Prosím o kontrolu logu. Dík.

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 15 dub 2008 19:29

Téma rozděleno, příště si založ vlastní téma, i kdyby se v daném tématu řešil stejný problém jako máš ty.
fredik


Preji dobry vecer.....

Jsem stary kozel....uz pres 50 jařin,ale delam chyby v PC.....no jo stari...chtel bych poprosit..jestli by jste se me nepodivali na logo......a dalsi vec......dekuji moc.....



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:09:20, on 15.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
D:\AvastPro\aswUpdSv.exe
D:\AvastPro\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spoolsv.exe
D:\AvastPro\ashDisp.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\History Sweeper\sweeper.exe
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\AvastPro\ashMaiSv.exe
D:\AvastPro\ashWebSv.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] D:\AvastPro\ashDisp.exe
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [Sweeper.exe] C:\Program Files\History Sweeper\sweeper.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout pomocí FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout vše pomocí FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O21 - SSODL: ogxtsepr - {11950FF4-1E7F-4782-BF43-5762784FFB81} - C:\WINDOWS\ogxtsepr.dll
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\AvastPro\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\AvastPro\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\AvastPro\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\AvastPro\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 10788 bytes

===================================================

dale me to vyhazuje chybu nekolikrat za den .....

instrukce na adrese 0x03c8508c odkazovala na adresu pameti 0x00000020.s pametí nelze provest operaci:read.
Klepnutim na tlacitko OK ukoncete program.


====================================================

dalsi......................

runtime error!

program:C/Programnfiles/internet explorer/explore.exe

R6025
- pure virtual function call


====================================================


dalsi.......................

pri spusteni nebo nebo i v prubehu me naskakuje oznameni,ze jsem zapojen offline....

======================================================

pouzivam Operu a IE 7.....Opera bez problemů...ale ,v prubehu pripojeni na net....jsem pripojen pres Operu a znicehonic se me spusti IE a naskoci me stranka Bitdefender centrum...uz jsem z toho vseho nestastny....
viz....

Kód: Vybrat vše

http://www.system-defender.com/freeware/2/?wmid=6010&mid=MjI6Mzc6MTgxNjM=&lndid=37&p=01


Dik moooooocccccccc za pomoc!!!!!!!!!!


Zdravi Hranolo

Obrázek
Naposledy upravil(a) hranol dne 16 dub 2008 01:49, celkem upraveno 1 x.

Reklama
Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod fredik » 15 dub 2008 20:53

Vítej na fóru

Stáhni si SDFix
- Spusť ho a rozbalí se ti na disk kde je nainstalovaný Windows (typicky to je C:\SDfix)
- Pak restartuj PC do nouzového režimu (zvol možnost: Stav nouze, ne Stav nouze s práci v síti)
- Otevři adresář kde je vybalený SDFix a spusť soubor RunThis.bat tím spustíš program.
* Pak stiskni klávesu Y a pak Enter pro zahájení čistícího procesu.
* Pro dokončení kontroly budeš vyzván ke stisknoutí libovolné klávesy a počítač se restartuje.
* Při nabíhání operačního systému se program spustí znovu a dokončí čistící proces. Až se objeví Finish, budeš muset po vyzvání stisknout libovolnou klávesu, tim se ukončí program a zobrazí se ti ikony na ploše
- Když se skončí načítání ikon na ploše, otevře se ti na obrazovce log z SDFix a zároveň ho uloží do adresáře kde je rozbalený SDFix jako soubor Report.txt
Pak sem zkopíruj jeho obsah + nový log z HijackThis.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 16 dub 2008 00:49

Jo...jasny...ja to bral...jako stejny.....dik moc....no zkusim to....

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 16 dub 2008 01:48

SDFix: Version 1.171
Run by hranol on st 16.04.2008 at 19:54

Microsoft Windows XP [Verze 5.1.2600]
Running From: C:\PROGRA~1\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 20:06:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:87,59,51,95,5f,01,36,53,d0,df,de,ce,82,84,7e,67,e6,d1,f2,00,27,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:87,59,51,95,5f,01,36,53,d0,df,de,ce,82,84,7e,67,e6,d1,f2,00,27,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:87,59,51,95,5f,01,36,53,d0,df,de,ce,82,84,7e,67,e6,d1,f2,00,27,..

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?v?e?l?k?é?)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?n?e?j?v?\e\1t?a\1í?)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
"D:\\Office12\\OUTLOOK.EXE"="D:\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\\Office12\\GROOVE.EXE"="D:\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"D:\\Office12\\ONENOTE.EXE"="D:\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Chronograph\\chrono.exe"="C:\\Program Files\\Chronograph\\chrono.exe:*:Enabled:Chronograph"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Ad Muncher\\AdMunch.exe"="C:\\Program Files\\Ad Muncher\\AdMunch.exe:*:Enabled:AdMunch"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\PROGRA~1\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 4 Aug 2007 48 ..SH. --- "C:\WINDOWS\S0602AC15.tmp"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Sun 3 Feb 2008 23 A.SH. --- "C:\WINDOWS\system32\ecfdef_r.dll"
Sun 16 Mar 2008 23 A.SH. --- "C:\WINDOWS\system32\ecfdef_z.dll"
Thu 17 May 2007 23 A.SH. --- "C:\WINDOWS\system32\faecaf9_r.dll"
Thu 16 Feb 2006 72,704 ..SHR --- "C:\Program Files\AsefSoft\Quick Smile 3\Uninstall.exe"
Sat 2 Feb 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT61.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\18b19374451d28a8fbaf1939cf31ff45\BIT65.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT60.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\911362f9031af35c5b51e12ecc909800\BIT62.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ddd366874e802b7f73320d55edd2e34f\BIT64.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e691f694d870764b4c31a5eb30b26139\BIT63.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f3a3b2a2e8ef3845fb7855c997a48858\BIT66.tmp"

Finished!


nejde me nahodit napoveda a odborna pomoc.......


================================================================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:21:57, on 16.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [8cf3f77c] rundll32.exe "C:\WINDOWS\system32\twxxmvux.dll",b
O4 - HKLM\..\Run: [BM8fc0c4e0] Rundll32.exe "C:\WINDOWS\system32\mrfegpyi.dll",s
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\AvastPro\aswUpdSv.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 10573 bytes

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod fredik » 16 dub 2008 22:58

Rezidentní ochranu od Spybota máš zapnutou?, protože neběží ale je nastaveno její spouštění.

Takže mrkni se jestli je zapnuta a pokud bude tak ji vypni :
- spusť Spybot - Search & Destroy
- nahoře v menu zvol: Režim => Pro pokročilé
- objeví se ti varovné okno kde zvol Ano
- okno programu se ti přepne do pokročilého zobrazení a tam zvol: Nástroje => Rezidentní
- tam zruš zatržení pokud bude u položky: Rezidentní program "TeaTimer" (Ochrana ...)
tt.JPG
- zavři program
Restartuj PC.

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Stáhni si ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 17 dub 2008 09:57

ComboFix 08-04-16.5 - hranol 2008-04-17 9:27:00.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.539 [GMT 2:00]
Running from: C:\Documents and Settings\hranol\Plocha\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 38
pv: No matching processes found
Nesprávná syntaxe příkazu


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\auhrxwhc.ini
C:\WINDOWS\system32\fsrixmrp.ini
C:\WINDOWS\system32\LnnUBcdd.ini
C:\WINDOWS\system32\LnnUBcdd.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mopAyGgh.ini
C:\WINDOWS\system32\mopAyGgh.ini2
C:\WINDOWS\system32\qvghwyhj.ini
C:\WINDOWS\system32\Rqtuvyay.ini
C:\WINDOWS\system32\Rqtuvyay.ini2
C:\WINDOWS\system32\sysdm.exe
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\UvxEOqru.ini
C:\WINDOWS\system32\UvxEOqru.ini2
C:\WINDOWS\system32\yayvutqR.dll
C:\WINDOWS\system32\yJQtsuvw.ini
C:\WINDOWS\system32\yJQtsuvw.ini2

.
((((((((((((((((((((((((( Files Created from 2008-03-17 to 2008-04-17 )))))))))))))))))))))))))))))))
.

2008-04-16 17:08 . 2008-04-16 17:55 <DIR> d-------- C:\Program Files\Avira
2008-04-16 13:46 . 2008-04-16 19:08 1,570,343 ---hs---- C:\WINDOWS\system32\xuvmxxwt.ini
2008-04-16 13:45 . 2008-04-16 18:06 101,197 --a------ C:\WINDOWS\BM8fc0c4e0.xml
2008-04-16 00:57 . 2008-04-16 00:58 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-16 00:48 . 2008-04-16 20:12 <DIR> d-------- C:\Program Files\SDFix
2008-04-16 00:28 . 2008-04-16 00:28 <DIR> d-------- C:\Program Files\ESET
2008-04-15 18:55 . 2008-04-15 18:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 06:24 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-14 06:24 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-14 06:24 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-14 06:24 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-14 06:24 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-14 06:24 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-14 06:24 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-14 06:24 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-14 06:24 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-14 02:30 . 2008-04-14 02:30 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 20:19 . 2008-04-13 22:33 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-13 13:09 . 2004-08-17 15:49 2,026,496 --a------ C:\WINDOWS\system32\netshell.backup
2008-04-13 13:09 . 2003-04-16 14:00 1,232,384 --a------ C:\WINDOWS\system32\write.backup
2008-04-13 13:09 . 2007-06-13 15:23 1,033,728 --a------ C:\WINDOWS\explorer.backup
2008-04-13 13:09 . 2004-08-17 15:49 260,096 --a------ C:\WINDOWS\system32\sndrec32.backup
2008-04-13 13:09 . 2005-07-06 14:58 219,648 --a------ C:\WINDOWS\system32\uxtheme.backup
2008-04-13 13:09 . 2003-04-16 14:00 152,064 --a------ C:\WINDOWS\system32\sndvol32.backup
2008-04-13 13:09 . 2004-08-17 15:49 77,824 --a------ C:\WINDOWS\system32\stobject.backup
2008-04-13 13:08 . 2007-10-25 18:44 8,464,384 --a------ C:\WINDOWS\system32\shell32.backup
2008-04-13 13:08 . 2004-08-17 15:49 924,672 --a------ C:\WINDOWS\system32\spider.backup
2008-04-13 13:08 . 2003-04-16 14:00 512,512 --a------ C:\WINDOWS\system32\mshearts.backup
2008-04-13 13:08 . 2003-04-16 14:00 504,832 --a------ C:\WINDOWS\system32\winmine.backup
2008-04-13 13:08 . 2003-04-16 14:00 441,856 --a------ C:\WINDOWS\system32\sol.backup
2008-04-13 13:08 . 2003-04-16 14:00 440,320 --a------ C:\WINDOWS\system32\freecell.backup
2008-04-13 13:08 . 2004-08-17 15:49 69,632 --a------ C:\WINDOWS\notepad.backup
2008-04-13 13:07 . 2001-11-08 06:56 6,094,336 --a------ C:\WINDOWS\system32\logonui.backup
2008-04-13 13:07 . 2004-08-17 15:48 2,927,616 --a------ C:\WINDOWS\system32\xpsp2res.backup
2008-04-13 13:07 . 2004-08-17 15:49 1,671,680 --a------ C:\WINDOWS\system32\msgina.backup
2008-04-13 13:07 . 2004-08-17 15:49 847,360 --a------ C:\WINDOWS\system32\mydocs.backup
2008-04-13 13:07 . 2004-08-17 15:49 727,040 --a------ C:\WINDOWS\system32\mspaint.backup
2008-04-13 13:07 . 2003-04-16 14:00 465,920 --a------ C:\WINDOWS\system32\charmap.backup
2008-04-13 13:07 . 2003-04-16 14:00 117,760 --a------ C:\WINDOWS\system32\calc.backup
2008-04-13 13:07 . 2004-08-17 15:49 76,288 --a------ C:\WINDOWS\system32\magnify.backup
2008-04-13 13:06 . 2004-08-17 15:49 2,376,704 --a------ C:\WINDOWS\system32\shimgvw.backup
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\WINDOWS\VCP_SAVE
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Wallpapers
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Fonts
2008-04-13 13:03 . 2005-09-28 02:31 49,152 --a------ C:\WINDOWS\system32\icon.exe
2008-04-13 13:02 . 2008-04-13 13:09 <DIR> d-------- C:\WINDOWS\VCP_TEMP
2008-04-13 12:38 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-04-13 01:22 . 2008-04-13 01:25 2,554 --a------ C:\WINDOWS\unins000.dat
2008-04-12 22:38 . 2008-04-12 23:12 354 --ahs---- C:\WINDOWS\system32\iatqmtmc.ini
2008-04-12 18:51 . 2008-04-12 19:39 466 --ahs---- C:\WINDOWS\system32\ugplfqaj.ini
2008-04-11 13:17 . 2008-04-11 13:17 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-04-11 13:13 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-11 13:09 . 2008-04-11 13:29 104,643 --a------ C:\WINDOWS\hpoins04.dat
2008-04-11 13:09 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat
2008-04-11 12:45 . 2008-01-14 18:44 104,250 --------- C:\WINDOWS\hpoins04.dat.temp
2008-04-11 12:45 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat.temp
2008-04-09 08:08 . 2008-03-01 15:02 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-09 08:08 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-09 08:08 . 2007-03-08 07:09 1,024,000 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-09 08:08 . 2008-03-01 15:02 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-09 08:08 . 2008-03-01 15:02 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-09 08:08 . 2008-03-01 15:02 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-09 08:08 . 2008-03-01 15:02 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-09 08:08 . 2008-03-01 15:02 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-09 08:08 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-06 10:22 . 2008-04-06 10:22 <DIR> d-------- C:\Program Files\inKline Global
2008-03-22 06:29 . 2008-03-22 06:29 <DIR> d-------- C:\Program Files\directx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 14:45 --------- d-----w C:\Program Files\PowerArchiver
2008-04-16 03:16 --------- d-----w C:\Program Files\Java
2008-04-14 01:41 --------- d-----w C:\Program Files\FlashGet
2008-04-13 19:18 --------- d-----w C:\Program Files\H264
2008-04-13 07:53 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-13 07:11 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-04-12 23:25 72,537 ----a-w C:\WINDOWS\unins000.exe
2008-04-06 11:50 --------- d-----w C:\Program Files\Opera
2008-04-03 06:13 --------- d-----w C:\Program Files\CD Eject Tool
2008-03-17 19:06 --------- d-----w C:\Program Files\History Sweeper
2008-03-16 07:43 --------- d-----w C:\Program Files\totalcmd
2008-03-16 07:07 --------- d-----w C:\Program Files\Ashampoo
2008-03-15 15:33 --------- d-----w C:\Program Files\Webteh
2008-03-13 14:52 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-03-13 14:52 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-03-13 14:52 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-03-13 14:44 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-03-13 14:43 40,456 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-03-12 12:05 --------- d-----w C:\Program Files\%temp&
2008-03-02 18:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-29 19:48 --------- d-----w C:\Program Files\FastStone Capture
2008-02-24 07:26 --------- d-----w C:\Program Files\DivX
2008-02-24 07:03 --------- d-----w C:\Program Files\Internet Download Manager
2007-05-17 21:16 23 -csha-w C:\WINDOWS\system32\faecaf9_r.dll
.

------- Sigcheck -------

2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\explorer.exe
2007-06-13 15:11 1033728 9b32416bd5988c97b6397ce0b02caf97 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2003-04-16 14:00 1004544 11d80755545cfb5eb9659ee88440eae2 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-17 15:49 4918784 c6c0c8de8425eed7c666f10f5d9104f0 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2007-06-13 15:23 1033728 ed7b460b142a32097b8a8f6ecc941815 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\VCP_TEMP\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02715E47-5A8E-495B-8F63-0D30470B8E72}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03FF3484-1297-4C3A-ACBE-212F5454A3A2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09FFD943-C05E-4B80-8893-46AD971FE34E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FB0E60C-BFC0-4DBD-8084-698CDB280AF7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{121E4E37-30F9-4DEA-9160-5166F5522BAE}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15ACA267-FDFD-4A1E-81B0-E211F0BAFED4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A43C67A-0787-4436-B0FD-B25BF65498CA}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C6E4C4F-36FD-4EDE-A6BE-D244F8BF66A1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{21EA63A7-04EB-41FF-9EF2-9382B8458885}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23E5396C-AC49-4D96-83E2-2A59E1E5AAA3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2766E49D-FAD1-4C13-B78A-9C038FD797DF}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2776798E-74DF-4499-A893-EEA0F32BCF1E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{288395DD-F28F-4E1E-9415-A40A0C81679F}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AEE8F68-BFB8-4D05-87D4-361BB69F109A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ACF159E-367E-454B-8E15-A94980B69FA6}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3BD1BD0B-9B33-4298-B6F7-40F97AFE039D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{443695FE-8E2B-49CC-BC65-499C39E7F3B3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CA86686-2441-4973-BCA4-B817F6B52927}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51A67331-7A47-4016-A705-205DCE341360}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{52A1B778-3C44-4EBA-AA2A-D8044ED18487}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53020DEF-D30A-4443-A76F-9EF08524BA18}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{594A022E-4C88-4AAF-BB18-EC272D257FB5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60B58FAF-1385-4918-B248-06C730A9C909}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60C06EB2-00DC-46FF-8DDF-D892FB65EBA9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6730A117-332F-477F-8977-9CB21743CFEB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6DEB2CD9-D07F-4A0E-9858-4E497F0EC508}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{763A8F24-01F1-4FE3-B7B7-B112FF07E25B}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{78C16285-70C9-493C-AA86-CA7E5C43E223}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7936A975-CD71-47C5-9B7F-CF849DF460CB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{81A83AA6-1712-4DE2-B7CD-19FA613CBBC3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8562332D-A8F5-4395-A28E-BBC45855E56D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{885E8919-33F0-4AF5-93F3-0C428BF3FA46}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A5DBEBA-3277-428A-B6A5-2E81EE9C1B13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F1E2C9B-0F73-4BD5-A641-FF3FC334C5A1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91D761C1-F3DF-4A2F-8C6A-B8A4073C9705}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97DCEDC8-04C8-4D37-AC6F-EEA7D17A1BC9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D30B3F7-8411-4C66-AF72-95CE9B73F6E9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACFDB92D-A0D9-4B22-AF23-D0C28B7A8A74}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BD0B5165-B525-4C86-BEBB-ABA416A6719C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CFDA6CCD-E94F-4D08-8E24-B7DFFDD53FBA}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DB470C87-8A40-45CB-94A8-8936A775931E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E45E37BD-600F-4224-A827-AED1D3043BE0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E8D03F4A-2731-43A3-B1E3-3481A212D996}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F20FEEC0-B86E-4337-A363-640D9F567ED5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA7D85A4-3C51-44C3-88D7-34DB5271DAE7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBE1F40F-29BC-4A6E-A109-DBC7B10E5395}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBFFDD72-0C03-4CAD-9865-16FF32AC9AC9}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="C:\Program Files\Chronograph\chrono.exe" [2007-04-26 00:04 3762768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-07-02 23:28 171448]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-02-21 08:44 2594224]
"PowerArchiver Tray"="C:\Program Files\PowerArchiver\PASTARTER.EXE" [2008-01-24 19:36 141352]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"RestoreDesktop"="C:\Program Files\Restore Desktop\RestoreDesktop.exe" [2003-03-11 10:52 45056]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SeznamAntidialer"="C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe" [2005-01-24 11:11 286720]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"GrooveMonitor"="D:\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"hmonitor"="C:\Program Files\Hmonitor\hmonitor.exe" [2006-11-14 18:15 860160]
"HP Software Update"="D:\HP Software Update\HPWuSchd2.exe" [2004-02-12 14:38 49152]
"DefragTaskBar"="C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2007-08-28 17:31 169312]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-13 16:48 1443072]
"8cf3f77c"="C:\WINDOWS\system32\twxxmvux.dll" [ ]
"BM8fc0c4e0"="C:\WINDOWS\system32\mrfegpyi.dll" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnMEUOG]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\yayvutqR

[HKLM\~\startupfolder\C:^Documents and Settings^hranol^Nabídka Start^Programy^Po spuštění^AdMuncher.lnk]
backup=C:\WINDOWS\pss\AdMuncher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8cf3f77c]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cleanup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 21:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-17 15:49 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iconcache]
--a------ 2006-02-18 07:19 621 c:\windows\vcp_temp\iconcache\icon.bat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
--a------ 2006-07-11 12:16 3147872 C:\Program Files\ICQLite\ICQLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero DriveSpeed]
--------- 2005-04-20 17:46 593920 D:\Ahead\NEROTO~1\DRIVES~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
--a------ 2007-05-17 13:58 26624 C:\WINDOWS\OETRN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QSmile]
--------- 2006-02-16 05:27 689017 C:\Program Files\AsefSoft\Quick Smile 3\QSmile.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sweeper.exe]
--a------ 2008-02-26 01:06 176128 C:\Program Files\History Sweeper\sweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"D:\\Office12\\OUTLOOK.EXE"=
"D:\\Office12\\GROOVE.EXE"=
"D:\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Chronograph\\chrono.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ad Muncher\\AdMunch.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 hmonitor;hmonitor;C:\WINDOWS\system32\drivers\hmonitor.sys [2006-10-05 14:31]
R3 AEXPAM;Philips SmartManage Service;C:\WINDOWS\system32\Drivers\aexpamdrv.sys [2004-09-01 14:10]
R3 DynCal;Dynamic Calibration Service;C:\WINDOWS\system32\drivers\Dyncal.sys [2001-05-21 14:01]
R3 PAC7311;Phenix-Q8;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 11:48]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 RockfireAnalogJoystickEnabler;Rockfire Analog Gamedevice driver;C:\WINDOWS\system32\drivers\RFTBtn.sys [2001-05-21 11:28]

.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 14:00:37 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-17 09:36:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="\"C:\\Program Files\\Chronograph\\chrono.exe\" /autorun"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\system32\PAStiSvc.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
D:\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2008-04-17 9:44:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-17 07:44:13

Adresářů: 16, Volných bajtů: 5,099,896,832
Adres ý…: 18, Volněch bajt…: 5,013,934,080
.
2008-04-14 09:07:14 --- E O F ---


=============================================

takze napoveda se mi objevila....sláva.....jinak dekuji moc......a tesim se na dalsi pokyny......

Hranol

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 17 dub 2008 12:46

Jo jeste me ESS vyhodil do karanteny pri projizdeni Combem soubor viz..

Obrázek

a

pri startu a restartu me skace hláška

Obrázek

a
pri zapnuti IE me to obcas vyhodi tuto hlasku viz

Obrázek

Jinak PC slape tedka o 1000 proc.lepe...jses borec......dik moc....a cekam na dalsi pokyny .....

Hranol

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod fredik » 17 dub 2008 20:00

Neřekl jsi nič ohledně toho TeaTimeru?

Ten soubor co našel NOD je v pořádku, více o něm se můžeš dočíst nař. zde

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok)
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

File::
C:\WINDOWS\system32\xuvmxxwt.ini
C:\WINDOWS\BM8fc0c4e0.xml
C:\WINDOWS\system32\iatqmtmc.ini
C:\WINDOWS\system32\ugplfqaj.ini

Folder::
C:\Program Files\SDFix

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02715E47-5A8E-495B-8F63-0D30470B8E72}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03FF3484-1297-4C3A-ACBE-212F5454A3A2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09FFD943-C05E-4B80-8893-46AD971FE34E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FB0E60C-BFC0-4DBD-8084-698CDB280AF7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{121E4E37-30F9-4DEA-9160-5166F5522BAE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15ACA267-FDFD-4A1E-81B0-E211F0BAFED4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A43C67A-0787-4436-B0FD-B25BF65498CA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C6E4C4F-36FD-4EDE-A6BE-D244F8BF66A1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{21EA63A7-04EB-41FF-9EF2-9382B8458885}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23E5396C-AC49-4D96-83E2-2A59E1E5AAA3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2766E49D-FAD1-4C13-B78A-9C038FD797DF}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2776798E-74DF-4499-A893-EEA0F32BCF1E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{288395DD-F28F-4E1E-9415-A40A0C81679F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AEE8F68-BFB8-4D05-87D4-361BB69F109A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ACF159E-367E-454B-8E15-A94980B69FA6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3BD1BD0B-9B33-4298-B6F7-40F97AFE039D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{443695FE-8E2B-49CC-BC65-499C39E7F3B3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CA86686-2441-4973-BCA4-B817F6B52927}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51A67331-7A47-4016-A705-205DCE341360}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{52A1B778-3C44-4EBA-AA2A-D8044ED18487}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53020DEF-D30A-4443-A76F-9EF08524BA18}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{594A022E-4C88-4AAF-BB18-EC272D257FB5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60B58FAF-1385-4918-B248-06C730A9C909}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60C06EB2-00DC-46FF-8DDF-D892FB65EBA9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6730A117-332F-477F-8977-9CB21743CFEB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6DEB2CD9-D07F-4A0E-9858-4E497F0EC508}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{763A8F24-01F1-4FE3-B7B7-B112FF07E25B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{78C16285-70C9-493C-AA86-CA7E5C43E223}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7936A975-CD71-47C5-9B7F-CF849DF460CB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{81A83AA6-1712-4DE2-B7CD-19FA613CBBC3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8562332D-A8F5-4395-A28E-BBC45855E56D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{885E8919-33F0-4AF5-93F3-0C428BF3FA46}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A5DBEBA-3277-428A-B6A5-2E81EE9C1B13}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F1E2C9B-0F73-4BD5-A641-FF3FC334C5A1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91D761C1-F3DF-4A2F-8C6A-B8A4073C9705}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97DCEDC8-04C8-4D37-AC6F-EEA7D17A1BC9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D30B3F7-8411-4C66-AF72-95CE9B73F6E9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACFDB92D-A0D9-4B22-AF23-D0C28B7A8A74}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BD0B5165-B525-4C86-BEBB-ABA416A6719C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CFDA6CCD-E94F-4D08-8E24-B7DFFDD53FBA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DB470C87-8A40-45CB-94A8-8936A775931E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E45E37BD-600F-4224-A827-AED1D3043BE0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E8D03F4A-2731-43A3-B1E3-3481A212D996}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F20FEEC0-B86E-4337-A363-640D9F567ED5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA7D85A4-3C51-44C3-88D7-34DB5271DAE7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBE1F40F-29BC-4A6E-A109-DBC7B10E5395}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBFFDD72-0C03-4CAD-9865-16FF32AC9AC9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"8cf3f77c"=-
"BM8fc0c4e0"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnMEUOG]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8cf3f77c]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cleanup]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť
Obrázek
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 17 dub 2008 22:03

ComboFix 08-04-16.5 - hranol 2008-04-17 21:08:50.3 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.530 [GMT 2:00]
Running from: C:\Documents and Settings\hranol\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\hranol\Plocha\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\BM8fc0c4e0.xml
C:\WINDOWS\system32\iatqmtmc.ini
C:\WINDOWS\system32\ugplfqaj.ini
C:\WINDOWS\system32\xuvmxxwt.ini
.
/wow section - STAGE 38
pv: No matching processes found
Nesprávná syntaxe příkazu


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\hranol\Data aplikací\ezpinst.log
C:\Program Files\SDFix
C:\Program Files\SDFix\apps\assosfix.reg
C:\Program Files\SDFix\apps\cliptext.exe
C:\Program Files\SDFix\apps\download.exe
C:\Program Files\SDFix\apps\dummy.sys
C:\Program Files\SDFix\apps\Enable_Command_Prompt.reg
C:\Program Files\SDFix\apps\ERDNT.E_E
C:\Program Files\SDFix\apps\ERDNTDOS.LOC
C:\Program Files\SDFix\apps\ERDNTWIN.LOC
C:\Program Files\SDFix\apps\ERUNT.EXE
C:\Program Files\SDFix\apps\ERUNT.LOC
C:\Program Files\SDFix\apps\fix.reg
C:\Program Files\SDFix\apps\FixBH.reg
C:\Program Files\SDFix\apps\FixComponents.reg
C:\Program Files\SDFix\apps\FIXCU.reg
C:\Program Files\SDFix\apps\FIXLM.reg
C:\Program Files\SDFix\apps\FixPath.exe
C:\Program Files\SDFix\apps\FixRedir.reg
C:\Program Files\SDFix\apps\FixSchedule.reg
C:\Program Files\SDFix\apps\FixWebCheck.reg
C:\Program Files\SDFix\apps\fixXP.reg
C:\Program Files\SDFix\apps\FixXPsp2.reg
C:\Program Files\SDFix\apps\grep.exe
C:\Program Files\SDFix\apps\HPFix.reg
C:\Program Files\SDFix\apps\HPFix2.reg
C:\Program Files\SDFix\apps\HPFix3.reg
C:\Program Files\SDFix\apps\HPFix4.reg
C:\Program Files\SDFix\apps\HPFix5.reg
C:\Program Files\SDFix\apps\HPFix6.reg
C:\Program Files\SDFix\apps\HPFix7.reg
C:\Program Files\SDFix\apps\isadmin.exe
C:\Program Files\SDFix\apps\leg2.txt
C:\Program Files\SDFix\apps\legacy.txt
C:\Program Files\SDFix\apps\legacybk.txt
C:\Program Files\SDFix\apps\locate.com
C:\Program Files\SDFix\apps\LS.exe
C:\Program Files\SDFix\apps\MD5File.exe
C:\Program Files\SDFix\apps\MyGcpvFix.reg
C:\Program Files\SDFix\apps\MyGkFix2.reg
C:\Program Files\SDFix\apps\Process.exe
C:\Program Files\SDFix\apps\procs.exe
C:\Program Files\SDFix\apps\psservice.exe
C:\Program Files\SDFix\apps\Rem.txt
C:\Program Files\SDFix\apps\Rem2.txt
C:\Program Files\SDFix\apps\Replace\regedit.exe
C:\Program Files\SDFix\apps\Replace\W2K.exe
C:\Program Files\SDFix\apps\Replace\w2k\beep.sys
C:\Program Files\SDFix\apps\Replace\w2k\null.sys
C:\Program Files\SDFix\apps\Replace\XP.exe
C:\Program Files\SDFix\apps\Replace\xp\beep.sys
C:\Program Files\SDFix\apps\Replace\xp\null.sys
C:\Program Files\SDFix\apps\Reset_AppInit_DLLs.reg
C:\Program Files\SDFix\apps\RestartIt!.exe
C:\Program Files\SDFix\apps\Restore_SecurityCenter.reg
C:\Program Files\SDFix\apps\Restore_SharedAccess.reg
C:\Program Files\SDFix\apps\sc.exe
C:\Program Files\SDFix\apps\sed.exe
C:\Program Files\SDFix\apps\SF.exe
C:\Program Files\SDFix\apps\shutdown.exe
C:\Program Files\SDFix\apps\srv2.txt
C:\Program Files\SDFix\apps\srv2bk.txt
C:\Program Files\SDFix\apps\svc.txt
C:\Program Files\SDFix\apps\svcbk.txt
C:\Program Files\SDFix\apps\swreg.exe
C:\Program Files\SDFix\apps\swsc.exe
C:\Program Files\SDFix\apps\unzip.exe
C:\Program Files\SDFix\apps\vfind.exe
C:\Program Files\SDFix\apps\WINMSG.EXE
C:\Program Files\SDFix\apps\winsec.reg
C:\Program Files\SDFix\apps\zip.exe
C:\Program Files\SDFix\backups\backupreg.zip
C:\Program Files\SDFix\backups\backups.zip
C:\Program Files\SDFix\backups\HOSTS
C:\Program Files\SDFix\backups_old\backupreg.zip
C:\Program Files\SDFix\backups_old\backups.zip
C:\Program Files\SDFix\backups_old\HOSTS
C:\Program Files\SDFix\backups_old1\backupreg.zip
C:\Program Files\SDFix\backups_old1\backups.zip
C:\Program Files\SDFix\backups_old1\HOSTS
C:\Program Files\SDFix\catchme.exe
C:\Program Files\SDFix\dummy.sys
C:\Program Files\SDFix\Report.txt
C:\Program Files\SDFix\Report_old_1.txt
C:\Program Files\SDFix\RunThis.bat
C:\Program Files\SDFix\SDFIX_ReadMe_Online.url
C:\WINDOWS\BM8fc0c4e0.xml
C:\WINDOWS\system32\aaccae5_r.dll
C:\WINDOWS\system32\ecfdef_r.dll
C:\WINDOWS\system32\ecfdef_z.dll
C:\WINDOWS\system32\iatqmtmc.ini
C:\WINDOWS\system32\ugplfqaj.ini
C:\WINDOWS\system32\xuvmxxwt.ini

.
((((((((((((((((((((((((( Files Created from 2008-03-17 to 2008-04-17 )))))))))))))))))))))))))))))))
.

2008-04-16 17:08 . 2008-04-16 17:55 <DIR> d-------- C:\Program Files\Avira
2008-04-16 00:57 . 2008-04-16 00:58 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-16 00:28 . 2008-04-16 00:28 <DIR> d-------- C:\Program Files\ESET
2008-04-15 23:16 . 2008-04-15 23:16 <DIR> d-------- C:\Documents and Settings\hranol\Data aplikací\URSoft
2008-04-15 18:55 . 2008-04-15 18:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 06:24 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-14 06:24 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-14 06:24 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-14 06:24 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-14 06:24 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-14 06:24 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-14 06:24 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-14 06:24 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-14 06:24 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-14 02:30 . 2008-04-14 02:30 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 20:19 . 2008-04-13 22:33 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-13 13:09 . 2004-08-17 15:49 2,026,496 --a------ C:\WINDOWS\system32\netshell.backup
2008-04-13 13:09 . 2003-04-16 14:00 1,232,384 --a------ C:\WINDOWS\system32\write.backup
2008-04-13 13:09 . 2007-06-13 15:23 1,033,728 --a------ C:\WINDOWS\explorer.backup
2008-04-13 13:09 . 2004-08-17 15:49 260,096 --a------ C:\WINDOWS\system32\sndrec32.backup
2008-04-13 13:09 . 2005-07-06 14:58 219,648 --a------ C:\WINDOWS\system32\uxtheme.backup
2008-04-13 13:09 . 2003-04-16 14:00 152,064 --a------ C:\WINDOWS\system32\sndvol32.backup
2008-04-13 13:09 . 2004-08-17 15:49 77,824 --a------ C:\WINDOWS\system32\stobject.backup
2008-04-13 13:08 . 2007-10-25 18:44 8,464,384 --a------ C:\WINDOWS\system32\shell32.backup
2008-04-13 13:08 . 2004-08-17 15:49 924,672 --a------ C:\WINDOWS\system32\spider.backup
2008-04-13 13:08 . 2003-04-16 14:00 512,512 --a------ C:\WINDOWS\system32\mshearts.backup
2008-04-13 13:08 . 2003-04-16 14:00 504,832 --a------ C:\WINDOWS\system32\winmine.backup
2008-04-13 13:08 . 2003-04-16 14:00 441,856 --a------ C:\WINDOWS\system32\sol.backup
2008-04-13 13:08 . 2003-04-16 14:00 440,320 --a------ C:\WINDOWS\system32\freecell.backup
2008-04-13 13:08 . 2004-08-17 15:49 69,632 --a------ C:\WINDOWS\notepad.backup
2008-04-13 13:07 . 2001-11-08 06:56 6,094,336 --a------ C:\WINDOWS\system32\logonui.backup
2008-04-13 13:07 . 2004-08-17 15:48 2,927,616 --a------ C:\WINDOWS\system32\xpsp2res.backup
2008-04-13 13:07 . 2004-08-17 15:49 1,671,680 --a------ C:\WINDOWS\system32\msgina.backup
2008-04-13 13:07 . 2004-08-17 15:49 847,360 --a------ C:\WINDOWS\system32\mydocs.backup
2008-04-13 13:07 . 2004-08-17 15:49 727,040 --a------ C:\WINDOWS\system32\mspaint.backup
2008-04-13 13:07 . 2003-04-16 14:00 465,920 --a------ C:\WINDOWS\system32\charmap.backup
2008-04-13 13:07 . 2003-04-16 14:00 117,760 --a------ C:\WINDOWS\system32\calc.backup
2008-04-13 13:07 . 2004-08-17 15:49 76,288 --a------ C:\WINDOWS\system32\magnify.backup
2008-04-13 13:06 . 2004-08-17 15:49 2,376,704 --a------ C:\WINDOWS\system32\shimgvw.backup
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\WINDOWS\VCP_SAVE
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Wallpapers
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Fonts
2008-04-13 13:03 . 2005-09-28 02:31 49,152 --a------ C:\WINDOWS\system32\icon.exe
2008-04-13 13:02 . 2008-04-13 13:09 <DIR> d-------- C:\WINDOWS\VCP_TEMP
2008-04-13 12:38 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-04-13 01:22 . 2008-04-13 01:25 2,554 --a------ C:\WINDOWS\unins000.dat
2008-04-12 23:25 . 2008-04-14 00:41 <DIR> d-------- C:\Documents and Settings\hranol\Data aplikací\SUPERAntiSpyware.com
2008-04-12 18:41 . 2008-04-13 16:00 <DIR> d-------- C:\Documents and Settings\hranol\Data aplikací\TmpRecentIcons
2008-04-11 13:17 . 2008-04-11 13:17 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-04-11 13:17 . 2008-04-11 13:17 <DIR> d----c--- C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2008-04-11 13:13 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-11 13:09 . 2008-04-11 13:29 104,643 --a------ C:\WINDOWS\hpoins04.dat
2008-04-11 13:09 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat
2008-04-11 12:45 . 2008-01-14 18:44 104,250 --------- C:\WINDOWS\hpoins04.dat.temp
2008-04-11 12:45 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat.temp
2008-04-09 08:08 . 2008-03-01 15:02 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-09 08:08 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-09 08:08 . 2007-03-08 07:09 1,024,000 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-09 08:08 . 2008-03-01 15:02 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-09 08:08 . 2008-03-01 15:02 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-09 08:08 . 2008-03-01 15:02 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-09 08:08 . 2008-03-01 15:02 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-09 08:08 . 2008-03-01 15:02 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-09 08:08 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-06 10:22 . 2008-04-06 10:22 <DIR> d-------- C:\Program Files\inKline Global
2008-03-22 06:29 . 2008-03-22 06:29 <DIR> d-------- C:\Program Files\directx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 15:12 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\DMCache
2008-04-16 15:00 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2008-04-16 14:45 --------- d-----w C:\Program Files\PowerArchiver
2008-04-16 03:16 --------- d-----w C:\Program Files\Java
2008-04-15 21:18 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2008-04-14 01:41 --------- d-----w C:\Program Files\FlashGet
2008-04-14 00:32 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-04-14 00:11 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\Vso
2008-04-13 19:18 --------- d-----w C:\Program Files\H264
2008-04-13 07:53 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-13 07:11 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-04-12 23:25 72,537 ----a-w C:\WINDOWS\unins000.exe
2008-04-09 06:47 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2008-04-06 11:50 --------- d-----w C:\Program Files\Opera
2008-04-03 06:13 --------- d-----w C:\Program Files\CD Eject Tool
2008-03-28 19:14 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Skype
2008-03-28 19:13 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\Skype
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-17 19:06 --------- d-----w C:\Program Files\History Sweeper
2008-03-16 07:43 --------- d-----w C:\Program Files\totalcmd
2008-03-16 07:07 --------- dc----w C:\Documents and Settings\All Users\Data aplikací\Ashampoo
2008-03-16 07:07 --------- d-----w C:\Program Files\Ashampoo
2008-03-15 15:33 --------- d-----w C:\Program Files\Webteh
2008-03-15 15:33 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\BSplayer PRO
2008-03-14 22:24 93,128 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll
2008-03-13 14:52 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-03-13 14:52 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-03-13 14:52 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-03-13 14:44 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-03-13 14:43 40,456 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-03-12 12:05 --------- d-----w C:\Program Files\%temp&
2008-03-11 21:05 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\GARMIN
2008-03-02 18:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 19:48 --------- d-----w C:\Program Files\FastStone Capture
2008-02-24 07:26 --------- d-----w C:\Program Files\DivX
2008-02-24 07:03 --------- d-----w C:\Program Files\Internet Download Manager
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-15 15:12 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-02-04 17:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2007-04-15 16:53 87,608 -c--a-w C:\Documents and Settings\hranol\Data aplikací\ezpinst.exe
2007-04-15 16:53 47,360 -c--a-w C:\Documents and Settings\hranol\Data aplikací\pcouffin.sys
2007-05-17 21:16 23 -csha-w C:\WINDOWS\system32\faecaf9_r.dll
.

------- Sigcheck -------

2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\explorer.exe
2007-06-13 15:11 1033728 9b32416bd5988c97b6397ce0b02caf97 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2003-04-16 14:00 1004544 11d80755545cfb5eb9659ee88440eae2 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-17 15:49 4918784 c6c0c8de8425eed7c666f10f5d9104f0 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2007-06-13 15:23 1033728 ed7b460b142a32097b8a8f6ecc941815 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\VCP_TEMP\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-17_ 9.43.31.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-17 07:35:33 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-17 15:11:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-12-15 15:53:19 166,455 ----a-w C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat
+ 2008-04-17 07:50:51 166,455 ----a-w C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat
- 2007-12-15 15:53:21 5,194 ----a-w C:\WINDOWS\PCHealth\HelpCtr\PackageStore\SkuStore.bin
+ 2008-04-17 07:50:51 5,194 ----a-w C:\WINDOWS\PCHealth\HelpCtr\PackageStore\SkuStore.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="C:\Program Files\Chronograph\chrono.exe" [2007-04-26 00:04 3762768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-07-02 23:28 171448]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-02-21 08:44 2594224]
"PowerArchiver Tray"="C:\Program Files\PowerArchiver\PASTARTER.EXE" [2008-01-24 19:36 141352]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"RestoreDesktop"="C:\Program Files\Restore Desktop\RestoreDesktop.exe" [2003-03-11 10:52 45056]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2006-07-11 12:16 3147872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SeznamAntidialer"="C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe" [2005-01-24 11:11 286720]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"GrooveMonitor"="D:\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"hmonitor"="C:\Program Files\Hmonitor\hmonitor.exe" [2006-11-14 18:15 860160]
"HP Software Update"="D:\HP Software Update\HPWuSchd2.exe" [2004-02-12 14:38 49152]
"DefragTaskBar"="C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2007-08-28 17:31 169312]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-13 16:48 1443072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]

C:\Documents and Settings\hranol\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - D:\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\hranol\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - D:\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\hranol\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - D:\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - D:\Reader\reader_sl.exe [2006-10-23 02:48:00 40048]
Adobe Reader Synchronizer.lnk - D:\Reader\AdobeCollabSync.exe [2007-05-11 11:29:22 738968]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-04-14 16:56:01 962663]
HP Digital Imaging Monitor.lnk - D:\Digital Imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]
Rychl‚ spuçtŘnˇ aplikace HP Image Zone.lnk - D:\Digital Imaging\bin\hpqthb08.exe [2004-05-29 00:06:36 53248]

[HKLM\~\startupfolder\C:^Documents and Settings^hranol^Nabídka Start^Programy^Po spuštění^AdMuncher.lnk]
backup=C:\WINDOWS\pss\AdMuncher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 21:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-17 15:49 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iconcache]
--a------ 2006-02-18 07:19 621 c:\windows\vcp_temp\iconcache\icon.bat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
--a------ 2006-07-11 12:16 3147872 C:\Program Files\ICQLite\ICQLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero DriveSpeed]
--------- 2005-04-20 17:46 593920 D:\Ahead\NEROTO~1\DRIVES~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
--a------ 2007-05-17 13:58 26624 C:\WINDOWS\OETRN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QSmile]
--------- 2006-02-16 05:27 689017 C:\Program Files\AsefSoft\Quick Smile 3\QSmile.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sweeper.exe]
--a------ 2008-02-26 01:06 176128 C:\Program Files\History Sweeper\sweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"D:\\Office12\\OUTLOOK.EXE"=
"D:\\Office12\\GROOVE.EXE"=
"D:\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Chronograph\\chrono.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ad Muncher\\AdMunch.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 hmonitor;hmonitor;C:\WINDOWS\system32\drivers\hmonitor.sys [2006-10-05 14:31]
R3 AEXPAM;Philips SmartManage Service;C:\WINDOWS\system32\Drivers\aexpamdrv.sys [2004-09-01 14:10]
R3 DynCal;Dynamic Calibration Service;C:\WINDOWS\system32\drivers\Dyncal.sys [2001-05-21 14:01]
R3 PAC7311;Phenix-Q8;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 11:48]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 RockfireAnalogJoystickEnabler;Rockfire Analog Gamedevice driver;C:\WINDOWS\system32\drivers\RFTBtn.sys [2001-05-21 11:28]

.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 14:00:37 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-17 21:12:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="\"C:\\Program Files\\Chronograph\\chrono.exe\" /autorun"
.
Completion time: 2008-04-17 21:16:51
ComboFix-quarantined-files.txt 2008-04-17 19:15:46
ComboFix2.txt 2008-04-17 08:41:47
ComboFix3.txt 2008-04-17 07:44:52

Adresářů: 16, Volných bajtů: 5,450,489,856
Adresářů: 18, Volných bajtů: 5,438,689,280
.
2008-04-14 09:07:14 --- E O F ---
================================================================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:42, on 17.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\tbu21C4\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: opnMEUOG - C:\WINDOWS\
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: aswUpdSv - ALWIL Software - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 11397 bytes
================================================================================================

Kód: Vybrat vše

http://trendsecure.custhelp.com/cgi-bin/trendsecure.cfg/php/enduser/std_alp.php


Tohle se me ukazalo pri Hijacku.....viz nahore http.......kdyz jsem spustil Hijack,chvilicku jel...potom naskocila chyba.....kdyz jsem dal...odklikl,tak naskocila ta stranka a Hijack normalne dokoncil kontrolu....zapomnel jsem
vypnout net....
Spybot....mel jsem zatrhlou rez.......jak jsi psal...tak jsem ji vypl.....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:42, on 17.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\tbu21C4\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: opnMEUOG - C:\WINDOWS\
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: aswUpdSv - ALWIL Software - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 11397 bytes
Naposledy upravil(a) hranol dne 18 dub 2008 07:01, celkem upraveno 3 x.

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 17 dub 2008 22:07

Jinak znova, dik Ti moc za ochotu a cekam na dalsi pokyny.....

Zdravi Hranol.......

Uživatelský avatar
fredik
člen Security týmu
Master Level 7
Master Level 7
Příspěvky: 4680
Registrován: červenec 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod fredik » 18 dub 2008 22:13

Rezidentní ochranu máš momentálně u SpyBota zapnutou, musíš si ji nastavit tak jak bylo popsáno a je znázorněno na obrázku.

Máš tam také pozůstatky po Avastu, tak použij na odstranění jeho pozůstatků tento nástroj:
Odinstalační nástroj pro avast!

Otestuj tento soubor na VirusTotal
C:\WINDOWS\system32\faecaf9_r.dll
rovnou zkopíruj celou cestu k souboru v okně na VirusTotal a vlož sem pak výsledek.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět

Uživatelský avatar
hranol
nováček
Příspěvky: 16
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu. Dík.

Příspěvekod hranol » 18 dub 2008 22:45

Antivirus Verze Poslední aktualizace Výsledek
AhnLab-V3 2008.4.19.0 2008.04.18 -
AntiVir 7.8.0.8 2008.04.18 -
Authentium 4.93.8 2008.04.18 -
Avast 4.8.1169.0 2008.04.17 -
AVG 7.5.0.516 2008.04.18 -
BitDefender 7.2 2008.04.18 -
CAT-QuickHeal 9.50 2008.04.18 -
ClamAV 0.92.1 2008.04.18 -
DrWeb 4.44.0.09170 2008.04.18 -
eSafe 7.0.15.0 2008.04.17 -
eTrust-Vet 31.3.5709 2008.04.18 -
Ewido 4.0 2008.04.18 -
F-Prot 4.4.2.54 2008.04.18 -
F-Secure 6.70.13260.0 2008.04.18 -
FileAdvisor 1 2008.04.18 -
Fortinet 3.14.0.0 2008.04.18 -
Ikarus T3.1.1.26 2008.04.18 -
Kaspersky 7.0.0.125 2008.04.18 -
McAfee 5277 2008.04.18 -
Microsoft 1.3408 2008.04.18 -
NOD32v2 3039 2008.04.18 -
Norman 5.80.02 2008.04.18 -
Panda 9.0.0.4 2008.04.18 -
Prevx1 V2 2008.04.18 -
Rising 20.40.42.00 2008.04.18 -
Sophos 4.28.0 2008.04.18 -
Sunbelt 3.0.1056.0 2008.04.17 -
Symantec 10 2008.04.18 -
TheHacker 6.2.92.282 2008.04.18 -
VBA32 3.12.6.4 2008.04.16 -
VirusBuster 4.3.26:9 2008.04.18 -
Webwasher-Gateway 6.6.2 2008.04.18 -
Rozšiřující informace
File size: 23 bytes
MD5...: d78a1fa307e61d6e0cecd79c612271b2
SHA1..: 768226a75747e8252445b9d0fb44b76afc9d6cf7
SHA256: 574249cb7682b4f1f020dbb4261e39a7bd280206d9cad3833248ded4abe24972
SHA512: f525e6a9ba7a207a6d1dd54fd8fdfa6b574932284152143e4944e2732392f76e
3115bdae38696bc8fa7e5b1e080947aef3ae5f1d69eed9ff5bfb99577750594d
PEiD..: -
PEInfo: -
=================================================================================================


Ten Spybot jsem opravil...sorry...ja si toho spatne vsiml.

tady Ti poslu jeste jednou pro jistotu Hijack...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:41:47, on 18.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\tbu21C4\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout pomocí FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout vše pomocí FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: opnMEUOG - C:\WINDOWS\
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: aswUpdSv - ALWIL Software - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 11139 bytes
================================================================================================

Opet diky moc za ochotu ......................a cekam na dalsi pokyny

Zdravi Hranol


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 89 hostů