOWS\system32\languages
2011-05-18 23:15:54 ----D---- C:\Program Files\Codec Pack - All In 1
2011-05-18 23:14:40 ----A---- C:\WINDOWS\Codec Pack - All In 1 Setup Log.txt
2011-05-18 22:11:08 ----D---- C:\Program Files\Common Files\Steam
2011-05-18 21:53:56 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2011-05-18 21:53:56 ----A---- C:\WINDOWS\system32\xvidcore.dll
2011-05-18 21:53:55 ----D---- C:\Program Files\Xvid
2011-05-18 17:23:35 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\WinRAR
2011-05-18 17:15:32 ----SHD---- C:\RECYCLER
2011-05-18 17:14:42 ----D---- C:\Program Files\WinRAR
2011-05-18 16:51:58 ----D---- C:\WINDOWS\system32\Lang
2011-05-18 16:09:22 ----A---- C:\WINDOWS\War3Unin.pif
2011-05-18 16:09:22 ----A---- C:\WINDOWS\War3Unin.exe
2011-05-18 16:04:48 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\Skype
2011-05-18 16:00:14 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2011-05-18 16:00:14 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2011-05-18 16:00:05 ----D---- C:\WINDOWS\Logs
2011-05-18 16:00:00 ----D---- C:\Program Files\Winamp Detect
2011-05-18 15:59:20 ----D---- C:\WINDOWS\RegisteredPackages
2011-05-18 15:58:55 ----N---- C:\WINDOWS\system32\drivers\PxHelp20.sys
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\vxblock.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxwma.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxwave.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxsfs.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxmas.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxinsi64.exe
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxdrv.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxcpyi64.exe
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\pxafs.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\px.dll
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\drivers\cdralw2k.sys
2011-05-18 15:58:54 ----N---- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2011-05-18 15:58:51 ----D---- C:\Program Files\Winamp
2011-05-18 15:58:51 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\Winamp
2011-05-18 15:56:40 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2011-05-18 15:56:30 ----D---- C:\Program Files\DAEMON Tools Lite
2011-05-18 15:56:16 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\DAEMON Tools Lite
2011-05-18 15:56:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2011-05-18 15:53:26 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\Macromedia
2011-05-18 15:53:26 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\Adobe
2011-05-18 15:51:29 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\teamspeak2
2011-05-18 15:43:06 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\Mozilla
2011-05-18 15:43:01 ----D---- C:\Program Files\Mozilla Firefox
2011-05-18 15:36:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2011-05-18 15:36:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
2011-05-18 15:35:36 ----A---- C:\WINDOWS\system32\OpenCL.dll
2011-05-18 15:35:35 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2011-05-18 15:35:35 ----A---- C:\WINDOWS\system32\nvgenco322060.dll
2011-05-18 15:35:35 ----A---- C:\WINDOWS\system32\nvdispco3220140.dll
2011-05-18 15:35:35 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2011-05-18 15:35:35 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2011-05-18 15:35:35 ----A---- C:\WINDOWS\system32\nvcuda.dll
2011-05-18 15:35:34 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2011-05-18 15:35:34 ----A---- C:\WINDOWS\system32\nvapi.dll
2011-05-18 15:35:34 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2011-05-18 15:35:34 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2011-05-18 15:34:42 ----D---- C:\Program Files\NVIDIA Corporation
2011-05-18 15:32:28 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2011-05-18 15:32:27 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2011-05-18 15:32:25 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2011-05-18 15:32:23 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2011-05-18 15:32:21 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2011-05-18 15:32:20 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2011-05-18 15:32:19 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2011-05-18 15:32:17 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2011-05-18 15:32:15 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011-05-18 15:32:13 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2011-05-18 15:32:11 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011-05-18 15:32:05 ----A---- C:\WINDOWS\system32\ksuser.dll
2011-05-18 15:32:05 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2011-05-18 15:32:05 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2011-05-18 15:31:47 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-18 15:31:16 ----D---- C:\Program Files\Marvell
2011-05-18 15:27:40 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-05-18 15:27:00 ----A---- C:\WINDOWS\system32\nvunrm.exe
2011-05-18 15:26:59 ----A---- C:\WINDOWS\system32\nvusmb.exe
2011-05-18 15:26:59 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2011-05-18 15:26:56 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-05-18 15:26:56 ----A---- C:\WINDOWS\system32\nvugart.exe
2011-05-18 15:25:06 ----D---- C:\Program Files\Common Files\InstallShield
2011-05-18 15:24:24 ----A---- C:\WINDOWS\system32\drivers\nvsnpu.sys
2011-05-18 15:24:24 ----A---- C:\WINDOWS\system32\drivers\nvnrm.sys
2011-05-18 15:24:24 ----A---- C:\WINDOWS\system32\drivers\nvnetbus.sys
2011-05-18 15:24:24 ----A---- C:\WINDOWS\system32\drivers\NVENETFD.sys
2011-05-18 15:24:24 ----A---- C:\WINDOWS\system32\drivers\nv_agp.SYS
2011-05-18 15:24:20 ----A---- C:\WINDOWS\system32\nvconrm.dll
2011-05-18 15:24:20 ----A---- C:\WINDOWS\system32\NVCOG.DLL
2011-05-18 15:24:20 ----A---- C:\WINDOWS\system32\fdco1ins.dll
2011-05-18 15:24:20 ----A---- C:\WINDOWS\system32\fdco1.dll
2011-05-18 15:24:20 ----A---- C:\WINDOWS\system32\bdco1ins.dll
2011-05-18 15:24:20 ----A---- C:\WINDOWS\system32\bdco1.dll
2011-05-18 15:24:17 ----D---- C:\drivers
2011-05-18 13:47:06 ----A---- C:\WINDOWS\system32\h323log.txt
2011-05-18 13:31:59 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2011-05-18 13:31:28 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2011-05-18 13:30:32 ----A---- C:\WINDOWS\system32\usbui.dll
2011-05-18 13:29:28 ----SHD---- C:\WINDOWS\Installer
2011-05-18 13:29:28 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-05-18 13:29:27 ----D---- C:\Program Files\Common Files\ODBC
2011-05-18 13:29:27 ----A---- C:\WINDOWS\ODBCINST.INI
2011-05-18 13:29:23 ----RD---- C:\Program Files
2011-05-18 13:29:23 ----D---- C:\Program Files\Common Files\SpeechEngines
2011-05-18 13:29:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-05-18 13:29:23 ----D---- C:\Program Files\Common Files
2011-05-18 13:29:19 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2011-05-18 13:29:19 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2011-05-18 13:29:19 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdur.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdru.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2011-05-18 13:29:18 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2011-05-18 13:29:16 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2011-05-18 13:29:16 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2011-05-18 13:29:16 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2011-05-18 13:29:16 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2011-05-18 13:29:16 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2011-05-18 13:29:16 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2011-05-18 13:29:16 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2011-05-18 13:29:15 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2011-05-18 13:29:15 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2011-05-18 13:29:15 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2011-05-18 13:29:15 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2011-05-18 13:29:15 ----RA---- C:\WINDOWS\system32\kbdest.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdro.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2011-05-18 13:29:11 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2011-05-18 13:29:09 ----A---- C:\WINDOWS\system32\spxcoins.dll
2011-05-18 13:29:09 ----A---- C:\WINDOWS\system32\irclass.dll
2011-05-18 13:29:09 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2011-05-18 13:29:09 ----A---- C:\WINDOWS\system32\dgsetup.dll
2011-05-18 13:29:09 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2011-05-18 13:29:07 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2011-05-18 13:29:07 ----A---- C:\WINDOWS\TASKMAN.EXE
2011-05-18 13:29:07 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2011-05-18 13:29:07 ----A---- C:\WINDOWS\system32\batt.dll
2011-05-18 13:29:07 ----A---- C:\WINDOWS\NOTEPAD.EXE
2011-05-18 13:29:03 ----A---- C:\WINDOWS\system32\storprop.dll
2011-05-18 13:28:55 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2011-05-18 13:27:24 ----RA---- C:\WINDOWS\SET8.tmp
2011-05-18 13:27:22 ----RA---- C:\WINDOWS\SET4.tmp
2011-05-18 13:27:20 ----RA---- C:\WINDOWS\SET3.tmp
2011-05-18 13:27:15 ----D---- C:\WINDOWS\system32\CatRoot2
2011-05-18 13:27:15 ----D---- C:\WINDOWS\system32\CatRoot
2011-05-18 13:27:09 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-05-18 13:26:54 ----A---- C:\WINDOWS\setuplog.txt
2011-05-18 13:26:49 ----SHD---- C:\System Volume Information
2011-05-18 13:26:49 ----D---- C:\Documents and Settings
2011-05-18 13:26:07 ----RASH---- C:\boot.ini
2011-05-18 13:23:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-05-18 13:23:31 ----RSD---- C:\WINDOWS\Fonts
2011-05-18 13:23:31 ----RD---- C:\WINDOWS\Web
2011-05-18 13:23:31 ----HD---- C:\WINDOWS\inf
2011-05-18 13:23:31 ----D---- C:\WINDOWS\WinSxS
2011-05-18 13:23:31 ----D---- C:\WINDOWS\twain_32
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Temp
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\wins
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\wbem
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\usmt
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\spool
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\ShellExt
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\Setup
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\ras
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\oobe
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\npp
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\mui
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\inetsrv
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\IME
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\icsxml
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\ias
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\export
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\drivers\etc
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\drivers\disdn
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\drivers
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\dhcp
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\cs-cz
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\cs
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\config
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\3com_dmi
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\3076
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\2052
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1054
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1042
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1041
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1037
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1033
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1031
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1029
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1028
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32\1025
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system32
2011-05-18 13:23:31 ----D---- C:\WINDOWS\system
2011-05-18 13:23:31 ----D---- C:\WINDOWS\security
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Resources
2011-05-18 13:23:31 ----D---- C:\WINDOWS\repair
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Provisioning
2011-05-18 13:23:31 ----D---- C:\WINDOWS\pchealth
2011-05-18 13:23:31 ----D---- C:\WINDOWS\PeerNet
2011-05-18 13:23:31 ----D---- C:\WINDOWS\NLDRV
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Network Diagnostic
2011-05-18 13:23:31 ----D---- C:\WINDOWS\mui
2011-05-18 13:23:31 ----D---- C:\WINDOWS\msapps
2011-05-18 13:23:31 ----D---- C:\WINDOWS\msagent
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Media
2011-05-18 13:23:31 ----D---- C:\WINDOWS\L2Schemas
2011-05-18 13:23:31 ----D---- C:\WINDOWS\java
2011-05-18 13:23:31 ----D---- C:\WINDOWS\ime
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Help
2011-05-18 13:23:31 ----D---- C:\WINDOWS\ehome
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Driver Cache
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Debug
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Cursors
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Connection Wizard
2011-05-18 13:23:31 ----D---- C:\WINDOWS\Config
2011-05-18 13:23:31 ----D---- C:\WINDOWS\AppPatch
2011-05-18 13:23:31 ----D---- C:\WINDOWS\addins
2011-05-18 13:23:31 ----D---- C:\WINDOWS
2011-05-18 13:23:31 ----ASH---- C:\pagefile.sys
2011-05-18 12:13:26 ----A---- C:\WINDOWS\ntbtlog.txt
2011-05-18 12:07:08 ----D---- C:\NVIDIA
2011-05-18 12:04:12 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2011-05-18 12:00:59 ----D---- C:\Documents and Settings\Xtreme\Data aplikací\Identities
2011-05-18 12:00:57 ----HD---- C:\Program Files\Uninstall Information
2011-05-18 12:00:47 ----ASH---- C:\Documents and Settings\Xtreme\Data aplikací\desktop.ini
2011-05-18 12:00:46 ----SD---- C:\Documents and Settings\Xtreme\Data aplikací\Microsoft
2011-05-18 11:59:11 ----D---- C:\WINDOWS\SoftwareDistribution
2011-05-18 11:59:10 ----D---- C:\WINDOWS\Prefetch
2011-05-18 11:59:09 ----SD---- C:\WINDOWS\system32\Microsoft
2011-05-18 11:59:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-05-18 11:52:43 ----D---- C:\WINDOWS\system32\xircom
2011-05-18 11:52:43 ----D---- C:\Program Files\xerox
2011-05-18 11:52:43 ----D---- C:\Program Files\microsoft frontpage
2011-05-18 11:52:17 ----RASH---- C:\MSDOS.SYS
2011-05-18 11:52:17 ----RASH---- C:\IO.SYS
2011-05-18 11:52:17 ----A---- C:\WINDOWS\control.ini
2011-05-18 11:52:17 ----A---- C:\CONFIG.SYS
2011-05-18 11:52:17 ----A---- C:\AUTOEXEC.BAT
2011-05-18 11:52:01 ----A---- C:\WINDOWS\OEWABLog.txt
2011-05-18 11:51:57 ----A---- C:\WINDOWS\system32\mapi32.dll
2011-05-18 11:51:02 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-05-18 11:51:02 ----RD---- C:\WINDOWS\Offline Web Pages
2011-05-18 11:51:02 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2011-05-18 11:50:56 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2011-05-18 11:50:51 ----HD---- C:\Program Files\WindowsUpdate
2011-05-18 11:50:47 ----D---- C:\Program Files\Online Services
2011-05-18 11:50:33 ----D---- C:\WINDOWS\system32\DirectX
2011-05-18 11:50:29 ----A---- C:\WINDOWS\system32\atrace.dll
2011-05-18 11:50:27 ----A---- C:\WINDOWS\system32\desktop.ini
2011-05-18 11:50:27 ----A---- C:\WINDOWS\desktop.ini
2011-05-18 11:50:21 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2011-05-18 11:50:20 ----D---- C:\Program Files\Common Files\Services
2011-05-18 11:50:20 ----A---- C:\WINDOWS\system32\acctres.dll
2011-05-18 11:50:18 ----SD---- C:\WINDOWS\Tasks
2011-05-18 11:50:18 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2011-05-18 11:50:17 ----D---- C:\Program Files\Common Files\MSSoap
2011-05-18 11:50:14 ----D---- C:\WINDOWS\srchasst
2011-05-18 11:50:13 ----D---- C:\WINDOWS\system32\Macromed
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wuweb.dll
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wups.dll
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wucltui.dll
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wuauserv.dll
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wuaueng.dll
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2011-05-18 11:50:11 ----A---- C:\WINDOWS\system32\wuauclt.exe
2011-05-18 11:50:10 ----A---- C:\WINDOWS\system32\wuapi.dll
2011-05-18 11:50:10 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2011-05-18 11:50:10 ----A---- C:\WINDOWS\system32\qmgr.dll
2011-05-18 11:50:10 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2011-05-18 11:50:10 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2011-05-18 11:50:10 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2011-05-18 11:50:08 ----D---- C:\Program Files\Movie Maker
2011-05-18 11:49:55 ----A---- C:\WINDOWS\system32\safrslv.dll
2011-05-18 11:49:55 ----A---- C:\WINDOWS\system32\safrdm.dll
2011-05-18 11:49:55 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2011-05-18 11:49:55 ----A---- C:\WINDOWS\system32\racpldlg.dll
2011-05-18 11:49:53 ----A---- C:\WINDOWS\system32\fltMc.exe
2011-05-18 11:49:53 ----A---- C:\WINDOWS\system32\fltlib.dll
2011-05-18 11:49:53 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2011-05-18 11:49:52 ----D---- C:\WINDOWS\system32\Restore
2011-05-18 11:49:52 ----A---- C:\WINDOWS\system32\srsvc.dll
2011-05-18 11:49:52 ----A---- C:\WINDOWS\system32\srrstr.dll
2011-05-18 11:49:52 ----A---- C:\WINDOWS\system32\srclient.dll
2011-05-18 11:49:52 ----A---- C:\WINDOWS\system32\mnmdd.dll
2011-05-18 11:49:52 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2011-05-18 11:49:52 ----A---- C:\WINDOWS\system32\ils.dll
2011-05-18 11:49:52 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2011-05-18 11:49:51 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2011-05-18 11:49:51 ----A---- C:\WINDOWS\system32\msconf.dll
2011-05-18 11:49:51 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2011-05-18 11:49:49 ----D---- C:\Program Files\NetMeeting
2011-05-18 11:49:49 ----A---- C:\WINDOWS\system32\msoert2.dll
2011-05-18 11:49:49 ----A---- C:\WINDOWS\system32\msoeacct.dll
2011-05-18 11:49:49 ----A---- C:\WINDOWS\system32\inetres.dll
2011-05-18 11:49:48 ----A---- C:\WINDOWS\system32\inetcomm.dll
2011-05-18 11:49:47 ----D---- C:\Program Files\Outlook Express
2011-05-18 11:49:47 ----A---- C:\WINDOWS\system32\schedsvc.dll
2011-05-18 11:49:47 ----A---- C:\WINDOWS\system32\mstinit.exe
2011-05-18 11:49:47 ----A---- C:\WINDOWS\system32\mstask.dll
2011-05-18 11:49:47 ----A---- C:\WINDOWS\system32\icwphbk.dll
2011-05-18 11:49:47 ----A---- C:\WINDOWS\system32\icwdial.dll
2011-05-18 11:49:46 ----A---- C:\WINDOWS\system32\isign32.dll
2011-05-18 11:49:46 ----A---- C:\WINDOWS\system32\inetcfg.dll
2011-05-18 11:49:43 ----D---- C:\Program Files\Common Files\System
2011-05-18 11:49:40 ----D---- C:\Program Files\Internet Explorer
2011-05-18 11:48:57 ----D---- C:\Program Files\ComPlus Applications
2011-05-18 11:48:55 ----A---- C:\WINDOWS\vbaddin.ini
2011-05-18 11:48:55 ----A---- C:\WINDOWS\vb.ini
2011-05-18 11:48:51 ----D---- C:\WINDOWS\Registration
2011-05-18 11:48:43 ----D---- C:\Program Files\Windows Media Player
2011-05-18 11:48:36 ----D---- C:\Program Files\Messenger
2011-05-18 11:48:33 ----D---- C:\Program Files\MSN Gaming Zone
2011-05-18 11:48:33 ----A---- C:\WINDOWS\system32\write.exe
2011-05-18 11:48:26 ----A---- C:\WINDOWS\system32\sndvol32.exe
2011-05-18 11:48:26 ----A---- C:\WINDOWS\system32\hticons.dll
2011-05-18 11:48:26 ----A---- C:\WINDOWS\system32\avwav.dll
2011-05-18 11:48:26 ----A---- C:\WINDOWS\system32\avtapi.dll
2011-05-18 11:48:26 ----A---- C:\WINDOWS\system32\avmeter.dll
2011-05-18 11:48:25 ----A---- C:\WINDOWS\system32\winchat.exe
2011-05-18 11:48:21 ----A---- C:\WINDOWS\system32\getuname.dll
2011-05-18 11:48:20 ----A---- C:\WINDOWS\system32\winmine.exe
2011-05-18 11:48:20 ----A---- C:\WINDOWS\system32\sol.exe
2011-05-18 11:48:20 ----A---- C:\WINDOWS\system32\mshearts.exe
2011-05-18 11:48:20 ----A---- C:\WINDOWS\system32\charmap.exe
2011-05-18 11:48:20 ----A---- C:\WINDOWS\system32\calc.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\tslabels.ini
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\tskill.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\tscon.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\shadow.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\rwinsta.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\reset.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\regini.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\qwinsta.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\qappsrv.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\msg.exe
2011-05-18 11:48:19 ----A---- C:\WINDOWS\system32\freecell.exe
2011-05-18 11:48:18 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2011-05-18 11:48:18 ----A---- C:\WINDOWS\system32\logoff.exe
2011-05-18 11:48:18 ----A---- C:\WINDOWS\system32\cdmodem.dll
2011-05-18 11:48:14 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2011-05-18 11:48:13 ----A---- C:\WINDOWS\system32\sndrec32.exe
2011-05-18 11:48:13 ----A---- C:\WINDOWS\system32\mplay32.exe
2011-05-18 11:48:13 ----A---- C:\WINDOWS\system32\hypertrm.dll
2011-05-18 11:48:13 ----A---- C:\WINDOWS\system32\accwiz.exe
2011-05-18 11:48:12 ----D---- C:\Program Files\Windows NT
2011-05-18 11:48:12 ----A---- C:\WINDOWS\system32\spider.exe
2011-05-18 11:48:12 ----A---- C:\WINDOWS\system32\mspaint.exe
2011-05-18 11:48:12 ----A---- C:\WINDOWS\system32\clipbrd.exe
2011-05-18 11:48:11 ----A---- C:\WINDOWS\system32\tsgqec.dll
2011-05-18 11:48:11 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2011-05-18 11:48:11 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2011-05-18 11:48:11 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2011-05-18 11:48:11 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2011-05-18 11:48:11 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2011-05-18 11:48:11 ----A---- C:\WINDOWS\system32\aaclient.dll
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\termsrv.dll
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\sessmgr.exe
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\remotepg.dll
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\rdshost.exe
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\rdpclip.exe
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\rdchost.dll
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\qprocess.exe
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\mstscax.dll
2011-05-18 11:48:10 ----A---- C:\WINDOWS\system32\mstsc.exe
2011-05-18 11:48:09 ----D---- C:\WINDOWS\system32\MsDtc
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\xolehlp.dll
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\mtxoci.dll
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\msdtctm.dll
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\msdtclog.dll
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\icaapi.dll
2011-05-18 11:48:09 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2011-05-18 11:48:08 ----D---- C:\WINDOWS\system32\Com
2011-05-18 11:48:08 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2011-05-18 11:48:08 ----A---- C:\WINDOWS\system32\mtxex.dll
2011-05-18 11:48:08 ----A---- C:\WINDOWS\system32\mtxdm.dll
2011-05-18 11:48:08 ----A---- C:\WINDOWS\system32\msdtc.exe
2011-05-18 11:48:08 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2011-05-18 11:48:08 ----A---- C:\WINDOWS\system32\comaddin.dll
2011-05-18 11:48:08 ----A---- C:\WINDOWS\system32\colbact.dll
2011-05-18 11:48:07 ----A---- C:\WINDOWS\system32\stclient.dll
2011-05-18 11:48:07 ----A---- C:\WINDOWS\system32\comsvcs.dll
2011-05-18 11:48:07 ----A---- C:\WINDOWS\system32\comrepl.dll
2011-05-18 11:48:07 ----A---- C:\WINDOWS\system32\clbcatex.dll
2011-05-18 11:48:07 ----A---- C:\WINDOWS\system32\catsrvut.dll
2011-05-18 11:48:07 ----A---- C:\WINDOWS\system32\catsrvps.dll
2011-05-18 11:48:07 ----A---- C:\WINDOWS\system32\catsrv.dll
2011-05-18 11:48:06 ----A---- C:\WINDOWS\system32\comuid.dll
2011-05-18 11:48:06 ----A---- C:\WINDOWS\system32\comsnap.dll
2011-05-18 11:48:06 ----A---- C:\WINDOWS\system32\clbcatq.dll
2011-05-18 11:48:02 ----A---- C:\WINDOWS\system32\servdeps.dll
2011-05-18 11:48:02 ----A---- C:\WINDOWS\system32\mmfutil.dll
2011-05-18 11:48:01 ----A---- C:\WINDOWS\system32\licwmi.dll
2011-05-18 11:48:01 ----A---- C:\WINDOWS\system32\cmprops.dll
2011-05-18 11:47:55 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2011-05-18 11:47:55 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 months======

2011-05-18 13:29:22 ----A---- C:\WINDOWS\system.ini
2011-05-18 11:52:17 ----A---- C:\WINDOWS\win.ini
2011-05-18 11:51:46 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-05-10 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-05-10 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-05-10 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-05-10 307928]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-05-10 49240]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-05-18 218688]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-05-10 19544]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-05-10 102616]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-08-18 4017536]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-04-08 12501600]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-01-13 33408]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-01-13 12928]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-05-10 42184]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-04-07 155752]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-05-18 403240]

-----------------EOF-----------------


A tohle je z HJT
------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:30:57, on 5.6.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
F:\Downloads\hijack analyza\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [Steam] "F:\Games\Css\Steam.exe" -silent
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-602162358-839522115-1606980848-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 4558 bytes

Re: Generic Host Process

Napsal: 05 čer 2011 11:12
od Rudy
Toto vypadá OK. Ještě udělejte sken ComboFix a dejte log:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: Generic Host Process

Napsal: 05 čer 2011 21:51
od Shoily
Tak sem poslechl a stáhl Combofix, provedl to jak bylo řečeno, netrvalo to 10 min ale asi 40, tak sem šel na cigaretku a kafe, jak bylo doporučeno a než sem odešel zahlásli to tohle: Combofix detekoval přitomnost aktivity rootkitu a vyžaduje restart počítače, tak sem tak učinil, po restartu se to rozběhlo, vyběhla zase tabulka a jelo to ty fáze... čekal sem asi 10 min bylo tu u 10 fáze, tak sem šel pryč. Vrátil sem se asi po těch 40 minutách byla tam nějaká finální fáze konečně, dokončilo se to ale žádna tabulka s logem, který bych mohl vypsat se neobjevila a problém je stále, tak nevím co mám dělat, nějaké další rady ? :(

Re: Generic Host Process

Napsal: 05 čer 2011 22:11
od Rudy
Pokud nenajdete log v souboru c:\combofix.txt, udělejte nový sken, ale v nouz. režimu. Pak dejte log.

Re: Generic Host Process

Napsal: 06 čer 2011 23:29
od Shoily
Tak sem zkusil rozjet win v nouzovém režimu ale bohužel to nejde... Napsalo mi to, že nějaky požadovaný soubor byl smazán... tak co teď combofix sem zkusi lasi 8x a nikdy mi to nevyjelo log, vždy mi to napíše tu hlášku s rootkitem, restart a jede to těch 50 fází, při 50 to dojede, restartuje, naběhne win a jakoby se nic nestalo.

Re: Generic Host Process

Napsal: 07 čer 2011 08:40
od stell
Zaskok za kolegu.
:arrow: Stiahnite si prosím TDSSKiller a uložte ho na plochu.

2x-klik na TDSSKiller.exe- spustiť aplikáciu, potom na Spustiť kontrolu-klik- Start Scan.
Ak je infikovaný súbor detekovaný, bude predvolená akcia Cure, kliknite na tlačidlo Continue.
Ak podozrivý[suspicious] súbor je detekovaný, bude predvolená akcia Skip, kliknite na Continue.
Môže vás požiadať, aby ste reštartovali počítač na dokončenie procesu. Kliknite na Reboot Now.
Ak nevyžaduje reštart, kliknite na tlačidlo Report. Log súbor by sa mal objaviť. Prosím, skopírujte a vložte obsah súboru tu.
Ak je vyžadované reštartovanie počítača, správa je k dispozícii vo vašom koreňovom adresári (zvyčajne C:\ zložka) vo forme "TDSSKiller. _log.txt". Prosím, skopírujte a vložte obsah suboru tu.

Re: Generic Host Process

Napsal: 08 čer 2011 14:24
od Shoily
Zdravím,

tak sem provedl a konečně mám report, takže to přenechám odborníkům :)

REPORT
--------

2011/06/08 15:22:03.0453 2252 TDSS rootkit removing tool 2.5.4.0 Jun 7 2011 17:31:48
2011/06/08 15:22:03.0531 2252 ================================================================================
2011/06/08 15:22:03.0531 2252 SystemInfo:
2011/06/08 15:22:03.0531 2252
2011/06/08 15:22:03.0531 2252 OS Version: 5.1.2600 ServicePack: 3.0
2011/06/08 15:22:03.0531 2252 Product type: Workstation
2011/06/08 15:22:03.0531 2252 ComputerName: JUST-087B3BEB0B
2011/06/08 15:22:03.0531 2252 UserName: Xtreme
2011/06/08 15:22:03.0531 2252 Windows directory: C:\WINDOWS
2011/06/08 15:22:03.0531 2252 System windows directory: C:\WINDOWS
2011/06/08 15:22:03.0531 2252 Processor architecture: Intel x86
2011/06/08 15:22:03.0531 2252 Number of processors: 1
2011/06/08 15:22:03.0531 2252 Page size: 0x1000
2011/06/08 15:22:03.0531 2252 Boot type: Normal boot
2011/06/08 15:22:03.0531 2252 ================================================================================
2011/06/08 15:22:04.0859 2252 Initialize success
2011/06/08 15:22:10.0375 2280 ================================================================================
2011/06/08 15:22:10.0375 2280 Scan started
2011/06/08 15:22:10.0375 2280 Mode: Manual;
2011/06/08 15:22:10.0375 2280 ================================================================================
2011/06/08 15:22:11.0453 2280 Aavmker4 (3f6884eff406238d39aaa892218f1df7) C:\WINDOWS\system32\drivers\Aavmker4.sys
2011/06/08 15:22:11.0609 2280 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/06/08 15:22:11.0718 2280 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/06/08 15:22:11.0843 2280 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/06/08 15:22:11.0937 2280 AFD (322d0e36693d6e24a2398bee62a268cd) C:\WINDOWS\System32\drivers\afd.sys
2011/06/08 15:22:12.0296 2280 ALCXWDM (34149a136b2b7525113950233f259ec1) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2011/06/08 15:22:12.0750 2280 aswFsBlk (7f08d9c504b015d81a8abd75c80028c5) C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011/06/08 15:22:12.0828 2280 aswMon2 (c2181ef6b54752273a0759a968c59279) C:\WINDOWS\system32\drivers\aswMon2.sys
2011/06/08 15:22:12.0906 2280 aswRdr (ac48bdd4cd5d44af33087c06d6e9511c) C:\WINDOWS\system32\drivers\aswRdr.sys
2011/06/08 15:22:12.0968 2280 aswSnx (b64134316fcd1f20e0f10ef3e65bd522) C:\WINDOWS\system32\drivers\aswSnx.sys
2011/06/08 15:22:13.0062 2280 aswSP (d6788e3211afa9951ed7a4d617f68a4f) C:\WINDOWS\system32\drivers\aswSP.sys
2011/06/08 15:22:13.0093 2280 aswTdi (4d100c45517809439c7b6dd98997fa00) C:\WINDOWS\system32\drivers\aswTdi.sys
2011/06/08 15:22:13.0140 2280 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/06/08 15:22:13.0250 2280 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/06/08 15:22:13.0375 2280 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/06/08 15:22:13.0515 2280 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/06/08 15:22:13.0625 2280 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/06/08 15:22:13.0859 2280 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/06/08 15:22:14.0000 2280 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/06/08 15:22:14.0093 2280 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/06/08 15:22:14.0171 2280 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/06/08 15:22:14.0437 2280 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/06/08 15:22:14.0515 2280 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
2011/06/08 15:22:14.0656 2280 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
2011/06/08 15:22:14.0750 2280 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/06/08 15:22:14.0843 2280 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/06/08 15:22:14.0937 2280 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/06/08 15:22:15.0046 2280 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
2011/06/08 15:22:15.0140 2280 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/06/08 15:22:15.0203 2280 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/06/08 15:22:15.0281 2280 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
2011/06/08 15:22:15.0328 2280 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/06/08 15:22:15.0390 2280 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
2011/06/08 15:22:15.0468 2280 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS
2011/06/08 15:22:15.0546 2280 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/06/08 15:22:15.0593 2280 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/06/08 15:22:15.0687 2280 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/06/08 15:22:15.0781 2280 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/06/08 15:22:15.0906 2280 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/06/08 15:22:16.0078 2280 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/06/08 15:22:16.0156 2280 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/06/08 15:22:16.0312 2280 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
2011/06/08 15:22:16.0390 2280 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/06/08 15:22:16.0484 2280 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/06/08 15:22:16.0546 2280 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/06/08 15:22:16.0625 2280 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/06/08 15:22:16.0703 2280 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/06/08 15:22:16.0796 2280 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/06/08 15:22:16.0843 2280 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/06/08 15:22:16.0906 2280 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/06/08 15:22:17.0000 2280 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/06/08 15:22:17.0156 2280 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/06/08 15:22:17.0234 2280 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
2011/06/08 15:22:17.0328 2280 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/06/08 15:22:17.0406 2280 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/06/08 15:22:17.0484 2280 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/06/08 15:22:17.0578 2280 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/06/08 15:22:17.0687 2280 MRxSmb (68755f0ff16070178b54674fe5b847b0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/06/08 15:22:17.0828 2280 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/06/08 15:22:17.0906 2280 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/06/08 15:22:17.0953 2280 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/06/08 15:22:18.0015 2280 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/06/08 15:22:18.0078 2280 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/06/08 15:22:18.0140 2280 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/06/08 15:22:18.0250 2280 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/06/08 15:22:18.0296 2280 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/06/08 15:22:18.0390 2280 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/06/08 15:22:18.0437 2280 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/06/08 15:22:18.0515 2280 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/06/08 15:22:18.0562 2280 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/06/08 15:22:18.0640 2280 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/06/08 15:22:18.0734 2280 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/06/08 15:22:18.0828 2280 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/06/08 15:22:18.0984 2280 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/06/08 15:22:19.0468 2280 nv (f1de35c89d98a883d1b4030dc9896855) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/06/08 15:22:19.0906 2280 NVENETFD (ac050fdc2d24c678bc49b5d5671e13be) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
2011/06/08 15:22:20.0000 2280 nvnetbus (81339157c429aada7a6aea97f3177da7) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
2011/06/08 15:22:20.0125 2280 nv_agp (3194e2f6c9000c39dcf9d0580754f714) C:\WINDOWS\system32\DRIVERS\nv_agp.sys
2011/06/08 15:22:20.0218 2280 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/06/08 15:22:20.0281 2280 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/06/08 15:22:20.0359 2280 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/06/08 15:22:20.0406 2280 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/06/08 15:22:20.0484 2280 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/06/08 15:22:20.0562 2280 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
2011/06/08 15:22:20.0656 2280 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/06/08 15:22:20.0750 2280 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/06/08 15:22:20.0843 2280 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/06/08 15:22:21.0171 2280 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/06/08 15:22:21.0250 2280 Processor (7eb15dce4ec3a0220bd796a15c18186e) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/06/08 15:22:21.0312 2280 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/06/08 15:22:21.0375 2280 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/06/08 15:22:21.0468 2280 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/06/08 15:22:21.0765 2280 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/06/08 15:22:21.0843 2280 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/06/08 15:22:21.0890 2280 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/06/08 15:22:21.0953 2280 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/06/08 15:22:22.0031 2280 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/06/08 15:22:22.0109 2280 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/06/08 15:22:22.0187 2280 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/06/08 15:22:22.0281 2280 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/06/08 15:22:22.0390 2280 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/06/08 15:22:22.0515 2280 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/06/08 15:22:22.0593 2280 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/06/08 15:22:22.0687 2280 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/06/08 15:22:22.0750 2280 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/06/08 15:22:22.0921 2280 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/06/08 15:22:23.0000 2280 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/06/08 15:22:23.0093 2280 Srv (5252605079810904e31c332e241cd59b) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/06/08 15:22:23.0218 2280 ss_bbus (eaa66218cd39f5bb1b4853a78c67c787) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys
2011/06/08 15:22:23.0312 2280 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/06/08 15:22:23.0421 2280 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/06/08 15:22:23.0671 2280 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/06/08 15:22:23.0781 2280 Tcpip (93ea8d04ec73a85db02eb8805988f733) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/06/08 15:22:23.0906 2280 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/06/08 15:22:23.0984 2280 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/06/08 15:22:24.0062 2280 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/06/08 15:22:24.0203 2280 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/06/08 15:22:24.0343 2280 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/06/08 15:22:24.0468 2280 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/06/08 15:22:24.0578 2280 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/06/08 15:22:24.0656 2280 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2011/06/08 15:22:24.0734 2280 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/06/08 15:22:24.0812 2280 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/06/08 15:22:24.0921 2280 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/06/08 15:22:24.0984 2280 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/06/08 15:22:25.0093 2280 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/06/08 15:22:25.0218 2280 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
2011/06/08 15:22:25.0375 2280 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR3
2011/06/08 15:22:25.0390 2280 ================================================================================
2011/06/08 15:22:25.0390 2280 Scan finished
2011/06/08 15:22:25.0390 2280 ================================================================================
2011/06/08 15:22:25.0406 2192 Detected object count: 0
2011/06/08 15:22:25.0406 2192 Actual detected object count: 0

Re: Generic Host Process

Napsal: 08 čer 2011 14:36
od stell
1:Nevidim tam FirewaLL
Aky Firewall mas ??

2:
1:Stiahnuť aswMBR.exe na plochu.
http://public.avast.com/%7Egmerek/aswMBR.exe
2:Dvakrát kliknite na aswMBR.exe a spusťte
3:Kliknite na tlačidlo "Scan" pre spustenie skenovania
4:V prípade infekcie Kliknite na tlačidlo "Fix"
5:Uložte asw.log na plochu.
6:Obsah vloz sem:

3:1:Ak nemáte,tak nainštalovať Win XP update "WindowsXP-KB894391"
2:Nainštalovať Firewall xp Firewall nestači!!
3:Otvorte Notepad (Poznámkový blok) a skopíruj do neho text.

Kód: Vybrat vše

@ECHO off
ECHO Generic Host Process for Win32 Services OPRAVA (www.virusstell.blogspot.com )
REM script created by: www.virusstell.blogspot.com
reg add "HKLM\SYSTEM\CurrentControlSet\Services\netbt\parameters" /v "TransportBindName" /t REG_SZ /d "" /f
reg add "HKLM\Software\Microsoft\OLE" /v "EnableDCOM" /t REG_SZ /d "N" /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\Browser\Parameters" /v "IsDomainMaster" /t REG_SZ /d FALSE /f
Netsh Winsock Reset
Potom klikneme na záložku Súbor v menu Uložiť ako.. .. Ako je Názov súboru tak do toho riadku napíšeme:oprava.bat Typ súboru tak tam vyberiete všetky súbory A uložíme ho na plochu. 2 x klikneme naň,povolíme zápis do registra,reštartujeme počítač.

a Napis ako sa chova pc

Re: Generic Host Process

Napsal: 09 čer 2011 21:12
od Shoily
Firewall nemám, jelikož mi to dost znepříjemňuje jiné záležitosti po internetu


Tady je ten log
-----------------

aswMBR version 0.9.5.256 Copyright(c) 2011 AVAST Software
Run date: 2011-06-09 22:08:26
-----------------------------
22:08:26.008 OS Version: Windows 5.1.2600 Service Pack 3
22:08:26.008 Number of processors: 1 586 0x2C02
22:08:26.008 ComputerName: JUST-087B3BEB0B UserName: Xtreme
22:08:31.179 Initialize success
22:09:40.258 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
22:09:40.274 Disk 0 Vendor: ST340014A 3.06 Size: 38165MB BusType: 3
22:09:42.305 Disk 0 MBR read successfully
22:09:42.305 Disk 0 MBR scan
22:09:42.305 Disk 0 unknown MBR code
22:09:44.304 Disk 0 scanning sectors +78159872
22:09:44.336 Disk 0 scanning C:\WINDOWS\system32\drivers
22:09:48.835 Service scanning
22:09:50.038 Disk 0 trace - called modules:
22:09:50.038 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
22:09:50.038 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86513ab8]
22:09:50.038 3 CLASSPNP.SYS[f761cfd7] -> nt!IofCallDriver -> \Device\0000005f[0x86515f18]
22:09:50.038 5 ACPI.sys[f74b3620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86585940]
22:09:50.038 Scan finished successfully
22:10:25.733 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Xtreme\Plocha\MBR.dat"
22:10:25.733 The log file has been saved successfully to "C:\Documents and Settings\Xtreme\Plocha\asw.log"

Re: Generic Host Process

Napsal: 09 čer 2011 21:24
od stell
Tak to:
Firewall nemám, jelikož mi to dost znepříjemňuje jiné záležitosti po internetu
Pokial ne na instalujes Firewall, tento problem,hocikedy sa obnovy. Ide o otvorene porty, ktore nemas zabezpecene, a system ta bude upozornovat.

Teraz sprav toto:
Disk 0 unknown MBR code
:arrow: Spust AWSMBR>>klikni na FIXMBR>>restratni pocitac.
:arrow: Nainstaluj Firewall
http://www.viry.cz/forum/viewtopic.php? ... 36#p868836

:arrow: A sprav ten script, co som napisal. ak to vsetko nespravis, tak potom zbytocne budes plakat, ze mas problem s Generic Host Process.
Potom odskusaj a napis.

Re: Generic Host Process

Napsal: 10 čer 2011 16:25
od Shoily
Takže script sem vytvořil a použil a je po problému velice děkuji za spolupráci a že máte trpělivost i s takovým mamlasem, jako sem já.

Jen mám dotaz, nač všechny ty scany atd, když ve finále stačilo jen tohle ? Nebo to jste nějak vytvořili ten script z těch dajů ze scanů ?
Btw Firwall uz je nainstalován, někdo mi říkal, že když mám router, tak je fw zbytečný ale už nvm proč... Co je na tom pravdy ?

Re: Generic Host Process

Napsal: 10 čer 2011 16:48
od stell
Shoily píše:Takže script sem vytvořil a použil a je po problému velice děkuji za spolupráci a že máte trpělivost i s takovým mamlasem, jako sem já.

Jen mám dotaz, nač všechny ty scany atd, když ve finále stačilo jen tohle ? Nebo to jste nějak vytvořili ten script z těch dajů ze scanů ?
Btw Firwall uz je nainstalován, někdo mi říkal, že když mám router, tak je fw zbytečný ale už nvm proč... Co je na tom pravdy ?
Naco su scany??no ide o nezabezpecene porty, a wiry.cz je zamerane na zistenie pritomnosti smejdov v pocitaci.Takze kludne si mohol mat napadnuty pocitac.

Router nestaci, musis mat aj softverovy Firewall.
Firewall v XP>.nestaci
Firewall vo win7 je dostacujuci, tu uz netreba instalovat.
Nemas zaco. :)