Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:51, on 2008-02-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\slmdmsr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\ICQ6\ICQ.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Vítězslav - Fischer\Plocha\instalační programy\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.atlas.cz/?from=icqhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.defaulthomepage.info
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [FreeCall] "C:\program files\freecall.com\freecall\freecall.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Mp4 Player] "C:\Program Files\Mp4 Player\Mp4Player.exe" hmw
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O16 - DPF: {50E43D86-A74D-11D0-98CE-004005249458} (AnimatedGif Control) - https://www.mojebanka.cz/jars/confwiz/MVSGif.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FCD3CE3-A492-4922-83F4-68E53B911A10}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{1038C02A-56E6-4B99-AEC5-894720643805}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{2671F829-6C2B-4352-AB62-6C6F136F024C}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{33D94E3C-54E0-4207-A14D-BB6245535F95}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BDBE977-5A85-4D80-9B5A-80A5F83D07EC}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB64C662-BB6B-4881-8B21-3B88E180039C}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4065618-4CCE-4EF0-AC59-7CFE5C858C63}: NameServer = 205.191.194.14
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FCD3CE3-A492-4922-83F4-68E53B911A10}: NameServer = 205.191.194.14
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slmdmsr.exe
--
End of file - 8111 bytes
prosim o kontrolu logu
Re: prosim o kontrolu logu
Zdravim!
Toto v okne programu HijackThis zafixujte:
HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FCD3CE3-A492-4922-83F4-68E53B911A10}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{1038C02A-56E6-4B99-AEC5-894720643805}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{2671F829-6C2B-4352-AB62-6C6F136F024C}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{33D94E3C-54E0-4207-A14D-BB6245535F95}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BDBE977-5A85-4D80-9B5A-80A5F83D07EC}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB64C662-BB6B-4881-8B21-3B88E180039C}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4065618-4CCE-4EF0-AC59-7CFE5C858C63}: NameServer = 205.191.194.14
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FCD3CE3-A492-4922-83F4-68E53B911A10}: NameServer = 205.191.194.14
Pri zafixovani O17 moze dojst ku znefukcneni internetoveho pripojenia. V takom pripade sa prihlaste este raz pod udajmi vasho providera.
Po tom urobte novy log a skopirujte ho sem.
Zatím nic nefixuj, jsou tyto adresy DNS serveru tvého poskytovatele
fredik
Toto v okne programu HijackThis zafixujte:
HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FCD3CE3-A492-4922-83F4-68E53B911A10}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{1038C02A-56E6-4B99-AEC5-894720643805}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{2671F829-6C2B-4352-AB62-6C6F136F024C}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{33D94E3C-54E0-4207-A14D-BB6245535F95}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BDBE977-5A85-4D80-9B5A-80A5F83D07EC}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB64C662-BB6B-4881-8B21-3B88E180039C}: NameServer = 205.191.194.14
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4065618-4CCE-4EF0-AC59-7CFE5C858C63}: NameServer = 205.191.194.14
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FCD3CE3-A492-4922-83F4-68E53B911A10}: NameServer = 205.191.194.14
Pri zafixovani O17 moze dojst ku znefukcneni internetoveho pripojenia. V takom pripade sa prihlaste este raz pod udajmi vasho providera.
Po tom urobte novy log a skopirujte ho sem.
Zatím nic nefixuj, jsou tyto adresy DNS serveru tvého poskytovatele
fredik
- zlobyl
- Tvůrce článků
-
Level 4.5
- Příspěvky: 1760
- Registrován: duben 06
- Bydliště: Slaný
- Pohlaví:
- Stav:
Offline
- Kontakt:
Fixni:
Dále můžeš fixnout takové ty lišty od ICQ, pokud je nepoužíváš:
Dále bych doporučil aktualizovat javu-ke stažení třeba zde.
Jinak je to jen prevence, nebo jsou s PC nějaké problémy?
Kód: Vybrat vše
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
Dále můžeš fixnout takové ty lišty od ICQ, pokud je nepoužíváš:
Kód: Vybrat vše
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
Dále bych doporučil aktualizovat javu-ke stažení třeba zde.
Jinak je to jen prevence, nebo jsou s PC nějaké problémy?
Prosím, omluvte mou častou nepřítomnost na fóru.Bohužel jsou věci, které člověk nemůže ovlivnit a já tudíž nemám moc času, abych se sem dostal.Budu se snažit tady být vždy, když to bude možné, ale nic zaručit nemohu.Je mi to líto.
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 63 hostů